Privacy Policy
Last Updated: May 2026
English legal version controls
This legal page is maintained in English as the authoritative version. Localized routes may include summaries for visitor convenience, but the English text controls unless a separately signed agreement says otherwise.
1. Controller and Contact Details
This Privacy Policy explains how ShiftNode Digital s.r.o. ("we," "our," or "us") collects, uses, protects, and retains personal data when you visit our website, apply for the AI Growth Audit, run the Free AI Diagnostic, use the Growth Gap Calculator, use the chatbot, contact us, or engage our services.
Controller details:
ShiftNode Digital s.r.o.
Registered office: Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic
Company ID (IČO): 249 06 123
Privacy contact: privacy@shiftnodedigital.com
Legal or procurement contact: legal@shiftnodedigital.com
We are the controller where we decide the purposes and means of processing. In some client engagements, we may act as a processor under a signed Data Processing Agreement or other written instructions from the client.
2. Data We May Process
Depending on how you use the site or services, we may process:
- Contact details such as name, business email, company name, role, and submitted messages.
- Company and commercial context such as website URL, goals, bottlenecks, CRM or follow-up status, lead volume, revenue bracket, and application answers.
- Tool inputs and outputs from the Free AI Diagnostic, Growth Gap Calculator, chatbot, form assist, and audit application.
- Public website signals when you submit a company URL for a diagnostic, calculator, chat, or audit-related preview.
- Email metadata and delivery information needed to send confirmations, summaries, and internal lead notifications.
- Analytics events, cookie preferences, device/browser information, approximate location, page views, referral source, and technical logs.
- Client billing, contract, and accounting information where you become a paying client.
We do not intentionally request sensitive personal data through public forms, diagnostic tools, calculator inputs, or the chatbot. Please do not submit confidential, regulated, or special-category personal data unless a signed agreement specifically requires it.
3. Purposes and Legal Bases
Responding to enquiries and reviewing audit fit: We use submitted business context to respond, qualify fit, and prepare next steps. The legal basis is contract preparation, performance of a requested service, or legitimate interest in handling B2B enquiries.
Operating free tools and AI-assisted previews: We use submitted inputs and public website signals to provide diagnostic, calculator, chatbot, and form-assist outputs. The legal basis is your request to use the tool and our legitimate interest in providing useful B2B previews.
Delivering emails and summaries: We use email addresses to send requested confirmations, diagnostic reports, calculator summaries, application confirmations, and related service communications.
Marketing communications: We send optional marketing or nurture emails only where we have consent or another lawful basis. You can unsubscribe or object at any time.
Analytics, measurement, and site improvement: We use analytics only according to your cookie choices where consent is required. We also use limited technical logs for security, troubleshooting, and service improvement.
Contracts, billing, tax, and legal compliance: We process client and invoice data to perform agreements, issue invoices, maintain business records, and comply with Czech and EU legal obligations.
4. AI-Assisted Features and Public Website Signals
The Free AI Diagnostic, Growth Gap Calculator, chatbot, form assist, and AI Growth Audit workflow may use AI-assisted processing. These features may review information you submit and public signals from the company website URL you provide. They do not inspect your private analytics, CRM, advertising accounts, or sales outcomes unless you later provide that access under a separate agreement.
AI-assisted outputs are previews, summaries, or recommendations for business review. They are not legal advice, financial advice, security certification, automated credit decisions, or a guarantee of commercial performance. We do not use these tools to make decisions that produce legal or similarly significant effects about individuals without human review.
5. Sharing and Processors
ShiftNode Digital s.r.o. does not sell personal data. We share data only where needed to operate the website, deliver requested tools, communicate with you, perform client work, maintain security, or comply with legal obligations. Processor categories may include:
- Hosting, CDN, and deployment providers.
- Email delivery and notification providers.
- Analytics and consent-management tooling where enabled.
- AI service providers used to generate diagnostic, calculator, chatbot, form-assist, or audit-support outputs.
- CRM, workflow, and lead-management tools where configured.
- Accounting, tax, legal, and professional advisers.
- Security, logging, and operational tooling.
Engagement-specific processor details can be confirmed before signing a binding DPA or statement of work.
6. International Transfers
Some providers may process data outside the European Economic Area. Where this happens, we rely on appropriate safeguards such as European Commission adequacy decisions, Standard Contractual Clauses, the EU-US Data Privacy Framework where applicable, and supplementary measures where appropriate for the provider and processing context.
7. Retention
We retain personal data only as long as needed for the relevant purpose, unless a longer period is required by law or necessary to establish, exercise, or defend legal claims.
- Audit applications and lead submissions: Kept while we review fit, communicate, maintain business records, and manage follow-up.
- Diagnostic, calculator, chatbot, and form-assist records: Kept only as needed to deliver requested results, improve service quality, support follow-up where consented, and maintain operational records.
- Marketing contacts: Kept until you unsubscribe, withdraw consent, or object, subject to suppression records needed to honor opt-outs.
- Analytics and technical logs: Kept for limited periods according to provider settings, security needs, troubleshooting, and measurement requirements.
- Invoices, contracts, and accounting records: Retained for the period required by Czech tax, accounting, and commercial law. Invoices and related tax records may need to be retained for up to 10 years.
8. Your Rights
Subject to applicable law and the relevant processing context, you may have the right to:
- Access a copy of personal data we hold about you.
- Ask us to correct inaccurate or incomplete personal data.
- Ask us to delete personal data where deletion is legally available.
- Ask us to restrict processing in certain circumstances.
- Object to processing based on legitimate interests or direct marketing.
- Request portability of personal data you provided, where applicable.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with a supervisory authority, including the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů - ÚOOÚ).
To exercise rights, email privacy@shiftnodedigital.com. We aim to respond within one month, unless the request is complex or applicable law permits an extension.
9. Cookies and Consent
We use strictly necessary cookies and local storage to keep the website working, remember preferences, maintain security, and store consent choices. With your consent, we may also use analytics, marketing, and CRM attribution cookies or similar technologies to understand site performance, measure conversion paths, connect submitted leads to the relevant campaign or landing page, and improve relevant communications.
You can accept, reject, or customize optional cookies through the cookie banner. You can reopen cookie settings from the footer at any time.
10. Security
We use technical and organizational measures designed to protect personal data against accidental loss, unauthorized access, misuse, alteration, and disclosure. These measures may include HTTPS/TLS in transit, provider security controls, access limitation, least-privilege operational practices, confidentiality obligations, logging, and review of security-relevant incidents.
No internet service can be guaranteed as completely secure. If you believe data connected to ShiftNode Digital has been exposed or misused, contact privacy@shiftnodedigital.com.
11. Updates to This Policy
We may update this Privacy Policy when our services, providers, legal obligations, or processing activities change. The latest version will be posted on this page with the updated date above.