Privacy Policy
Last updated: 16 May 2025
This Privacy Policy explains how TAAPI.IO, s.r.o. ("TAAPI.IO", "we", "us", or "our") collects, uses, stores, and shares your personal data when you use our website at taapi.io and the TAAPI.IO API service (collectively, the "Service").
We are committed to protecting your personal data and processing it in accordance with the EU General Data Protection Regulation (GDPR) and applicable Czech data protection law.
1. Who We Are (Data Controller)
The data controller responsible for your personal data is:
- Company: TAAPI.IO, s.r.o.
- Registered address: Primátorská 296/38, Libeň, 180 00 Praha 8, Czech Republic
- Company ID (IČO): 08500398
- Email: [email protected]
If you have any questions or concerns about how we handle your data, please contact us at the address above.
2. What Data We Collect
2.1 Account Registration
When you create an account, we collect:
- First and last name
- Email address
- Password (stored as a cryptographic hash — we never store your plain-text password)
- Intended use case (optional, collected during onboarding)
2.2 API Usage & Logs
When you use the API, we automatically collect:
- IP address of the requesting client
- API endpoint called, parameters, and timestamp
- Response status and latency
- Your API key identifier (not the full key)
These logs are used to enforce rate limits, detect abuse, debug issues, and calculate your usage statistics.
2.3 Payment Information
We do not store your payment card details. All payment processing is handled by Stripe, Inc. When you add a payment method, Stripe collects and securely stores your card information on our behalf. We receive from Stripe only non-sensitive summary data such as card brand, last four digits, expiry date, and billing address (used for tax calculation purposes).
2.4 Contact & Support Enquiries
When you contact us by email or through our contact form, we collect your name, email address, and the content of your message. This information is used solely to respond to your enquiry.
2.5 Cookies & Analytics
We use cookies and similar tracking technologies as described in Section 10 below.
3. Legal Basis for Processing
Under GDPR, we must have a valid legal basis for each type of processing. The following table summarises the legal bases we rely on:
| Processing Activity | Legal Basis (GDPR Art. 6) |
|---|---|
| Creating and managing your account | Performance of a contract (Art. 6(1)(b)) |
| Providing the API service and enforcing rate limits | Performance of a contract (Art. 6(1)(b)) |
| Processing payments and issuing invoices | Performance of a contract + Legal obligation (Art. 6(1)(b) & (c)) |
| Sending transactional emails (trial reminders, payment receipts, alerts) | Performance of a contract (Art. 6(1)(b)) |
| Retaining financial records for accounting purposes | Legal obligation — Czech Accounting Act (Art. 6(1)(c)) |
| Detecting abuse, fraud, and security threats | Legitimate interests (Art. 6(1)(f)) |
| Website analytics (Google Analytics) | Consent (Art. 6(1)(a)) |
| Responding to support enquiries | Legitimate interests (Art. 6(1)(f)) |
4. How We Use Your Data
We use your personal data to:
- Provide, operate, and improve the Service.
- Authenticate your identity and secure your account.
- Process subscription payments and issue invoices.
- Send transactional emails: account confirmations, trial expiry reminders, payment receipts, and payment failure notifications.
- Calculate applicable VAT or other taxes based on your billing address.
- Monitor API usage to enforce plan limits and detect abuse.
- Respond to support and contact enquiries.
- Comply with legal and regulatory obligations.
We do not sell your personal data to third parties. We do not use your data for profiling or automated individual decision-making that produces legal or similarly significant effects.
5. Who We Share Your Data With
We share your personal data only with the third-party service providers ("processors") listed below, and only to the extent necessary for them to perform their services on our behalf:
| Processor | Purpose | Location | Privacy Policy |
|---|---|---|---|
| Stripe, Inc. | Payment processing, subscription billing, invoice generation | USA (EU data handling available) | stripe.com/privacy |
| DigitalOcean, LLC | Cloud hosting and infrastructure (servers, databases) | USA / EU (we use EU regions where available) | digitalocean.com/legal/privacy-policy |
| Mailgun Technologies, Inc. | Transactional email delivery (account notifications, receipts) | USA (EU data center available) | mailgun.com/legal/privacy-policy |
| Google LLC (Google Analytics) | Website analytics (only with your consent) | USA | policies.google.com/privacy |
We do not share your personal data with any other third parties except where required by law (e.g. in response to a valid court order or regulatory request), in which case we will notify you unless legally prohibited from doing so.
