1. Who we are
This Policy explains how the provider of the SmileCrop application processes personal data of website visitors, customers, application users, and persons who contact support.
SmileCrop is a desktop application designed for local processing of photographs on the user's device. By default, the Provider does not receive or store patient photographs.
2. Important distinction: customer data vs. patient photographs
The Provider may process ordinary personal data of customers, such as name, email, billing details, order details, licence details, payment information, support communication, and technical data necessary for operating the website and licence.
Patient photographs that the User inserts into the Application are normally processed only locally on the User's device. The Provider does not have access to them unless the User provides them, for example as an email attachment for technical support. The User should not send patient data to the Provider unless it is necessary and agreed in advance. More information is available in the Patient Photos & Local Processing Statement.
3. What data we process
- Identification and contact data: name, surname, email, and, where applicable, company name, Company ID, VAT ID, and billing address.
- Purchase and licence data: purchased plan, purchase date, subscription status, Licence Key, activation history, and customer ID with the payment provider.
- Technical data: IP address, browser type, operating system, application version, device or instance identifier for activation and licence protection purposes.
- Communication: content of emails, support requests, error messages, and data voluntarily provided by the User.
- Website operation and performance measurement: Cloudflare processes technical and security information required to deliver and protect the website. Cloudflare Web Analytics uses a cookie-free performance beacon for aggregated visit and page-load metrics; it does not create a user profile or track visitors across websites. See the Cookie Policy.
- Checkout: Paddle.js is loaded on the purchase page after the visitor starts the purchase flow. Paddle may process the IP address, device and browser data, checkout interactions, and information entered for the order.
4. Purposes and legal bases of processing
| Purpose | Data categories | Legal basis |
|---|---|---|
| Order fulfilment, licence delivery, and subscription management | contact, billing, payment, and licence data | performance of a contract |
| Technical support under an existing contract | email, message content, and technical information | performance of a contract |
| Response to a general enquiry and defence of legal claims | email, message content, and related records | legitimate interest in communication and protection of legal rights |
| Licence verification | Licence Key, device/instance ID, activation status | performance of a contract |
| Fraud and Licence-abuse prevention | activation, order, device, and security-event data | legitimate interest in protecting the product and customers |
| Accounting and tax obligations | billing and payment data | legal obligation |
| Website and infrastructure security | IP address, logs, and technical data | legitimate interest |
| Cookie-free aggregated website performance measurement | load timing, page, device type, and aggregated visit metrics | legitimate interest in measuring and improving the website |
| Commercial communications | email and purchase history | consent, or legitimate interest for similar own services sent to existing customers, always with an opt-out |
| Any future analytics or marketing cookies | cookie identifiers and website behaviour | consent (currently not used) |
5. Payment provider (Paddle) and tax documents
Payments are processed by Paddle.com Market Limited ("Paddle") as Merchant of Record and authorised reseller. Paddle is an independent controller for information required to enter into and manage the payment relationship, invoicing, tax calculation, and fraud prevention. Paddle and its services, including ProfitWell group tools, may process contact and billing details, IP address, device and browser data, checkout interactions, Subscription status, and payment information. The SmileCrop Provider does not have access to the full payment card number.
Paddle is listed as the seller/merchant on the issued invoice or receipt. Paddle's own privacy policy applies to its processing of personal data.
6. Processors and recipients
Depending on the infrastructure used, personal data may be made available in particular to providers of hosting, domains, email communication, payments, licensing, customer support, and accounting. Currently we use in particular:
- Cloudflare — DNS, website hosting (Cloudflare Pages), CDN, security protection, and cookie-free aggregated website performance measurement;
- Paddle.com Market Limited — payments, invoicing, tax calculation and remittance (Merchant of Record), subscription management, and tax documents;
- Microsoft — distribution of the Application through the Microsoft Store under Microsoft's terms and privacy notice;
- Email provider — support communication and transactional emails;
- Accountant/tax advisor — processing of tax and accounting agenda.
Some recipients may process information outside the EU/EEA. Transfers rely on an adequacy decision, including the EU–US Data Privacy Framework for certified recipients, or the European Commission's Standard Contractual Clauses with supplementary safeguards. Information about the specific mechanism or a copy of the relevant safeguards may be requested by email.
7. Retention period
- Order, billing, and accounting data are retained for the period required by legal regulations, usually 10 years under accounting law.
- Licence and activation data is retained for the duration of the contract and generally for 3 years afterwards to defend legal claims and prevent abuse; records relating to a dispute or incident are retained while it is being resolved.
- Customer support communications are retained while the request is handled and generally for 3 years afterwards; longer only where required for a dispute or by law.
- Ordinary technical and security logs are generally retained for no more than 30 days; security-incident records are retained for the time needed to resolve the incident and defend legal rights.
- Cloudflare makes aggregated Web Analytics data available for the previous 6 months and, according to its documentation, retains unsampled beacon data for 7 days.
- Marketing contacts are retained until unsubscribe or objection, unless another legal basis applies.
8. Data subject rights
Under the conditions of the GDPR, the data subject has in particular the right of access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interest, and the right to withdraw consent where processing is based on consent.
Requests may be sent to [email protected]. The data subject also has the right to lodge a complaint with the Czech Office for Personal Data Protection (uoou.gov.cz).
9. Required information and automated decision-making
Information marked as required at checkout is contractually necessary. Without it, the order cannot be prepared, the tax treatment determined, the Licence delivered, or support provided. Company details, optional fields, and commercial communications are voluntary unless stated otherwise for a particular field.
The Provider does not make decisions based solely on automated processing that produce legal or similarly significant effects for a data subject. Paddle may use automated fraud-prevention tools under its own privacy notice.
10. Security
We adopt appropriate technical and organizational measures to protect personal data, including access limitation, use of secure infrastructure providers, and minimization of processed data. However, no system is absolutely secure.
11. Patient photographs and sensitive data
Because patient photographs may be personal data and, under certain circumstances, sensitive data or part of medical documentation, the Customer is responsible for their lawful processing. The Customer should ensure an appropriate legal basis, internal rules, access permissions, device security, and backups.
If it is necessary to send the Provider a sample file for support, we recommend using anonymized or sample data. Sending real patient data should take place only after prior agreement and with an appropriate legal basis. More information is available in the Patient Photos & Local Processing Statement.
12. Changes to the Policy
This Policy may be updated. The current version will always be available at smilecrop.app/privacy-en.html.