Back to Home

Privacy Policy

Version 1.0 — Effective 7 June 2025

Why read this? Because we respect your privacy and want you to understand exactly how and why we handle your personal data.

(This policy is drafted to meet EU GDPR 2016/679, UK GDPR, and Czech Act 110/2019 Sb. If you operate outside the EEA/UK, additional local rules may apply.)

1. Who we are — Data Controller

Duc Luan Dam ("SoT", "we", "us")

Reg. No.: 06957315

Registered office: Bochorakova 3074/17, 616 00, Brno, Czech Republic

Email: privacy@scoutsof.tech

2. What data we collect & why

CategoryExamplesPurposeLegal basis (Art. 6)Retention
Contact dataName, email, phoneRespond to enquiries, schedule callsb) Contract or f) Legitimate interest24 months after last contact
Calendly metadataPreferred time, IP, user-agentBook meetingsb) Contract2 yrs (Calendly default)
Marketing signalsNewsletter opt-in, open/click ratesSend updatesa) ConsentUntil withdrawal
Analytics (Plausible)Pseudonymous page viewsImprove UXf) Legitimate interest12 months (aggregated)
Server logsIP, referrer, timestampDetect fraud & ensure uptimec) Legal obligation (art. 32)30 days

We never knowingly collect special-category data (Art. 9) or data on children < 16.

3. Cookies & tracking

We use a strictly-necessary session cookie for load balancing, plus an optional analytics cookie set by Plausible (EU-hosted, cookieless by default). The cookie banner lets you decline non-essential cookies. See full cookie table in Appendix A.

4. How we share data

RecipientPurposeSafeguard
Resend, Inc. (USA)Transactional email deliveryStandard Contractual Clauses (SCC 2021)
Vercel Inc. (USA/EU region)Website hosting & Edge FunctionsSCC + EU datacentres
Calendly LLC (USA)Scheduling widgetSCC

We never sell your data.

5. International transfers

When partners sit outside the EEA/UK, we rely on SCCs plus risk assessments. Copies are available on request.

6. Your rights

You may access, rectify, erase, restrict, object, or port your data at any time. Email privacy@scoutsof.tech. We respond within 30 days. If unhappy, lodge a complaint with the Czech DPA (ÚOOÚ) or your local authority.

7. Security measures

  • TLS 1.3 for transport
  • OWASP-compliant code reviews
  • Field-level encryption for PII at rest
  • Role-based access & MFA for staff

8. Data retention & deletion

We keep personal data only as long as necessary for the purpose collected, then securely delete or anonymise. See table §2.

9. Changes

We may update this notice. Material changes → we'll email you or display a banner.

10. Contact

For privacy questions: privacy@scoutsof.tech