// privacy
Privacy Policy
How DUAL Software s.r.o. handles personal data under Regulation (EU) 2016/679 (GDPR) and Act No. 110/2019 Coll. on personal data processing.
In short
- We collect what you type into the two forms on this site, and nothing else.
- No analytics, no advertising pixels, no third-party scripts, no cookies used for tracking.
- We do not rely on consent for the forms, so there is no consent for you to withdraw — we rely on pre-contractual steps and legitimate interest, and you can object.
- Enquiry records are deleted 24 months after the last contact.
- Hosted by Hostinger Operations UAB on a server in Frankfurt am Main, Germany — inside the EEA.
1. Who is responsible for your data
The controller is DUAL Software s.r.o., a company incorporated in the Czech Republic, registration number (IČO) 25182145, VAT number (DIČ) CZ25182145, with its registered office at Polní 923, 373 41 Hluboká nad Vltavou, Czech Republic. You can check these details in the Czech business register (ARES).
For anything in this policy, write to privacy@dualsoftwaresro.com. We have not appointed a Data Protection Officer; Article 37 GDPR does not require one for processing of this kind and scale, and we would rather say so than imply an office that does not exist.
2. What we collect, why, and on what legal basis
We do not rely on consent for any of the processing below. That matters in a practical way: because consent is not the basis, there is no consent for you to withdraw, and you will not be asked to tick a box to use a form. What you get instead is this notice and a right to object.
Quotation requests (the configurator)
- Required — Article 6(1)(b) GDPR: company name, your name, your work email address, and the configuration you selected, together with the bill of materials our server derives from it. We cannot prepare a quotation without these, so processing them is necessary for steps taken at your own request before entering into a contract.
- Optional — Article 6(1)(f) GDPR: your telephone number and any message you add. These are not necessary to produce a quotation — we can answer everything by email — so we do not claim they fall under Article 6(1)(b). If you choose to give them, we process them on our legitimate interest in replying the way you invited us to, and you may object at any time under Article 21. Leaving them blank has exactly the same effect and does not affect your quotation.
- Why: to prepare a quotation and answer you.
- Why we split this out: "necessary for a contract" is a strict test. A field you are free to leave empty cannot be necessary, so describing the whole submission as Article 6(1)(b) would overstate the basis for the optional parts. The form, this policy and the API response all list the same fields, the same optionality and the same basis.
Contact form
- What, and whether you have to give it: your name, email address, the subject you choose and your message are required — without them we cannot reply. Your company name and telephone number are optional; the form works without them and we process them only if you choose to type them in.
- Why: to answer your enquiry.
- Basis: Article 6(1)(f) GDPR — our legitimate interest in answering enquiries addressed to us. That covers messages from consumers and from businesses alike: this form is also the route we ask consumers to use for complaints and warranty claims. Where your message is a data protection request, the basis is Article 6(1)(c) — our legal obligation to deal with it.
- The optional fields: where you choose to give a telephone number or a company name, those rest on the same Article 6(1)(f) interest — being able to answer you in the way you invited. You can object to it under Article 21, and simply leaving the fields blank has the same effect.
Abuse prevention
- What: a one-way hash of your IP address combined with the current date, and your browser's user-agent string. We do not store the address itself, and because the hash is salted with the date it stops being useful as an identifier after 24 hours.
- Why: to rate-limit the forms and to keep automated submissions out.
- Basis: Article 6(1)(f) — our legitimate interest in keeping the service working.
Server logs
The web server keeps standard access logs (IP address, time, requested URL, status code, user-agent) for a short period for security and diagnostics, under Article 6(1)(f). They are not linked to form submissions and are not used for analytics.
3. What we do not do
- No analytics or measurement products of any kind, first- or third-party.
- No advertising or remarketing pixels, and no conversion tracking script.
- No third-party fonts, maps, video embeds, chat widgets or CDNs — fonts are served from this domain, so loading a page contacts no other company.
- No profiling and no automated decision-making within the meaning of Article 22.
- No sale, rental or sharing of personal data for anyone else's marketing, ever.
- This describes the site as it is today, and it is enforced in the build: if a measurement or advertising tag ever appears in the published code while this page denies it, the release fails and does not ship. No such tag will be added without first updating this page and the cookie page, and introducing a consent mechanism that meets Section 89(3) of Act No. 127/2005 Coll. — the tag would then load only after consent is given, never before.
