Przejdź do treści

Polityka prywatności

Wersja 2026-09, obowiązuje od 1 października 2026

PROJEKTProjekt — jeszcze nie sprawdzony przez prawnika. Ten tekst opisuje, jak platforma ma działać, i nie jest jeszcze wiążącym dokumentem prawnym.

Operator

Banbosh Studio, Petr Knobloch, nr identyfikacyjny 06535666, Praha, CZ. Kontakt: hello@fordeal.ai.

Version 2026-09, effective from 1 października 2026. This policy explains how Banbosh Studio, Petr Knobloch, company ID 06535666, Praha, CZ (the "Operator", "we") processes personal data in connection with the platform at https://fordeal.ai and its interfaces (the "Platform"). It is the information required by Articles 13 and 14 of Regulation (EU) 2016/679 (the "GDPR").

1. Controller and contact

1.1 The controller of personal data processed through the Platform is Banbosh Studio, Petr Knobloch, company ID 06535666, Praha, CZ.

1.2 For anything concerning personal data write to hello@fordeal.ai or use the address above. We reply within one month; where a request is complex we may extend the period by a further two months and will tell you why.

1.3 We have not appointed a data protection officer because the conditions of Article 37 GDPR are not met. If that changes, we will publish the contact details here.

1.4 Providers act as independent controllers for the personal data they receive about a Customer in order to perform a Job. Their obligations are set out in the Terms of Service. Principals of AI agents act as controllers for the data their agents send to us.

2. Whose data we process and where it comes from

2.1 Customers (people and businesses ordering services, consultations or goods): data you enter on the website or through the API, data your AI agent sends on your behalf, and data generated by your use of the Platform.

2.2 Providers (businesses offering services): data you give us during registration on the website or in a WhatsApp conversation with our assistant, data from public registers we use to verify you, data generated by Jobs, and — for providers we approached ourselves — data from the sources listed in Section 12.

2.3 Principals and their AI agents: registration data of the person or company that registered the agent, the agent's API-key metadata, and every request the agent sends, which may contain personal data of the Principal or of third parties (for example a delivery address). The Principal is responsible for having a legal basis to give us that data.

2.4 Contact persons and visitors: people who write to us, visit the website or interact with our public interfaces.

2.5 Third parties mentioned in a Job: for example a relative for whom a service is ordered, or a person at the delivery address. We process these data only to perform the Job.

3. Categories of personal data

  • Identification and contact data: name, e-mail address, phone number (including the WhatsApp number), preferred language, country, and for Providers the business name, registration number, VAT number, registered address and licence or registry numbers.
  • Job data: description of the request, category, photos you upload, address and location, time windows, prices, offers, confirmations, evidence of completion (photos, GPS position and timestamp for micro-tasks), reviews and complaints.
  • Communication data: messages exchanged through the Platform, WhatsApp, SMS or e-mail with us or with the other party to a Job, including messages our AI assistant drafts or interprets.
  • Payment data: the payment status, amounts, currency, the last four digits and brand of a card, the identifier of the payment at the Payment Provider, payout records and the tax documents for the Commission. We never see or store full card numbers; they are entered directly with the Payment Provider.
  • Verification data: results of checks against public business registers and professional registries, and where required a copy of an identity or licence document.
  • Agent data: API-key identifier, spending limits, audit log of every action the agent took (time, parameters, result), rate-limit counters.
  • Technical data: IP address, device and browser type, time of access, error logs, security logs and the pages or endpoints you used.
  • Recruiting data (Section 12): name, e-mail, phone, city, trade, website, the source we obtained the contact from, and delivery, open and click events of our e-mails.
  • Health data: only where you explicitly upload a medical document for an explanation service or order a medical consultation. See Section 6.

