Privacy Policy

Version 2026-10 · effective from 1 November 2026

This is an English translation for convenience. The Czech version is legally binding.

1. Who processes the data

Rebis services, s.r.o., Obřice 22, 411 15 Podsedice, Czech Republic, company ID 22342508 (“we”). Data protection contact: webmaster@rebis.cz, or by post to our registered office.

2. Two roles

3. Data we process as a controller

datapurposelegal basis
name, e-mail, phone (if given), organisation and role, password only as a hash, passkeys where usedaccount and sign-in across the familyperformance of the contract with the Customer, legitimate interest in managing its users
sign-in history: time, IP address, browser and deviceaccount security, sign-in overview for the userlegitimate interest (security)
orders, invoices, contact person and invoicing addressconcluding the contract, invoicing, accountingperformance of the contract, legal obligation
bug reports: text, attachments, technical details you chose to attach, name and e-mail of the authorhandling the report by a person, fixeslegitimate interest in a working service
devices with the ourApp app: notification identifier, device typedelivering notificationsperformance of the contract
server logs: IP address, time, requested address, browsersecurity, troubleshootinglegitimate interest (security and operation)
mail passing through our mail servers (ourEmail)delivering mailas a processor for the Customer (section 2)

We collect anonymous ourCAD usage telemetry only with your consent; it contains no identity, IP address or document content (see the Cookie Policy).

4. Where the data are

All applications and data run on our own servers in the Czech Republic (Obřice and Krupská, two sites for backup and recovery). The exception is one rented virtual server at Forpsi (Czech Republic) used for monitoring, the service status page, certificate validation and as a backup mail server: when the main mail server does not respond, it accepts incoming mail and holds it for at most 14 days before passing it on. No other customer data are stored there.

5. Who we share data with

Transfers to the USA rely on the European Commission’s standard contractual clauses (Implementing Decision (EU) 2021/914) in our contracts with the named providers. We do not sell data or use it for advertising.

For files shared by link from ourCIS and ourDisk: the link is temporary (at most 30 days), the address is the only key, every download is logged (time, link, IP address, browser) and the IP address is anonymised after 90 days.

6. Security

Encrypted connections (HTTPS), passwords stored only as hashes, access by role and organisation (one company cannot see another’s data), two-factor authentication, sign-in history, monitoring, regular backups to a second site and to removable disks, physically secured own premises.

7. Artificial intelligence and automated processing

We use language models from Anthropic PBC (USA) in two areas that differ in which data they can access:

  1. ourCAD assistant — when you use it (a question, dimensioning, drawing review, simplification suggestions, document review), it receives your question and the necessary part of the model or drawing. It runs under Anthropic’s paid commercial terms: Anthropic acts as our processor under a data processing agreement with standard contractual clauses (Implementing Decision (EU) 2021/914), does not use the data to train models and keeps it for at most 30 days. For customer data we are the processor and Anthropic is a sub-processor under module 3 of those clauses. Without your request the assistant receives nothing.
  2. Development and operations — an AI assistant helps us develop, maintain and fix the services. It works with source code, technical data and anonymised copies of data from which no individual can be identified (names, e-mails, phone numbers, free text and files are replaced). It has no access to personal data or to customer data in production; changes to production data are made by our staff.

Bug reports are handled by people.

Automated decision-making under Art. 22 GDPR does not take place: AI does not decide on access, contracts, pay or attendance.

8. Cookies

We use only essential cookies for sign-in and running the applications; ourCAD additionally collects anonymous telemetry with consent. Details are in the Cookie Policy.

9. How long we keep data

dataperiod
user accountwhile the account exists; the organisation administrator or we may close it
sign-in history90 days
in-app notifications90 days
download records of files shared by linkIP address anonymised after 90 days, the record remains
ourDisk trash90 days, then the file is deleted
invoices and accounting documents10 years (VAT Act)
record of account deletion (name, e-mail, who deleted the account and when)3 years after deletion
bug reportswhile the service is provided, as a history of fixes; anonymised on request
web server logs14 days; application and system logs 30 days
mail queued on the backup mail serverat most 14 days
customer data after the contract endsunder Article 6 of the Terms (at least 14 days, then deletion)
backupsapplication data 30 days, mail 7 days, mail server database 365 days; offline copies on removable disks according to their rotation

10. Your rights

You have the right to access your data, to rectification, erasure, restriction of processing, portability and to object to processing based on legitimate interest. Write to webmaster@rebis.cz; we reply within 30 days. For data we process for the Customer (section 2), contact the Customer. You may lodge a complaint with the Czech Office for Personal Data Protection (www.uoou.cz).

Account deletion

To have your ourApps account deleted, and with it your access to the ourApp app, ask your organisation's administrator, or write to webmaster@rebis.cz from the e-mail address of the account. We first block the account and delete it within 30 days of the request; we will let you know the outcome.

Deleting the account removes: the password hash, passkeys and backup codes; signed-in devices and notification identifiers of the ourApp app; sign-in history, sessions and in-app notifications; memberships in organisations and teams and access to applications.

In the applications you worked in, we replace your e-mail with an invalid address and remove the link to the account. Your name stays on records that belong to your organisation (messages, tasks, documents, attendance) — the organisation is their controller (section 2) and decides on their erasure.

What remains: a record of the account deletion (name, e-mail, who deleted the account and when) for 3 years as evidence for security purposes, invoices and accounting documents for the statutory period, and bug reports you sent (anonymised on request). The data disappear from backups within 30 days, and from offline copies according to their rotation (section 9).

11. Changes

We publish new versions on this page and inform you of significant changes by e-mail or in the application.