1. Introduction
The operator of the Apino service considers the protection of user privacy and personal data as paramount. This privacy policy describes how we collect, use, and protect your personal data in compliance with Slovak Act No. 18/2018 Coll. on personal data protection and the GDPR regulation.
2. Data We Collect
We collect only data necessary for providing the service:
- Email address - for account creation and essential communication
- Billing data - name/company, address, VAT ID - entered at checkout directly in the Stripe payment gateway, which issues the invoices; the operator does not store it in its own database (legal requirement)
- API usage data - request logs for diagnostics and billing purposes
- IP addresses — in operational logs these are anonymised after 30 days and used only for security and rate limiting. We separately retain the IP address recorded when the terms are accepted and when a change digest subscription is confirmed; there it is the evidence of when and from where the action was taken (Art. 7(1) GDPR), it is not anonymised, and it is deleted together with the record it belongs to.
2a. Data from public registers
The service consists of data from the Slovak Register of Legal Entities and the Czech Register of Economic Subjects. These registers also contain personal data of natural persons — the names of statutory representatives, shareholders and sole traders, and their addresses. We process it on the basis of legitimate interest (Art. 6(1)(f)) in making available data whose publication is required by the law establishing the register concerned. Before serving Slovak records we remove personal identifiers and reduce the addresses of statutory representatives and shareholders to municipality and country; names are kept as the register publishes them. We do not enrich the data from other sources and change it only to correct evident transcription errors, with the original text remaining available. If you appear in a register as a natural person, we cannot change what the record says — that must be raised with the authority maintaining the register; against us you may exercise your rights under Art. 15-21 GDPR, including objecting to processing based on legitimate interest.
3. Legal Basis for Processing (GDPR Art. 13(1)(c))
We process your personal data based on the following legal grounds:
- Contract performance (Art. 6(1)(b)) — account creation, API access provision, billing, and subscription management
- Legitimate interest (Art. 6(1)(f)) — security monitoring, abuse prevention, rate limiting, anonymized analytics, and service improvement
- Legal obligation (Art. 6(1)(c)) — tax records, invoice retention, and compliance with Slovak law
- Consent (Art. 6(1)(a)) — receiving the daily change digest at an address a customer added to a watchlist (see 5a). Consent can be withdrawn at any time.
4. Payment Processing
Payments are processed through Stripe (stripe.com). We share your email address and name with Stripe to create your customer account. The operator does not have access to payment details (card number, CVV) entered by users during the payment process. This data is not stored on the operator's servers. Service activation occurs automatically upon confirmation of successful payment by the payment gateway. Stripe's privacy policy: https://stripe.com/privacy.
5. Communications
We send only operational messages relating to your account and the service: email verification, password resets, security alerts, usage warnings, payment notices, and — where change monitoring is in use — the daily digest and its confirmation requests. These cannot be declined, as they are necessary to perform the contract and run the service; the daily digest itself can be switched off in the watchlist settings or through the link carried by every one of them. We do not currently send commercial messages — newsletters, offers or other advertising — at all. Should we begin to, we will ask for separate consent and every such message will carry a free unsubscribe link.
5a. Digest recipients
A customer can add another person's email address to a watchlist so the daily change digest reaches them. Nothing is sent to such an address until its holder confirms it themselves by pressing the button in the confirmation request; until then we merely store it, and after 30 days without confirmation we delete it automatically. The legal basis is consent (Art. 6(1)(a) GDPR). As proof of consent we retain the email address, the date and IP address of the addition, the date and IP address of the confirmation, the identity of the customer who added it, and the version of this privacy notice in force at the time of confirmation. Consent can be withdrawn at any time via the unsubscribe link in every digest or by writing to the contact address below; on withdrawal we delete both the address and the consent record. The holder of the address has the same rights under Art. 15-21 GDPR as any other data subject, including the right to learn who added their address.
6. Cookies
Our service uses the following cookies: (1) Authentication cookies — secure, httpOnly cookies valid for 7 days or until logout; (2) Language preference — stores your language choice, valid for 1 year. Both are strictly necessary to provide the service you asked for and under § 109(8) of Act No. 452/2021 Coll. on electronic communications they require no consent. Traffic is measured with a self-hosted Plausible Analytics instance; it stores no cookies or other data on your device, creates no visitor identifiers and does not track you across sites, so it requires no consent either. We use no marketing or tracking cookies and show no consent banner, because there is nothing to consent to.
