PERSONAL DATA PROCESSING AND PRIVACY POLICY

1. Introductory Provisions

1.1. This Personal Data Processing and Privacy Policy (hereinafter referred to as the “Policy”) explains how Rac Development s. r. o. processes personal data in connection with the Fynode software platform, the related websites, and associated services, integrations, APIs, automations, and artificial intelligence features.

1.2. This Policy applies in particular to:

1.3. Where we process the personal data of our Customer’s customers, employees, suppliers, or other persons solely on the Customer’s behalf and in accordance with its instructions, we act as a processor. In such a case, the relevant Customer is primarily responsible for determining the purposes and legal bases of the processing and for fulfilling the information obligations towards data subjects.

1.4. Capitalised terms not defined in this Policy have the meanings assigned to them in the General Terms and Conditions of the Fynode Service.

2. Controller and Contact Details

2.1. The personal data controller is:

Rac Development s. r. o. registered office: Karpatské námestie 7770/10A, 831 06 Bratislava – Rača borough, Slovak Republic Company ID No.: 56 692 293 Tax ID No.: 2122393053 registration: Commercial Register of the Bratislava III Municipal Court, Section Sro, File No. 184241/B e-mail: info@fynode.com website: www.fynode.com hereinafter referred to as the “Provider”, “we”, or the “controller”.

2.2. Questions, requests, and objections concerning personal data protection may be sent to info@fynode.com or to the address of our registered office.

2.3. If we have not appointed a data protection officer under Article 37 of the GDPR, the e-mail address specified above serves as the contact point for personal data protection matters and does not designate a data protection officer within the meaning of the GDPR.

3. Legal Framework

3.1. We process personal data primarily in accordance with:

3.2. Depending on the purpose, we process personal data on the basis of:

4. Data Processed During Registration and Account Management

4.1. When creating and managing an Account, we may process in particular:

4.2. We process this data for the purposes of:

4.3. The legal basis is the performance of the Agreement, taking steps prior to entering into the Agreement, and our legitimate interest in the secure management of the Service, demonstrating communications, and protecting our rights.

4.4. If the Customer creates an Account for its employee or another authorised person, we may obtain the relevant identification and contact details from the Customer or the administrator of its Account.

5. Orders, Payments, and Billing

5.1. When ordering and paying for the Service, we may process in particular:

5.2. As a rule, we neither process nor store complete payment card details. These are processed by the relevant payment service provider. We may receive limited information, such as the payment status, transaction identifier, card type, last digits of the card, or its expiry date.

5.3. We process the data for the purposes of:

5.4. The legal basis is the performance of the Agreement, compliance with legal obligations, and our legitimate interest in protecting our assets, preventing fraud, and enforcing legal claims.

6. Communications, Customer Support, and Business Enquiries

6.1. If you contact us by e-mail, form, telephone, through the Application, or via another communication channel, we may process:

6.2. We process the data for the purposes of:

6.3. The legal basis is taking steps prior to entering into a contract, the performance of the Agreement, or our legitimate interest in communicating with customers, providing support, improving the Service, and protecting legal claims.

6.4. If a message sent to customer support contains personal data that we process exclusively on behalf of the Customer, we process such data as a processor in accordance with the Customer’s instructions.

6.5. The Customer should not disclose more personal data through customer support than is necessary to resolve the request. Specially protected or sensitive data should not be sent unless this is necessary and has been agreed in advance.

7. Technical, Operational, and Security Data

7.1. When you visit a website or use the Service, we may automatically obtain:

7.2. We use this data primarily to:

7.3. The legal basis is the performance of the Agreement and our legitimate interest in the secure, stable, and efficient operation of the Service, the protection of data, the prevention of misuse, and the protection of legal claims.

7.4. If technical logs contain personal data originating from the Customer’s systems, depending on the circumstances, we may also process such data as a processor.

8. Integrations and Connected Services

8.1. If the Customer connects the Service to an online store, accounting or ERP system, marketplace, carrier, payment service, bank, e-mail service, API, or another Connected Service, we may obtain:

8.2. We use authentication data to establish and operate the integration, carry out the Customer’s instructions, and protect the connection.

