VIRKODEX · Privacy
Privacy notice
This notice explains what data we need, why we use it, and what rights you have. We do not use the content of private AI cases for advertising or publish it.
Who controls your data
The controller for VIRKODEX is SEVK s. r. o., Palárikova 193/26, 018 41 Dubnica nad Váhom, Slovakia, company ID 56 122 292. Send questions and requests to virkodex@virkodex.com.
Data we handle
- account and contact: email, language, pseudonymous ID, and session-security data;
- membership and course: access status, orders, renewals, progress, knowledge-check answers, and highlights;
- AI cases: user-selected name, response settings, text, summaries, facts, and voluntarily uploaded screenshots;
- support and email: address, subject, thread content, attachments, and status;
- technical data: IP address, time, request path, device type, security logs, and error logs;
- payment: VIRKODEX mainly receives order and subscription status, amount, currency, and provider reference. We do not handle complete card details.
Purposes and legal bases
- Contract and steps before a contract: account, course access, progress, an AI request, support, and membership management.
- Legal obligation: accounting, tax, consumer rights, and lawful requests.
- Legitimate interests: security, abuse prevention, fault resolution, and legal claims. Private case content is not used for marketing profiles.
- Consent: marketing email, an express choice where required for sensitive processing, and any future non-essential analytics or marketing storage. Consent may be withdrawn at any time.
AI cases and screenshots
VIRKODEX AI is clearly identified as artificial intelligence. When enabled, only the context needed for the specific answer is sent to the AI provider. The Responses API request is made with store=false; under the provider's current rules, limited security logs may still be retained by default for a restricted period. We will publish the exact production setting and any reduced-retention arrangement before AI is activated.
Before uploading a screenshot, remove names, photos, phone numbers, addresses, notifications, and anything unnecessary. Upload only communication you are entitled to use. Do not upload intimate content, identity documents, medical records, children's data, or third-party material without authority. You may retain an attachment in a case or use it once; a one-use working copy is marked for deletion after processing.
Providers and feature status
A website visit alone does not send an AI case to OpenAI or payment data to Lemon Squeezy. A provider receives data only when the related feature is enabled and you use it.
| Provider | Role | When data is shared |
|---|---|---|
| Cloudflare | Delivery of the website and API, abuse protection, and technical logs. | Used when you visit the website. |
| Supabase | Sign-in, database, progress, private cases, and files. | Used for accounts and the member area. |
| Bunny Stream | Protected video playback and technical playback-quality data. | Only after activation and when a video is played. |
| OpenAI API | Moderation and generation of an AI response from text or screenshots submitted by the user. | Only after AI is activated and a request is expressly submitted. |
| Resend | Receiving and sending support, operational, and transactional email. | Only for email communication and after the production service is connected. |
| Lemon Squeezy | Hosted checkout, payment, tax, invoice, subscription, and refund handling as Merchant of Record. | Only after sales are activated; for the transaction it also acts as the independent seller and controller identified at checkout. |
Some providers or subprocessors may handle data outside the EEA. Where they do, a valid GDPR transfer mechanism is used, such as an adequacy decision or Standard Contractual Clauses. Before each feature is activated in production, the relevant processing agreement and subprocessor list must be reviewed.
How long data remains
- account and progress while the account exists, then only as needed for deletion, legal duties, or claims;
- AI messages and summaries until the case or data is deleted; attachments according to the “keep in this case” or “use once, then delete” choice;
- support email while it is being handled and for necessary follow-up; a thread placed in Trash is scheduled for permanent deletion after 30 days;
- orders and tax records for the statutory period;
- security and audit logs for no longer than is proportionate to protecting the service and documenting relevant events.
An ongoing dispute, legal duty, or abuse-prevention need may justify limited further retention. The binding retention schedule and backup rotation must be approved before payments and AI are enabled.
Your rights
Subject to the GDPR, you may request access, correction, deletion, restriction, portability, and object to processing based on legitimate interests. You may withdraw consent for the future. We may reasonably verify your identity.
VIRKODEX AI does not make decisions with legal or similarly significant effects. Its output is a suggestion and the decision remains yours. You may complain to the Slovak data protection authority or the authority where you usually live.
Security, children, and changes
The service is for adults aged 18 and over. We use separation of roles, private storage, short-lived links, access auditing, and encrypted transport. No internet service can promise absolute security.
We will explain material changes on the website or by email. The date above identifies the current version. See Cookies and storage for browser data.