Privacy Policy

Effective as of: February 20, 2026. A clear and transparent view of how we handle your data.

At Content Makers s.r.o. (operator of the Klidly platform), we take your privacy very seriously. This Privacy Policy clearly explains how we collect, use, and protect the personal data of our website visitors, newsletter subscribers, and our clients' representatives.

This document is prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the 'GDPR').

1
Who we are and who this policy applies to

The controller of your personal data described in this document is:
Content Makers s.r.o.
IČO: 07649517, DIČ: CZ07649517
Registered address: Nádražní 879/27, Moravská Ostrava, 702 00 Ostrava
The company is registered in the Commercial Register.
Contact email: [email protected]

Important distinction (Controller vs. Processor):

This document applies exclusively to situations where we determine the purpose of data processing (we are in the role of Controller). This applies to visitors of the klidly.com marketing website, our newsletter subscribers, and administrators (company representatives) who create and manage a company account with us.

If you are a regular employee of a company that uses our Klidly platform for its internal HR agenda (you have a personnel card, goals, reviews, absences in the system), your employer is the Controller of your workplace data. We (Klidly) only technologically store and process this data in the role of Processor based on a Data Processing Agreement (DPA) concluded with your company. If you wish to exercise your rights regarding this HR data, you must contact your HR department directly.

2
What data do we process, why, and on what basis?

We collect personal data only to the extent necessary for specific purposes:

A) Website Visitors (Analytics and Cookies)

  • Data we collect: IP address (anonymized), browser type, device information, and website interactions.
  • Why we collect it: Proper website functioning, cybersecurity, and traffic analysis for improvement.
  • Legal basis: Legitimate interest (technically necessary cookies, security) and consent (analytical and marketing cookies via the cookie banner).

B) Newsletter Subscribers (HR Tips)

  • Data we collect: Email address.
  • Why we collect it: Sending tips, case studies, and Klidly news.
  • Legal basis: Consent (can be revoked at any time by unsubscribing in the email footer).

C) Customers (Company Representatives and Admins)

  • Data we collect: Name, email, phone, company, billing information. (Cards are processed exclusively by the payment gateway).
  • Why we collect it: Creation and management of organization, support, billing, and system notifications.
  • Legal basis: Performance of the contract (Terms) and fulfillment of legal (accounting and tax) obligations.

D) Customer Support Communication

  • Data we collect: Email address, name, and the content of your communication.
  • Why we collect it: Resolving a technical issue or answering an enquiry.
  • Legal basis: Legitimate interest in high-quality service and performance of the contract.

3
How long do we keep your data?

We do not keep your data longer than is strictly necessary:

  • Newsletter subscribers: Until consent is withdrawn (unsubscribing).
  • Customer data: For the duration of the active account. After account deletion, basic data is deleted within 30 days; billing documents are kept for 10 years (legal obligation).
  • Cookies and logs: Depends on the specific cookie setting, but at most 13 months.

4
To whom do we transfer your data?

We do not sell your personal data to third parties. We only use verified sub-processors to whom we transfer data to the extent necessary:

  • Cloud hosting and database providers (data within the EEA).
  • Email marketing and transactional email tools.
  • Certified payment gateway providers for subscription processing.
  • Analytical tool providers (based on consent given in the cookie banner).

If a partner is located outside the EEA (e.g., USA), we ensure protection through Standard Contractual Clauses (SCC) or Data Privacy Framework certification.

Note on KlidlyAI: We never provide your Controller data to third-party AI API services for their own training. AI outputs in the HR application are governed by the DPA.

5
Data Security

Security of your data is our absolute priority. Communication is encrypted using HTTPS/TLS. Databases are subject to strict access control, passwords are stored in a technically irreversible form (hash), and automated backups are performed to prevent data loss.

6
What are your rights?

According to the GDPR, you have full control over your data:

Access
To request information about processed data.
Rectification
To request rectification of inaccurate data.
Erasure (right to be forgotten)
To request deletion of data.
Restriction
To suspend the processing of your data.
Object
E.g., against sending B2B communications.
Withdraw consent
To unsubscribe from newsletters at any time.

How can you exercise your rights?

Email us at our contact address: [email protected]. We will process your request free of charge and without undue delay, within 30 days at the latest.

Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority, which in the Czech Republic is the Office for Personal Data Protection (www.uoou.cz). However, we would be happy if we tried to resolve any misunderstanding together first.

7
Changes to the Privacy Policy

We may update this policy periodically. The latest version will always be posted on this page with the update date indicated. We will inform registered customers of significant changes by email.