8.3. The provider of a Connected Service may process personal data as an independent controller or processor, depending on its terms and its role in the specific processing. The Customer is also required to familiarise itself with the privacy terms of the relevant third party.

8.4. If we transfer data between Connected Services solely in accordance with the Customer’s configuration and instructions, we act as a processor in relation to such data.

9. E-mail Features

9.1. If the Customer activates an e-mail account connection or e-mail features, depending on the Customer’s settings, the Service may:

9.2. In such processing, we generally act as the Customer’s processor. The Customer is responsible for establishing the legal basis for access to e-mail communications, informing data subjects, configuring permissions, and ensuring the appropriate use of automation.

9.3. We may process the contents of e-mail communications for our own purposes only to the extent necessary to ensure security, diagnose an issue, comply with a legal obligation, or protect legal claims, depending on the circumstances on the basis of a legal obligation or legitimate interest.

10. Artificial Intelligence Features

10.1. The Service may use artificial intelligence for text generation, translations, searches, recommendations, analysis of products, Orders or statistics, communication processing, chatbots, AI Mailer, AI agents, and other automated features.

10.2. Depending on the feature and the Customer’s settings, AI features may process in particular:

10.3. If an AI feature processes the personal data of the Customer or its customers in accordance with the Customer’s instructions, we generally act as a processor. The Customer determines the purpose, scope of data, permissions, instructions, and level of automation.

10.4. To operate AI features, we may use external providers of AI models, cloud infrastructure, or technical tools as sub-processors. Providers and models may change depending on availability, security, quality, price, and legal requirements.

10.5. We do not provide data to external AI providers for the independent training of their generally available models unless this has been transparently disclosed in advance, is legally permitted, and is covered by the relevant legal basis or the Customer’s instructions.

10.6. To improve the Service, we may use anonymised or aggregated data from which neither a natural person nor a specific Customer can be identified.

10.7. AI outputs may contain personal data if such data formed part of the input data or the available context. The Customer is required to configure access permissions so that the AI feature only has access to the data necessary for the specified purpose.

10.8. Special categories of personal data, data concerning criminal offences, or other exceptionally sensitive data should not be entered into AI features unless the relevant feature is expressly designed for such processing and the necessary legal, contractual, and security measures have been implemented.

11. Analytics and Improvement of the Service

11.1. We may analyse how the websites and the Service are used for the purposes of:

11.2. If analytics use or access information stored on an end device and do not constitute essential technical functionality, we perform such analytics on the basis of consent granted through the cookie management tool.

11.3. We may carry out basic operational and security analytics necessary for the operation and protection of the Service on the basis of our legitimate interest without using optional cookies.

11.4. Where possible, we use aggregated or pseudonymised data for analytical and statistical purposes.

12. Commercial Communications and Marketing

12.1. We may process personal data for:

12.2. We send marketing communications:

12.3. Each marketing e-mail contains an unsubscribe option or information about another simple method of objecting.

12.4. Withdrawal of consent or an objection to direct marketing does not affect the sending of essential operational, security, billing, or contractual communications.

12.5. We may retain a record that a person does not wish to receive marketing communications to ensure that their choice is respected.

13. Cookies and Similar Technologies

13.1. Our websites and the Application may use cookies, local storage, pixels, SDKs, and similar technologies.

13.2. Depending on their purpose, we may use:

13.3. We use essential cookies without consent to the extent permitted by law. We use preference, analytics, and marketing cookies on the basis of consent where consent is required.

13.4. Current information about the cookies used, their providers, purposes, and storage periods is provided in the cookie management tool available on the relevant website.

13.5. Consent may be changed or withdrawn at any time through the cookie settings. The withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

13.6. Cookies may also be managed through browser settings. Blocking essential cookies may cause certain features to become unavailable or not function properly.

14. Social Networks and External Websites

14.1. We may operate profiles on social networks and process data concerning persons who interact with them, in particular profile identifiers, publicly available information, reactions, comments, and messages.

14.2. We process the data for the purposes of communication, support, building business relationships, and promoting the Service, on the basis of our legitimate interest or consent where required.

