PRIVACY POLICY Marketing Express — Tradix app s.r.o. Version 2026-10-04, effective from 4 October 2026 1. CONTROLLER 1.1 The controller of personal data is Tradix app s.r.o., Company ID (IČO) 24926370, with its registered office at Jana Zajíce 924/16, Bubeneč, 170 00 Praha 7, registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, Insert 446092 (“we”), the operator of the Marketing Express service. Contact for all questions about personal data: support@tradixapp.com, phone +420 775 054 042. 1.2 We have not appointed a data protection officer, as the law does not require us to do so. We will deal with you directly at the e-mail address above. 1.3 We process data in accordance with Regulation (EU) 2016/679 (GDPR), Act No. 110/2019 Coll., on the processing of personal data (zákon o zpracování osobních údajů), and Act No. 127/2005 Coll., on electronic communications (zákon o elektronických komunikacích). 2. WHAT DATA WE PROCESS Category | What exactly Account | e-mail, phone (if you provide it), password hash (we do not know the password itself), chosen language of the website and e-mails, date of registration and of consent to the terms Orders | the chosen service and settings, the brief (prompt), Brand Voice and brand documents, uploaded materials (videos, photographs, logos, documents), which may contain people’s likeness or voice, finished results, messages on the order, delivery method (e-mail or WhatsApp number) Payments and subscriptions | amount, payment status, card type and its last four digits, payment and customer identifiers at Stripe, subscription plan and period; we never see the full card number Communication | e-mails, WhatsApp messages and phone calls with us Withdrawals, complaints, notices | the data you provide in the form or message, date and time of sending Technical data | IP address and number of failed login attempts (account protection), login cookie, server operating logs at the hosting provider 2.1 We obtain the data directly from you. If you include data of other persons in your materials (for example a video with an employee or a customer), you are responsible for being authorised to do so and for having informed those persons. 3. WHY WE PROCESS DATA, ON WHAT LEGAL BASIS AND FOR HOW LONG Purpose | Legal basis | Retention period Registration and account management | performance of a contract (Art. 6(1)(b) GDPR) | for the lifetime of the account Creating and delivering the order, including processing with AI tools, revisions and delivery | performance of a contract (Art. 6(1)(b)) | for the lifetime of the account; files older than 12 months may be deleted after prior notice Payments and subscriptions | performance of a contract (Art. 6(1)(b)) | for the lifetime of the account Accounting and taxes (payment records) | legal obligation (Art. 6(1)(c)), the Accounting Act and tax legislation | for the period laid down by that legislation, usually 5 years, for some records up to 10 years Confirmation of the contract, record of consents to the terms and to the commencement of performance, handling of withdrawals and complaints | legal obligation (Art. 6(1)(c)) and legitimate interest in being able to provide proof (point (f)) | for the duration of the contract and 4 years after it ends Communication and support, delivery of results by e-mail or via WhatsApp | performance of a contract (Art. 6(1)(b)); WhatsApp only if you choose it | while the matter is being handled and for the lifetime of the account Protecting the account and the service against misuse (blocking password guessing, security logs) | legitimate interest (Art. 6(1)(f)) | IP address only for the duration of the block (tens of minutes); hosting logs for a short time, usually days Content moderation and handling notices of illegal content | legal obligation (Digital Services Act) and legitimate interest | while the matter is being handled and for 3 years afterwards Establishing and defending legal claims | legitimate interest (Art. 6(1)(f)) | for the limitation period, no longer than 4 years after the contract ends, or until the end of a dispute 3.1 We do not send commercial communications (newsletters). Should we send them to existing customers in the future, it would only be about our own similar services, with the option to opt out at any time with one click (§ 7(3) of Act No. 480/2004 Coll., on certain information society services). 3.2 Providing the data needed for the account and the order is a contractual requirement: an account cannot be created without an e-mail address, and an order cannot be processed without materials and a brief. 3.3 If you delete your account, we immediately remove all files (materials, results, Brand Voice documents) as well as texts and messages. For orders, we keep only the data we must retain under accounting and tax legislation and the record of consents in case of a dispute. 4. PROCESSING USING ARTIFICIAL INTELLIGENCE 4.1 To create the result, we pass to AI model providers (Article 5) only what is needed for the order in question: the brief, brand information, text from uploaded documents, previews and frames from the materials, speech transcripts and, for generated footage, avatars, images and voice, also the photographs or texts from which they are created. 4.2 Speech-to-subtitle transcription and the editing and rendering of the video itself take place on our own computer in the Czech Republic. Working copies of the materials are deleted from it after each order is completed. 