AVANTERRO
FunzionalitàAVANTERRO GOPrezziDomandeBlogContattiAccedi
FunzionalitàAVANTERRO GOPrezziDomandeBlogContattiAccedi al sistema
AVANTERRO

La gestione della Sua azienda in un unico sistema. Prenotazioni, fatturazione, magazzini e paghe senza tabelle o caos.

Prodotto

  • Funzionalità
  • Prezzi
  • Domande frequenti
  • Blog
  • Contatti

Azienda

AVANTERRO SYSTEMS s.r.o.
P. IVA / ID: 24568082
Sede legale: Příčná 1892/4, Nové Město, 110 00 Praga 1

Legale

  • Termini e condizioni
  • Refund Policy
  • Informativa sulla privacy
  • Cookie

© 2026 AVANTERRO SYSTEMS s.r.o.. Tutti i diritti riservati.

Creato condal team AVANTERRO
Lingua
🇮🇹Italiano
🇲🇾Bahasa Melayu
🇧🇬Български
🇨🇿Čeština
🇩🇰Dansk
🇩🇪Deutsch
🇬🇷Ελληνικά
🇬🇧English (UK)
🇺🇸English (US)
🇪🇸Español
🇫🇮Suomi
🇫🇷Français
🇮🇳हिन्दी
🇭🇷Hrvatski
🇭🇺Magyar
🇮🇩Indonesia
🇮🇹Italiano
🇯🇵日本語
🇰🇷한국어
🇳🇱Nederlands
🇳🇴Norsk
🇵🇱Polski
🇵🇹Português
🇷🇴Română
🇷🇺Русский
🇸🇰Slovenčina
🇷🇸Srpski
🇸🇪Svenska
🇹🇭ไทย
🇹🇷Türkçe
🇺🇦Українська
🇻🇳Tiếng Việt
🇨🇳中文
Cookie e diagnostica degli errori

Utilizziamo i cookie necessari (accesso, lingua) per il funzionamento del sito. Se Lei acconsente, utilizziamo anche una registrazione diagnostica opzionale delle azioni (60 secondi a ritroso, testo mascherato). Dettagli nel documento Informativa sui cookie.

Privacy Policy

Effective date: 12 August 2026 Version: 1.4 Controller: AVANTERRO SYSTEMS s.r.o.


1. Who we are and how to contact us

This Privacy Policy describes how AVANTERRO SYSTEMS s.r.o. (hereinafter "Avanterro" or "we") processes your personal data in connection with providing the Avanterro service – a cloud-based information system for service businesses (hereinafter the "Service").

Controller identification:

  • Name: AVANTERRO SYSTEMS s.r.o.
  • Company ID (IČO): 24568082
  • Registered office: Příčná 1892/4, Nové Město, 110 00 Prague 1, Czech Republic
  • Registered in the Commercial Register kept by the Municipal Court in Prague, Section C, Insert 442318
  • E-mail for data protection enquiries: [email protected]
  • Website: https://avanterro.com

Avanterro has not appointed a Data Protection Officer (DPO), as it is not required to do so under Article 37 GDPR. Please direct any data protection enquiries to the e-mail address above.

2. When we are a controller and when we are a processor

When providing the Service, we act in two distinct roles:

a) As a controller – when we process data relating to you personally as a customer of Avanterro (e.g. registration, billing, marketing communications, support). This Policy concerns this role.

b) As a processor – when you store data of your own customers on our servers (bookings, contacts, invoices, photographs of work orders, etc.). In that case you remain the controller and Avanterro processes the data solely on your instructions. This relationship is governed by Annex 1 to the Terms – Data Processing Terms under Article 28 GDPR, which forms part of the contract and requires no separate signature.