14.3. The operator of a social network may process personal data for its own purposes in accordance with its terms. In the case of certain statistical features, we and the platform operator may act as joint controllers to the extent determined by applicable law and the platform’s terms.

14.4. Our websites may contain links to third-party websites. We are not responsible for their privacy policies or personal data processing practices.

15. Suppliers, Business Partners, and Applicants

15.1. In our relationships with suppliers and business partners, we may process identification, contact, employment-related, contractual, billing, and communication data concerning their representatives and contact persons.

15.2. The legal basis is the performance of a contract, compliance with legal obligations, and our legitimate interest in managing business relationships and protecting legal claims.

15.3. If a person applies for employment or cooperation, we may process their CV, contact details, information about their education and experience, and other data provided as part of the selection process.

15.4. We process applicant data for the purposes of the selection process on the basis of taking steps prior to entering into a contract. The retention of data for future selection processes is based on consent.

16. Fynode as a Processor

16.1. Through the Service, the Customer may process personal data originating in particular from:

16.2. Such data may include, in particular, names, contact details, addresses, Orders, purchase history, billing and shipping information, communication content, customer identifiers, and technical data.

16.3. If the Customer determines the purposes and essential means of such processing, the Customer is the controller and we are its processor.

16.4. As a processor, we:

16.5. The detailed processing terms pursuant to Article 28 of the GDPR form part of the General Terms and Conditions of the Fynode Service.

16.6. Data subjects whose data we process exclusively on behalf of the Customer should primarily contact the relevant Customer to exercise their rights. If we receive such a request, we will forward it to the Customer or provide the Customer with reasonable assistance, unless the law requires us to follow a different procedure.

17. Sources of Personal Data

17.1. We obtain personal data primarily:

17.2. If the Customer provides us with the personal data of other persons, the Customer is responsible for ensuring that it obtained and disclosed such data lawfully and provided the data subjects with the necessary information.

18. Recipients of Personal Data

18.1. We may disclose personal data, only to the extent necessary, to the following categories of recipients:

18.2. Not every recipient is a processor. Certain recipients may act as independent controllers, in particular banks, payment service providers, public authorities, legal advisers, or operators of certain Connected Services.

18.3. We require processors to undertake appropriate contractual obligations concerning data protection, confidentiality, security, and the use of data solely in accordance with our instructions.

18.4. We may make an up-to-date list of significant sub-processors available on the website, in the Application, or upon request, provided that doing so does not compromise the security or confidentiality of our systems.

19. Transfers to Third Countries

19.1. We primarily use providers and locations within the European Economic Area. However, certain providers, particularly providers of cloud, analytics, communication, or AI services, may also process data outside the European Economic Area.

19.2. We will only transfer data to a country outside the European Economic Area where a valid legal mechanism exists, in particular:

19.3. Where necessary, we assess the risks associated with the transfer and implement supplementary contractual, technical, or organisational measures.

19.4. Information about the applicable transfer mechanism or a copy of the relevant safeguards may be requested using the contact details specified in Article 2, while we may protect trade secrets and security-related information.

20. Retention Periods

20.1. We retain personal data only for as long as necessary for the purpose for which it was obtained or for the period required by law.

20.2. In general, we apply the following retention periods in particular:

20.3. We retain data processed as a processor for the duration of the Agreement and subsequently in accordance with the Customer’s instructions, the General Terms and Conditions, and technical deletion cycles.

20.4. Data in backups is deleted as part of regular backup overwrite cycles. Until deletion, such data remains protected and is not used for ordinary operational purposes.

20.5. We may extend the retention period where necessary to comply with a legal obligation, investigate a security incident, resolve a dispute, or establish, demonstrate, or defend a legal claim.

20.6. After the applicable retention period expires, we delete or anonymise the data unless its continued retention is required by law.

21. Personal Data Security

21.1. We implement appropriate technical and organisational measures corresponding to the nature, scope, context, and purposes of processing, as well as the likelihood and severity of the risks.

21.2. Depending on the circumstances, the measures may include in particular:

21.3. Specific measures may change depending on developments in technology, threats, and the Service. For security reasons, we do not disclose details that could facilitate the circumvention of protective mechanisms.

