Legal · privacy
Personal Data Processing Policy
Effective from 19 September 2026
1. Who processes your data
The controller of personal data is Libor Podolan, Company ID No. 17342368, with registered office at Oplocany 143, 751 01 Oplocany, Czech Republic (the “controller” or “we”), operator of the CUSTOMER DECISION MAP™ application available at we-neuro.app.
Contact address for all questions and for exercising your rights: info@we-velopit.net
The controller has not appointed a data protection officer, as it is not required to do so.
2. What this policy covers
This policy explains what personal data we process when operating the application, why we process it, who receives it and how long we retain it. It applies both to users with their own account and to people invited to the application by link to view a specific output.
3. What data we process
Account data. Email address, the name entered in your profile, a profile photo if you upload one, and sign-in data.
Content you enter into the application. Answers to questions T1–T28, earlier versions of those answers, workshop brief information (industry, market and target group), and the resulting reports.
Questions asked in the live consultation, including their text and any images you attach.
Competitor analyses. The website address you submit for analysis and the text retrieved from it.
Payment data. Billing details, amounts, currencies, payment status and payment identifiers. We never receive your payment card number; it is processed exclusively by the payment provider.
Application usage records. For users with their own account, we record the type of application area visited (for example, “report”, “model” or “pricing”), and the time and duration of the visit. We do not store specific addresses, answer content or IP addresses. For people invited by link, we record only the time of their last sign-in.
Collaboration records. Where several people work on a model, the other participants can see who is currently present, that person’s name and profile photo, and, in real time, the text the person is typing into an answer before it is saved.
Security records. Records of access being granted or revoked, role changes and model deletions.
4. Data about other people
The application is designed to model the decision-making of a representative customer, not a specifically identified person. You should therefore not include third-party personal data in your answers, in particular names, contact details or information about the health of specific individuals. If you nevertheless do so, you are responsible for having a lawful basis, and we process that data as part of the content you have entered.
5. Why we process data and our legal bases
Providing the service — operating accounts, creating and displaying models and reports, live consultation, competitor analysis and sharing outputs. Legal basis: performance of a contract (Article 6(1)(b) GDPR).
Payments and billing — processing orders, subscriptions and credits. Legal basis: performance of a contract and compliance with a legal obligation (Article 6(1)(b) and (c) GDPR).
Retention of accounting documents — tax and accounting legislation. Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR).
Security and protection against misuse — records of access and permission changes. Legal basis: our legitimate interest in keeping the service secure (Article 6(1)(f) GDPR).
Understanding use of the service — aggregate and individual application usage records that show us how the service is used and what needs improvement. Legal basis: our legitimate interest in developing and operating the service (Article 6(1)(f) GDPR). You may object to this processing at any time.
6. Who receives the data
We do not disclose data to anyone for their own purposes. We use only processors that operate the service on our behalf:
Lovable Cloud and Supabase — application hosting, database, authentication and file storage. They process all application data, including answers, reports and profile photos.
OpenAI, L.L.C. (United States of America) — artificial-intelligence text processing. We send the verbatim T1–T28 answers, workshop brief information, the text of live-consultation questions and attached images, and text retrieved from competitors’ websites. Processing takes place under an executed data processing agreement. OpenAI does not use this data to train its models; it retains the data for 30 days to detect abuse and then deletes it.
Stripe — payment processing. We provide the email address, user identifier, amount and information about the purchased service.
Email service provider within Lovable Cloud — sending operational messages such as invitations, order confirmations and model-sharing notifications. We provide the recipient’s email address and the message content.
We disclose data to public authorities when required by law.
We do not use any third-party analytics, advertising or other tracking tools.
7. Transfers outside the European Economic Area
Processing by OpenAI takes place in the United States of America. The transfer relies on standard contractual clauses approved by the European Commission and incorporated into the executed data processing agreement. We will provide you with a copy of these clauses on request.
Other processors may also transfer data outside the European Economic Area subject to comparable safeguards.
8. How long we retain data
Model content, answers and reports — for as long as your account exists. These are outputs you have paid for, so we do not delete them on our own initiative. We delete them when your account is cancelled or at your request.
Application usage records — 12 months, after which they are deleted automatically.
Live-consultation questions and competitor analyses — for as long as the account exists, and no later than its cancellation.
Security records — for as long as the account exists.
Accounting and tax documents — for the period required by tax and accounting legislation. We must retain these documents even after your account is cancelled; however, they are disconnected from you as described below.
9. Account cancellation
You can cancel your account at any time in your settings. Cancellation is irreversible.
Permanently deleted: your profile and profile photo; all your models, including answers, answer history and reports; live-consultation questions; competitor analyses; application usage records; collaboration records; access rights and invitations; notifications; credits and subscription data; billing address; and the login account itself.
Anonymised: orders and invoices. The amount, currency, date, status and payment identifier remain, but the document is disconnected from you. We are required to retain these documents under tax and accounting legislation.
Left unchanged: content in other users’ models on which you collaborated. Your authorship is removed from those models, while the data itself belongs to the person who commissioned the model.
You may also request account cancellation by emailing info@we-velopit.net.
10. Your rights
You have the right to access your data, have it corrected or erased, restrict its processing, obtain data portability, and object to processing based on legitimate interests.
You can exercise your rights by emailing info@we-velopit.net. We will handle your request without undue delay and within one month at the latest.
You also have the right to lodge a complaint with the supervisory authority, which in the Czech Republic is Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Prague 7, www.uoou.gov.cz.
11. Automated decision-making
The application’s outputs are calculated using a predefined methodology, and some text is formulated by artificial intelligence. This is not automated decision-making that produces legal effects concerning you, nor is it profiling of you within the meaning of Article 22 GDPR. The application models the decision-making of a representative customer of your business, not you.
12. Security
Access to data is restricted by role and enforced directly at database level. Communications are encrypted. Data stored in the database is protected by the infrastructure provider’s safeguards.
13. Changes to this policy
We may update this policy, particularly if the way the service operates or the group of processors changes. The current version, together with its effective date, is always available on this page. We will notify you of material changes by email.