Privacy Policy – 2026-07-16
Information about personal data processing in the Validarium web and mobile applications.
Version 2026-07-16 · effective from 07/16/2026
Privacy Policy
This document explains how Pavel Zaněk, as the data controller, processes personal data of users of the Validarium web and mobile applications.
Data I process
- Identification and contact details, especially name and email address.
- Data stored in Cloud mode, such as item names, expiration dates, categories, notes, reminders, workspace memberships, and attachments.
- Contact form and newsletter data when the user chooses to use those services.
- Necessary technical and security data, such as request time, the account used, and information required to diagnose errors and protect the service.
Device and Cloud modes
Data created in the mobile app's Device mode remains only on the phone and is not processed by Validarium servers unless the user chooses to transfer it to Cloud mode. Cloud mode data is transmitted to Validarium servers so it can be synchronized, displayed in the web app, and shared with authorized workspace members.
Purposes and legal grounds
I process data to create and manage accounts, provide cloud synchronization and attachment storage, deliver user-configured notifications, provide support, secure the service, and comply with legal obligations. Processing required for an account and Cloud mode is based on providing the requested service. Security and diagnostics are based on the legitimate interest in reliable operation. Newsletters are sent only with consent, which can be withdrawn at any time.
Cloudflare R2 and cloud attachments
Cloud attachments are stored in a private Cloudflare R2 bucket operated by Cloudflare, Inc., acting as a processor for this purpose. The bucket is configured for the European Union jurisdiction. Attachments are not public, and client applications do not receive storage credentials or a direct public object URL. Uploads, previews, downloads, and deletions are handled through the authorized Validarium server interface.
Cloudflare's contractual terms and data processing addendum apply to its processing. If service operation involves a transfer outside the European Economic Area, an appropriate legal transfer mechanism must be used.
Sharing data
I disclose data only to technical service providers to the extent necessary to operate Validarium or where required by law. Content in a shared workspace is available to its authorized members according to their role. I do not sell personal data.
Retention and deletion
Account and Cloud mode data is retained while the account or relevant workspace exists. An attachment is removed when it is deleted or when the related item, workspace, or account is removed. Technical records may be kept for a limited period necessary for security, error resolution, and the protection of legal rights. Newsletter data is retained until consent is withdrawn or the user unsubscribes.
Security
Access to cloud data is restricted through user authorization and workspace permissions. The R2 bucket is not public, and access keys are stored only in server configuration. Nevertheless, no internet service can guarantee absolute security.
User rights
Users may request access, rectification, deletion, restriction of processing, or portability of their personal data and may object to processing based on legitimate interests. Consent may be withdrawn at any time. Users also have the right to lodge a complaint with the competent data protection authority.
Contact
Requests and questions about personal data protection can be sent to info@pavelzanek.com.
Version archive
- 2026-07-18 — Current version Added Paddle, billing data, shared accounts, and retention after downgrade.
- 2026-07-16 — Displayed version Added Cloud mode, workspaces, and private Cloudflare R2 attachment storage.
- 2026-06-20 First recorded version of the document.