21.4. No system can be considered absolutely secure. Customers and Users are required to protect their login credentials, use reasonably secure passwords, configure appropriate permissions, and notify us without undue delay of any suspected unauthorised access.

22. Automated Decision-Making and Profiling

22.1. When processing personal data for our own purposes, we generally do not carry out decision-making based solely on automated processing that produces legal effects concerning a data subject or similarly significantly affects the data subject within the meaning of Article 22 of the GDPR.

22.2. We may carry out limited automated analysis for security, misuse detection, User experience personalisation, analytics, or marketing purposes. Such processing generally does not produce legal or similarly significant effects.

22.3. Customers may configure AI features or automations through the Service that process the data of their customers or other persons. In such a case, the Customer determines the purpose and rules of the processing and is responsible for assessing whether it constitutes automated decision-making under Article 22 of the GDPR, as well as for ensuring the appropriate legal basis, information, human intervention, and other rights of data subjects.

22.4. If we introduce automated decision-making for our own purposes that produces legal or similarly significant effects, we will provide data subjects with the information required by the GDPR, including information about the logic involved, the significance, and the envisaged consequences of the processing.

23. Mandatory or Voluntary Provision of Data

23.1. The provision of personal data is generally voluntary. However, certain data is necessary to:

23.2. If the necessary data is not provided, we may be unable to enter into the Agreement, create an Account, process an Order, or provide the requested Service.

23.3. The provision of data for optional analytics or marketing is voluntary, and refusal to grant consent does not affect the basic use of the paid Service.

24. Rights of Data Subjects

24.1. Subject to the conditions laid down in the GDPR, you have the right to:

24.2. The withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

24.3. The right to erasure is not absolute. We may not be required to erase data where its processing is necessary, in particular, to comply with a legal obligation, exercise the right to freedom of expression and information, or establish, demonstrate, or defend legal claims.

24.4. We will assess an objection to processing based on legitimate interest according to the specific circumstances. We may continue processing if we demonstrate compelling legitimate grounds that override the data subject’s rights or if the processing is necessary for legal claims.

24.5. We will comply with an objection to direct marketing without further assessment and will cease using the data for that purpose.

25. Exercising Your Rights

25.1. You may exercise your rights by sending an e-mail to info@fynode.com or by writing to the address of the controller’s registered office.

25.2. Your request should include sufficient information to identify the person concerned and the right you wish to exercise. Do not send us copies of identity documents unless we expressly request them.

25.3. If we have reasonable doubts concerning the requester’s identity, we may request additional information necessary to verify their identity. We verify identity in an appropriate manner to prevent the disclosure of data to an unauthorised person.

25.4. We will respond to a request without undue delay, generally within one month. In the case of a complex request or a high number of requests, this period may be extended by a further two months; we will inform you of the extension and the reasons for it.

25.5. We handle requests free of charge. If a request is manifestly unfounded or excessive, particularly because of its repetitive nature, we may charge a reasonable fee or refuse to act to the extent permitted by the GDPR.

25.6. If we process personal data exclusively as a processor for a specific Customer, we may forward the request to that Customer or ask you to address the request directly to the Customer.

26. Right to Lodge a Complaint

26.1. If you believe that we process personal data in violation of applicable law, you have the right to lodge a complaint with a supervisory authority.

26.2. The supervisory authority in the Slovak Republic is:

Office for Personal Data Protection of the Slovak Republic website: https://dataprotection.gov.sk/

26.3. The right to contact a supervisory authority does not affect any other administrative or judicial remedies. Before lodging a complaint, you may contact us so that we have an opportunity to investigate and resolve your request.

27. Amendments to this Policy

27.1. We may update this Policy, in particular, as a result of changes to the Service, technologies used, providers, applicable law, or processing methods.

27.2. We will publish the current version on the website or in the Application, together with its effective date.

27.3. We will provide appropriate notice of any material change that significantly affects how personal data is processed, for example through a notification in the Application or by e-mail. If consent is required for new processing, we will obtain it before commencing such processing.

27.4. We may retain previous versions for the purposes of demonstrating compliance with information obligations and protecting legal claims.

28. Effective Date

28.1. This Policy takes effect on 24 August 2026.