Legal

Privacy Policy

Effective 25 September 2026

This policy explains what personal data Liubomyr Manastyretskyi, a self-employed person (OSVČ) registered in the Czech Republic and trading as Vizitka ("Vizitka", "we", "us") collects when you visit vizitka.app, hold a Vizitka account, connect a coding agent to it, or write to us; why we collect it; who sees it; how long we keep it; and what you can ask of us. It also explains what happens to the data of people who visit a website one of our customers built with Vizitka.

Vizitka is run by one self-employed person, not a company, and that person is the controller of the data described here. We process personal data under the EU General Data Protection Regulation (GDPR) and Czech Act No. 110/2019 Coll., on the processing of personal data.

1. Who is responsible

The controller of the personal data described in this policy is:

  • Liubomyr Manastyretskyi, self-employed (OSVČ), trading as Vizitka

  • Place of business: Počernická 3492/1a, 100 00 Praha 10 - Strašnice, Czech Republic

  • Registration number (IČO): 24961370

  • Registered in the Trade Register (živnostenský rejstřík)

  • Email for privacy matters: [email protected]

2. Two roles: when we decide, and when a customer does

Vizitka is a platform on which customers build and publish their own websites. That gives us two different roles.

We are the controller for the data of people who visit vizitka.app and docs.vizitka.app, who join our waitlist, who hold a Vizitka account, who connect a coding agent to it, and who write to us. Sections 3 to 9 describe that processing.

We are a processor for the data of people who visit a website a customer publishes with Vizitka, for example somebody who fills in a contact form on a photographer's site. The customer who owns that site decides what is collected and why, and is the controller. We process that data only on the customer's instructions, under our Data Processing Agreement. Section 10 describes what that means for you as a visitor of such a site.

3. Visiting vizitka.app and the docs

When your browser requests a page from vizitka.app, docs.vizitka.app or any other address we serve, we process:

  • Server logs: your IP address, browser and device details (the user agent string), the address requested, the page you came from, the time, and how we answered. We use them to serve the page, keep the service secure, rate-limit abuse and diagnose faults. Legal basis: our legitimate interest in running a reliable and secure service (Article 6(1)(f) GDPR). Logs are kept for 14 days.

  • Cookies: a session cookie that protects forms against forgery, a language cookie if you choose a language, and a consent cookie once you have answered the cookie banner. None of them identifies you to us. The Cookie Policy lists every cookie we set.

  • Analytics: vizitka.app uses Google Analytics and Google Tag Manager to learn which pages are read and where visitors come from. They load only after you accept them in the cookie banner, which is shown where the law requires consent; if you reject, or do not answer, they are not loaded and no analytics cookie is set. Google then processes, on our behalf and under Google's data processing terms, your IP address (used for a rough location and not stored), the pages you view, your browser and device details, and a random identifier kept in the _ga cookies. We use the result as aggregate statistics about the site and for nothing else. Legal basis: your consent (Article 6(1)(a) GDPR), which you can withdraw at any time by deleting the consent cookie and answering the banner again.

  • Fonts: our pages use typefaces served by Google Fonts. When your browser fetches a font file, Google LLC receives your IP address and browser details, as with any file your browser downloads from a third party. Google does not set a cookie for this. Legal basis: our legitimate interest in showing the site as designed.

  • Edge network: every request reaches us through Cloudflare, which processes your IP address as our processor to deliver the page and block attacks.

4. Joining the waitlist

If you leave your email address on vizitka.app, we store it in a private list and use it for one thing: to tell you when access opens and, occasionally, what has changed in the product. Legal basis: your consent (Article 6(1)(a) GDPR), which you can withdraw at any time by emailing [email protected]; we then delete the address. Joining the waitlist creates no account. We keep the address until you withdraw, or until the waitlist is closed and everyone on it has been invited.

5. Your account and signing in with Instagram

5.1 What Instagram gives us

Vizitka accounts are created and opened with Instagram Login, a service of Meta Platforms Ireland Limited. When you continue with Instagram, Meta sends us:

  • your Instagram user id, username and name;

  • your account type (business or creator);

  • your follower count and the number of posts on the account;

  • the address of your profile picture, which we show on screen and do not store;

  • an access token that lets us confirm it is still you the next time you sign in.

We use this data to create your account, to sign you in, to name your first site after your account and to show which Instagram account is connected. Legal basis: performance of our contract with you (Article 6(1)(b) GDPR).

We do not read your posts, stories, comments, messages or insights, and we do not post, comment or message on your behalf. Meta's own handling of your data is described in Meta's Privacy Policy, which applies to Meta and not to us.

You can revoke our access at any time by removing Vizitka under "Apps and websites" in your Instagram settings, or by disconnecting Instagram on the Account screen of the dashboard. The Data Deletion page explains how to have everything we hold from Instagram removed.