4. Purposes, legal bases and retention

PurposeDataLegal basisRetention
Operating your account, matching requests with providers, forming and performing Jobs, escrow, payouts, notifications about a JobIdentification, Job, communication, payment, agent dataPerformance of a contract, Art. 6(1)(b) GDPRDuration of the account and 3 years after its closure (limitation period)
Accounting, tax and payment-service recordsPayment data, tax documents, Job price and partiesLegal obligation, Art. 6(1)(c) GDPR (accounting and VAT law of Czechia and Slovakia, anti-money-laundering law of the Payment Provider)10 years from the end of the tax year in which the document was issued
Verifying providers against public registers and professional registries, first-jobs supervisionVerification data, identification dataLegitimate interest, Art. 6(1)(f) GDPR (safety of customers, trust in the Platform); legal obligation where a registry check is required by lawDuration of the account and 3 years after
Handling complaints and disputes, deciding on escrow, defending legal claimsJob, communication, payment data, evidencePerformance of a contract, Art. 6(1)(b); legitimate interest, Art. 6(1)(f) GDPR (establishing, exercising or defending legal claims)3 years after the dispute was closed, or until the final end of court proceedings
Preventing fraud, abuse, payment outside the Platform, and protecting the security of the Platform and its UsersTechnical data, agent data, Job and communication dataLegitimate interest, Art. 6(1)(f) GDPRSecurity logs 6 months; records of confirmed abuse 3 years
Drafting messages to providers, classifying requests, estimating prices, parsing provider replies and summarising evidence in disputes with the help of AI models (Section 7)Job and communication dataPerformance of a contract, Art. 6(1)(b); legitimate interest, Art. 6(1)(f) GDPR (efficient operation of the Platform)Same as the underlying Job data; the AI provider deletes inputs under Section 8
Publishing reviews and provider statisticsReviews, Job outcomesPerformance of a contract, Art. 6(1)(b) GDPR, and legitimate interest, Art. 6(1)(f) (informing customers)Duration of the Provider's account
Approaching businesses we consider suitable providers by e-mail or phone (Section 12)Recruiting dataLegitimate interest, Art. 6(1)(f) GDPR (direct marketing towards businesses, recital 47)Until you object or unsubscribe, and no longer than 3 years after the last contact; an unsubscribed address is kept on a suppression list so we do not write again
Sending newsletters or product news to customers who asked for themE-mail, languageConsent, Art. 6(1)(a) GDPRUntil consent is withdrawn
Answering enquiriesContact data, content of the enquiryLegitimate interest, Art. 6(1)(f) GDPR1 year after the enquiry was closed
Providing a medical-document explanation or a medical consultationHealth dataExplicit consent, Art. 9(2)(a) GDPRUploaded documents are deleted immediately after the explanation is delivered unless you ask us to keep them; consultation records as the consultant's professional rules require

4.1 Where processing is based on legitimate interest you have the right to object at any time (Section 10). We have carried out a balancing test for each of these interests and will provide a summary on request.

4.2 Where processing is based on consent you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

4.3 Providing identification, contact, Job and payment data is necessary to conclude a contract with us and with a Provider; without them we cannot provide the Platform. All other data are optional.

5. Automated processing and AI

5.1 We use large language models (currently Claude models provided by Anthropic) to classify requests into categories, to estimate price ranges, to draft messages sent to Providers, to interpret Providers' WhatsApp replies into structured offers, to guide Provider registration conversations, and to summarise evidence and propose an outcome in disputes.

5.2 These outputs are suggestions. No decision that produces legal effects concerning you or similarly significantly affects you — such as the outcome of a dispute, the release or refund of escrow, the suspension of an account or the rejection of a Provider — is taken solely by automated means. A person at the Operator reviews the proposal and takes the decision. You may express your point of view and contest any decision through the Complaints Policy.

5.3 Matching a request with Providers and ordering offers is automated, based on the parameters described in the Terms of Service. It only determines which Providers see a request first; it does not deny anyone access to the Platform.

6. Health data and other special categories

6.1 We do not ask for health data. If you upload a medical report for an explanation service, or describe a health condition when booking a medical consultation, we process those data only with your explicit consent given at the moment of upload, only for that purpose, and we delete the uploaded document as soon as the explanation has been delivered, unless you ask us to keep it in your account.

6.2 The consultant who provides a medical consultation is a separate controller bound by professional secrecy and medical-records rules.

6.3 Please do not include special-category data (health, religion, ethnic origin, sexual orientation, political opinions, trade-union membership, biometric or genetic data) in a request for a non-medical service. If you do, we process them only to the extent needed for the Job and delete them with the Job data.

