Danito
Features Pricing How it works FAQ
Čeština Log in Create account

Privacy Policy

Last updated: 2026-08-06

This English version is a convenience translation; the Czech version prevails in case of any discrepancy.

This policy describes what personal data the Danito service (the “service”) collects, why it processes them, and how it protects users’ rights under Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and related Czech legislation (Act No. 110/2019 Coll., on the Processing of Personal Data).

Controller and contact

The operator of the service and the controller of personal data is Daniel Pelikán, a natural person doing business under a Czech trade licence (Company ID / IČO 04814525). Contact for all questions regarding personal-data protection and the exercise of data-subject rights:

  • E-mail: privacy@danito.cz
  • Address: Učňovská 379/6, Hrdlořezy, 190 00 Praha 9, Czech Republic

The controller has not yet appointed a data protection officer; the scope of processing at the current size of the service does not require it.

Categories of processed data

The service processes the following categories of personal data:

  • Data for creating and managing an account: e-mail address and password (stored only as a cryptographic hash using Argon2id; the password itself is never stored or logged by the service).
  • Identification data of the billing subject: first and last name of a natural person or the name of a legal entity, address, company ID (IČO), tax ID (DIČ) — used by the user to issue invoices.
  • Data on invoices, expenses, and platform income: invoice items, amounts, due dates, payers and recipients, expense descriptions, data on income received through a platform (e.g. platform name, amount, date).
  • An uploaded payout document retained to improve processing (only with your consent): if an uploaded payout document cannot be recognized automatically and you actively choose to leave it with us, we temporarily store its file in order to fine-tune the automatic processing of this type of document. If you decline, close the dialog, or do nothing, nothing is stored.
  • Subscription status: chosen tariff, activation and renewal date, change history (no payments yet — see “Payment processor” below).
  • Tax documents issued by Danito for the subscription: the invoices Danito issued to you as the supplier of the subscription — document number, issue date, date of taxable supply and due date, description of the tariff and the billed period, amounts and VAT, the payment identifier at the payment gateway — and the customer’s billing details shown on the document: first and last name of a natural person or the name of a legal entity, company ID (IČO), tax ID (DIČ), and address. They are kept as a database record and as a PDF; the document contains neither an e-mail address nor any content you created in the service.
  • Feedback: the content of messages sent by the user through the feedback form.
  • Operational logs and audit trail: records in audit tables about changes to key entities, and application logs limited to an allow-list of fields (no PII in the logs).

Legal basis for processing

Data categoryLegal basis
Data for creating and managing an accountPerformance of a contract (Art. 6(1)(b) GDPR)
Identification data of the billing subjectPerformance of a contract and legitimate interest in providing the service
Invoices, expenses, platform incomePerformance of a contract
An uploaded payout document retained to improve processingConsent (Art. 6(1)(a) GDPR)
Subscription statusPerformance of a contract
Tax documents issued by Danito for the subscriptionCompliance with a legal obligation of the controller (Art. 6(1)(c) GDPR) — Section 35 of the Czech VAT Act
FeedbackLegitimate interest in improving the service
Operational logs and audit trailLegitimate interest in the security, integrity, and accountability of operations

Retention period

  • Account and user content (subjects, invoices, expenses, platform income, subscription, feedback): for the duration of the account. When the user deletes the account, the data is hard-deleted via the Delete subject / Delete account feature (cascade delete at the database level). The only exception is the tax documents Danito itself issued for the subscription — see the next item.
  • Tax documents issued by Danito for the subscription: these are kept even after the account is deleted, for at least 10 years from the end of the tax period in which the supply took place. Under Section 35 of the Czech VAT Act the duty to keep an issued tax document rests with whoever issued it — here Danito as the controller, not the user — so the customer deleting their account cannot end it. For that reason a copy of the document is stored outside the account’s data structure (a separate record and PDF file with no link to the account) and deleting the account does not affect it. Independently of this, the user as a business also has a duty to keep their own tax documents — but that duty covers the documents the user issued, and Danito does not discharge it on their behalf.
  • An uploaded payout document retained to improve processing: stored only when, after unsuccessful recognition, you actively leave the document with us; if you decline, close the dialog, or do nothing, nothing is stored. We use the stored file solely to fine-tune automatic processing and physically delete it within 30 days at the latest (the deletion concerns the file itself in storage). If you requested to be notified once this type of document can be processed, that promise is tied to the retention period — once the document is deleted, we will no longer send the notification.
  • Audit trail: for the duration of the account. Audit records are part of the relevant account and are deleted together with it.
  • Operational logs: short-term (on the order of days to a few weeks); the logs contain only items from an allow-list — no PII, passwords, or user content.

Recipients and processors

The service is operated with a minimum of external processors. All data is primarily stored on infrastructure in the European Union. Sub-processors used:

  • Hosting in the European Union — hosting of the PostgreSQL database and the marketing pages.
  • Postmark (ActiveCampaign, LLC, USA) — sending transactional e-mails (account confirmation, forgotten password, billing notifications). Transfer outside the EU takes place on the basis of Standard Contractual Clauses; the e-mail content contains no sensitive data beyond the recipient and the message text.

Payments for paid tariffs are processed by the GoPay payment gateway (GOPAY s.r.o., Czech Republic) as a separate processor. Payment details (card number, etc.) are entered by the user directly on GoPay’s secured page — the Danito service never sees or stores them. From GoPay, Danito receives only the payment metadata (payment identifier, status, amount in CZK, and date) needed to activate and renew the subscription. The transfer takes place on the basis of a GDPR data-processing agreement; data is processed within the European Union.

Data-subject rights

In accordance with the GDPR, the user has the right:

  • to access the personal data the service processes about them;
  • to rectification of inaccurate data;
  • to erasure (“the right to be forgotten”) — the user can carry it out themselves via the Delete subject / Delete account feature, or upon a written request; erasure does not extend to the tax documents Danito itself issued for the subscription: Section 35 of the Czech VAT Act requires the controller to keep them, and Art. 17(3)(b) GDPR expressly exempts such processing from the right to erasure;
  • to restriction of processing in the cases set out by the GDPR;
  • to portability of the data in a structured, commonly used, and machine-readable format;
  • to object to processing based on legitimate interest;
  • to withdraw consent to processing where consent is the legal basis (an uploaded payout document retained to improve processing);
  • to lodge a complaint with the Office for Personal Data Protection (www.uoou.cz).

Exercising these rights is free of charge. Contact: privacy@danito.cz. The controller usually handles requests within 30 days of receipt.

Changes to this policy

This policy may be updated from time to time — in particular when a new processor is involved or the scope of processed data changes. The current version is always available on this page and includes the date of the last update. Substantial changes (in particular involving a new processor or payment intermediary) will be announced to users by e-mail at least 30 days before they take effect.

Site language: English

  • Help
  • Feedback
  • Cookies
  • Privacy Policy
  • Terms of Service
  • Čeština
  • GoPay
  • Visa
  • Visa Electron
  • Mastercard
  • Mastercard Electronic
  • Maestro
  • Verified by Visa
  • Mastercard SecureCode

© Danito