4.3 Anthropic has contractually undertaken not to use content from the API to train its models and deletes it within 30 days at the latest. Under its terms, fal.ai uses content only to provide the service; we set the files we upload to fal.ai and the files created there to be deleted automatically within 24 hours, and fal.ai keeps request logs for no more than 30 days. 4.4 We do not carry out automated decision-making or profiling that would have legal effects on you (Art. 22 GDPR). AI creates content; it does not make decisions about you. We do not use photographs or voice to uniquely identify persons (this is not biometric data); we create a person’s digital likeness or voice only at your request and only for your order. 5. WHO WE PASS DATA TO 5.1 The data are processed by our suppliers as processors, only on our instructions and on the basis of a data processing agreement under Art. 28 GDPR. Some of them also process part of the data as independent controllers, which is indicated for them. Recipient | Purpose | Where and with what safeguards Vercel Inc. (USA) | website hosting and file storage | USA; EU–US Data Privacy Framework certification and standard contractual clauses Databricks, Inc. / Neon, LLC (USA) | database of accounts and orders | the region chosen when the database was created (USA or EU); Data Privacy Framework Stripe Payments Europe, Limited (Ireland) | payments and subscriptions; for fraud prevention, compliance with anti-money-laundering rules and the Link service, Stripe is an independent controller | EU; for transfers to the USA, Data Privacy Framework and standard contractual clauses Anthropic Ireland, Limited (Ireland) | Claude AI model: proposing the edit, graphics and texts | processing in the USA; standard contractual clauses Features & Labels, Inc. – fal.ai (USA) | generating footage, avatars, images and voice; passes requests on to the providers of the individual models (e.g. ByteDance, ElevenLabs, Google) as its subcontractors | USA and other countries; standard contractual clauses Google Cloud EMEA Limited (Ireland) | e-mail inbox (Google Workspace) | EU and USA; Data Privacy Framework and standard contractual clauses Resend, Inc. (USA) | sending confirmation e-mails | USA; standard contractual clauses WhatsApp Ireland Limited (Ireland) | delivery of results if you choose WhatsApp; it is an independent controller for its own service | EU and USA; Data Privacy Framework and standard contractual clauses 5.2 We also pass data to public authorities (courts, the police, the Czech Trade Inspection Authority, the tax office) where the law requires us to, and, where applicable, to an external accountant or lawyer, who are bound by confidentiality. We do not sell data or pass them to anyone for their marketing. 6. TRANSFERS OF DATA OUTSIDE THE EU 6.1 Some suppliers process data in the United States. Transfers are covered by the European Commission’s adequacy decision (EU–US Data Privacy Framework, Implementing Decision (EU) 2023/1795) for certified recipients and by standard contractual clauses under Implementing Decision (EU) 2021/914 for the others. We will provide you with a copy of the safeguards on request. 7. YOUR RIGHTS 7.1 You have the right of access to your data, to rectification, erasure, restriction of processing and data portability, the right to object to processing based on legitimate interest and the right to withdraw consent where processing is based on consent. We describe them in detail on the Your rights (GDPR) (https://marketingexpress.app/legal/gdpr) page. 7.2 You can download a copy of your data and delete your account yourself in the “My data and account” section of your account. You can exercise the other rights by e-mail; we will handle them without undue delay, within one month at the latest. 7.3 You have the right to lodge a complaint with the supervisory authority: Office for Personal Data Protection (Úřad pro ochranu osobních údajů, ÚOOÚ), Pplk. Sochora 727/27, 170 00 Praha 7, https://uoou.gov.cz. 8. COOKIES 8.1 We use only a strictly necessary login cookie, a cookie with your chosen language and browser storage for an order in progress. We do not use analytics or advertising cookies. Details are on the Cookies (https://marketingexpress.app/legal/cookies) page. 9. SECURITY – all communication with the website is encrypted (HTTPS); – we store passwords only as a salted cryptographic hash (scrypt); – files are kept in non-public storage, and access to them is tied to a logged-in account or to a secured processing interface; – the administration is protected by a separate password, and we block repeated login attempts; – only the operator and people who strictly need the data to process an order have access to them. 9.1 If a security breach occurs that would pose a high risk to you, we will inform you without undue delay. 10. CHILDREN 10.1 The service is intended for persons over 18 years of age, and we do not knowingly process children’s data. If you upload materials featuring children, you must have the consent of their legal guardians. 11. CHANGES TO THIS POLICY 11.1 We may update this policy, for example when our suppliers or the legislation change. We will inform you of material changes by e-mail in advance. 11.2 This policy is effective from 4 October 2026 (version 2026-10-04).