5.2 Account details

Your account also holds the email address you give us, the name of your organization, the sites in it, and the members you invite. We use these to run your account, to send you service messages such as a notification that a form on your site was submitted, and to contact you about your account. Legal basis: performance of our contract with you. We do not send marketing email to account holders without asking first.

5.3 Sign-in sessions

Each time you sign in we record the IP address and browser you signed in from, and when. We use this to secure your account and to show you where you are signed in. Legal basis: our legitimate interest in account security. A session lasts until you sign out or delete your account, and is deleted with it.

6. What you build

Everything you create in Vizitka is stored so that we can publish it: pages and templates, the stylesheet, scripts, files you upload, tables and their rows, workflows, translations, connected domains and integration settings. Each change is kept in a version history that records who made it, when, and through which client (the dashboard or the name of a coding agent), so that you can restore an earlier version and see what an agent did. Legal basis: performance of our contract with you.

Content stays for as long as the site exists. Older published versions of a page beyond the newest fifty are removed after ninety days, and the history of workflow runs is kept for thirty days. When you delete a site, or your whole account, its content is deleted, as Section 8 describes.

7. Connecting a coding agent

You can let a coding agent (a program such as Claude Code, ChatGPT or another client that speaks the Model Context Protocol) work on your sites. When you authorize one, we store the name of the client, the scopes you granted, and when the connection was made and last used. The agent can then read and change your sites within the scopes you granted, except that it can never read the rows of a private table, such as the enquiries visitors sent you. Legal basis: performance of our contract with you, since the connection is one you asked for.

The agent's own provider, not Vizitka, runs the model and processes whatever the agent reads, under that provider's terms. We do not run AI models ourselves and send nothing to one.

An agent may file a feature request with us on your behalf. The text of that request, the identifier of your site and the path of the page it concerns are recorded with GitHub, Inc., where we keep track of our development work, so that we can build what was asked for. Legal basis: our legitimate interest in developing the product. Please do not put personal data in a feature request. Feature requests are kept as part of our development records.

You can revoke an agent at any time on the Account screen of the dashboard. Revoking an agent invalidates every token it holds.

8. Deleting a site or your account

You can delete any site you own from the Site screen of the dashboard, and your whole account from the Account screen. Deleting a site removes its pages, versions, tables and rows, uploaded files, workflows, domains and integrations from our live systems, and releases any custom domain connected to it. Deleting your account removes your account, your sign-in sessions, your Instagram connection, the agents you connected, and every organization you alone own together with its sites.

Some traces outlive a deletion for a bounded time: server logs for 14 days and error reports for 90 days, both described elsewhere in this policy, and the change history of a site's table rows, which we remove within 30 days of the site's deletion. Issues already filed from your feature requests stay in our development records.

9. Other processing for our own purposes

  • Error reports. When something breaks, technical details of the failing request, including your IP address and, if you are signed in, your user id, are sent to Sentry, an error monitoring service run by Functional Software, Inc., and stored in its European Union region. Legal basis: our legitimate interest in finding and fixing faults. Error reports are kept for 90 days.

  • Email we send. Service email, such as the notification that a form on your site was submitted, is delivered through Brevo (Sendinblue SAS, France), which receives the recipient address and the message in order to deliver it.

  • Email you send us. When you write to us, we keep the correspondence for as long as we need it to answer you and for our records, normally no longer than three years. Our mailboxes are hosted by Google Workspace.

  • Payments. During early access there is nothing to pay. When paid plans launch, payment will be handled by a payment provider we will name on the Subprocessors page and at checkout before the first payment is taken; it will collect your payment details and billing address itself, and we will receive your plan, its status, your billing country and the invoices. We keep invoices and payment records for as long as Czech tax and accounting law requires, which is up to ten years. Legal basis: performance of the contract, and compliance with a legal obligation (Article 6(1)(c) GDPR).

  • Abuse prevention. We count requests per IP address for a short time to stop floods and form spam. The counters are not kept beyond the window they measure.

  • Legal claims and obligations. We may keep or disclose data where the law requires it or where it is necessary to establish, exercise or defend a legal claim. Legal basis: compliance with a legal obligation, or our legitimate interest in defending our rights.

We do not sell personal data, we do not use it for advertising, and we make no decisions about you by automated means that have legal or similarly significant effects.

10. If you visit a website built with Vizitka

Websites at addresses ending in .vizitka.page, and websites on our customers' own domains, are built and published by our customers. The customer who owns the site is the controller of the data collected there, and their own privacy notice, if they publish one, applies. Vizitka processes that data as the customer's processor:

  • Content and forms. Whatever a form on the site asks for is stored in the site's tables and shown to the site's owner and the members they invite. We do not read it for our own purposes, and coding agents connected to the site cannot read private tables at all. Submissions stay until the owner deletes them or deletes the site.

