1. Who we are
This Policy explains how the Provider of the SmileCrop application processes the personal data of website visitors, customers, users of the application, and people who contact support.
SmileCrop is a desktop application that processes photographs locally on the user's device. Network functions for updates and licence management are described in section 3. Photo processing is separate from purchases, licensing and messages you choose to send us.
2. Important distinction: customer data vs. patient photographs
The Provider may process ordinary customer personal data such as name, e-mail, billing details, order, licence, payment, support communication, and the technical data necessary to operate the website and the licence.
Patient photographs that the User loads into the Application are processed only locally on the User's device. The Provider has no access to them unless the User supplies them, for example as an e-mail attachment for technical support. The User should not send patient data to the Provider unless it is necessary and agreed in advance. More in the patient photograph statement and in section 15.
3. What the application sends over the network
Local photo processing does not mean the application never communicates over a network. The following describes network functions for updates and trial or paid use. Infrastructure providers also process IP addresses and associated technical information when receiving network requests.
| When | To | What is sent |
|---|---|---|
| On every launch | smilecrop.app (Cloudflare) |
A request for the file describing the latest version. It sends the application name and version (e.g. SmileCrop/3.6.1). As with any HTTP request, Cloudflare records the IP address, time and country. The application itself is updated by the Microsoft Store; this request serves to report what is new and to allow an update of the recognition model. |
| Only on unlicensed installations (trial) | Our own server (a Cloudflare Worker) | Device identifier, application version and platform (for example Windows, or an installation from the Microsoft Store). This keeps the 14-day trial clock on the server so it cannot be reset by reinstalling. Once a licence key is entered, this connection is no longer made. |
| On licence validation (the result is cached for 24 hours) | Keygen LLC, USA | Licence key and device identifier for validation. Creating an activation slot also sends the computer name and operating system. The licence provider also receives the network request's IP address. These data support licence validation and the permitted-device record. |
Patient data: photo processing does not require sending photographs, patient names, folder contents or file paths to the Provider. Information you choose to send us for support is a separate disclosure. Do not send patient data without prior agreement.
About the device identifier. It is not anonymous data and we do not describe it as such. It is a pseudonymised persistent identifier: a one-way digest (SHA-256) of the network adapter address, the computer name and the processor architecture. The digest does not directly reveal the original values, though where the range of possible values is known they could in theory be guessed and checked. The identifier stays the same and is linked to the licence record — which is why we treat it as personal data. We consider reading these values from the device necessary for the service the user has explicitly requested (running the application under a licence or a trial), and we do not use them for any other purpose. Should that exception under § 89 of Czech Act No. 127/2005 Coll. not apply, we will obtain consent in advance.
Additional protection of trial identifiers. The identifier sent by the application is recalculated using our secret key before the result is stored with the licensing provider. This limits direct linkage to a device, but does not guarantee anonymity or exclude linkage using other available information. For a paid licence, the activation slot is recorded under the identifier the application sends.
4. Artificial intelligence in the application
SmileCrop uses a machine-learning object-detection model to identify photograph types and select crops. Its functions and data flows are described below.
- The model runs on your computer. It is part of the installation. Recognition does not happen in the cloud and does not require an internet connection. Licence validation and update checks are separate functions that do need a connection — see section 3.
- Data flows one way only. The model is downloaded to you when it is updated. Your photographs are never sent back, and the model does not learn or retrain on them.
- What the model does. It determines the type of a photograph and its crop. It does not recognise anyone's identity, does not infer age, sex, origin or emotion, and performs no biometric identification or categorisation of people.
- What the model does not do. It produces no diagnosis, no clinical assessment and no treatment recommendation — no such output exists. It is a tool for standardising and organising image documentation; what the treating clinician then does with the finished photograph is for them to decide.
- The decision stays with you. Photographs the model is unsure about are flagged for review; any result can always be corrected or overridden by hand.
