Legal
Privacy Policy
Last updated: 7 July 2026
This policy explains what personal data UntilPaid collects, why, and what rights you have over it. It’s written to meet the GDPR, the UK GDPR, and the Czech Act No. 110/2019 Coll. on the Processing of Personal Data. We’ve kept it as plain as we can.
1. Two hats: controller and processor
It matters which role we’re playing:
- For your account. When you sign up and use the service, we’re the controller of your own personal data (your name, email, and how you use the app). This policy covers that.
- For your clients’ data. When we read your invoices and contact the people you bill, we’re acting as your processor — you decide what happens, we carry it out. That relationship is governed by our Data Processing Addendum, not this policy. You should have your own privacy notice for your clients.
2. What we collect
Data you give us or that comes from Stripe
- Account details — your email address and the Stripe account identifier and email we receive when you connect Stripe.
- Configuration — the escalation rules, message templates, timezone, quiet hours, and sending settings you create.
- Billing details — if you subscribe, Polar (Polar Software Inc.), acting as merchant of record, processes your payment and handles any VAT or sales tax. We never see or store your full card number; we receive limited information such as your plan, payment status, and billing country.
Data we generate
- Activity logs — records of what the service did (which reminder was sent for which invoice, when, and whether it succeeded, failed, or was skipped).
- Suppression records — email addresses and phone numbers that have unsubscribed, bounced, or opted out, so we don’t contact them again.
- Technical data — IP address, browser type, and log data when you use the app, used to keep it secure and working.
Your clients’ data (as processor)
To do its job the service also handles your clients’ names, email addresses, phone numbers, and invoice details, read from Stripe. We process that only to run your follow-ups. See the DPA.
3. Why we use it, and our legal basis
Under the GDPR we need a lawful basis for each use. Here’s ours:
| What we do | Legal basis |
|---|---|
| Provide the service, run your account, and take payment | Performance of our contract with you |
| Keep the service secure, prevent abuse, and troubleshoot | Our legitimate interests in running a safe, reliable service |
| Send you essential service messages (e.g. a failed-reminder alert, security notices) | Performance of our contract / legitimate interests |
| Improve the product and understand how it’s used | Legitimate interests (balanced against your privacy) |
| Send you marketing (if we ever do) | Your consent, which you can withdraw at any time |
| Comply with legal, tax, and accounting obligations | Legal obligation |
Where we rely on legitimate interests, we’ve weighed them against your rights, and you can object (see Your rights).
6. International transfers
Some of our providers process data in the United States — Stripe, Polar, Postmark, Twilio, and (depending on the deployment region) Railway. When personal data is transferred outside the EEA/UK, we rely on an appropriate safeguard: the EU–U.S. Data Privacy Framework where the provider is certified under it, and otherwise the European Commission’s Standard Contractual Clauses (with the UK addendum) — so your data keeps an equivalent level of protection. You can ask us for details.
7. How long we keep it
- Account & configuration data — for as long as you have an account. When you disconnect Stripe or close your account, we delete it, along with your rules, sequences, and logs.
- Suppression records — kept for as long as needed to keep honouring an opt-out.
- Billing and tax records — kept for the period required by Czech tax and accounting law (up to 10 years for VAT documents under Act No. 235/2004 Coll.; accounting records for 5 years under Act No. 563/1991 Coll.).
- Backups and security logs — kept for a limited period, then rotated out.
8. How we protect it
We take security seriously and use measures appropriate to the risk, including: encryption in transit (HTTPS); encryption at rest for the sensitive secrets we store (such as connection tokens and provider credentials); signed, verifiable webhooks; access controls and least-privilege access to production systems; and validated, origin-checked requests to guard against forgery. No system is perfectly secure, but we work to keep the risk low, and we’ll notify you and the relevant authority of a personal-data breach where the law requires.
9. Your rights
If the GDPR or UK GDPR applies to you, you have the right to:
- access the personal data we hold about you, and get a copy;
- correct data that’s wrong or incomplete;
- erase your data (“the right to be forgotten”), in the circumstances the law allows;
- restrict or object to certain processing, including anything based on our legitimate interests;
- portability — receive your data in a structured, common format; and
- withdraw consent at any time, where we relied on it.
To exercise any of these, email [email protected]. We’ll respond within the time the law allows (usually one month). You won’t be charged, and we won’t treat you differently for asking. If you’re unhappy with how we’ve handled your data, you can complain to your local data-protection authority — for us, the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, ÚOOÚ, uoou.gov.cz) — but we’d appreciate the chance to put things right first.
If you’re one of our customers’ clients and want your data changed or removed, please contact that business (the controller). We’ll help them act on your request.
10. Children
The service is for businesses, not for children. We don’t knowingly collect data from anyone under 16. If you believe a child has given us data, contact us and we’ll delete it.
11. Changes
We may update this policy as the service or the law changes. We’ll post the new version here and update the date at the top; if a change is significant, we’ll tell you directly.
12. Contact
For any privacy question, email [email protected]. The controller is Jonas Vondracek, Czech Republic. We have not appointed a Data Protection Officer, as one is not required for processing on this scale.