Privacy Policy — Cybermindnet s.r.o.
1. Controller
The controller within the meaning of Art. 4(7) GDPR is:
Cybermindnet s.r.o.
represented by Mgr. Mikuláš Peksa, Ph.D., Managing Director
Vícenice 24, 339 01 Klatovy, Czech Republic
E-mail: info@cybermindnet.eu
Telephone: +420 778 206 679
Registered in the Commercial Register kept by the Regional Court in Plzeň, Section C, Insert 36267 — Company ID (IČO) 07126042
cybermindnet.de is the German-language presentation of the same company, not a separate legal entity under German law. The company is established solely in the Czech Republic.
2. Data Protection Officer
No Data Protection Officer has been appointed. The conditions of Art. 37(1) GDPR are not met: we are not a public authority, we carry out no large-scale regular and systematic monitoring, and we do not process special categories of data under Art. 9 GDPR on a large scale.
3. Processing when you visit our website
When our pages are loaded, technically necessary data is processed: IP address, time of access, the resource requested and the browser type transmitted. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is the secure and stable operation of the website.
4. Contact form
Through the form on the Contact page we collect: subject, name, company, e-mail address, telephone number and the text of your message. We store this data in our own CRM in order to handle your enquiry.
The legal basis is Art. 6(1)(b) GDPR where the enquiry is directed towards entering into a contract, otherwise Art. 6(1)(f) GDPR.
Retention periods:
| Situation | Period |
|---|---|
| enquiry did not lead to a contract | 6 months from the last communication |
| enquiry led to a contract | in line with statutory archiving obligations, in the Czech Republic up to 10 years from the end of the contractual relationship (accounting and tax rules) |
| consent to receiving marketing communications | 5 years at most, withdrawable at any time |
5. Processing using language models on our own infrastructure
We process contact form submissions and the subsequent commercial correspondence with the support of language models (AI) that we operate on our own infrastructure.
- The text of your message is not passed to any external AI provider. We do not use third-party cloud APIs for this purpose.
- The model prepares background material or a draft reply. Handling the enquiry and sending the reply remain with a human being.
- This is therefore not automated individual decision-making or profiling within the meaning of Art. 22 GDPR — see § 11.
- The legal basis is the same as for handling the enquiry itself (§ 4). AI is a processing tool, not a new purpose.
This is a deliberate design decision, not a description of an accidental state: we keep the processing of customer enquiries on our own hardware precisely so that a cloud model provider does not gain access to it.
6. Social media publishing service
We operate a self-hosted social media publishing tool at postiz.cybermindnet.eu. We use it for our own channels and for the channels of clients whose social media presence we manage under contract. The associated Meta application is registered as “Postiz Cybermindnet” (app id 1461633349043216).
Who this concerns. This section applies to the person who connects a Facebook Page or Instagram account to the tool — typically a Page administrator or the account holder — and to us as the operator. It does not concern ordinary visitors to our website.
What we obtain from Meta. When a channel is connected, the authorising person grants the application access via Meta's standard OAuth dialogue and we receive and store:
| Data | Purpose |
|---|---|
| Meta user ID, Page ID or Instagram account ID | to address the correct channel when publishing |
| Page or account name and profile picture | so the user can tell the channels apart in the interface |
| access token for the Page or account | to publish on the channel on the user's behalf without a repeated login |
| content prepared for publication (text, images, video) and publication times | the very purpose of the service |
| identifiers and statistics of published posts returned by Meta | reporting on what was published and how it performed |
Permissions requested. For Facebook Pages: pages_manage_posts, pages_read_engagement, pages_show_list, pages_manage_engagement, pages_read_user_content, read_insights, business_management. For Instagram: instagram_business_basic, instagram_business_content_publish, instagram_business_manage_comments, instagram_business_manage_insights. Each is used solely for the purposes in the table above.
Legal basis. Art. 6(1)(b) GDPR — performance of the contract with the client whose channels we manage; for our own channels Art. 6(1)(f) GDPR (legitimate interest in our own communication).
