I. Who We Are
Sustainly s.r.o., ID (IČO): 21802106, with registered office at Dlouhá 3403/2b, 702 00 Ostrava, Czech Republic, registered in the Commercial Register maintained by the Regional Court in Ostrava, file no. C 96563 ("Sustainly", "we", "us").
Contact for all privacy matters: info@sustainly.tech
II. Two Roles: Controller and Processor
This policy covers two distinct situations, and your rights differ depending on which applies.
We act as a data controller for personal data relating to our own relationship with you: your account, our communications with you, our website, and our invoicing. Section III to Section VIII below describe this processing.
We act as a data processor for the content our customers upload into the platform — energy bills, payroll records, financial documents, supplier data and similar business records. Where those documents contain personal data (an employee name on an invoice, a signatory on a contract), the customer that uploaded them is the controller and decides why and how that data is processed. We process it only on that customer's documented instructions.
That processing is governed by our Data Processing Addendum, not by this policy. If you are an employee or contact of one of our customers and want to exercise your rights over data contained in uploaded documents, please contact that company directly — they control it. We will assist them in responding to you.
III. Personal Data We Process as Controller
| Category | Data | Source |
|---|---|---|
| Account data | Name, work email, job title, company name, password (hashed) | You |
| Communication data | Correspondence with our support and sales, enquiry form submissions | You |
| Billing data | Company billing details, VAT ID, invoice and payment records | You |
| Technical data | IP address, browser and device type, timestamps, application logs | Automatically |
| Cookie data | As set out in our [Cookie Policy](/en/cookie-policy) | Automatically |
We do not knowingly collect special categories of personal data (Art. 9 GDPR) in our capacity as controller, and we ask our customers not to upload such data into the platform.
IV. Purposes and Legal Bases
| Purpose | Legal basis |
|---|---|
| Providing the platform and delivering reports and calculations | Performance of a contract, Art. 6(1)(b) |
| Account administration, authentication, support | Performance of a contract, Art. 6(1)(b) |
| Technical and service notifications | Performance of a contract, Art. 6(1)(b) |
| Invoicing, accounting, tax records | Legal obligation, Art. 6(1)(c) |
| Security, fraud prevention, abuse detection, service integrity | Legitimate interest, Art. 6(1)(f) — protecting our service and our users |
| Improving and developing our services, including using data in aggregated and anonymised form | Legitimate interest, Art. 6(1)(f) — see Section V |
| Direct marketing to existing customers about similar services | Legitimate interest, Art. 6(1)(f) — you may object at any time |
| Marketing to prospective customers, non-essential cookies | Consent, Art. 6(1)(a) — withdrawable at any time |
| Establishing, exercising or defending legal claims | Legitimate interest, Art. 6(1)(f) |
Where we rely on legitimate interest, we have assessed that interest against your rights and freedoms. You may object to such processing at any time (see Section VIII), and we will stop unless we can demonstrate compelling legitimate grounds.
V. Benchmarking and Aggregated Data
We produce industry benchmarks and trend reports. These are built exclusively from data that has been aggregated and anonymised so that no individual company, person, or facility can be identified or singled out, whether directly or in combination with other information available to us. Once anonymised, the resulting data is no longer personal data and falls outside the GDPR.
Where the underlying material was uploaded by a customer, our right to use it in this way is set out in our Terms of Service and Data Processing Addendum, not assumed unilaterally by us.
VI. Retention
We keep personal data no longer than necessary for the purpose it was collected for.
| Data | Retention period |
|---|---|
| Account and profile data | Duration of the contract, then 3 years (Czech limitation period for contractual claims) |
| Customer-uploaded content and generated reports | Duration of the contract, then deleted within 90 days unless you request earlier deletion or export |
| Invoices, accounting and tax records | 10 years from the end of the relevant tax period, as required by Czech VAT and accounting legislation |
| Application and security logs, IP addresses | 12 months |
| Support and sales correspondence | 3 years from the last interaction |
| Marketing contact data (consent-based) | Until consent is withdrawn, or 3 years of inactivity, whichever is sooner |
| Cookie data | As stated in the Cookie Policy |
Where data is retained for the defence of legal claims, we retain it until those claims are time-barred or finally resolved.
VII. Storage, Transfers and Sub-processors
Location. Customer data is stored on servers located within the European Union. Where a service provider offers a choice of hosting region, we select an EU region.
International transfers. We do not routinely transfer personal data outside the European Economic Area. Should a transfer become necessary, we will rely on an adequacy decision under Art. 45 GDPR or on Standard Contractual Clauses under Art. 46 GDPR, together with any supplementary measures required, and we will update our sub-processor list accordingly.
Sub-processors. We use third-party providers for cloud hosting, application infrastructure, artificial intelligence services used to extract data from uploaded documents, email delivery, customer relationship management, and payment and accounting. A current list of our sub-processors, including their function and location, is published at /en/subprocessors. Each is bound by a written agreement imposing data protection obligations no less protective than those we owe our customers.
AI services. Where we use artificial intelligence services to process uploaded documents, we contract on terms under which submitted content is not used to train the provider's models, and we select EU-based processing where the provider offers it.
We do not sell personal data.
VIII. Your Rights
Under the GDPR you have the right to:
- access your personal data and obtain a copy of it;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten"), where one of the grounds in Art. 17 applies;
- restrict processing in the circumstances set out in Art. 18;
- data portability — receive data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
- object to processing based on legitimate interest, including profiling, and to object at any time and without justification to processing for direct marketing;
- withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal;
- not be subject to a decision based solely on automated processing producing legal or similarly significant effects. We do not carry out such decision-making.
To exercise any of these rights, write to info@sustainly.tech. We will respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month.
Right to complain. You may lodge a complaint with the Czech Data Protection Authority: Úřad pro ochranu osobnÃch údajů, Pplk. Sochora 27, 170 00 Praha 7, www.uoou.cz. You may also complain to the supervisory authority in your country of residence or workplace.
IX. Data Protection Officer
We have assessed our processing against Art. 37 GDPR and have concluded that appointment of a Data Protection Officer is not mandatory. Privacy enquiries should be sent to info@sustainly.tech.
X. Security
We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, least-privilege administrative access, logging and monitoring, regular backups, and a documented incident response procedure. A summary of these measures is available in Annex 2 of our Data Processing Addendum.
XI. Cookies
Our use of cookies and similar technologies is described in our Cookie Policy. Non-essential cookies are set only with your consent, which you may withdraw at any time through the cookie settings on our website.
XII. Changes to This Policy
We may update this policy from time to time. Material changes will be notified to registered users by email or in-app notice at least 30 days before taking effect. The "last updated" date above always reflects the current version.
Questions regarding our privacy or legal terms?
Our compliance and data protection team is ready to assist you.
info@sustainly.tech