How we handle personal data of website visitors, audit applicants and EasyCare 365 customers. No analytics tracking, no export of data beyond what running the service strictly requires.
This is a translation for convenience. The binding version is the Czech one at easycare365.cz/zasady-ochrany-dat; in case of any discrepancy the Czech wording prevails.
The data controller is accelapps s.r.o., Company ID: 06628362, VAT ID: CZ06628362, registered in the Commercial Register kept by Městský soud v Praze, oddíl C, vložka 285754. Registered office: Hvězdova 1716/2b, Nusle, 140 00 Praha 4.
EasyCare 365 is a service and a brand of this company, as is the EasyPortal 365 product line.
Contact for personal data matters: info@easyportal365.com, phone +420 234 715 878. We have not appointed a Data Protection Officer – we are not required to by law.
Mandatory: first name, surname, e-mail and the message; optional: company and phone. The form is processed by Zoho Forms (see section 6).
Name, e-mail, phone and any note about the slot. Booking runs through Zoho Bookings.
E-mail, optionally company name and domain, plus IP address and browser details (to protect the form against abuse). The request is stored as a record in our private repository at GitHub and serves solely to let us get back to you and arrange the audit.
The quick domain check on the audit page finds out only what is publicly available about the given domain to anyone on the internet: public DNS records (MX, SPF, DKIM, DMARC, DNSSEC, CAA, MTA-STS), data from the public domain registry, certificate validity and website security headers, the public certificate transparency log, and whether the domain is on Google Web Risk's list of dangerous sites. We sign in nowhere and do not touch your environment in any way.
The check runs on our server (Microsoft Azure, European Union), which queries those public sources on your behalf. We do not store the result anywhere – once the answer is sent to your browser we discard it. Two things stay temporarily in the server's memory: responses from public services (certificate transparency and Google Web Risk) for 6–24 hours so we don't have to ask again on a repeated check of the same domain, and the number of requests from your IP address for one hour as abuse protection. Both disappear on their own and are written nowhere.
If you have the result sent by e-mail, we use your address solely to send that one report. We do not add it to any contact database or mailing list.
For customers of the service we read configuration, metrics and events from their tenant: security and sharing settings, assigned roles and licences, security score, records of configuration changes and the account details needed to describe a finding (typically the sign-in name of the administrator or guest the finding concerns).
We never read content – documents, e-mails, Teams messages or files. Access is technically read-only and the customer can revoke it at any time in a single step.
Monitoring data sits in our Microsoft Azure subscription in the European Union, separated per customer.
Company name, Company ID and VAT ID, billing address, names and contacts of responsible persons.
The website runs on GitHub Pages, which keeps standard access logs. We do not use Google Analytics or any other advertising measurement tools.
| Data | Retention |
|---|---|
| Message from the contact form | 24 months from the last communication |
| Meeting booking | 24 months |
| Audit request | 12 months from completion |
| Monitoring events and metrics | 24 months |
| Tenant configuration snapshots | 90 days (the approved baseline for the term of the contract) |
| Customer data after the service ends | deleted within 30 days |
| Contractual and accounting documents | as required by law, usually 10 years |
| Website operational logs | 30 days |
Processors who provide parts of the service for us:
Transfers outside the EU are covered by standard contractual clauses under Art. 46 GDPR. Tenant monitoring data stays in the EU and we pass it to nobody else.
You have the right to access your data, to rectification, erasure, restriction of processing, portability, to object to processing based on legitimate interest, and to withdraw consent at any time. Send your request to info@easyportal365.com; we will handle it within 30 days (in complex cases the period may be extended by 2 months, of which we will notify you).
You also have the right to lodge a complaint with the Czech Office for Personal Data Protection (uoou.gov.cz).
The site itself uses no tracking cookies and has no cookie banner – there is nothing to consent to. Cookies may only appear when you interact with the form or the booking (Zoho). Details are on the Cookies page.
All communication runs over HTTPS. Access to data is limited to the team providing the service and protected by multi-factor authentication. Access to customer tenants is technically read-only; changes are made by people under a traceable identity and with time-limited permissions.
For service customers, where we process data of their employees, a data processing agreement under Art. 28(3) GDPR applies – it is part of the Terms & Conditions (article 10 “Data and personal data”), which exist in Czech only. A standalone DPA is available on request.
We may amend this policy if the scope of the service or the legislation changes. We inform customers of material changes in advance by e-mail; the current version is always on this page.