5. What data we process
- Identification and contact data: first name, surname, e-mail, and where applicable company name, company ID, VAT ID, billing address.
- Purchase and licence data: the plan purchased, purchase date, subscription status, licence key, activation history, customer ID at the payment provider.
- Technical data: IP address, browser type, operating system, computer name during activation, application version, and a pseudonymised device identifier for activation and licence protection (see section 3).
- Communication: the content of e-mails, support enquiries, error reports and data the User voluntarily provides.
- Website operation: as our hosting and protection provider, Cloudflare processes the technical and security data that arises with every request to the server — IP address, request headers and time. The website cannot be delivered or protected without them. We place no measurement script in your browser. We estimate traffic only from the aggregate server-side reports Cloudflare compiles from ordinary traffic records; no visitor identifier is created. Details are in the cookie information.
- Checkout: Paddle.js loads on the purchase page and — if you reach the pricing section — on the home page as well, to show prices in your currency and to process payment. We verified by measurement that displaying the price alone writes no cookies or other storage to your browser; it is a transfer of your IP address used to estimate currency and tax. The final tax treatment is determined from the billing details entered at checkout. During an actual purchase, Paddle may process the IP address, device and browser data, checkout interactions, and the data entered for the order.
6. Purposes and legal bases of processing
| Purpose | Data categories | Legal basis |
|---|---|---|
| Fulfilling the order, delivering the licence, managing the subscription — where the customer is a natural person | contact, billing, payment, licence data | performance of a contract |
| The same where the customer is a clinic or company: data about the contact person, director or employee | name, work e-mail, role | legitimate interest in concluding and administering the relationship with the customer |
| Technical support under an existing contract | e-mail, message content, technical information | performance of a contract |
| Answering a general enquiry and defending legal claims | e-mail, message content, related records | legitimate interest in communication and protection of rights |
| Licence validation and activation-slot records | licence key, device identifier, activation status | performance of a contract |
| Running and protecting the trial period on the server side | device identifier, application version, installation type | steps taken prior to entering into a contract at the request of the user who started the trial; for subsequent checks, legitimate interest in preventing the trial period from being reset repeatedly |
| Checking the availability of application and model updates | application name and version, IP address, time and country of the request | legitimate interest in users — including those on a trial — running a current, secure and working version |
| Showing the price in local currency on the website (Paddle price preview) | IP address and the country derived from it | steps prior to a contract at the request of the visitor who opened the pricing section; further, legitimate interest in the price matching the visitor's currency and tax |
| Fraud prevention and licence abuse prevention | activation, order, device and security-event data | legitimate interest in protecting the product and customers |
| Accounting and tax obligations | billing and payment data | legal obligation |
| Website and infrastructure security | IP address, logs, technical data | legitimate interest |
| Commercial messages to existing customers about our own similar services | e-mail obtained in connection with a sale, purchase history | legitimate interest under Art. 6(1)(f) GDPR, subject to the conditions of § 7(3) of Czech Act No. 480/2004 Coll. — limited to our own similar services, with the ability to refuse both when the address is collected and in every individual message |
| Commercial messages in all other cases | consent, withdrawable at any time | |
| Any analytics or marketing cookies | cookie identifiers and on-site behaviour | consent (we currently deploy no analytics or marketing cookies; you may, however, activate a third-party service yourself — see section 9) |
| Playing an embedded video | IP address, device and browser data, storage written by Google | consent given by clicking (see section 9) |
7. Payment provider (Paddle) and tax documents
Payments are processed by Paddle.com Market Limited ("Paddle") as Merchant of Record and authorised reseller. Paddle is an independent controller of the data needed to enter into and administer the payment relationship, invoicing, tax calculation and fraud prevention. Paddle and its services, including ProfitWell tools, may process contact and billing data, IP address, device and browser data, checkout interactions, subscription status and payment data. The Provider of SmileCrop has no access to the full payment card number.
