Privacy Policy

1. What this policy is about

DOMLUV.TO is a tool in which two people write down a job agreement: one writes down the work, the date, the price and the payment and sends a link; the other opens it in a browser and confirms the agreement, declines it or proposes a change. The service does not send money, does not issue invoices and does not act as an intermediary for work.

This policy describes how we process personal data on the website domluv.to, in the app app.domluv.to and in the mini app and bot in Telegram, under Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 Coll., on the processing of personal data.

2. Controller and contact

The controller of personal data is [name of the controller – to be filled in by the operator], [address of the controller – to be filled in by the operator].

For any matter concerning personal data, write to us at . We have not appointed a data protection officer, because Art. 37 GDPR does not require us to.

3. What data we process and why

We process only what the service actually needs in order to work:

  • Account: email, name, phone (optional), interface language and profile picture, if Google or Telegram provides one. Purpose: running the account and signing in. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Sign-in methods: the Google account identifier and the email Google has verified; the Telegram account identifier, username, name and photo from Telegram, and whether our bot may message you. Legal basis: performance of a contract.
  • One-time codes and sign-ins on devices: the email we sent the code to, and the period of validity. We do not store the code or the sign-in token in readable form, only their hash. Legal basis: performance of a contract and our legitimate interest in keeping accounts secure (point (f)).
  • Agreements: the name of the job, the date, the price, the payment terms, the place of work (address and, where given, coordinates), notes, ratings, photos and the full change history. Legal basis: performance of a contract; towards the other side, the legitimate interest of both sides in having the agreement documented.
  • Contacts and saved places: names, emails and phone numbers of the people you make agreements with, for people picked from Telegram their Telegram identifier and username, and the addresses of places where work is done. You enter them and we keep them for you. Legal basis: performance of a contract; for the people entered, legitimate interest.
  • Dictation: we send the audio recording to be converted into text and do not store it. We keep the transcript for 30 days. Legal basis: performance of a contract.
  • Notifications: email, the subscription address and your browser keys for web push, the chat with the bot in Telegram. You turn on web push by allowing it in your browser, and the bot only messages you if you have allowed it to in Telegram; you can turn either off at any time. Legal basis: performance of a contract.
  • Welcome from the bot: anyone who presses Start in our bot or allows it to message them gets a welcome message once. So that it does not arrive twice, we keep the Telegram account identifier and the time of the welcome; if someone does not create an account with us, we forget them after 30 days. Legal basis: legitimate interest.
  • Machine processing of text: a sentence you type or dictate may be read by a language model to pre-fill the form; shared texts (the terms and shared notes) are translated into Czech, Ukrainian, Russian, English, Romanian and Filipino, so that the other side can read them in their own language. We send private notes nowhere. Legal basis: performance of a contract.
  • Content checks: text that the other side will read may be checked automatically to make sure it is not offensive; we check photos for harmful files on our own server. Legal basis: legitimate interest in the safety of users.
  • Address search: we send the address text or coordinates to the Nominatim service without any data about you. Your browser loads the map directly from the OpenStreetMap servers, and only when you open the map. Legal basis: performance of a contract.
  • Emails you send us: the message (sender, recipients, subject, text and attachments) is received by the Resend service and we forward it to the people who run the service so that they can reply to you. We do not store the content of the message ourselves or write it into logs. Legal basis: legitimate interest in replying to you (point (f)); if the message concerns your account, performance of a contract.
  • Technical logs: shortened IP address (without the last block), browser type, time and address of the request. Sign-in data, codes and links to agreements are not in the logs. Purpose: protection against abuse and fixing errors. Legal basis: legitimate interest.

We do not use the data for advertising, do not sell it and do not build profiles from it. The automatic text check may reject an offensive message – it tells you what is wrong and stores nothing; this is not decision-making with legal effects under Art. 22 GDPR.

4. The other side of the agreement

Whoever receives a link to an agreement and opens it in a browser does not have to create an account. If they open it in Telegram (in the mini app), Telegram signs them in – so the first time they open it, an account is created for them, just as when signing in with Telegram – and the agreement is saved to their history. Their name, email or phone number is entered by the author of the agreement into their contacts and into the agreement. What the recipient writes or uploads through the link – a reply, a proposed change, a note, a photo – we process as part of the agreement.

The legal basis is the legitimate interest of both sides in having the agreement documented (Art. 6(1)(f) GDPR). The recipient has the same rights as everyone else and can exercise them at . If they later create an account, they can take the agreement over into their account.

5. Who we pass data to

The agreement can be seen by both of its sides and by whoever has the link. Apart from that, we use the following processors, who may handle the data only on our instructions. Some of them we switch on only when the feature in question is in operation.

If you link your account to Telegram or Google, those services pass data about you to us as independent controllers under their own policies. Web push notifications are delivered by the service of your browser’s maker; the content of the notification is encrypted.

6. Transfers outside the European Union

Some processors are based in the USA or elsewhere outside the EU. We transfer data to them on the basis of a European Commission adequacy decision (the EU–US Data Privacy Framework for certified companies; the United Kingdom) or standard contractual clauses under Art. 46 GDPR. We will provide a copy of the safeguards on request.

7. How long we keep data

Data that is no longer needed is overwritten automatically during the daily clean-up:

8. Deleting your account

You delete your account yourself in your profile, under “Danger zone”. We immediately end all sign-ins, cancel pending requests for a copy of your data, remove prepared archives and overwrite your email, name, phone, profile picture, Google and Telegram links, contacts, saved places, dictation transcripts, private notes, draft agreements and notification devices – including their change history. Photos that only you have seen are removed from storage.

Agreements you have already sent remain with the other side, because they are also that person’s record of what you agreed on (Art. 17(3)(e) GDPR and the legitimate interest of the other side). Instead of your name they will show “Deleted user”, and your contact details will disappear from them. You can then use the same email and the same Google and Telegram accounts to create a new account.

If the operator keeps database backups, the deleted data disappears from them as the backups are routinely replaced.

9. Your rights

You have the right:

  • of access to your data – in your profile you can request a copy of all your data: we prepare a ZIP archive in the background (a data.json file, your photos and a short description), let you know, and it is available for download for 7 days; a list of your requests stays in your profile;
  • to rectification – you change your name, phone and language in your profile;
  • to erasure – you delete your account in your profile;
  • to data portability – the data in the archive is in the machine-readable JSON format;
  • to restriction of processing;
  • to object to processing based on legitimate interest;
  • to turn off notifications and stop the bot from messaging you at any time;
  • to lodge a complaint with the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, www.uoou.gov.cz.

Send requests to . We will reply without undue delay and within one month at the latest. So that we do not hand data over to anyone else, we may ask you to confirm that the account is yours.

10. Cookies and browser storage

The app uses only strictly necessary cookies, without which sign-in and the choice of language cannot work; so we do not need consent for them. We use no analytics, advertising or tracking tools. This website (domluv.to) sets no cookies.

11. Security

All communication is encrypted (HTTPS). Sign-in tokens are kept in cookies that scripts on the page cannot access. We store codes, tokens and links to agreements only as a hash. Photos are kept in non-public storage and are shown through short-lived links that only a party to the agreement receives. We check uploaded photos before anyone sees them.

12. Children

The service is not intended for people under 16. If we find out that a child has created an account, we delete it.

13. Changes to this policy

We may update this policy when the service or the law changes. The current version is always on this page with its effective date; we will tell you about significant changes in advance in the app or by email.

Back to the home page