6. International Data Transfers
Some of our third-party processors (Stripe, DigitalOcean, Mailgun, Google) are headquartered in the United States, which means your personal data may be transferred to and processed in a country outside the European Economic Area (EEA).
Where such transfers occur, we ensure they are protected by appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission, as incorporated in the Data Processing Agreements we hold with each processor.
- Where applicable, reliance on a processor's certification under an EU-recognised adequacy framework.
You may request a copy of the relevant safeguards by contacting us at [email protected].
7. How Long We Retain Your Data
| Data Category | Retention Period | Reason |
|---|---|---|
| Account data (name, email) | Duration of account + 12 months after deletion request | Service provision; grace period for reactivation |
| API usage logs | 90 days | Rate limiting, abuse detection, debugging |
| Payment and invoice records | 10 years | Czech Accounting Act (zákon č. 563/1991 Sb.) |
| Support correspondence | 3 years from last contact | Legitimate interests (dispute resolution) |
| Cookie / analytics data | Up to 26 months (Google Analytics default) | Web analytics |
When data reaches the end of its retention period, it is securely deleted or anonymised.
8. How We Protect Your Data
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure, including:
- All data in transit is encrypted using TLS (HTTPS).
- Passwords are stored using strong one-way cryptographic hashing (bcrypt).
- API keys are stored as prefixed hashes; the full key is shown only once at generation.
- Payment card data is never stored on our servers — this is delegated entirely to Stripe, who is PCI DSS certified.
- Access to production systems is restricted to authorised personnel on a least-privilege basis.
- Development and test environments use anonymised or synthetic data, not production personal data.
9. Your Rights Under GDPR
As a data subject under GDPR, you have the following rights:
- Right of access (Art. 15): You can request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): You can ask us to correct inaccurate or incomplete data.
- Right to erasure (Art. 17): You can ask us to delete your personal data, subject to legal retention obligations.
- Right to restriction of processing (Art. 18): You can ask us to limit how we use your data in certain circumstances.
- Right to data portability (Art. 20): You can request your data in a structured, machine-readable format.
- Right to object (Art. 21): You can object to processing based on legitimate interests at any time.
- Right to withdraw consent (Art. 7(3)): Where processing is based on your consent (e.g. analytics cookies), you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint (Art. 77): You have the right to lodge a complaint with the Czech supervisory authority — the Office for Personal Data Protection (ÚOOÚ) — at uoou.cz.
To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days. We may ask you to verify your identity before processing your request.
10. Cookies
We use the following categories of cookies on our website:
| Category | Examples | Purpose | Consent required? |
|---|---|---|---|
| Strictly necessary | Session cookie, CSRF token | Authentication and security — required for the Service to function | No |
| Analytics | Google Analytics (_ga, _gid) | Understanding how visitors use the website; improving the Service | Yes |
We are in the process of implementing a cookie consent banner that will allow you to accept or decline non-essential cookies before they are set. Until that is in place, Google Analytics is loaded only on the public marketing site, not within the authenticated application.
You can also control cookies through your browser settings. Note that disabling strictly necessary cookies will impair your ability to log in and use the Service.
11. Data Breach Procedures
In the event of a personal data breach, we will:
- Notify the Czech Office for Personal Data Protection (ÚOOÚ) within 72 hours of becoming aware of the breach, where it is likely to result in a risk to your rights and freedoms (GDPR Art. 33).
- Notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms, including a description of the nature of the breach and the steps we are taking to address it (GDPR Art. 34).
- Maintain an internal record of all breaches, including those not reportable to the supervisory authority.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email.
We encourage you to review this page periodically.
13. Contact & Complaints
For any questions, requests, or concerns relating to this Privacy Policy or how we handle your data, please contact us:
- Email: [email protected]
- Post: TAAPI.IO, s.r.o., Primátorská 296/38, Libeň, 180 00 Praha 8, Czech Republic
If you are not satisfied with our response, you have the right to lodge a complaint with the Czech Office for Personal Data Protection (ÚOOÚ):
- Website: uoou.cz
- Email: [email protected]
- Address: Pplk. Sochora 27, 170 00 Praha 7, Czech Republic