Privacy Policy
Last updated: 2026-09-23
This Privacy Policy explains how personal data is processed in connection with Regulatory Gate (the “Service”).
1. Data controller
The data controller is:
AFINA, spol.s r.o.
Kaprova 42/14, 110 00 Praha, Czechia
Company registration number (IČO): 25056557
VAT number: CZ25056557
Data protection / GDPR contact: privacy@eucertify.eu
General support: support@eucertify.eu
Processing at a glance
The sections below give the full detail. This table summarizes it in one place: what we collect, why, on what legal basis, who else sees it, and for how long.
| Data category | Purpose | Legal basis | Recipients | Retention |
|---|---|---|---|---|
| Contact and inquiry data | Routing, evaluating and responding to your request | Steps at your request before a contract, where applicable; legitimate interest | AFINA team; WEDOS (hosting); AWS SES (email delivery) | Until the request is resolved, then only as reasonably needed for follow-up or legal claims |
| Account data | Registration, authentication | Performance of a contract | WEDOS (hosting only) | Duration of account + 2 years |
| Assessment data (intake, documents, reports) | Preparing your assessment | Performance of a contract | AFINA experts; WEDOS (storage); Anthropic (limited fields only, see below) | 5 years from submission |
| Technical & security data (sessions, audit log) | Security, fraud prevention, accountability | Legitimate interest | WEDOS (hosting only) | Sessions/logs up to 12 months; audit log 5 years |
| Legal-acceptance records | Evidence of accepted Terms/Privacy Notice version | Legitimate interest | WEDOS (hosting only) | 5 years |
| Order and billing/VAT data | Order fulfillment, invoicing, VAT treatment | Performance of a contract; legal obligation (accounting) | Stripe (payment only); WEDOS (hosting) | Same lifecycle as the related case (see “Assessment data” above) |
| Service analytics (aggregate, non-identifying) | Improving the Service | Legitimate interest | None (internal only) | Not linked to you — see “What we collect” below |
For the full list of who we work with and where — including precise roles and international-transfer basis — see the Subprocessor List.
2. What we collect
- Contact and inquiry data — your name, work email, organization (if provided), selected topic, subject and message when you use the contact form.
- Account data — email address, password (stored only as a salted hash), organization name and role.
- Assessment data — what you enter in the intake form (product description, intended purpose, claims, target markets, budget figures) and the documents you upload. See how documents are handled.
- Technical and security data — sign-in sessions (IP address and browser identifier) and an audit log of important actions such as sign-ins, submissions and document access.
- Service analytics — aggregate counts and durations about how the intake is used (for example: started, submitted, time to submit). These records deliberately contain no free text, documents or claims that you type.
- Anonymous website analytics — first-party counts of public page views, guide and tool clicks, Gate Snapshot calls to action and completed registrations. These events contain only the event type, public page path and date. They do not contain a cookie identifier, IP address, email, browser fingerprint or text you enter. A browser Do Not Track setting disables this collection.
- Order and payment data — the package, price and status of your order. Card details are entered with the payment provider (Stripe) and are not stored by us.
3. Purposes
- Routing, evaluating and responding to contact requests, including assessment and investor-pilot inquiries.
- Providing the Service: registration, authentication, your assessment and report.
- Service messages: verification, password reset, order and report notifications.
- Security, fraud prevention and troubleshooting.
- Compliance with legal obligations, including accounting.
- Preparing your Gate Snapshot and expert working summaries with AI assistance (see below).
AI-assisted preparation
When our experts prepare your free Gate Snapshot, a working summary of your intake, or a draft list of the requirements that apply to your product, an AI model drafts it. For that, we send the model only part of what you submitted: the product name and description, its composition, users and place of use, intended purpose and claims, manufacturer type, product stage, the kinds of evidence you have, target countries and sales channels, launch date, the decision you are seeking, and your answers about AI, radio and software or data connections.
We do not send your budget, price or revenue figures, your name, email address or organization, or your uploaded documents.