3. What data we process and why

3.1 Registration and user account management

  • Data: first and last name, e-mail, password hash, language, time zone, IP address at registration, company (tenant) ID, role.
  • Purpose: creating and maintaining the account, authentication, separating data between tenants.
  • Legal basis: performance of a contract (Article 6(1)(b) GDPR).
  • Retention period: for the duration of the Subscription. After the Subscription ends, the account is deactivated, or there is a longer period of inactivity, Client Data may be retained for a limited period to allow the Service to be restored and to comply with statutory obligations. Before permanently deleting data, we send a notice to the Client's contact e-mail, typically after 5 months of inactivity. If the Client does not extend data retention using the link in that e-mail, does not resume activity in the account, or does not activate a Subscription, the data may be permanently deleted, typically after 6 months of inactivity. The link in the notice e-mail extends data retention by another 5 months. Accounting and tax documents linked to the account are retained for the period required by law (10 years pursuant to Section 35 of Act No. 235/2004 Coll. on VAT and Section 31 of Act No. 563/1991 Coll. on Accounting).

3.2 Subscription and payments

  • Data: billing name, address, Company ID (IČO), VAT ID (DIČ), e-mail, order and invoice history, payment gateway transaction ID.
  • Purpose: conclusion and performance of the subscription contract, issuance of documents, accounting.
  • Legal basis: performance of a contract (Article 6(1)(b) GDPR), compliance with a legal obligation (Article 6(1)(c) GDPR – accounting and tax legislation).
  • Retention period: 10 years from the end of the tax period.
  • Note on payments: all payment transactions are processed by Paddle.com Market Limited acting as the seller of record under the Merchant of Record model. Avanterro does not receive or process payment card data – you enter such data directly into the Paddle environment, which is PCI-DSS Level 1 certified.

3.3 Operation and support of the Service

  • Data: login logs, IP address, browser identifier (User-Agent), records of user actions in the application (audit log), content of communications with support.
  • Purpose: ensuring security, incident handling, technical support, abuse prevention.
  • Legal basis: legitimate interest (Article 6(1)(f) GDPR) – interest in the secure and reliable operation of the Service; for support, performance of a contract.
  • Retention period: security logs 12 months, audit logs 24 months, support tickets 36 months from closure.

3.4 Error diagnostics

  • Data: technical information about the error (stack trace), URL, pseudonymous user identifier, browser version; subject to consent, also a recording of user interface actions for 60 seconds preceding an error, with text masked and media blocked.
  • Purpose: detecting and fixing application errors.
  • Legal basis: legitimate interest (Article 6(1)(f) GDPR) for basic diagnostics; consent (Article 6(1)(a) GDPR) for optional session recording, granted through the cookie banner.
  • Recipient category: technical diagnostics and error-monitoring provider.
  • Retention period: 90 days.

3.5 Marketing communications

  • Data: e-mail, name, segment (e.g. type of business), open and click history.
  • Purpose: sending Service news, tips and commercial communications.
  • Legal basis: legitimate interest in sending commercial communications to existing customers regarding similar services (Section 7(3) of Act No. 480/2004 Coll.); for non-customers, consent (Article 6(1)(a) GDPR).
  • Retention period: until consent is withdrawn or an objection is raised, no longer than 5 years from the last contact.
  • You can unsubscribe at any time with a single click in every e-mail or by writing to [email protected].

3.6 Visits to avanterro.com

  • Data: IP address, approximate location (country), browser, operating system, device type, pages visited, referrer, time of visit and technical page performance metrics.
  • Purpose: ensuring website security, protection against DoS attacks, aggregated traffic and technical performance measurement of the public website.
  • Legal basis: legitimate interest (Article 6(1)(f) GDPR).
  • Recipient category: network security, CDN and cookie-free aggregated performance measurement provider.
  • Retention period: server logs 30 days; non-aggregated technical measurements no longer than 7 days, aggregated outputs for a limited period.

3.7 Google Calendar integration

If you voluntarily connect your Google Calendar in the application, Avanterro uses access to your Google account only for calendar synchronisation features.

  • Data: Google account identifier, account e-mail address, list of available calendars and metadata of the selected calendar, event data needed to synchronise tasks and appointments (title, time, description, attendees, event identifier), OAuth access token and refresh token.
  • Purpose: connecting Google Calendar, checking available calendars, and creating, updating and deleting events related to tasks and appointments managed in Avanterro.
  • Scope of use: Avanterro creates, updates and deletes only events created by or managed through Avanterro. We do not use Google Calendar data for advertising, profiling, sale to third parties or training artificial intelligence models.
  • Legal basis: performance of a contract (Article 6(1)(b) GDPR), because the integration is a Service feature activated by the user; where applicable, consent within the Google OAuth consent screen.
  • Retention period: for as long as Google Calendar remains connected. We store the OAuth refresh token in server-side storage with restricted access so that synchronisation can work without repeated manual sign-in. Protection of data at rest depends on the configuration of the deployed database infrastructure. When you disconnect the integration, we delete the token and stop further synchronisation.
  • Disconnection: you can disconnect Google Calendar at any time in Avanterro settings or by revoking access in your Google account settings.

