EURO.SUPPORT / LEGAL DOCUMENTS
Privacy Policy
How euro.support processes the personal data of visitors, clients and contact persons
1. Who the controller is
The controller of the personal data described in this Policy is European Business Solutions s. r. o., Budatínska 20, 851 06 Bratislava, Slovak Republic, Company ID 54 230 012, VAT ID SK2121621689 (hereinafter “we” or “euro.support”). Questions and requests may be sent to info@euro.support.
This Policy applies to visitors to euro.support, prospects, Clients, Account Users, contact persons of suppliers, and persons who communicate directly with us. If we process chats, email or Gmail tickets, WhatsApp, Messenger or Instagram messages, order data or other content on behalf of a Client, we act as a processor and the Client determines the purpose; Section 9 and the DPA apply.
2. What data we collect
- Account and contact details: name, work email, telephone number, company, position, language, country, account identifier and settings.
- Contract and billing: business and billing details, Company ID, VAT ID, address, selected Plan, price, currency, payment status, and Stripe or Shopify identifiers; we do not store full card details.
- Communications with us: the content of emails, forms, support requests, demos, feedback and attachments.
- Usage and security: IP address, browser, device, time, language, pages visited, session, login and security events, diagnostics and audit logs.
- Integrations and connected messaging accounts: store identifier, Gmail address, WhatsApp Business account and phone number identifier, Facebook Page or Instagram account identifier, permissions granted, connection and synchronization status, encrypted OAuth or access tokens, and technical data required for authentication, webhooks and synchronization.
- Marketing preferences: consent, objection, unsubscribing, contact source and interaction with our communications.
- Cookies and localStorage: data specified in the Cookie Policy.
We obtain data from you, your employer or administrator, from your use of the Service, from Stripe, Shopify, Google, Meta or another integration you activate, and from public business registers where necessary to verify contractual details. We will mark mandatory fields; without them, we may be unable to create an account, enter into a contract, accept a payment or handle a request.
3. Purposes and legal bases
Purpose | Data | Legal basis |
|---|---|---|
Account, contract and Service | Contact, account, company, role, settings and usage | Performance of a contract and steps prior to entering into one; legitimate interest in relation to business contacts |
Billing and accounting | Company, address, Company ID, VAT ID, Plan, price, status and payment identifiers | Performance of a contract and statutory accounting and tax obligations |
Support and communications | Contact details, request content, attachments and resolution history | Performance of a contract or legitimate interest in handling a question and documenting communications |
Connection of Gmail and Meta accounts | Email address, account, Page or phone number identifiers, OAuth and access tokens, permissions, synchronization status and security events | Performance of the contract and the Client’s instruction to activate the integration; legitimate interest in secure and demonstrable operation |
Security and abuse prevention | IP address, session, device, events, logs and technical identifiers | Legitimate interest in protecting the Service, Clients and claims; legal obligation where applicable |
Public website analytics | Online identifiers, events and visit data | Consent; we load Google Analytics only after analytical cookies are enabled |
Direct B2B marketing | Work contact details, company, preferences and interactions | Consent where required, or legitimate interest in reasonable communications with the option to object |
Legal claims and compliance | Contractual, communication, security and billing records | Legal obligation and legitimate interest in establishing or defending a claim |
Service improvement | Aggregated statistics, diagnostics and feedback | Legitimate interest in developing a secure and useful Service; we anonymise data where possible |
Where we rely on legitimate interest, we assess necessity and the impact on your rights. You may object under Section 10. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. We do not sell personal data.
4. Recipients and suppliers
Where necessary, we disclose data to the following categories of recipients:
- hosting and database – Hetzner Online GmbH;
- email, object storage and related infrastructure – Amazon Web Services EMEA SARL;
- AI, translations and embeddings – OpenAI Ireland Limited;
- optional vector search – Qdrant Solutions GmbH, if the cloud service is activated;
- Google Ireland Limited and affiliated companies – Google sign-in, Google Analytics after consent, map display and, when the Gmail API is activated, the authorized email address, messages, attachments, headers, mailbox history and technical labels;
- Meta Platforms Ireland Limited and affiliated companies – authorization, webhooks and sending messages through WhatsApp Business, Messenger and Instagram, including account, Page, phone number, conversation, participant and profile identifiers where the Client activates the feature;
- Stripe Payments Europe, Limited – direct payment and billing portal;
- Shopify International Limited and affiliated companies – app installation, permissions, plan and platform billing;
- professional advisers, auditors, public authorities and legal successors where necessary and lawful.
