Privacy

Privacy policy

Clear information about what personal data we process, why we process it, who helps us process it, how long we keep it and how you can use your GDPR rights.

Effective from: 8 September 2026

Data controller

Anton Čeremnych

Registered office: Cesta brigádníků 819, Kralupy nad Vltavou, 278 01, Czechia

Identification number: 04560540

Czech Republic

Use these details for privacy questions, GDPR rights requests and requests about how a proposal or form submission is handled.

Who this policy covers

This policy explains how mnyx labs processes personal data when you visit this website, send a project brief, request contact, receive or respond to a private proposal, or communicate with us about services. For client delivery work, mnyx labs may also act as a processor under a separate contract or data processing agreement.

Personal data we process

Contact and enquiry data

Name, company, email address, phone number, preferred contact time, project context, message content and any links or files you choose to send.

Proposal and client data

Client records, proposal titles, offer codes, selected contact admin, proposal status, expiry date, price strings, screenshots uploaded for a proposal, feedback messages and limited viewing-session records needed to keep private proposal links controlled.

Website and security data

IP address, approximate technical request data, browser and device information, security logs, Cloudflare Turnstile verification results and similar data needed to keep forms and private links reliable.

Analytics data

When analytics is enabled, mnyx labs uses privacy-focused website analytics to understand aggregate traffic and page usage. We do not use advertising profiling on this website.

Why we process data and the legal basis

Answering enquiries and preparing scope

We process enquiry and contact data to respond to your request, understand the work and prepare a proposal. The legal basis is taking steps before a contract and, where the request is not yet contractual, our legitimate interest in replying to relevant business enquiries.

Delivering services and managing client work

We process client and project data to deliver agreed services, manage communication, issue proposals and keep necessary project records. The legal basis is contract performance and our legitimate interest in running a small software studio responsibly.

Security, abuse prevention and private links

We process technical and verification data to protect forms, prevent spam, limit abuse, maintain private proposal sessions and diagnose service problems. The legal basis is our legitimate interest in securing the website and services.

Accounting, tax and legal duties

Where invoices, contracts or legally relevant communications must be retained, we process the necessary records to comply with legal obligations.

Analytics and improvement

We use analytics only where configured for the site and only to understand aggregate usage and improve the website. Non-essential cookies or similar technologies are used only when the applicable consent rules allow them.

Cookies and similar technologies

The website may use strictly necessary cookies or similar storage for security, language, session and form protection. Private offer pages use a viewing session so a link sent to one recipient does not become an uncontrolled public page. Cloudflare Turnstile helps verify that public forms are not automated abuse. If non-essential analytics cookies or similar technologies are introduced, they must be disabled until valid consent is given and must remain easy to refuse or withdraw.

Who receives data

Personal data is shared only where needed: hosting and infrastructure providers, Cloudflare for bot protection, analytics infrastructure when enabled, the mnyx backend and notification channel used to deliver form submissions, professional advisers when necessary, public authorities where required by law, and subcontractors who help deliver agreed work under confidentiality and data protection obligations.

International transfers

We prefer providers and processing locations in the EU or EEA where practical. If personal data is transferred outside the EU or EEA, we use an appropriate GDPR transfer mechanism such as an adequacy decision, standard contractual clauses or another lawful safeguard.

How long we keep data

Enquiries

Briefs and contact messages are normally kept for up to 24 months after the last meaningful contact, unless a longer period is needed because the enquiry becomes client work or a dispute requires preservation.

Client and contract records

Project, contract, invoice and tax records are kept for the period required by Czech and EU law and for the limitation periods needed to establish, exercise or defend legal claims.

Private proposals

Proposal records are kept while the offer is active and afterwards for client history, auditability and legal claim purposes. Private viewing sessions are short-lived and are used only to control concurrent access and release the viewing slot when the page is closed.

Security and technical logs

Security and diagnostic logs are kept only as long as needed for reliability, security and incident investigation, unless a specific incident requires longer retention.

Your GDPR rights

You may ask for access to your personal data, correction, deletion, restriction of processing, portability, objection to processing based on legitimate interests, and withdrawal of consent where processing is based on consent. You also have the right not to be subject to a solely automated decision with legal or similarly significant effects. mnyx labs does not make such automated decisions on this website.

How to exercise your rights

Send a request through the contact details on this page or through the contact form. We may ask for information needed to verify your identity and will respond without undue delay, normally within one month. If you believe your rights have not been respected, you can complain to the Czech supervisory authority: Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, Czech Republic.

Children

This website and mnyx labs services are intended for business use. We do not knowingly target or request personal data from children.

Changes to this policy

We update this policy when the website, services, providers or legal requirements change. The current version is published on this page with its effective date.

Supervisory authority

For Czech data protection supervision, you can contact Úřad pro ochranu osobních údajů. Their website provides current guidance and complaint information.

Open uoou.gov.cz