MaxiZdrav s.r.o.
IČO: 213 21 388
Registered office: Varšavská 715/36, Vinohrady, 120 00 Praha 2, Czech Republic
Registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, File 399573.
Electronic contact: ProfitTriage contact form
1. Controller
The data controller for ProfitTriage AI is MaxiZdrav s.r.o., IČO 213 21 388, at the registered office shown above. Privacy, access, correction, deletion and other data-protection requests can be submitted through the contact form by selecting “Privacy / data request”.
2. Data we process
Depending on how you use the service, we may process:
- account information such as your email address and authentication identifiers;
- monthly profit snapshots that a signed-in Pro user explicitly chooses to save;
- Stripe customer, subscription and subscription-status identifiers needed to provide paid access;
- support, billing, account and privacy requests you send to us;
- limited first-party product-usage events such as page views, scan completion, upgrade clicks, checkout events, referrer and campaign parameters.
Passwords are handled by Supabase Auth and are not stored by ProfitTriage in readable form. Full payment-card details are processed by Stripe and are not stored by ProfitTriage.
3. Free Profit Scan
The Free Profit Scan is calculated in your browser. Raw Free Scan financial inputs are not persistently stored in our database merely because you run the scan. ProfitTriage stores monthly business snapshots only when a signed-in Pro user explicitly chooses “Save Current Month”. Limited analytics events may record that a scan was started or completed, but are not designed to store the raw financial figures entered into the scan.
4. Purposes and legal bases
- Contract / steps requested before contract: to create and secure accounts, provide Free and Pro features, maintain subscription access, process support connected with the service and deliver saved Pro features.
- Legal obligations: where processing is required for accounting, tax, consumer-protection or other legal obligations.
- Legitimate interests: to protect the service against abuse and fraud, maintain security, diagnose technical problems, respond to general support, and understand limited first-party product usage so we can operate and improve ProfitTriage. We do not use these analytics as cross-site advertising tracking.
- Consent: only where we separately ask for consent for an optional activity that requires it.
5. Service providers and recipients
We use service providers needed to operate ProfitTriage, including Vercel for hosting and delivery, Supabase for authentication, database and server functions, Resend for transactional authentication and account-security email delivery, and Stripe for subscription payments and billing management. Stripe processes payment and transaction data for subscription payments, billing, fraud prevention, security, legal compliance and related payment services. Depending on the processing activity, Stripe may act as a processor on our behalf or as an independent controller under its own privacy terms. When Resend is used to send authentication emails such as password-reset or account-security notifications, it may process the recipient email address and related email-delivery metadata for that purpose. These providers process data under their applicable contractual and data-protection terms. We do not sell personal data.
6. International processing
Some service providers may process information outside the European Economic Area. Where required, such transfers rely on applicable legal safeguards and transfer mechanisms provided under data-protection law.
7. Retention
We retain personal data only for as long as reasonably necessary for the purposes described above. Account and saved-service data may be retained while an account is active and for a limited period afterward where needed for security, dispute handling or legal obligations. Billing and transaction-related records may be retained for the periods required by accounting, tax and other applicable laws. Support and analytics records are retained only for as long as reasonably necessary for their operational purpose.
8. Your GDPR rights
Where the GDPR applies, you may have rights to be informed, access your personal data, correct inaccurate data, request erasure, restrict processing, receive portable data, object to processing based on legitimate interests, and withdraw consent where processing is based on consent. You also have the right to lodge a complaint with a competent supervisory authority. In the Czech Republic, the supervisory authority is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), uoou.gov.cz.
9. Security
ProfitTriage uses HTTPS, Supabase authentication, row-level database security for user-owned records, server-side access checks for Pro features, and leaked-password protection. No online service can guarantee absolute security.
10. Automated calculations
ProfitTriage generates mathematical business-analysis outputs from information entered by the user. These calculations are decision-support tools and are not used by ProfitTriage to make legal or similarly significant automated decisions about you.
11. Changes
We may update this Privacy Policy when the service, providers or legal requirements change. The “Last updated” date identifies the current version.