The precise list of sub-processors for Client Content is provided in the Sub-processors and Platform Partners document. Payment providers and distribution platforms also process some data as independent controllers under their own terms.
5. Transfers outside the EEA
We primarily use European contracting entities and regions. However, global suppliers may involve branches or sub-processors outside the EEA. The transfer is based on an adequacy decision, standard contractual clauses or another lawful derogation and, where necessary, supplementary technical and organisational measures. Information about the relevant mechanism or a copy of the clauses may be requested at info@euro.support; we may protect commercial and security-related sections.
6. How long we retain data
Category | Usual period or criterion |
|---|---|
Account and contractual contacts | During the contract; after termination, an active account is generally closed within 30 days. We retain basic contractual records for 4 years after termination, or longer if a claim is ongoing. |
Invoices and accounting records | 10 years following the year to which they relate, or longer if required by applicable law. |
Support and business communications | 3 years from closing the request or the last substantive communication; longer if they form part of a contractual or legal file. |
Routine technical and access logs | Generally 90 days; records relating to an incident, abuse or claim for no more than 24 months or until the matter is closed. |
Marketing data | Until consent is withdrawn or an objection is made, for a maximum of 3 years from the last active interaction; we retain a minimal record of unsubscribing to respect your choice. |
Proof of consent or objection | During processing and generally for 4 years after it ends, where necessary to demonstrate compliance. |
Cookies and localStorage | As set out in the Cookie Policy; some data remains until deleted in the browser. |
Client Content processed on behalf of a Client | According to the Client’s settings and the DPA; after termination, generally active systems within 60 days and backups within 180 days. |
OAuth and access credentials for Gmail and Meta | For the active connection; the stored access token is removed upon disconnection. A connection identifier may remain with the communication history until its deletion under the Client’s settings and the DPA. |
We may shorten the period through minimisation or anonymisation. We may extend it if the data is needed for a legal obligation, a security investigation, legal proceedings or the establishment of a claim; in that case, access is restricted to that purpose.
7. Security
We use appropriate technical and organisational measures, in particular access and role management, encrypted transmission, protection of sessions and secrets, logging, tenant isolation, backups, updates, incident procedures and contractual review of key suppliers. No system is risk-free; report any suspected incident to info@euro.support.
8. AI and automation
In operating the Service, we use AI primarily for translations, response suggestions, summaries, categorisation, searching knowledge sources and the AI agent. For your own account, you decide which features are activated. The account’s internal analytics alone do not produce a decision with legal or similarly significant effects on you. If AI processes Client Content, we do so on behalf of the Client under the DPA.
We do not use Client Content to train our own general-purpose model. In standard mode, the OpenAI API does not use inputs and outputs to train models unless the API customer expressly opts to share them; the provider’s security logs may have their own limited retention period.
9. When we act as a processor
For customer chats, email and Gmail tickets, WhatsApp, Messenger and Instagram messages, order data, knowledge sources and content entered by the Client, the Client determines the purpose. Address requests for this data first to the organization with which you are communicating. We will provide assistance to the Client in accordance with the DPA. We will not use the data for our own marketing or to create a separate profile of the End User.
10. Your rights
Under the GDPR, you may request access, rectification, erasure, restriction, portability, object to processing based on legitimate interests and withdraw consent. In the case of direct marketing, you may object at any time. You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, unless a statutory exception applies.
Send your request to info@euro.support. We may reasonably verify your identity and the scope of the request. We will respond within the statutory time limit. If the data concerns the Client, we will forward the request to the Client or refer you to them. You have the right to lodge a complaint with the Office for Personal Data Protection of the Slovak Republic or the competent supervisory authority according to your habitual residence or place of work.
11. Children, links and changes
The Service is a B2B tool and is not intended for children to create an account. A Client whose support is intended for minors is responsible for providing specific information, determining the legal basis and implementing age-appropriate settings. The website may link to third-party services; their processing is governed by their own policies.
We may update these Policies when the Service or the law changes. We will notify you of a material change in an appropriate manner and state the new document date. Previous versions may be available upon request.
Version | 1.1 |
Document date | 24 July 2026 |
Operator | European Business Solutions s. r. o. | Budatínska 20, 851 06 Bratislava, Slovak Republic | Company ID No.: 54 230 012 | VAT ID: SK2121621689 | info@euro.support |