The AI produces a draft. An AFINA expert reviews it, can correct it, and decides what is released to you; nothing you see from us is decided by the AI alone, and no decision with legal or similarly significant effect on you is made by automated means. AI drafts are kept with your case record.
4. Legal bases
Depending on context, we process personal data based on one or more of: (i) steps taken at your request before entering a contract and performance of a contract, (ii) our legitimate interests (responding to inquiries, security, and improving the Service), (iii) consent, where applicable, and (iv) compliance with legal obligations.
5. Recipients
The AFINA experts assigned to your case see your assessment data. We also use the following service providers acting on our instructions. For the full picture — role, location and international-transfer basis for each one — see the Subprocessor List.
- WEDOS Internet, a.s. (Czech Republic) — VPS hosting for the servers running the Service, including storage of uploaded documents. All of this infrastructure is located in the EU.
- Amazon Web Services (AWS SES) — delivery of transactional emails (verification, password reset, order and report notifications) and contact-request notifications.
- Stripe — payment processing. Card details are entered with Stripe directly and are not stored by us.
AI provider. To help our experts prepare your free Gate Snapshot and summarise your intake, we use an AI model provided by Anthropic PBC, which acts as our processor on our instructions. See AI-assisted preparation above for exactly what is sent. Anthropic's commercial terms incorporate a Data Processing Addendum with Standard Contractual Clauses. Under Anthropic's standard API retention, inputs and outputs are deleted from its backend within 30 days, subject to limited exceptions for legal and misuse-prevention obligations. Anthropic does not use commercial API inputs or outputs to train its models by default.
Where required by law, we may disclose data to authorities.
6. Retention
We keep personal data only as long as necessary for the purposes above, unless the law requires longer:
- Contact and inquiry data: until the request is resolved, then only for as long as reasonably needed for follow-up, service administration or the establishment, exercise or defence of legal claims.
- Account data: for the duration of the account, plus 2 years after closure for legal and dispute-resolution purposes.
- Assessment data (intake answers, uploaded documents, reports, AI drafts and released Snapshots): 5 years from submission, to support warranty, regulatory and dispute-resolution obligations.
- Technical and web-server log data: up to 12 months.
- Records of data-deletion requests: 5 years, to demonstrate compliance.
- Security audit-log entries are immutable by design and are kept for 5 years, in line with assessment data.
- Legal-acceptance records (proof of which Terms/Privacy Notice version you accepted, and when) are immutable evidence of the same kind as the audit log, and are kept for the same period, 5 years.
7. Security
We apply technical and organizational measures to protect personal data, including encrypted connections, hashed passwords, access controls limited to the people working on your case, restricting uploads to document and image file types, and an audit log. No system is completely secure.
8. Your rights
Depending on your location you may have the right of access, rectification, deletion, restriction, objection, portability and withdrawal of consent. To exercise them, write to privacy@eucertify.eu.
9. Cookies and local storage
- Session cookie (HTTP-only) — keeps you signed in. Strictly necessary; no consent is required. Clearing it logs you out.
- Local storage — your browser may store one small preference: the package you selected on our website, until it is attached to your first case. It stays on your device.
We do not use advertising or analytics cookies, third-party trackers, or third-party fonts on this Service.
10. International transfers
We store your assessment data and uploaded documents in the European Union, and your uploaded documents are never sent outside it. Two providers may process data outside the EEA: our AI provider, Anthropic, which receives the limited intake content described above, and our payment provider, Stripe, which processes payment data. In both cases we rely on the safeguards in their data-processing terms, such as standard contractual clauses. Anthropic processes the limited API data in the United States under its Data Processing Addendum, which incorporates the EU Standard Contractual Clauses.
11. Supervisory authority
If you are in the EU/EEA and believe we process your personal data unlawfully, you may complain to the supervisory authority in your country. The lead supervisory authority for the operator is the Úřad pro ochranu osobních údajů (ÚOOÚ), the Czech Office for Personal Data Protection.
12. Changes
We may update this policy from time to time. The “Last updated” date above shows when the latest version became effective.