Zolvexa.official
Pricing Billing Contact Request access
Legal document

Privacy Policy

Version 1.0 · effective 2026 · controller: RUNESTONE HANDLUNG s.r.o., IČO 23389702

Zolvexa serves business customers only. This policy describes the processing of personal data of business contacts, account administrators and users of the platform, as well as visitors of this website.
1. Controller 2. Scope 3. Categories of data 4. Legal bases 5. Website & cookies 6. Recipients 7. Transfers 8. Retention 9. Security 10. Your rights 11. DPIA & breach 12. Changes

1. Data controller

The controller of personal data is RUNESTONE HANDLUNG s.r.o., IČO 23389702, Soukenická 877/9, Moravská Ostrava, 702 00 Ostrava, Czech Republic, registered with file number C 99911 at the Krajský soud v Ostravě, operating the Zolvexa platform (formerly known as CloudDroid).

Data protection enquiries, requests and complaints regarding this policy:
support@zolvexaofficial.com

2. Scope

This policy applies to:

  • visitors of the public website www.zolvexaofficial.com;
  • prospective and existing business customers and their named users (account administrators, developers, QA engineers);
  • contacts of customer organisations, including billing and accounts payable contacts;
  • support correspondence and API authentication events processed by the platform control plane.

3. Categories of personal data

Account & users

Name, business e-mail address, role, company affiliation, user ID, authentication and access events.

Billing & contract

Company name, registered address, IČO, VAT identification number, billing contact, order and invoice data, payment transaction references.

Technical & usage

IP address, device and browser data, node identifiers, Android image versions, CPU and memory metrics, uptime records, API request metadata, error and diagnostic logs.

Communications

Content of support requests, e-mail correspondence, sales enquiries and responses to access requests.

The controller does not intentionally collect special categories of personal data (for example health, political opinions, religious beliefs, biometric data or data concerning sexual orientation) and does not request such data from customers. Content processed by the Customer inside its own virtual Android environments is processed on behalf of the Customer as a processor and is not inspected by the controller except where required for security incident response or a legally binding request.

4. Legal bases for processing

  • Performance of a contract (Art. 6(1)(b) GDPR) — account creation, provisioning and operation of workspaces and Android node instances, invoicing and support.
  • Legitimate interests (Art. 6(1)(f) GDPR) — network and information security, fraud and abuse prevention, service reliability, troubleshooting, capacity planning and communication with existing business contacts. The legitimate interest is the operation of a secure and reliable B2B cloud platform.
  • Legal obligation (Art. 6(1)(c) GDPR) — accounting and tax records, and responding to competent public authorities.
  • Consent (Art. 6(1)(a) GDPR) — optional marketing communication and any non-essential cookie or analytics technology. Consent may be withdrawn at any time without affecting the lawfulness of processing before withdrawal.
  • Legitimate interest of the data subject's organisation — where an individual's business contact details are processed in the customer's request for a commercial contact.

5. Website, logs and cookies

The public website is served as static files from a self-hosted environment. It uses no advertising cookies, no cross-site tracking, no embedded third-party analytics and no social media widgets. No consent banner is required because the site sets no non-essential cookies.

The only personal data generated by a visit to the website is the technical request data processed by the web server in order to deliver the page (IP address, timestamp, requested path, HTTP status), which is retained in server logs for a maximum of 14 days for security and troubleshooting purposes. Google Fonts are not self-hosted; font requests are therefore transmitted to Google, which may process the requestor's IP address under Google's own privacy terms.

Inside the authenticated platform, strictly necessary storage (session token, dashboard preferences) is used to operate the service. Such storage cannot be disabled without breaking the service and is therefore not subject to consent.

6. Recipients and sub-processors

Personal data is disclosed only where necessary and only to:

  • Sub-processors for infrastructure and cloud hosting — providers of compute, storage and network capacity used to run virtual Android nodes and the control plane, bound by data processing agreements and confidentiality obligations.
  • Payment service providers — the acquiring partner that processes card payments independently as a controller; full card data is never received or stored by the controller.
  • Accounting and tax services — external accountants and tax advisers, subject to statutory or contractual confidentiality.
  • IT and support service providers — engaged under confidentiality and data processing agreements.
  • Public authorities — where disclosure is required by law or a binding legal obligation.

