Latch-X Logo

Privacy Policy – Latch‑X

Effective date: 2025‑11‑23
Business name: Peter Kováč – Latch‑X
Company ID (IČO): 57092753
Address: Pri vinohradoch 269/G, 83106 Bratislava, Slovakia
Contact: support@latch-x.com

1. What Data We Collect

We may collect the following personal data:

We do not collect sensitive personal data (e.g. health, biometric, or special category data).

2. How We Collect It

3. Why We Collect It (Legal Bases)

We process your data to:

4. Data Sharing & Processors

We may share your data with trusted service providers (“subprocessors”) who support the delivery of the Latch‑X service (e.g., billing, authentication, hosting, email delivery, logging/metrics, and security/CDN).

Our current list of subprocessors, including their roles and change history, is maintained at /legal/subprocessors.html.

OpenAI — AI assistant (on-demand only). When you use the assistant, we send your prompt and any content you explicitly include, plus minimal technical metadata (timestamps, request ID), to generate a response. We do not invoke the assistant or transmit your content in the background. Legal basis: Art. 6(1)(b) GDPR (performance of a contract — providing the requested feature). Retention: We do not persist prompts server-side beyond what’s necessary to return the result and operate the service; limited operational logs may exist for reliability and abuse prevention for a short period. See also Subprocessors.

We never sell or rent your data.

5. International Transfers

Some of our service providers are based outside the EU/EEA (e.g., Lemon Squeezy, Fly.io).

Transfers are based on Standard Contractual Clauses (EU 2021/914) or other legal safeguards to ensure your data is protected under EU law.

6. Your Rights (GDPR)

You have the right to:

We will respond to any request within 30 days.

You may contact:

Residents of the EU may also raise concerns with their local supervisory authority.

7. Data Retention

8. Security Measures

We protect your data using:

9. Data Breach Notification

In the event of a personal data breach, we will notify the Slovak DPA and affected users within 72 hours, in accordance with Articles 33–34 GDPR, if legally required.

10. Cookies

We use only strictly necessary (essential) cookies required for the proper operation of the Latch-X website and application. These cookies do not require your consent and cannot be disabled without affecting the service’s functionality.

Types of essential cookies we use:

These cookies are not used to track user behaviour and do not contain personal data beyond the technical identifiers required for operation.

We do not use analytics, marketing, or profiling cookies.

11. Changes to This Policy

We may update this Privacy Policy to reflect legal, technical, or operational changes.

You will be notified if changes significantly affect your rights or the use of your data.

12. Contact for Privacy Matters

For any questions, please email privacy@latch-x.com. We will respond within 30 days.

13. Change Log

– Updated retention windows to 60 days for temporary data, backups, and operational logs. 2025-11-23.

– Added Google Workspace (email hosting/communications) and replaced the in-document processor list with a link to the Subprocessors page. 2025-10-26.

– Initial release 2025-08-31.