Where the data is held. On our own servers in Germany (see § 7). Access tokens are held in the application database, to which access is restricted to the administrators of the service. We do not transfer them to anyone.
What we never do with it. We do not sell this data, we do not pass it to third parties, we do not use it for advertising targeting, and we do not use it to train language models. We do not read private messages of connected accounts, and we do not access data about a Page's followers beyond the aggregate statistics Meta itself returns for a published post.
Retention and deletion. Content and publication history remain in the tool until deleted by the user or until the end of the contractual relationship. Uploaded media files are held on our servers; video files may, after publication, be replaced by a placeholder to save storage space. Disconnecting a channel deletes the associated access token.
How to have your data deleted. You have three independent routes and any one of them is sufficient:
- In the tool: disconnect the channel at
postiz.cybermindnet.eu. The token is deleted. - At Meta: on Facebook under Settings → Business Integrations, or on Instagram under Settings → Apps and Websites, remove the application “Postiz Cybermindnet”. This revokes our access immediately.
- By e-mail: write to info@cybermindnet.eu and we will delete the channel, its token and the associated publication history. We will confirm this to you.
7. Recipients and processors
We do not pass data to third parties, with the exception of the following processors, who work for us on our instructions and under a contract pursuant to Art. 28 GDPR:
| Processor | What they do for us | Place of processing |
|---|---|---|
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (HRB 6089, Ansbach) | operation of the servers running this website, our e-mail system, our CRM and the publishing tool under § 6 | data centres Falkenstein (Saxony) and Nuremberg (Bavaria), both in Germany |
| Sendinblue SAS (“Brevo”), 9-17 rue Salneuve, 75017 Paris, France (RCS Paris 498 019 298) | technical dispatch of our outgoing e-mail, including replies to your enquiries | European Union |
We operate the CRM ourselves on the servers named above — no further processor is involved. This tends to cause misunderstanding: readers usually imagine a cloud service behind the word "CRM", whereas here it is our own installation. The language models under § 5 likewise run on our own infrastructure, so no external processor is involved there either.
Meta Platforms Ireland Limited is not our processor in respect of § 6. Where we publish content to Facebook or Instagram, Meta processes it as an independent controller under its own privacy policy.
No transfer to a third country outside the EEA takes place.
8. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object to processing based on legitimate interests (Art. 21). A message to the e-mail address given above is sufficient.
9. Where you can complain
If you believe we are not processing your data lawfully, you may turn to a supervisory authority. You have a choice here and you do not have to approach one abroad.
The authority competent for us in the Czech Republic: Úřad pro ochranu osobních údajů (Office for Personal Data Protection) Pplk. Sochora 27, 170 00 Prague 7, Czech Republic uoou.gov.cz
As the company has its registered office in the Czech Republic, this authority is our lead supervisory authority (Art. 56 GDPR).
Or the supervisory authority where you live or work. If you live in Germany, you may equally well approach the supervisory authority of your federal state. It will accept your complaint and coordinate with the Czech authority. This right is given by Art. 77(1) GDPR.
10. Analytics
On our websites we use Matomo, which we operate ourselves at matomo.cybermindnet.eu. We use it to find out which pages are visited and which links are clicked, so that we can improve the site.
We store no cookies on your device in doing so. Our Matomo runs in cookieless mode, enforced centrally on the server, so it applies to all our websites regardless of their individual configuration. That is why there is no consent banner — without storing anything on your device, § 89(3) of Czech Act No. 127/2005 Coll. does not require one. Your IP address is additionally anonymised at the point of recording.
The data does not leave our own infrastructure and no third-party analytics or advertising tool is used — there is no Google Analytics, no Google Tag Manager, no Meta pixel or anything comparable.
The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is understanding the use of our own website. You may object to this processing at any time (§ 8).
11. Automated decisions
No automated individual decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. The involvement of language models under § 5 does not change this — the model prepares material, a human being makes the decision and writes the reply.
12. Status
Version 1.2 of 10 September 2026. Translated from the Czech canonical version.