A current list of sub-processors with their function and country of processing is provided on request and is available under the data processing agreement.

7. International transfers

The controller is established in the Czech Republic. Personal data may be processed in other countries in which the relevant sub-processor is established, including the United States, the United Kingdom, Canada and other EEA member states, in line with the published regional deployment options. Where a transfer outside the EEA takes place, it relies on an adequacy decision or on appropriate safeguards, in particular standard contractual clauses adopted by the European Commission, together with supplementary measures where necessary.

8. Retention periods

Website server logs

14 days from the request.

Sales & contact enquiries

Up to 12 months from the last contact, or until the enquiry is closed.

Contract & invoice data

For the duration of the contract and for the statutory retention period under Czech accounting and tax legislation (typically 10 years for accounting documents).

Platform telemetry & usage logs

13 months in aggregate; longer only if required for an open security investigation or a dispute.

Support correspondence

24 months from the last case activity, unless a dispute is pending.

Customer data in workspaces

For the term of the contract, then deleted or irreversibly anonymised within 30 days of termination; backups within 90 days.

9. Security measures

  • Encryption in transit using current TLS versions, and encryption at rest of stored platform data and backups.
  • Isolation of each virtual Android node in a sandboxed environment with per-tenant boundaries.
  • Role-based and project-scoped API credentials, credential rotation and least-privilege defaults.
  • Access to production systems restricted by role, logged and reviewed.
  • Documented incident response procedure; affected customers and the supervisory authority are informed without undue delay in the event of a personal data breach.
  • Processor agreements concluded with all sub-processors handling customer personal data.

10. Rights of data subjects

Where the data subject is a contact person of a customer organisation, the controller is subject to the legitimate-interest provisions applicable to business contacts. Data subjects have the right to:

  • obtain confirmation whether personal data is processed and access to that data (Art. 15 GDPR);
  • rectify inaccurate or incomplete data (Art. 16 GDPR);
  • request erasure (Art. 17 GDPR);
  • request restriction of processing (Art. 18 GDPR);
  • receive personal data in a structured, commonly used, machine-readable format (Art. 20 GDPR);
  • object to processing based on legitimate interest (Art. 21 GDPR) and withdraw consent at any time;
  • lodge a complaint with the supervisory authority.

Requests are handled free of charge and answered within one month, extendable by two further months in justified cases. Where the request concerns the data of an identifiable customer user, the customer organisation may be consulted to verify the identity of the requester.

Supervisory authority: Úřad pro ochranu osobních údajů, Přikopská 834/22, 110 00 Praha 1, Czech Republic — uoou@uoou.gov.cz, www.uoou.gov.cz.

11. Data protection impact assessment and breach notification

A data protection impact assessment is carried out where a processing activity is likely to result in a high risk, in particular for large-scale monitoring, or where required by the supervisory authority. In the event of a personal data breach, the controller contains the incident, documents it, assesses the risk to the rights and freedoms of data subjects, and notifies the supervisory authority without undue delay and in any event within 72 hours where notification is required. Affected data subjects are informed without undue delay where a high risk is identified.

12. Changes to this policy

This policy is updated when the scope of processing changes or the legal framework requires it. The version and effective date are stated at the top of the page. Material changes affecting customers are announced by e-mail at least 14 days before they take effect.

Controller

RUNESTONE HANDLUNG s.r.o.

IČO: 23389702

Spisová značka: C 99911
vedená u Krajského soudu v Ostravě

Registered office

Soukenická 877/9
Moravská Ostrava
702 00 Ostrava
Česká republika

Legal documents

Imprint · Terms of Service

Billing & refunds · Acceptable Use

support@zolvexaofficial.com

© 2026 Zolvexa — formerly CloudDroid. Operated by RUNESTONE HANDLUNG s.r.o. All rights reserved. IČO 23389702 · C 99911 · Krajský soud v Ostravě