7. Recipients and processors

7.1 Providers and Customers: the other party to a Job receives the data needed to perform it. A Provider sees the request, the photos, the time window and the approximate location; once the Customer accepts the Provider's offer, the Provider also sees the exact address, the Customer's name and phone number. The Customer sees the Provider's business name, verified status, statistics, reviews and, after acceptance, the Provider's phone number.

7.2 Principals: the Principal of an AI agent sees the full audit log of what the agent did, including the data of the Jobs it ordered.

7.3 Processors who process data on our behalf under a data-processing agreement in accordance with Article 28 GDPR:

ProcessorPurposeLocation of processing
Supabase, Inc.Database, authentication and file storage of the PlatformEuropean Union (Frankfurt region); support access may occur from the United States under the EU–US Data Privacy Framework
Vercel Inc.Hosting of the website and API, edge network and logsEuropean Union edge regions; logs and build infrastructure in the United States under the EU–US Data Privacy Framework and standard contractual clauses
Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc.Payment processing, escrow, payouts to Providers, identity verification of Providers required by payment lawEuropean Union; Stripe, Inc. in the United States under the EU–US Data Privacy Framework and standard contractual clauses. Stripe is an independent controller for the data it must process under payment and anti-money-laundering law
Meta Platforms Ireland Limited (WhatsApp Business Platform)Delivering and receiving WhatsApp messages between the Platform and Providers or CustomersEuropean Union; Meta Platforms, Inc. in the United States under the EU–US Data Privacy Framework and standard contractual clauses
Twilio Ireland LimitedSending and receiving SMS and, where used, WhatsApp messagesEuropean Union; Twilio Inc. in the United States under the EU–US Data Privacy Framework and standard contractual clauses
Resend (Plus Five Five, Inc.)Sending transactional and recruiting e-mails, delivery and open statisticsUnited States under standard contractual clauses
Anthropic, PBCAI processing described in Section 5 through the Claude APIUnited States under the EU–US Data Privacy Framework and standard contractual clauses. Anthropic does not use API inputs or outputs to train its models and deletes them from its systems within 30 days unless a longer period is required by law or a shorter, zero-retention arrangement applies

7.4 We may also disclose data to professional advisers (lawyers, accountants, auditors) bound by confidentiality, to courts, authorities and alternative dispute resolution bodies where the law requires it, and to a successor operator of the Platform in the event of a transfer of the business, of which you would be informed.

7.5 We do not sell personal data and do not share them with advertising networks.

8. Transfers outside the European Economic Area

8.1 Our primary storage is in the European Union. Some processors listed in Section 7 are established in, or have affiliates in, the United States. Transfers to them rely on the European Commission's adequacy decision for the EU–US Data Privacy Framework where the recipient is certified under it, and otherwise on the standard contractual clauses adopted by the European Commission (Decision (EU) 2021/914), supplemented where needed by additional safeguards such as encryption in transit and at rest and minimisation of the data sent.

8.2 You can obtain a copy of the relevant clauses and a list of the current certifications by writing to hello@fordeal.ai.

9. Retention

9.1 Retention periods are stated in the table in Section 4. In summary: Job, account and payment records for the life of the account and 3 years after; accounting and tax records for 10 years as required by the accounting and VAT laws of Czechia and Slovakia; dispute files for 3 years after closure; security logs for 6 months; recruiting contacts until objection and at most 3 years after the last contact; medical documents only until the explanation is delivered.

9.2 When a retention period ends we delete or anonymise the data. Anonymised statistics (for example the average price of a category in a city) are not personal data and may be kept.

9.3 Deleting your account removes your profile and personal data from the live Platform immediately; data we must keep under a legal obligation or for the defence of legal claims are moved to restricted storage for the remainder of their retention period.

10. Your rights

You have the following rights under the GDPR, exercisable by writing to hello@fordeal.ai or through your account:

