1. Introduction
Topensol ("we", "us", "our") operates a multi-tenant e-commerce SaaS platform that enables businesses ("Merchants" or "Tenants") to launch and manage their online stores. This Privacy Policy explains how we collect, use, store, and protect personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Czech law.
2. Data Controller
The data controller for data collected through topensol.net is: TOP Real Estate s.r.o., Zdiměřická 1436/27, 149 00 Prague, Czech Republic. Contact: [email protected]
For complaints regarding data processing, you may contact the Czech supervisory authority: Úřad pro ochranu osobních údajů (ÚOOÚ), www.uoou.cz
3. Our Role: Controller and Processor
Our platform operates in two distinct capacities:
- As Data Controller — for data of our direct clients (Merchants/Tenants): account registration data, billing information, subscription and invoice data.
- As Data Processor — for data of end customers of our Merchants. In this case, each Merchant acts as the Data Controller and is solely responsible for the lawfulness of processing their customers' data. We process such data only on the Merchant's instructions and in accordance with a Data Processing Agreement.
4. Data We Collect
From Merchants (our direct clients):
- Name, company name, VAT number
- Email address
- Billing address
- Payment transaction records (processed via Stripe — we do not store card details)
- Domain name and technical configuration data
- Communication history with our support team
Automatically collected:
- IP address, browser type, operating system
- Access logs and timestamps
- Cookies (see Section 10)
We do not collect sensitive personal data (health, religious beliefs, biometric data, etc.).
5. Purpose and Legal Basis
| Purpose | Legal Basis |
|---|---|
| Account registration and management | Performance of a contract |
| Subscription billing and invoicing | Performance of a contract, Legal obligation |
| Customer support | Legitimate interests |
| Platform security and fraud prevention | Legitimate interests |
| Compliance with tax and accounting law | Legal obligation |
| Analytics and service improvement | Legitimate interests |
| Marketing communications | Consent (withdrawable at any time) |
6. Payment Data
We do not process or store payment card details. All payments are processed securely through Stripe, Inc. Stripe acts as an independent data controller for payment data. We recommend reviewing Stripe's Privacy Policy at stripe.com/privacy.
Invoice data (amounts, periods, currency) is stored by us for accounting and legal compliance purposes.
7. Data Sharing
We share personal data only where necessary:
- Stripe — payment processing (USA; transfer covered by Standard Contractual Clauses)
- Email service providers — transactional emails (verification, invoices)
- Public authorities — where required by law (tax authorities, courts)
We do not sell personal data to third parties.
8. Data Retention
- Account and billing data: retained for the duration of the contract and 10 years thereafter (accounting obligations under Czech law)
- Support communications: 3 years
- Access logs: 12 months
- Marketing consent records: until consent is withdrawn + 1 year
9. Data Storage and Security
Personal data is stored on servers located in the European Union. We implement appropriate technical and organisational measures including:
- Encrypted data transmission (HTTPS/TLS)
- Encryption of sensitive credentials at rest
- Access controls and authentication
- Regular security reviews
No method of transmission over the Internet is 100% secure. We cannot guarantee absolute security but commit to industry-standard practices and prompt notification in case of a breach.
10. Cookies
We use the following types of cookies:
| Type | Purpose | Legal Basis |
|---|---|---|
| Essential | Site functionality, authentication | Legitimate interests |
| Preference | Language, regional settings | Consent |
| Analytics | Usage statistics (Google Analytics) | Consent |
| Marketing | Relevant advertising | Consent |
Non-essential cookies are used only with your consent, which you may withdraw at any time via our cookie banner or browser settings.
11. Your Rights Under GDPR
You have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion where data is no longer necessary
- Restriction — limit processing in certain circumstances
- Portability — receive your data in a machine-readable format
- Object — object to processing based on legitimate interests
- Withdraw consent — at any time, without affecting prior processing
To exercise any right, contact us at: [email protected]
We will respond within 30 days. For complaints, you may contact ÚOOÚ (www.uoou.cz).
12. Children
Our platform is intended for businesses and is not directed at persons under the age of 16. We do not knowingly collect personal data from children.
13. Merchants' Responsibilities
If you are a Merchant using our platform to operate your own store, you are the Data Controller for your customers' personal data. You are responsible for:
- Having a lawful basis for processing your customers' data
- Publishing your own Privacy Policy
- Responding to your customers' data subject requests
- Compliance with GDPR in your jurisdiction
We provide infrastructure and process your customers' data solely on your instructions under a Data Processing Agreement available upon request.
14. International Transfers
Some service providers (notably Stripe) are based outside the EU. Such transfers are conducted under appropriate safeguards including Standard Contractual Clauses approved by the European Commission.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a notice on our platform. The current version is always available at topensol.net/pages/privacy.
Last updated: 01.07.2026 — Topensol, Top Engineering Solutions