Terms and Conditions for the use of OrgPad
Introduction
- OrgPad (referred to as “the application”) is developed and managed by OrgPad s.r.o. The company is located at Hanusova 1537/1b, Michle, 140 00 Prague 4, with VAT ID: CZ09480994. It is officially registered in the Commercial Register at the Municipal Court in Prague, section C, insert 336715.
- In the application, users can create digital boards to manage and store data as they see fit. OrgPad s.r.o. ensures that the data is accessible and regularly backed up.
- These terms and conditions outline the rights and responsibilities of both OrgPad s.r.o. and the application's users. The application is accessible via orgpad.info and orgpad.com. Users accept these terms by using the application.
- For any inquiries or additional information, please contact OrgPad s.r.o. at support@orgpad.info.
Rights and Obligations
- The application is owned by OrgPad s.r.o. Users may not make changes that would disrupt the functionality of the application without the written consent of OrgPad s.r.o.
- Users have the right to use the application from the date the contract with OrgPad s.r.o. is concluded, unless otherwise agreed.
- OrgPad s.r.o. is not responsible for the content of the data stored by users in the application.
- Users agree not to store any data in the application that is illegal, contrary to good morals, or disruptive to public order.
- OrgPad s.r.o. reserves the right to remove any data from the application if it is found to be illegal, contrary to good morals, or disruptive to public order, without prior notice and without any compensation.
- Users are not entitled to compensation for damages or other harm resulting from the use or display of content in the application.
General Data Protection
- OrgPad s.r.o. processes personal data in accordance with the Regulation of the European Parliament and the Council (EU) No. 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation or “GDPR”) and the Act No. 110/2019 Coll., on personal data processing.
- The GDPR defines personal data as any information related to an identified or identifiable natural person (referred to as the "data subject"). An identifiable natural person is someone who can be identified, directly or indirectly, by reference to an identifier such as a name, identification number, position, etc.
- OrgPad s.r.o. acts as the controller and processor of personal data provided by data subjects, in accordance with the GDPR.
- Use of the application does not require data subjects to provide OrgPad s.r.o. with sensitive personal data concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health status, sexual life, and sexual orientation, or other similar sensitive data.
Data Subjects Rights
- Under the General Data Protection Regulation (GDPR), OrgPad s.r.o. is required to provide data subjects with information about itself, as listed in Article I, Section 1. OrgPad s.r.o. can be contacted at support@orgpad.info. No Data Protection Officer has been appointed as OrgPad s.r.o. is not obligated to appoint one.
- The processing of personal data is carried out to fulfill obligations arising from contracts and from legal regulations. The recipients of personal data may be public authorities that are legally entitled to conduct inspections of OrgPad s.r.o.
- OrgPad s.r.o. backs up user data with entities located in the territory of the European Union member states (Article 6).
- OrgPad s.r.o. is required by law to retain personal data for the period specified by legal regulations, for example, accounting records for 5 years from the end of the accounting period to which they relate.
- Data subjects have the right to access personal data related to them and to receive confirmation from OrgPad s.r.o. whether their personal data is being processed. Data subjects also have the right to have OrgPad s.r.o. promptly correct or complete inaccurate personal data.
- OrgPad s.r.o. must delete personal data without undue delay if they are no longer necessary for the purposes for which they were processed. Data subjects may exercise the right to erasure after the period during which OrgPad s.r.o. is obligated to retain the personal data.
- The processing of personal data does not rely on the consent of the data subject. It is necessary for the performance of a contract with the data subject and for compliance with legal obligations under applicable laws.
- Providing personal data is a legal and contractual requirement for processing by OrgPad s.r.o. If a data subject wishes to use the application, they must provide the necessary personal data. OrgPad s.r.o. does not engage in automated decision-making processes in the handling of personal data.
- If a data subject is dissatisfied with the handling of their personal data, they may file a complaint with OrgPad s.r.o. or contact the supervisory authority, which is the Office for Personal Data Protection located at Pplk. Sochora 27, 170 00 Prague 7.
Protection of Third-Party Personal Data
- The data protection measures in the application do not extend to other websites or applications.
- OrgPad s.r.o. uses the Stripe payment gateway. Therefore, it recommends that users familiarize themselves with the privacy regulations that apply to the use of this payment gateway.