- No payment data. There is no checkout on this site; orders are invoiced against a written quotation.
4. How long we keep it
- Quotation requests and enquiries: 24 months from the last contact, then deleted.
- Records attached to a concluded sale: moved into our accounting records and kept for the statutory period — Act No. 563/1991 Coll. on accounting and the VAT Act require retention of accounting and tax documents for up to 10 years.
- Rate-limiting hashes: deleted automatically within 30 minutes.
5. Who else sees your data
Hosting — one processor, named. The website, this API and the database all run on a single virtual server operated by Hostinger Operations UAB, a company established in Lithuania. That server is physically located in Frankfurt am Main, Germany.
We checked this rather than assumed it. On the day the server was commissioned we verified its location from the machine itself — the regional internet registry (RIPE NCC) records the address block as German, the first upstream router on the route out of the server is in Frankfurt, and network latency from the server to Frankfurt is a fraction of a millisecond while the nearest non-European facility is over ninety times further away. We mention the method because a hosting statement written from a brochure rather than from the server is exactly the kind of claim that quietly becomes untrue.
Germany is a member state of the European Economic Area, so your data does not leave the EEA and there is no Chapter V transfer to disclose under Article 13(1)(f) — no standard contractual clauses, no adequacy decision and no other safeguard is needed, because no third country is involved. If that ever changes, this paragraph changes with it before the move happens.
Full list of processors — it is deliberately short, and this is all of it:
- Hostinger Operations UAB — Hosting of the website, the API and the database. Location: Germany (Frankfurt am Main datacentre); provider established in Lithuania.
- Hostinger Operations UAB — Inbound email to @dualsoftwaresro.com mailboxes (info@, sales@, support@, privacy@). Location: Hostinger Mail; provider established in Lithuania.
There is no content delivery network, no analytics provider, no CRM, no chat service, no marketing platform and no third-party form handler. Nothing about your visit is sent to any other company.
Inbound email. Messages you send to info@dualsoftwaresro.com, sales@dualsoftwaresro.com, support@dualsoftwaresro.com or privacy@dualsoftwaresro.com are received through Hostinger Operations UAB's mail service — the same legal entity as our hosting provider, established in Lithuania. That is listed above as a separate processor role and is not the same flow as the contact forms on this site.
Outbound form notifications. Automatic notification email from the website forms is currently disabled. Form submissions are written to our own database and read from there; no email provider is involved in delivering those notifications. If that changes, this paragraph will name the provider.
Beyond the above we disclose personal data only where we are legally obliged to — for example to a public authority acting within its powers — and to our accountants and legal advisers where a transaction requires it. Everyone in that group is bound by confidentiality.
6. Your rights
Under the GDPR you can ask us to:
- confirm what we hold about you and give you a copy (Article 15);
- correct anything inaccurate (Article 16);
- erase it, where one of the grounds in Article 17 applies;
- restrict how we use it while a dispute is resolved (Article 18);
- give you the data you provided in a portable format, where the processing is based on Article 6(1)(b) (Article 20);
- stop processing based on legitimate interest — you can object at any time under Article 21, and we will stop unless we can show compelling grounds that override your interests.
Write to privacy@dualsoftwaresro.com. We answer within one month, as Article 12(3) requires.
7. Complaints
If you think we have handled your data badly, please tell us first — most things are fixed faster that way. You also have the right to complain to the supervisory authority:
Úřad pro ochranu osobních údajů (Office for Personal Data Protection)
Pplk. Sochora 27, 170 00 Praha 7
https://uoou.gov.cz/
Consumer disputes about a purchase, as opposed to data protection, go to a different body — see Consumer rights.
8. Security
The site is served over HTTPS. Form submissions are validated on the server, stored in a database that is not exposed to the public internet, and the forms are rate-limited per source address. Access to the stored enquiries is limited to the people who need to answer them. No system is perfect, and we would rather describe what we actually do than claim a standard we have not been audited against.
9. Changes
If this policy changes materially — a new processor, a different retention period, a change in where data is hosted — we will update this page and the date below. This version is dated 2 September 2026.