Some customer and order data reaches us from Paddle rather than directly from the customer — in particular the e-mail, name, billing details and order status required to issue and deliver the licence. The source of that data is therefore Paddle.
How the licence key reaches you
The whole path is worth describing, because several services take part in it:
- You pay Paddle. On a successful payment it sends us a message (a webhook) containing your e-mail address and the order details.
- Our server at Cloudflare receives that message and asks Keygen to create a licence key.
- We e-mail the key to you through Resend.
The server sends the customer's email address and Paddle customer/subscription identifiers to Keygen when issuing or updating a paid licence. The desktop application does not send the email address again during activation. It does send licensing and technical data, including the computer name. This name may contain a person's or practice's name, so we do not treat these records as anonymous.
Paddle is shown as the seller/merchant on the document issued. Paddle's processing of personal data is governed by its own privacy policy.
8. Processors and recipients
Depending on the infrastructure used, personal data may be made available to providers of hosting, domains, e-mail communication, payments, licensing, customer support and accounting. Currently these are:
| Recipient | Role | What data | Where processed |
|---|---|---|---|
| Cloudflare | DNS, website hosting, CDN, security protection, cookie-free performance measurement, the trial server, and processing the order once payment completes | IP address, request headers and time, application version, device identifier on trial installations, and on purchase the e-mail address and order details from Paddle. Our licence database also runs at Cloudflare — see below. | global network including servers outside the EU/EEA |
| Paddle.com Market Limited | payments, invoicing, tax calculation and remittance (Merchant of Record), subscription management | contact, billing and payment data, IP address, checkout interactions | United Kingdom and other countries under Paddle's own policy |
| Keygen LLC | issuing and validating licence keys, records of activation slots and trial licences | customer email, Paddle customer and subscription identifiers, licence key, pseudonymised device identifier, computer name, operating system, IP address, activation status and history | USA (Amazon Web Services, Virginia); Keygen offers no EU data residency |
| Microsoft | distribution of the Application through the Microsoft Store | account and purchase data under Microsoft's terms; the scope made available to the developer is determined by Microsoft | under Microsoft's policies |
| Resend (Plus Five Five, Inc.) | sending transactional e-mail — in particular delivery of the licence key | e-mail address, subject and message content | USA |
| Google (support mailbox) | receiving and storing e-mail sent to the support address | e-mail address and message content, including any attachments you send us | under Google's policies, including servers outside the EU/EEA |
| Accountant / tax adviser | tax and accounting administration | billing and payment data | Czech Republic |
Our licence database
We keep orders and licences in a database hosted at Cloudflare. Data may also appear in support messages, records and the systems of the recipients listed here. We therefore assess erasure requests across all relevant systems and take legal retention grounds into account.
It holds: the customer's e-mail address, the Paddle order and subscription identifiers, the licence key with its status and expiry date. Alongside that we store a record of every payment message Paddle sends us. That record keeps the message as it arrived, including the billing details Paddle puts in it. Its purpose is to make sure one payment is never processed twice, and to allow us to trace what happened when an order fails.
9. Embedded video (YouTube)
Purpose: to show how SmileCrop is set up and used.
When a transfer happens: only after you press "Load video from YouTube". Nothing is sent to Google before that.
Data: IP address, device and browser data, and playback information. The scope is determined by Google, not by us.
Recipient: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, and its sub-processors.
Legal basis: consent under Art. 6(1)(a) GDPR, given by pressing a button whose label states what pressing it does.
Withdrawing consent: the "Disconnect the player" button beside the player. It stops further loading; data already sent cannot be recalled.
If you decline: nothing happens except that the video does not play. Every video guide has a complete written version.
10. Transfers outside the EU/EEA
We consider a general statement that "some data may be transferred outside the EU" to be inadequate. We therefore name the specific mechanism for each recipient a transfer actually reaches:
- Keygen LLC (USA) — processes in the USA and offers no EU data residency. The transfer is made under the European Commission's Standard Contractual Clauses. According to its own documentation Keygen is not certified under the EU–US Data Privacy Framework. Transferred data includes: customer email, Paddle customer and subscription identifiers, licence key, pseudonymised device identifier, computer name, operating system, IP address and activation status.