  • Server logs and the edge network work as in Section 3, for the same 14 days.

  • Cookies. A site sets the session and language cookies listed in the Cookie Policy. If the owner has connected Google Analytics or Google Tag Manager, those tags are loaded only after you accept them in the site's cookie banner, where consent is required.

  • Workflows. A site's owner may set up automation that sends a submission to another service they choose. That is the owner's decision and disclosure to make.

To exercise your rights over data a customer's site collected about you, contact the site's owner. If you cannot reach them, write to [email protected] and we will pass the request on and help the owner answer it.

11. Who else sees your data

We share personal data only with providers that process it on our behalf under a contract, with Meta when you sign in with Instagram, and with authorities when the law requires it. Our current providers are:

Provider

What for

Where

Hetzner Online GmbH

Hosting

Germany, Finland

Cloudflare, Inc.

Delivery of our pages, protection against attacks, file storage

Global network; United States

Functional Software, Inc. (Sentry)

Error monitoring

Stored in Sentry's European Union region; the company is in the United States

Brevo (Sendinblue SAS)

Delivery of service email

France, European Union

GitHub, Inc.

Feature requests sent by coding agents

United States

Google LLC and Google Ireland Limited

Fonts on our pages; Google Analytics and Google Tag Manager on vizitka.app, after your consent; business email (Google Workspace)

United States; European Union

Meta Platforms Ireland Limited

Instagram Login (Meta acts as an independent controller)

Ireland; United States

Our payment provider, once paid plans launch

Payment processing; named on the Subprocessors page and at checkout before it is used

To be announced

The Subprocessors page keeps this list current, with the safeguard each transfer relies on. If the Vizitka business is ever transferred to a company or to another owner, your data may pass to them under this policy, and we will tell you before that happens.

12. Transfers outside the European Economic Area

Our servers and database are in the European Union. Some of the providers above are in the United States or run global networks. Where personal data leaves the European Economic Area, we rely on the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework for providers certified under it, and otherwise on the Commission's Standard Contractual Clauses, together with the safeguards in each provider's data processing agreement. The Subprocessors page names the mechanism for each provider. You can ask us for a copy of the relevant clauses.

13. How long we keep data

Data

Kept for

Server logs

14 days

Error reports

90 days

Waitlist email address

Until you withdraw, or the waitlist closes and you have been invited

Account, organization and Instagram connection

Until you delete your account

Sign-in sessions

Until you sign out or delete your account

Agent connections

Until you revoke them or delete your account

Site content and uploads

Until you delete the site or your account

Older published versions of a page (beyond the newest fifty)

90 days

Workflow run history

30 days

Change history of a site's table rows

Until 30 days after the site is deleted

Feature requests

As part of our development records

Correspondence with you

Up to 3 years

Invoices and payment records

Up to 10 years, as tax and accounting law requires

14. How we protect data

We protect personal data with technical and organisational measures suited to the risk, including encryption and access limited to the people who run the service. If we learn of a breach that puts your rights at risk, we will notify the supervisory authority and, where the law requires it, you, without undue delay.

If you find a security problem, please tell us at [email protected].

15. Your rights

You have the right to ask us for access to the personal data we hold about you, to have it corrected or deleted, to restrict or object to its processing, and to receive the data you gave us in a portable form. Where we rely on your consent, you can withdraw it at any time, without affecting what was done before.

Much of this you can do yourself in the dashboard: edit your details, disconnect Instagram, revoke an agent, delete a site, or delete your account. For everything else, email [email protected]. We may ask you to confirm that you are the person the data is about. We answer within one month, and tell you if we need longer.

If you believe we have handled your data unlawfully, you can complain to the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, www.uoou.cz, or to the supervisory authority where you live or work. If you are in Ukraine, you may also contact the Ukrainian Parliament Commissioner for Human Rights, who supervises personal data protection there.

16. Children

Vizitka is a service for businesses and is not directed at children. You must be at least 18 years old to hold an account. We do not knowingly collect personal data from anyone under 16; if you believe we have, write to [email protected] and we will delete it.

17. Changes to this policy

When we change this policy we publish the new version here with a new effective date. If a change matters to you, for example a new purpose or a new category of provider, we will tell account holders in the dashboard or by email before it takes effect.

18. Contact

Liubomyr Manastyretskyi, self-employed (OSVČ), trading as Vizitka. Place of business: Počernická 3492/1a, 100 00 Praha 10 - Strašnice, Czech Republic. Privacy matters: [email protected]. Everything else: [email protected].