  • Access (Art. 15): to obtain confirmation whether we process your data and a copy of them, together with the information in this policy.
  • Rectification (Art. 16): to have inaccurate data corrected and incomplete data completed. You can edit most data in your account or, for Providers, by message to our WhatsApp assistant.
  • Erasure (Art. 17): to have your data deleted where they are no longer needed, where you withdraw consent, where you object and we have no overriding grounds, or where processing was unlawful. Data subject to a legal retention duty are retained but restricted.
  • Restriction (Art. 18): to have processing limited while a dispute about accuracy or lawfulness is resolved.
  • Portability (Art. 20): to receive the data you provided to us in a structured, commonly used, machine-readable format (JSON) and to have them transmitted to another controller where technically feasible. Your account offers an export.
  • Objection (Art. 21): to object at any time to processing based on legitimate interest, including direct marketing. After an objection to direct marketing we stop immediately. After another objection we stop unless we demonstrate compelling legitimate grounds that override your interests.
  • Withdrawal of consent (Art. 7(3)): at any time, with effect for the future.
  • Not to be subject to a solely automated decision (Art. 22): see Section 5; you can always ask for human review.
  • Complaint to a supervisory authority (Art. 77): in Czechia the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, www.uoou.gov.cz; in Slovakia the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky), Hraničná 12, 820 07 Bratislava 27, www.dataprotection.gov.sk; or the authority of the Member State where you live or work.

10.1 We may ask you to verify your identity before acting on a request, for example by replying from the e-mail address or phone number on your account. Requests are free of charge unless manifestly unfounded or excessive.

10.2 AI agents may exercise access and portability on behalf of their Principal through the API; any other right is exercised by the Principal.

11. Cookies and similar technologies

11.1 The website uses only cookies and local storage that are strictly necessary for it to work: the language you chose, your session and authentication token, a security token protecting forms, and the Payment Provider's fraud-prevention cookie set on the payment page. These do not require consent under Section 89(3) of Act No. 127/2005 Coll., on Electronic Communications (Czechia) and Section 109(8) of Act No. 452/2021 Coll., on Electronic Communications (Slovakia).

11.2 We do not use advertising, analytics or cross-site tracking cookies. If we introduce any cookie that is not strictly necessary we will ask for your consent first and update this section.

11.3 Server-side, we count page views and API calls in aggregate without cookies and without building profiles of individual visitors.

12. Information for businesses we approach as potential providers (Art. 14 GDPR)

12.1 We build the supply side of the Platform by contacting tradespeople, salons, professionals and companies that publicly offer the services our customers ask for. If you have received an e-mail, a WhatsApp message or a call from us without having registered, this section applies to you.

12.2 Source of your data: your own website or public business listing, public business registers (ARES in Czechia, the Register of Legal Entities and the Trade Register in Slovakia), professional registries, business directories and maps, or a recommendation from an existing user or partner. We record the exact source with each contact and will tell you which one it was on request.

12.3 Data we hold: name or business name, e-mail address, phone number, city, trade or profession, website, the source, the dates and content of our messages, and whether they were delivered, opened or clicked. We also create a non-public draft profile of your business on the Platform, based on the same public information, so that you have less to fill in if you decide to join. The draft profile is not shown to anyone and is not indexed by search engines until you activate it.

12.4 Purpose and legal basis: offering you a business opportunity — receiving paid jobs through the Platform. The legal basis is our legitimate interest in acquiring business users (Art. 6(1)(f) GDPR; recital 47 recognises direct marketing as a legitimate interest). We contact only businesses, only about the trade they publicly offer, and only in a limited sequence of at most three messages.

12.5 Your rights: you can object at any time, without giving a reason, by clicking the unsubscribe link in any e-mail, by replying "STOP", or by writing to hello@fordeal.ai. We stop immediately, delete the draft profile and keep only your address on a suppression list so that we do not contact you again. All other rights in Section 10 apply.

12.6 Retention: until you object, and in any case no longer than 3 years after our last contact if you have not responded.

12.7 Recipients: the e-mail service provider and the messaging providers listed in Section 7; nobody else.

13. Security

13.1 Data are stored in the European Union with encryption at rest and in transit. Access is limited to the Operator and to processors bound by contract, and is logged. Payment card data never touch our systems. API keys are stored hashed. We review access rights and logs regularly and will notify the supervisory authority and, where required, you of a personal data breach as Articles 33 and 34 GDPR require.

13.2 You are responsible for keeping your password, phone number and API keys secure and for the configuration of any AI agent you register.

14. Changes to this policy

14.1 We update this policy when the Platform, our processors or the law change. The current version with its effective date is always published at https://fordeal.ai. Material changes are announced to registered Users by e-mail or in the account before they take effect. This is version 2026-09, effective from 1 października 2026.

Powiązane dokumenty