- Cloudflare — operates a global network, so a request may be served from a location outside the EU/EEA. Transfers to the United States rely on Cloudflare's certification under the EU–US Data Privacy Framework; transfers to other countries are covered by the Standard Contractual Clauses Cloudflare enters into alongside that certification.
- Google Ireland Ltd. (embedded video) — the recipient is the Irish entity; onward transfers within the Google group follow the mechanisms Google publishes for its services. This transfer happens only if you click.
- Paddle — acts as an independent controller. Any onward transfer it makes is governed by its own policy and safeguards; it is not a mechanism chosen by us.
Resend (Plus Five Five, Inc., USA) — sends transactional e-mail, and therefore processes your e-mail address in the USA. It is certified under the EU–US Data Privacy Framework and additionally enters into Standard Contractual Clauses. It publishes its sub-processors, which are likewise US-based, in its own list.
Google — the support mailbox. Transfers are governed by Google's policies for that service.
We checked the Data Privacy Framework certifications directly against the official U.S. Department of Commerce list on 31 August 2026, rather than relying on the vendor's own claim: Cloudflare, Inc. — active; Resend — active, with a re-certification under review. Status can change; the current entry is publicly verifiable.
A copy of the safeguards used, or information about the specific mechanism, can be requested at [email protected].
11. Retention period
For successfully processed payment events, the original message body is configured for removal after 90 days during the next weekly cleanup, subject to a per-run limit. The event identifier remains for replay protection. Unresolved or failed events need separate resolution; this cleanup does not delete licences or all order data.
- Accounting documents (invoices and related records) are kept for 5 years from the end of the accounting period they relate to — § 31(2)(b) of Czech Act No. 563/1991 Coll. on Accounting. Financial statements are kept for 10 years under § 31(2)(a) of the same Act. Where a document is also subject to the Czech VAT Act, the longer period under that Act applies.
- Licence and activation data are kept for the duration of the contract and normally 3 years afterwards to defend legal claims and prevent abuse; data related to a dispute or incident for as long as it is being resolved.
- The trial record is kept indefinitely, and deliberately so. It is the only thing preventing someone from uninstalling the application repeatedly and starting a fresh 14-day trial each time. The purpose is to prevent repeated trials on the same device. What we process is minimal: the stored value is a digest recalculated with our own secret key, it is linked to no name or e-mail, and we treat it as pseudonymous personal data, not anonymous information. We assess erasure requests and objections under GDPR. Deletion may allow a new trial on that device. Indefinite technical storage does not itself establish legal necessity; retention must remain proportionate to a continuing purpose.
- Customer support communication is kept until the request is resolved and normally 3 years afterwards; longer only where an ongoing dispute or legal obligation requires it.
- Technical and security records of website traffic are retained by Cloudflare under its own rules for that service; we keep no copy of them. Aggregate traffic reports are available in the dashboard for a matter of months, not years.
- For Keygen, different data categories have different retention periods: its privacy policy describes up to 30 days for operational logs and up to 90 days for webhook data. This is not a guarantee that all copies disappear within 30 days. Licence records and backups must be assessed separately.
- Marketing contacts are kept until unsubscribe or objection, unless another legal ground applies. A record of the unsubscribe is kept afterwards as well — otherwise we could not guarantee that no further message reaches you.
12. Data subject rights
Under the conditions of the GDPR, a data subject has in particular the right of access, rectification, erasure, restriction of processing, portability, the right to object to processing based on legitimate interest, and the right to withdraw consent where processing is based on consent.
