Last updated: June 2026

Privacy Policy

1. Introduction

This Privacy Policy explains how UGIPO Group s.r.o. ("we", "us", "our"), operating the ChatBakers platform, collects, uses, stores, and protects your personal data when you use our website (chatbakers.com) and application (app.chatbakers.com).

We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and applicable Czech and EU data protection laws.

2. Data Controller

The data controller responsible for your personal data is:

UGIPO Group s.r.o.

Pobrezni 249/46, Karlin, 186 00 Praha, Czech Republic

ICO: 10907271 | DIC: CZ10907271

Email: [email protected]

3. Data We Collect

We collect the following categories of personal data:

  • Account data: Name, email address, and password when you register for an account.
  • Organization data: Company name, website URL, and billing information.
  • Usage data: Information about how you interact with our platform, including pages visited, features used, and preferences.
  • Payment data: Billing details processed securely through our payment provider, Stripe. We do not store your full credit card information on our servers.
  • Technical data: IP address, browser type, operating system, and device information collected automatically when you access our service.
  • Communication data: Any information you provide when contacting us via email or through our contact form.

4. How We Use Your Data

We use your personal data for the following purposes:

  • To provide, maintain, and improve our AI visibility monitoring service.
  • To process your subscription and manage billing.
  • To send you service-related communications, including weekly reports and alerts.
  • To respond to your inquiries and provide customer support.
  • To analyze usage patterns and improve our platform's functionality.
  • To detect, prevent, and address technical issues and security threats.
  • To comply with legal obligations.

5. Legal Basis for Processing

We process your personal data based on the following legal grounds under GDPR:

  • Contract performance: Processing necessary to provide you with our services under your subscription agreement.
  • Legitimate interests: Processing necessary for our legitimate business interests, such as improving our service and ensuring security.
  • Consent: Where you have given explicit consent, such as for marketing communications.
  • Legal obligation: Processing necessary to comply with applicable laws and regulations.

6. Data Sharing

We do not sell your personal data. We may share your data with the following categories of third parties:

  • Payment processors: Stripe, for processing subscription payments.
  • Hosting providers: Infrastructure providers that host our application and store data.
  • Analytics providers: Services that help us understand how our platform is used.
  • Legal authorities: When required by law or to protect our rights.

All third-party processors are bound by data processing agreements that ensure GDPR compliance.

7. International Data Transfers

Your data is primarily stored and processed within the European Economic Area (EEA). Where data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.

8. Data Retention

We retain your personal data for as long as your account is active or as needed to provide you with our services. After account deletion, we retain certain data for up to 30 days for backup purposes, and billing records as required by tax and accounting regulations (typically up to 10 years under Czech law).

9. Google Services Integration

ChatBakers connects to Google services on your behalf via OAuth 2.0. Specifically, we may request access to:

  • Google Analytics (read-only): Traffic and engagement metrics for websites you choose to monitor within ChatBakers.
  • Google account identity: Your name and email address, used solely to create and identify your ChatBakers account.

We access only the minimum data required to deliver the service. Data obtained through Google APIs is used exclusively to populate your ChatBakers dashboard and generate your monitoring reports. We do not:

  • Sell or transfer Google user data to third parties.
  • Use Google user data for advertising, AI model training, or credit assessments.
  • Allow humans to read your Google data except as needed to provide or improve user-facing features, or as required by law.

You can revoke ChatBakers access to your Google account at any time via your Google Account permissions page. Revoking access will disable Google-dependent features in the platform.

Our use of Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

10. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These measures include:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS (HTTPS).
  • Encryption at rest: Sensitive data stored on our servers is encrypted at rest using industry-standard algorithms.
  • Access controls: Access to personal data is restricted to authorised personnel on a need-to-know basis. We apply the principle of least privilege to all internal systems.
  • Third-party security: We use reputable infrastructure and payment providers (including Stripe and our hosting provider) that maintain their own security certifications.
  • Security monitoring: We monitor our systems for anomalies and potential security incidents.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by GDPR (within 72 hours of becoming aware of the breach where feasible).

No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security.

11. Your Rights

Under GDPR, you have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your personal data ("right to be forgotten").
  • Right to restriction: Request restriction of processing in certain circumstances.
  • Right to data portability: Receive your data in a structured, machine-readable format.
  • Right to object: Object to processing based on legitimate interests.
  • Right to withdraw consent: Withdraw consent at any time where processing is based on consent.

To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with the Czech Data Protection Authority (UOOU) or your local supervisory authority.

12. Cookies

We use cookies and similar technologies to operate our service. For detailed information about the cookies we use and how to manage them, please see our Cookie Policy.

13. Children's Privacy

Our service is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and, where appropriate, by email. Your continued use of the service after such changes constitutes acceptance of the updated policy.

15. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

[email protected]