Data Storage
- Data and their backups are stored on servers at Hetzner Online GmbH, Industriestrasse 25, 91710 Gunzenhausen, Germany, VAT ID: DE812871812. Hetzner Online GmbH is certified under DIN ISO/IEC 27001. OrgPad s.r.o. has a Data Processing Agreement with this company.
- Additional fully encrypted data backups are stored with the German company Contabo GmbH, Aschauer Straße 32a, 81549 München, VAT ID: DE267602842, and with the Lithuanian company Interneto vizija, UAB, J. Kubiliaus g. 6, 08234 Vilnius, VAT ID: LT263507314.
Access to Data in the Application
- OrgPad s.r.o. does not share data stored in the application with any third parties.
- User data is securely stored, and backups are encrypted. Documents and uploaded files can only be accessed with appropriate permissions, which users grant in the document share dialog.
- OrgPad s.r.o. fully respects user privacy and only accesses user data when addressing specific user issues. Automatic data conversions are also performed in connection with application upgrades, such as changes in data formats.
Cookies
- Cookies are data records stored by a visited website in a user's browser and remain there even when the website is reopened. All cookies are automatically sent back to the server during communication. They are used to distinguish between users and ensure the proper functionality of the application. Cookies help remember user activities and settings for a certain period, so users do not have to redo settings when they return to the application or navigate from another webpage.
- The application uses only technical cookies, so their approval is not required at the first visit.
- The application uses a secure-ring-session cookie. This cookie is a random session identifier on the server, which facilitates all communication by the user. OrgPad s.r.o. uses this to verify that the messages come from a specific user. OrgPad s.r.o. can associate various data with the session, such as the account under which the user is logged in, thus giving the user the right to access and modify their documents.
- The application uses an access-token cookie. Upon login, a random access code is generated, valid for one month. If the user returns to the application later, this cookie is used for re-login so that the user does not have to re-enter their email and password.
- The application uses a device-id cookie. This is a random identifier assigned to a user's device. Various preferences are stored for the user without needing an account in the application. This includes language selection or a list of open cells in a document so that the application can reopen them on the user’s next visit.
- The application does not use any third-party cookies.
- Users can choose to disable cookies through their individual browser settings. For more detailed information on managing cookies in web browsers, OrgPad s.r.o. refers to the respective browser websites.
Embedded External Websites
- Cells within documents may embed external websites. In such cases, the user's browser connects to the external website, and information such as the user's IP address may be shared. These external sites do not have access to user data within the application. YouTube videos are embedded only when the user clicks the play button.
- Files uploaded from Microsoft Office can be directly embedded into a cell using the Microsoft 365 online service. In such cases, the uploaded file is shared with Microsoft. Users are informed of this sharing through a notification within the application before the first embedding.
Logging in via email, Google, Facebook and Microsoft
- For security reasons, OrgPad s.r.o. verifies that the email address used at registration belongs to the user. This prevents third parties from impersonating the user or using unverified accounts to test stolen credit cards.
- If a user registers using an email, they must first activate the account through a link sent in an email by OrgPad s.r.o.
- If a user registers using existing accounts with Meta, Google, or Microsoft, these companies verify whether the account belongs to the user and inform OrgPad s.r.o. accordingly. If an account under that email already exists, the user is logged into it. If the user does not yet have an account in the application, OrgPad s.r.o. creates one and copies the name and profile picture from the service provided by Meta, Google, or Microsoft. The user can change or delete these details at any time in settings.
Log Files
- The application follows standard procedures for using log files. These files log visitors when they visit websites.
- The information collected in log files includes internet protocol (IP) addresses, browser type, Internet Service Provider (ISP), date and time stamp, referring/exit pages, number of clicks and their location, mouse movements, and keyboard interactions.
- The purpose of collecting this information is to analyze trends, manage the site, monitor user movement within the application, study user behavior while using the application, and gather demographic information.
Final Provisions
- These terms and conditions apply unless otherwise agreed in a contract between OrgPad s.r.o. and the user.
- OrgPad s.r.o. reserves the right to modify these terms and conditions to a reasonable extent, particularly in response to changes in legislation or due to other changes independent of the company. In such cases, OrgPad s.r.o. will notify all users of the changes at least one month in advance.
- These terms and conditions take effect on May 3, 2024.