Privacy Policy
Last updated: July 22, 2026
This Privacy Policy explains how Jiří Dočkal, a self-employed individual (sole trader) registered in the Czech Republic, Company ID (IČO) 05438861, with registered address at Lužánecká 1887/8, 602 00 Brno, Czech Republic ("we", "us") collects and processes personal data when you use Burnlytics (the "Service"). We are the data controller for the processing described here.
1. Data we collect
- Account data: email address, password (stored hashed by our authentication provider), and optional display name.
- Financial planning data: the assumptions, revenue, expense, and headcount figures you enter. These are business forecasts you control; we recommend not entering personal data of identifiable individuals (e.g. use roles instead of employee names).
- Billing data: subscription status and a customer reference held by our payment processor, Stripe. We never store your full card details.
- Technical data: server logs (IP address, request metadata) retained briefly for security and debugging.
2. Purposes and legal bases
- Providing the Service (contract performance): account management, storing your forecasts, billing.
- Security and abuse prevention (legitimate interest): authentication, logging, rate limiting.
- Service communications (contract performance): transactional emails such as email confirmation, password reset, and billing notices. We do not send marketing emails without your consent.
3. Cookies
The Service uses only strictly necessary cookies: authentication session cookies set by our auth provider (Supabase). We currently use no analytics, advertising, or third-party tracking cookies, which is why no cookie consent banner is shown. If this changes, we will update this policy and request consent where required.
4. Processors and data transfers
We share data only with processors needed to run the Service:
- Supabase — authentication and database hosting.
- Stripe — payment processing.
- Vercel — application hosting and logs.
Where these providers process data outside the EU/EEA, transfers are protected by appropriate safeguards such as the EU Standard Contractual Clauses or an adequacy decision (e.g. the EU–US Data Privacy Framework).
5. Retention
We keep your data for as long as your account exists. When you delete your account (Settings → Account → Delete account), your account data and all forecasts are deleted immediately from our production database; residual copies in encrypted backups expire on the backup rotation schedule. Billing records are retained as required by tax and accounting law.
6. Your rights
Subject to applicable law (including the GDPR if you are in the EU/EEA), you have the right to access, rectify, delete, and receive a copy of your personal data, to restrict or object to processing, and to lodge a complaint with a supervisory authority. You can exercise deletion yourself in the app; for other requests contact us at jiri.dockal5@gmail.com.
7. Security
Data is encrypted in transit (TLS) and at rest by our hosting providers. Access to production systems is restricted and authenticated. No method of transmission or storage is 100% secure, but we work to protect your data using industry-standard measures.
8. Changes
We may update this policy from time to time. Material changes will be announced by email or in-app notice before they take effect.
9. Contact
Privacy questions and requests: jiri.dockal5@gmail.com.