Privacy Policy

Effective from: 24 September 2026

1. Introduction

The operator of the Apino service considers the protection of user privacy and personal data as paramount. This privacy policy describes how we collect, use, and protect your personal data in compliance with Slovak Act No. 18/2018 Coll. on personal data protection and the GDPR regulation.

2. Data We Collect

We collect only data necessary for providing the service:

  • Email address - for account creation and essential communication
  • Billing data - name/company, address, VAT ID - entered at checkout directly in the Stripe payment gateway, which issues the invoices; the operator does not store it in its own database (legal requirement)
  • API usage data - request logs for diagnostics and billing purposes
  • IP addresses — truncated as soon as they are written (IPv4 to the first three parts, IPv6 to the first 48 bits), so no full IP address is kept in our database; they are used only for security and rate limiting, and in the server's operational logs they are anonymised after 30 days at the latest. The truncated address is also what we keep when the terms are accepted and when a change digest subscription is added and confirmed, where together with the time it records when and from where the action was taken (Art. 7(1) GDPR); it is deleted together with the record it belongs to.
  • Withdrawal from the contract — your name and surname, email address, any invoice number or message you give with it, the time it was sent, a truncated IP address and the user agent. We keep these for 3 years as evidence that and when the withdrawal arrived; the legal basis is compliance with a legal obligation under § 20a of Act No. 108/2024 Coll. (Art. 6(1)(c) GDPR) and our legitimate interest in being able to show it was handled (Art. 6(1)(f) GDPR).
  • Connected AI assistants — when you connect an assistant such as Claude or ChatGPT to your account over OAuth: the name and return address the assistant registered itself with, your consent to it (what it may do and when you gave it), and the tokens that keep it connected. Its lookups are recorded like API requests — which tool, when, and with what result — but not what it asked about.

2a. Data from public registers

The service consists of data from the Slovak Register of Legal Entities and the Czech Register of Economic Subjects, and for VAT verification also from the lists of the Slovak Financial Administration and the VAT register of the Czech Ministry of Finance, which is asked at the moment of the request. These registers also contain personal data of natural persons — the names of statutory representatives, shareholders and sole traders, and their addresses. We process it on the basis of legitimate interest (Art. 6(1)(f)) in making available data whose publication is required by the law establishing the register concerned. Before serving Slovak records we remove personal identifiers and reduce the addresses of statutory representatives and shareholders to municipality and country; names are kept as the register publishes them. A natural person's Czech VAT number (DIČ) is derived from their birth number: we do not store it, do not provide it on a lookup by company ID, and strip it from our request logs; it is returned only to whoever entered it. We do not enrich the data from other sources and change it only to correct evident transcription errors, with the original text remaining available. If you appear in a register as a natural person, we cannot change what the record says — that must be raised with the authority maintaining the register; against us you may exercise your rights under Art. 15-21 GDPR, including objecting to processing based on legitimate interest.

3. Legal Basis for Processing (GDPR Art. 13(1)(c))

We process your personal data based on the following legal grounds:

  • Contract performance (Art. 6(1)(b)) — account creation, API access provision, billing, and subscription management
  • Legitimate interest (Art. 6(1)(f)) — security monitoring, abuse prevention, rate limiting, anonymized analytics, and service improvement
  • Legal obligation (Art. 6(1)(c)) — tax records, invoice retention, and compliance with Slovak law
  • Consent (Art. 6(1)(a)) — receiving the daily change digest at an address a customer added to a watchlist (see 5a). Consent can be withdrawn at any time.

4. Payment Processing

Payments are processed through Stripe (stripe.com). We share your email address and name with Stripe to create your customer account. The operator does not have access to payment details (card number, CVV) entered by users during the payment process. This data is not stored on the operator's servers. Service activation occurs automatically upon confirmation of successful payment by the payment gateway. Stripe's privacy policy: https://stripe.com/privacy.

5. Communications

We send only operational messages relating to your account and the service: email verification, password resets, security alerts, usage warnings, payment notices, and — where change monitoring is in use — the daily digest and its confirmation requests. These cannot be declined, as they are necessary to perform the contract and run the service; the daily digest itself can be switched off in the watchlist settings or through the link carried by every one of them. We do not currently send commercial messages — newsletters, offers or other advertising — at all. Should we begin to, we will ask for separate consent and every such message will carry a free unsubscribe link.

5a. Digest recipients

A customer can add another person's email address to a watchlist so the daily change digest reaches them. Nothing is sent to such an address until its holder confirms it themselves by pressing the button in the confirmation request; until then we merely store it, and after 30 days without confirmation we delete it automatically. The legal basis is consent (Art. 6(1)(a) GDPR). As proof of consent we retain the email address, the date and truncated IP address of the addition, the date and truncated IP address of the confirmation, the identity of the customer who added it, and the version of this privacy notice in force at the time of confirmation. So that adding addresses cannot be used to send confirmation requests in bulk, we record for 2 days the time of each request sent and the customer who caused it — without the recipient's address. Consent can be withdrawn at any time via the unsubscribe link in every digest or by writing to the contact address below; on withdrawal we delete both the address and the consent record. So that we cannot send you another confirmation request after you unsubscribe or ask for erasure, even if someone adds your address again, we keep only a one-way fingerprint (hash) of it from which the address cannot be read directly — it can only confirm whether a given address is the same one — on the basis of our legitimate interest in honouring your decision (Art. 6(1)(f) GDPR), until you ask us to remove it. The holder of the address has the same rights under Art. 15-21 GDPR as any other data subject, including the right to learn who added their address.