3.8 Service termination, export and company data lifecycle

  • Internal tenant data: customer and employee data, memberships and access, orders, bookings, vouchers and passes, customer invoices and receipts, attachments, messages, integration tokens and operational configuration.
  • Retention process: for standard automated retention, the period starts when the last active service period ends, which we record when the Subscription ends, the account is deactivated, or provision of the Service otherwise demonstrably ends. Internal tenant data are normally scheduled for deletion 6 months from that point. We send a warning approximately 1 month before scheduled deletion. Only express confirmation through the link postpones scheduled deletion by a further 5 months; merely opening the link or an e-mail scanner checking it changes nothing. A new active Subscription starts a new service period.
  • Export following a verified request: no self-service export is available once access has ended. Support verifies an authorised request and a superadmin can create a private ZIP with a manifest and checksums before deletion, stored encrypted at rest in private storage. The download link is short-lived and one-time. After deletion, only the lawfully retained, minimised audit subset can be provided.
  • Minimised record after deletion: the company's basic legal and business identity, company name, contact e-mail and telephone number, service periods, plan, amount, currency and Paddle transaction and settlement data, referral/affiliate attribution and payouts, proof of acceptance of legal documents, and export or deletion audit evidence. After deletion, the contact e-mail and telephone number are retained only for contractual and accounting reconciliation, compliance with specific legal obligations, and the establishment, exercise or defence of legal claims. Addresses, files and other free-text fields without a specific purpose are deleted or pseudonymised. For sole traders and contact persons, business fields may still constitute personal data.
  • Purpose and legal basis: termination and settlement of the contract (Article 6(1)(b) GDPR), compliance with accounting and other legal obligations (Article 6(1)(c) GDPR), and legitimate interests in fraud prevention, evidencing the Service provided, and establishing, exercising or defending legal claims (Article 6(1)(f) GDPR).
  • Retention of the minimum record: accounting and tax records for the statutory period in section 3.2; the contact e-mail, telephone number and other minimised contractual, referral and lifecycle evidence only for as long as required for those purposes and applicable limitation periods, and longer only where a dispute is pending or another specific legal obligation applies. We delete or anonymise them when that purpose ends.
  • Backups: backups are not a customer export. After deletion from the live system, data are progressively overwritten through rolling rotation no later than 35 days, unless isolated for a security incident or legal obligation; until then, backups are isolated and not used for ordinary processing. Selective restoration or export of an individual company from a backup is not provided.

4. Recipients and categories of recipients

We use only providers needed for a specific purpose. Depending on the functions used, they may fall within these categories:

Recipient categoryPurpose
Hosting and database infrastructureOperating the application and storing operational data
Object storage and backupsAttachments, photographs, exports and backup copies
Network security, CDN and performance measurementAvailability, attack protection and aggregated technical measurements
Diagnostics and customer supportError detection and handling support requests
Transactional communicationsDelivery of service and security e-mails
Payments, billing and accountingProcessing orders, payments and statutory records
Client-activated integrationsTransfer of data needed for a voluntarily connected external service

The exact current register of approved providers and recipients, including role, purpose, location and transfer safeguards, is available only to authenticated Client administrators in Settings → Legal documents. Administrators will be notified of an intended addition or replacement of a sub-processor at least 30 days in advance.

We may also transfer personal data to:

  • public authorities to the extent required by law (Czech Police, courts, tax authorities, etc.),
  • legal and tax advisors and auditors bound by professional confidentiality,
  • a successor in business in the event of the sale or merger of Avanterro – in such a case you will be informed in advance and the same safeguards will be preserved.

Avanterro does not sell personal data to third parties.