7. Data Sharing
We do not sell your personal data or provide it to third parties for their own purposes. The following act as processors: Hetzner Online GmbH (Germany) — server and database hosting, under a data processing agreement pursuant to Art. 28 GDPR; Stripe, Inc. and Stripe Payments Europe, Ltd. — payment processing and invoicing, under the data processing agreement that forms part of the Stripe Services Agreement; WebCreators, s.r.o. (Slovakia), the HostCreators service — mailbox operation and message delivery, with mail servers in Slovakia, under the data processing agreement pursuant to Art. 28 GDPR that forms part of its terms of service. Each processes data on our instruction and for the purpose we entrusted it with. Website traffic is measured with our own self-hosted instance of Plausible Analytics, and nothing from it is passed to anyone. We may provide data to public authorities where the law requires it.
8. International Data Transfers (GDPR Art. 13(1)(f))
Your personal data may be transferred to countries outside the EU/EEA:
- Stripe, Inc. (USA) — payment processing. Stripe is certified under the EU-U.S. Data Privacy Framework (DPF), providing adequate safeguards for data transfers under GDPR Art. 45.
- For any other transfers, we rely on EU Standard Contractual Clauses (Art. 46(2)(c)) or adequacy decisions where available.
9. Data Retention
Account data is retained for the life of the active account. API logs are kept for 90 days for diagnostics and billing. Aggregated usage statistics are kept for 365 days. IP addresses in logs are anonymised after 30 days. Security events and audit records of administrator actions are kept for 2 years. The record of terms acceptance is kept for the life of the account and deleted with it. A digest recipient's address and consent record are deleted on unsubscribe; an unconfirmed address is deleted automatically after 30 days. Webhook delivery records are kept for 30 days. On account deletion personal data is removed immediately; residual copies in backups are overwritten in the normal backup cycle.
10. Your Rights (GDPR Art. 15-21)
Under GDPR, you have the following rights:
- Right of access - obtain a copy of your personal data (in account settings)
- Right to rectification - correct inaccurate or incomplete data
- Right to erasure - delete your account and all associated data
- Right to restriction of processing - limit how we process your data
- Right to data portability - export your data in machine-readable format (JSON)
- Right to object - object to processing based on legitimate interests
- Right to lodge a complaint - you may lodge a complaint with the Slovak Data Protection Authority (Úrad na ochranu osobných údajov SR) at dataprotection.gov.sk
You can exercise these rights directly in account settings (export and deletion) or by contacting privacy@apino.sk.
11. Account Deletion
You can delete your account at any time in the settings. Deletion is immediate and irreversible. Removed are: your profile and personal data, all API keys, API usage history, all active sessions, the record of your terms acceptance, and your watchlists including digest recipient addresses and configured webhooks. After deletion, access to the service and its data cannot be restored.
12. Security
We take appropriate technical and organisational measures to protect your data: encryption in transit (TLS 1.3), hashing of passwords and API keys, encryption of access tokens in the database, least-privilege access control and continuous operational monitoring. Neither the database nor the cache is reachable from the internet. Servers are located in a data centre in Germany (Hetzner Online GmbH). Server disks are not encrypted at the device level. The last security audit of the code was carried out in February 2026.
12a. Whether you must provide data, and automated decision-making
We need your email address and a password in order to create an account and provide the service — this is a contractual requirement and without them no account can exist. Billing details for a paid plan are required by accounting and VAT law; without them we cannot issue an invoice and therefore cannot activate a paid plan. A free account and the public parts of the site can be used without further data. We require nothing else, and not providing anything else has no other consequence. We carry out no automated decision-making or profiling within the meaning of Art. 22 GDPR — no automated system decides anything about your rights or obligations. The only thing that happens automatically is the enforcement of the limits of the plan you chose, which has no legal or similarly significant effect on you.
13. Contact
The controller is Michal Piják DEV, Na Hrebienku 1498/35, 811 02 Bratislava, Slovakia, IČO: 57396655, registered in the Trade Register of the Bratislava District Office, trade register number 110-362285. The controller has not designated a data protection officer. For matters of data protection and to exercise your rights, contact us at