6. Cookies

Our service uses the following cookies: (1) Authentication cookies — secure, httpOnly cookies valid for 7 days or until logout; (2) Language preference — stores your language choice, valid for 1 year. Both are strictly necessary to provide the service you asked for and under § 109(8) of Act No. 452/2021 Coll. on electronic communications they require no consent. Traffic is measured with a self-hosted Plausible Analytics instance; it stores no cookies or other data on your device, creates no visitor identifiers and does not track you across sites, so it requires no consent either. We use no marketing or tracking cookies and show no consent banner, because there is nothing to consent to.

7. Data Sharing

We do not sell your personal data or provide it to third parties for their own purposes. The following act as processors: Hetzner Online GmbH (Germany) — server and database hosting, under a data processing agreement pursuant to Art. 28 GDPR; Stripe, Inc. and Stripe Payments Europe, Ltd. — payment processing and invoicing, under the data processing agreement that forms part of the Stripe Services Agreement; WebCreators, s.r.o. (Slovakia), the HostCreators service — mailbox operation and message delivery, with mail servers in Slovakia, under the data processing agreement pursuant to Art. 28 GDPR that forms part of its terms of service. Each processes data on our instruction and for the purpose we entrusted it with. Website traffic is measured with our own self-hosted instance of Plausible Analytics, and nothing from it is passed to anyone. What an AI assistant you have connected looks up is delivered, at your direction, to that assistant's operator (for example Anthropic or OpenAI); the operator is not our processor, and its own terms apply. We may provide data to public authorities where the law requires it.

8. International Data Transfers (GDPR Art. 13(1)(f))

Your personal data may be transferred to countries outside the EU/EEA:

  • Stripe, Inc. (USA) — payment processing. Stripe is certified under the EU-U.S. Data Privacy Framework (DPF), providing adequate safeguards for data transfers under GDPR Art. 45.
  • For any other transfers, we rely on EU Standard Contractual Clauses (Art. 46(2)(c)) or adequacy decisions where available.

9. Data Retention

Account data is retained for the life of the active account. API logs are kept for 90 days for diagnostics and billing. Aggregated usage statistics are kept for 365 days. IP addresses are stored only truncated; in the server's operational logs they are anonymised after 30 days at the latest. Security events and audit records of administrator actions are kept for 2 years. The record of terms acceptance is kept for the life of the account and deleted with it. A digest recipient's address and consent record are deleted on unsubscribe; an unconfirmed address is deleted automatically after 30 days. Webhook delivery records are kept for 30 days. Records of withdrawal from the contract are kept for 3 years. Invoices and VAT ID verification records are kept for the 10 years the accounting act requires, also after the account is deleted, no longer linked to it. Your consent to a connected AI assistant lasts until you disconnect it in the dashboard or delete the account; its tokens are deleted within a day of expiring, at the latest 30 days after they were last used, and an assistant registration through which nobody ever connected is deleted after 30 days. Other personal data is removed immediately on account deletion; residual copies in the encrypted backups disappear within 3 months, when the backup is deleted.

10. Your Rights (GDPR Art. 15-21)

Under GDPR, you have the following rights:

  • Right of access - obtain a copy of your personal data (in account settings)
  • Right to rectification - correct inaccurate or incomplete data
  • Right to erasure - delete your account and all associated data
  • Right to restriction of processing - limit how we process your data
  • Right to data portability - export your data in machine-readable format (JSON)
  • Right to object - object to processing based on legitimate interests
  • Right to lodge a complaint - you may lodge a complaint with the Slovak Data Protection Authority (Úrad na ochranu osobných údajov SR) at dataprotection.gov.sk

You can exercise these rights directly in account settings (export and deletion) or by contacting privacy@apino.sk.

11. Account Deletion

You can delete your account at any time in the settings. Deletion is immediate and irreversible. Removed are: your profile and personal data, all API keys, API usage history, all active sessions, the record of your terms acceptance, your watchlists including digest recipient addresses and configured webhooks, and your connected AI assistants. After deletion, access to the service and its data cannot be restored.

12. Security

We take appropriate technical and organisational measures to protect your data: encryption in transit (TLS 1.3), hashing of passwords and API keys, encryption of access tokens in the database, least-privilege access control and continuous operational monitoring. Neither the database nor the cache is reachable from the internet. Servers are located in a data centre in Germany (Hetzner Online GmbH). Server disks are not encrypted at the device level. The last security audit of the code was carried out in February 2026.

12a. Whether you must provide data, and automated decision-making

We need your email address and a password in order to create an account and provide the service — this is a contractual requirement and without them no account can exist. Billing details for a paid plan are required by accounting and VAT law; without them we cannot issue an invoice and therefore cannot activate a paid plan. A free account and the public parts of the site can be used without further data. We require nothing else, and not providing anything else has no other consequence. We carry out no automated decision-making or profiling within the meaning of Art. 22 GDPR — no automated system decides anything about your rights or obligations. The only thing that happens automatically is the enforcement of the limits of the plan you chose, which has no legal or similarly significant effect on you.

13. Contact

The controller is Michal Piják DEV, Na Hrebienku 1498/35, 811 02 Bratislava, Slovakia, IČO: 57396655, registered in the Trade Register of the Bratislava District Office, trade register number 110-362285. The controller has not designated a data protection officer. For matters of data protection and to exercise your rights, contact us at