5. Transfers outside the EU/EEA

Some providers in the categories above may process data in the United States or another country outside the EU/EEA. We transfer data only under a valid Chapter V GDPR mechanism, in particular an adequacy decision, the EU–US Data Privacy Framework where applicable, or Standard Contractual Clauses adopted by the European Commission, supplemented by technical measures where appropriate.

Current details are available in the administrator register; copies of the applicable safeguards are available on request at [email protected].

6. Your rights

In connection with the processing of your personal data you have the following rights:

  • Right of access (Article 15 GDPR) – to obtain confirmation as to whether we process your data and to receive a copy of it.
  • Right to rectification (Article 16 GDPR) – to have inaccurate data corrected and incomplete data completed.
  • Right to erasure (Article 17 GDPR) – the "right to be forgotten" where data is no longer needed, you withdraw consent, you successfully object, or we process the data unlawfully.
  • Right to restriction of processing (Article 18 GDPR) – in certain cases, to have processing limited to mere storage.
  • Right to data portability (Article 20 GDPR) – to receive your data in a structured, machine-readable format (JSON/CSV).
  • Right to object (Article 21 GDPR) – to processing based on legitimate interests, in particular to direct marketing.
  • Right to withdraw consent (Article 7(3) GDPR) – at any time, without affecting the lawfulness of processing prior to withdrawal.
  • Right not to be subject to automated decision-making (Article 22 GDPR) – see section 7 below.

You may exercise these rights by writing to [email protected]. We respond without undue delay, no later than within 30 days; in more complex cases this period may be extended by a further two months, of which we will inform you. We may request additional information to verify your identity.

If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the supervisory authority:

Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů – ÚOOÚ) Pplk. Sochora 27, 170 00 Prague 7, Czech Republic www.uoou.cz, [email protected]

7. Automated decision-making and profiling

Avanterro does not carry out automated individual decision-making within the meaning of Article 22 GDPR, nor does it carry out profiling that produces legal or similarly significant effects on the data subject. Algorithmic features within the Service (e.g. ordering, scheduling suggestions) are mere aids; the final decision is always taken by the human operator of the application.

8. Cookies and similar technologies

The Avanterro website (avanterro.com) displays a cookie banner with two options: "Accept all" (allows strictly necessary cookies and optional diagnostic session recording) and "Only necessary" (only cookies essential for website functionality — sign-in, language). You may change your selection at any time by removing the avanterro_cookies_v2 key from localStorage and reloading the page.

On the public website we also use a tool for aggregated traffic and performance measurement. It does not use analytics cookies and is not used for advertising, retargeting or individual visitor profiling. For details, please see our separate Cookie Policy available at https://avanterro.com/en/cookies.

9. Security of processing

Taking into account the risks involved and the state of the art, we apply in particular the following technical and organisational measures:

  • encryption of web application and API traffic using HTTPS/TLS and encryption at rest according to the deployed providers' configuration,
  • separation of tenant data through mandatory company scoping in the application and database-query layers,
  • restricted administrator access protected by strong authentication according to the deployed provider's capabilities,
  • principle of least privilege and access logging (audit log),
  • backup and recovery according to the current production-hosting configuration and internal continuity plan; specific RPO/RTO targets are binding only when separately agreed,
  • vulnerability scanning and dependency updates, static security analysis in CI/CD,
  • penetration testing in line with the significance of changes,
  • confidentiality obligations and role-appropriate data-protection instructions for persons with access to the data,
  • processes for handling data subject requests and for incident reporting (Incident Response Plan).

10. Personal data breaches

In the event of a personal data breach that poses a risk to the rights and freedoms of natural persons, we will notify the supervisory authority (ÚOOÚ) without undue delay, no later than within 72 hours of becoming aware of it (Article 33 GDPR). Where the breach is likely to result in a high risk, we will also notify the affected data subjects without undue delay (Article 34 GDPR).

11. Changes to this Policy

We may update this Policy from time to time, for example in response to changes in legislation or expansion of the Service. We will inform you of material changes at least 30 days in advance by e-mail or by an in-app notice. Minor wording adjustments are published without separate notice.

The current version is always available at https://avanterro.com/en/privacy. Version history is maintained internally and a copy will be provided upon request.


This document takes effect on 12 August 2026. Version 1.3.