Send requests to [email protected]. We will inform you of action taken without undue delay and within one month. Where necessary because of the complexity or number of requests, this may be extended by up to two further months; we will explain the extension within the first month. We may request proportionate identity verification where reasonable doubts exist. Erasure is not unconditional: we will explain the reason and scope of any data that must be retained.
Because "erasure" means something different in every system, here is specifically what happens:
| Data | Where it is held | What we do |
|---|---|---|
| E-mail and support communication | the support mailbox (Google) and send records at Resend | Removed from the active mailbox and archive where erasure conditions are met. Backups are overwritten on their own cycle, so a copy may persist briefly until it expires. |
| The licence and order record in our own database (including the e-mail and the payment message from Paddle) | our database at Cloudflare | Where erasure conditions are met, we remove data from the active database. Legal duties, ongoing claims and backup recovery are assessed separately. |
| Customer and payment record | Paddle | We pass an erasure request to Paddle. The decision rests with Paddle as an independent controller — it keeps data for which it has its own legal ground, in particular tax and accounting. |
| Licence, device identifier, activation history | Keygen | Deleted. Note: this makes the licence key stop working. Once the local 72-hour offline grace period expires, the application switches to limited mode. We will therefore warn you of this consequence in advance and carry out the erasure once you confirm it even so. |
| Invoices and accounting documents | accounting records | Cannot be deleted for the duration of the statutory period (see section 11). This is a legal obligation under Art. 17(3)(b) GDPR. They are destroyed once the period expires. |
| Marketing contact | subscriber list | Unsubscribed immediately. We keep only the minimum record needed to avoid contacting you again by mistake. |
A data subject also has the right to lodge a complaint with the Czech Office for Personal Data Protection, uoou.gov.cz.
"Do Not Track" and Global Privacy Control signals
Some browsers send a Do Not Track or Global Privacy Control signal to say you do not wish to be tracked. Our answer is simple: we do not track you whether or not you send the signal. The website uses no advertising or analytics cookies, builds no profiles, and we neither sell personal data nor share it for targeted advertising. There is nothing to switch off — the site behaves identically with or without the signal.
13. Required information and automated decision-making
Fields marked as required at checkout are a contractual requirement; without them an order cannot be prepared, the tax treatment determined, the licence delivered or support provided. Company details, optional fields and receiving commercial messages are voluntary unless stated otherwise for a specific field.
Licence validation is automated and may restrict access when a licence is invalid or validation fails. If you believe the result is wrong, contact [email protected] to request human review. Licence validation does not assess patients' health. Paddle may use its own fraud-prevention tools under its policies.
14. Security
We take appropriate technical and organisational measures to protect personal data, including access restrictions, the use of secure infrastructure providers, and minimising the data processed. No system, however, is absolutely secure.
About distribution. Both SmileCrop and SmileQR are installed and updated exclusively through the Microsoft Store, so Microsoft signs and delivers the package. The earlier direct download of an installer from our own storage has been discontinued and the files deleted. Should we ever need to distribute a file outside the Store, we operate a rule that no personal data may be placed in publicly accessible storage.
15. Patient photographs and sensitive data
Because patient photographs may be personal data and, in certain circumstances, sensitive data or part of medical records, the Customer is responsible for processing them lawfully. The Customer should ensure an appropriate legal basis, internal rules, access permissions, device security and backups.
Support rule: do not send us real patient data by ordinary e-mail. An anonymised or sample image is almost always sufficient to resolve a problem. If sending a real image were exceptionally necessary, we will agree in advance on a secure method of transfer, a written processing instruction under Art. 28 GDPR, and a deadline by which we will delete the file. Without such an agreement we neither ask for real patient data nor expect it.
If it arrives anyway. If a real patient image reaches us without a prior agreement, that cannot be undone — so we have a procedure: we do not process the message beyond what is needed to recognise what it is, we securely delete the file, and we inform the clinic. More in the patient photograph statement.
16. Changes to the Policy
This Policy may be updated. The current version will always be available at smilecrop.app/en/privacy.