

Privacy Policy
1.1 This Privacy Policy (the “Policy”) explains how Wonder Makers s.r.o., with its registered office at Mezibranská 1668/5, 110 00 Prague – Nové Město, Company ID No.: 17844576, VAT ID: CZ17844576, (the “Company”), processes personal data in connection with the provision of its service (the “Service”).
1.2 The Company acts in the processing of personal data:
as a controller in relation to personal data of its users (e.g., account, billing),
as a processor in relation to personal data processed on behalf of the user within the Service.
The Company may process, in particular:
identification data (e.g., name, company name),
contact data (e.g., email address),
access and authentication data,
technical data (e.g., IP address, device, logs),
data on the use of the Service (e.g., activity, interactions within the system),
content created by the user (e.g., comments, notes, feedback).
The Company does not intentionally process special categories of personal data (e.g., health data, biometric data, etc.).
Personal data is obtained:
directly from the user (registration, communication),
automatically when using the Service (logs, technical data),
through technical code (e.g., a script) implemented in the user’s environment.
Personal data is processed for the purposes of:
provision and operation of the Service,
management of user accounts,
ensuring security and prevention of misuse,
improvement and development of the Service (e.g., analysis of usage),
compliance with legal obligations.
Processing of personal data is carried out on the basis of:
provision and operation of the Service,
management of user accounts,
ensuring security and prevention of misuse,
improvement and development of the Service (e.g., analysis of usage),
compliance with legal obligations.
In the case of data processed through a script in the user’s environment, the legal basis for processing is ensured by the user (the Company’s customer).
6.1 The Service may be provided through the implementation of technical code (e.g., a script) into the user’s website or digital environment.
6.2 Such code serves exclusively to enable the functionality of the Service (e.g., creation and display of feedback) and may record limited technical data and interactions, such as:
clicks and interactions with the interface,
positions of elements on the page,
basic information about the device or browser.
6.3 The Company:
does not record the content of forms, text inputs, or sensitive data, unless they are explicitly part of feedback created by the user,
does not perform hidden monitoring of users or behavioural tracking for marketing purposes,
does not process data beyond what is necessary for the provision of the Service.
6.4 The user (the Company’s customer) is responsible for ensuring that:
they have a legal basis for such processing (e.g., consent, legitimate interest),
they fulfil their information obligations towards visitors,
they use the Service in compliance with applicable laws (in particular GDPR and ePrivacy).
6.5 In relation to data obtained through the script:
the user acts as the controller,
the Company acts as the processor.
7. Position of the Company (Controller vs. Processor)
7.1 The Company acts as a controller in relation to:
user account data,
communication with customers,
technical and operational data regarding the use of the Service.
7.2 Where the user processes personal data of third parties through the Service:
the user acts as the controller,
the Company acts as the processor.
7.3 Such processing is governed by a separate Data Processing Agreement (DPA).
8. Data Sharing and Sub-processors
8.1 Personal data may be disclosed to third parties to the extent necessary, in particular:
providers of cloud infrastructure (e.g., hosting),
providers of database and backend services,
providers of payment services,
providers of analytical and monitoring tools,
providers of communication services.
8.2 The Company may engage additional processors (“sub-processors”).
8.3 An up-to-date list of sub-processors is available at: www.fubi.dev/security
8.4 The Company ensures that sub-processors provide appropriate safeguards for personal data protection and are contractually bound in accordance with GDPR.
9. International Transfers of Data
9.1 Personal data may be transferred outside the European Economic Area.
9.2 In such cases, the Company ensures an adequate level of protection through:
Standard Contractual Clauses (SCC),
or other appropriate safeguards under GDPR.
10. Data Retention
Personal data is retained:
for the duration of the user account,
for the period necessary for the performance of the contract,
for the period required by applicable laws,
technical logs for a maximum period of 90 days (unless longer retention is required for security purposes).
Upon termination of the account, data is typically deleted within 30 days.
11. Rights of Data Subjects
The user has the right to:
access personal data,
rectification of inaccurate data,
erasure,
restriction of processing,
object to processing,
data portability,
lodge a complaint with a supervisory authority.
The Company responds to requests without undue delay, no later than within 30 days.
12. Security
12.1 The Company implements appropriate technical and organisational measures to protect personal data.
12.2 Such measures include, in particular:
access control,
secure communication,
infrastructure protection,
monitoring and logging.
12.3 In the event of a security incident, the Company proceeds in accordance with applicable laws and adopts appropriate measures without undue delay.
13. Cookies and Similar Technologies
13.1 The Service may use cookies and similar technologies necessary for its operation
13.2 Detailed information on the use of cookies, including their types, purposes, and retention periods, is provided in a separate document “Cookie Policy”, available at: fubi.dev/cookie-policy
13.3 Where the Service (e.g., script) is implemented on the user’s website, the user is responsible for ensuring compliance with applicable laws, in particular in relation to cookies and tracking technologies.
14. Transfer of the Company
In the event of a sale of the Company or part thereof, personal data may be transferred to a new owner in accordance with applicable laws.
15. Non-disclosure of Data
The Company does not sell personal data to third parties.
16. Changes to the Policy
This Policy may be updated from time to time.
17. Contact Details
For any questions regarding personal data protection, you may contact: info@fubi.dev

