Privacy Policy
Aenze s.r.o. explains here how personal data is used when you visit, register for, pay for, administer, or contact FoxDesk Cloud. Customer workspace content is covered by the customer agreement and DPA. This policy does not apply to the separately operated self-hosted edition.
Who is responsible
Aenze s.r.o., Company ID 28534395, VAT ID CZ28534395, registered in the Commercial Register maintained by the Municipal Court in Prague, file C 148584, with registered office at Moskevská 1842, 272 04 Kladno, Czech Republic, is the controller for website visits, signup, accounts, billing, service security, support, and our own business records. For personal data in a customer workspace, the customer is normally the controller and we act as its processor.
Data we receive
We may process account and contact details; company, workspace and role details; billing, invoice and tax details; legal-acceptance records; support and billing communications; login, IP, device, browser and security records; email-delivery and inbound-routing metadata; service settings; product usage and automation records; and customer workspace content such as organisations, contacts, tickets, comments, internal notes, attachments, time entries and reports. Payment card details are entered into the payment provider’s hosted service and are not stored by FoxDesk.
Where data comes from
Data comes from you, your workspace owner or administrator, other authorised workspace users, people who email a workspace address, service providers involved in hosting, delivery, security and billing, and technical collection when a browser, email system, API client or integration connects to FoxDesk. Where a customer supplies another person’s data, that customer is responsible for the required legal basis and notice.
Purposes and legal bases
We use account, workspace and service data to provide and administer the contract; billing and tax data to perform the contract and comply with legal duties; security, access, delivery and abuse-prevention data for our legitimate interests in protecting a business service and its customers; support communications to perform the contract and respond to requests; legal-acceptance and dispute records for contract evidence and legal claims; and optional communications or technologies on consent where the law requires consent. Customer workspace content is processed on documented customer instructions under the DPA.
Our legitimate interests
Our legitimate interests are preventing fraud and abuse, securing accounts and infrastructure, diagnosing failures, maintaining reliable service, understanding aggregate product operation, enforcing agreements, and establishing, exercising or defending legal claims. We balance those interests against the affected person’s rights and use proportionate access, retention and minimisation controls. You may object as described below.
Required data and consequences
An email address, essential account identifiers, security data and acceptance of the customer documents are required to create and operate a workspace. Billing and tax information is required only when a paid subscription is purchased. Without required data we cannot create the account, provide the requested feature, process payment, or meet a legal duty. Optional fields are identified by the interface or can be left blank.
Cookies, local storage and measurement
FoxDesk uses strictly necessary session and security cookies to sign users in and protect requests. An optional remember-me token lasts up to 30 days unless revoked sooner. Theme or interface preferences may be stored locally in the browser. We do not use advertising cookies. The application records limited first-party page-view data for up to 90 days, and the public website may record allowlisted conversion events without storing full URLs, free text, email addresses, IP addresses or user-agent strings in the marketing-event payload. If non-essential cookie-based analytics are introduced, we will provide any consent mechanism required by law before using them.
Recipients and service providers
Authorised members of our team and the customer’s authorised users receive data according to their roles. We use service providers for hosting, content delivery, security, storage, email routing and delivery, payment and tax processing, and professional accounting or legal support. The current operational provider list is published on the Subprocessors page. We may also disclose data where required by law, to protect rights and security, or in a corporate transaction subject to appropriate safeguards. We do not sell personal data or customer workspace content.
International transfers
We select European processing locations where practical. If a provider processes personal data outside the European Economic Area, we use a lawful transfer mechanism where required, such as an adequacy decision, the EU Standard Contractual Clauses, or another valid safeguard, together with supplementary measures where appropriate. Contact [email protected] to request information about the safeguard relevant to your data.
Retention
Workspace content is retained while the workspace is active. After a verified termination or deletion request, we provide a reasonable export window, normally 30 days, and then schedule production deletion unless law, security, payment, dispute or customer instructions require otherwise. Routine database backups currently expire after 14 days; data already deleted from production may remain inaccessible in a backup until that cycle completes. Expired trial data may be deleted after 90 days. First-party application page views are deleted after 90 days. Billing, tax and accounting records are kept for the statutory period, commonly five or ten years depending on the record. Contract acceptance, security, support and dispute records are kept only as long as reasonably needed for contract evidence, security investigations, legal duties and applicable claim periods.
Automated processing
FoxDesk may automatically detect abuse, apply rate or automation limits, route email, and change access after trial expiry or payment failure according to configured rules. We do not use personal data for solely automated decisions that produce legal or similarly significant effects on individuals. A workspace administrator may contact support to request human review of an access, billing or abuse decision.
Your rights
Where GDPR applies, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. Requests about workspace content should normally be sent first to the customer that controls that workspace; we assist that customer under the DPA. Contact [email protected]. We may verify identity and will respond within the legally required period.
Complaints
You may complain to the data-protection authority where you live, work, or believe an infringement occurred. Our lead contact is Office for Personal Data Protection of the Czech Republic (ÚOOÚ), Pplk. Sochora 27, 170 00 Prague 7, https://uoou.gov.cz. We invite you to contact us first so we can investigate promptly.
Children and sensitive data
FoxDesk Cloud is a business service and is not directed to children. Customers must not intentionally upload payment card numbers, passwords, special-category data, criminal-offence data, national identifiers, medical data, or other highly sensitive regulated information unless we have expressly agreed in writing that the service and safeguards are suitable.
Nothing in these documents excludes a statutory duty, remedy, or right that applicable mandatory law does not permit the parties to exclude or limit.