Privacy Notice
This notice explains what personal data we collect, why we use it, and what rights you have. We provide it under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Act No. 110/2019 Coll., on personal data processing.
1. Who we are
Oryen Technologies s.r.o. is the controller of the personal data described in this notice. We provide cybersecurity products and services to organisations.
| Item | Detail |
|---|---|
| Controller | Oryen Technologies s.r.o. |
| Company ID (IČO) | 29718961 |
| Registered office | Plzeňská 3352/156, 150 00 Praha 5, Czech Republic |
| Commercial register | Kept by the Městský soud v Praze, file no. C 451165/MSPH |
| info@oryentech.ai | |
| Data box (datová schránka) | a294mpy |
| Post | Plzeňská 3352/156, 150 00 Praha 5, Czech Republic |
| Supervisory authority | Úřad pro ochranu osobních údajů (ÚOOÚ) |
Oryen has its registered office in the Czech Republic, so in addition to the GDPR we are also subject to Act No. 110/2019 Coll., and our supervisory authority is ÚOOÚ. Because that office is in the Czech Republic and the EU, we do not need to appoint a representative under Article 27.
2. Who and what this notice covers
"Personal data" means any information about an identified or identifiable natural person — a name, an identification number, location data, an online identifier, or any factor specific to that person's physical, economic, cultural or social identity. In our case that person is usually a customer, an enquirer, a supplier or subcontractor, or someone acting for one of them.
This notice applies when we decide why and how personal data is used — that is, when we act as a controller. It covers visitors to oryentech.ai, people who contact us or sign up for our content, the people who work at our customers and prospects, job applicants, and security researchers who report issues to us.
This notice does not cover:
- Our employees and contractors, whose data is handled under our internal HR privacy notice
- Candidates in an advertised recruitment process, who receive a separate notice when they apply
3. Using our website
You do not have to give us any personal data to browse oryentech.ai. Where the site does collect it — a contact form, a demo request, a newsletter signup — we either ask for your consent or tell you at that point how the data will be used.
Our servers record standard log information whenever you visit: your IP address, browser type and language, time of access, and the referring web address. We use it to keep the site available and secure and to investigate abuse. The legal basis is our legitimate interest in operating our own site safely, Art. 6(1)(f), which Recital 49 recognises for network and information security.
We do not use web beacons — small tracking images that count who opened a page — or any comparable technology to build statistics about visitors.
The site does not collect special categories of personal data. Please do not enter anything sensitive into our web forms, such as data about health, racial or ethnic origin, political opinions, religion or trade union membership. Our site is not aimed at children; see section 15.
Cookies and similar technologies
We currently set only cookies that are strictly necessary to make the site work and keep it secure. We do not use analytics, advertising, session replay, heatmaps or any other tracking technology, and we do not share data about your visit with third parties for those purposes.
Strictly necessary cookies do not require consent under Section 89(3) of Act No. 127/2005 Coll., on electronic communications — the obligation is to inform you, which is what this section does. That is why you do not see a cookie banner on our site.
We are adding website analytics shortly. Before the first analytics cookie is set we will update this notice and ask for your consent, and you will be able to refuse as easily as accept and to change your mind later. Once we start asking for consent, we will record each visitor's decision against a unique ID so that we can prove it as Article 7(1) requires, and this section will say how long those records are kept.
4. Enquiries about our products and services
| Item | Detail |
|---|---|
| Personal data | Name and any academic title, email address, phone number, employer, country, the content of your enquiry, and the IP address and time of the submission |
| Data subjects | Prospective customers and anyone who contacts us |
| Purpose | Answering enquiries, arranging demos and trials, preparing quotations |
| Legal basis | Steps taken at your request before entering into a contract, Art. 6(1)(b). Where you write on behalf of a company, our legitimate interest in responding to business enquiries, Art. 6(1)(f) |
| Retention | See section 11. |
5. Newsletters and commercial communications
We send news, technical write-ups, threat research and event invitations. You can unsubscribe from any message, or by writing to us using any of the contact routes in section 1. We send at most one a week.
| Item | Detail |
|---|---|
| Personal data | Name, email address, and whether you opened or clicked our messages |
| Data subjects | Customers, partners, distributors and subscribers |
| Purpose | Informing you about our products, research and events |
| Legal basis | Your consent, Art. 6(1)(a). If you are already our customer, Section 7(3) of Act No. 480/2004 Coll. lets us write to you about our own similar products unless you object, and the basis is then our legitimate interest, Art. 6(1)(f) |
| Retention | See section 11. |
6. Speculative job applications
This section covers approaches you make on your own initiative. If you apply for an advertised vacancy, you get a separate recruitment privacy notice when you apply.
| Item | Detail |
|---|---|
| Personal data | Name and title, date of birth, address, email and phone, education, previous experience, certifications and qualifications, and whatever else your CV and covering documents contain. We may add information from public professional sources |
| Data subjects | People who approach us about a job or an internship |
| Purpose | Assessing whether we have a suitable role for you now or soon |
| Legal basis | Our legitimate interest as a prospective employer in considering candidates properly, Art. 6(1)(f) |
| Retention | See section 11. |
7. Sales, contracts and customer support
| Item | Detail |
|---|---|
| Personal data | Billing details (name and title, delivery and billing address, email, phone, IČO and DIČ); identification and contact details of the people who act for a customer, including their job titles; records of what was bought and of our correspondence with you |
| Data subjects | Customers, business partners, and the people who act for them |
| Purpose | Fulfilling orders, delivering the contract, providing support and maintenance, handling complaints and warranty claims, training your staff |
| Legal basis | Performance of a contract, Art. 6(1)(b). Legal obligations in tax, accounting and warranty law, Art. 6(1)(c). After the contract ends, our legitimate interest in defending legal claims, Art. 6(1)(f) |
| Retention | See section 11. |
We share these details with our partners and resellers only as far as fulfilling your order requires.
8. References and case studies
If you agree to let us publish your experience of working with us, we will put it on our website and social media and may present it at events.
| Item | Detail |
|---|---|
| Personal data | Name, job title, employer, and your likeness in photographs or recordings |
| Data subjects | Customers and former customers |
| Purpose | Telling others about their experience with our product and services |
| Legal basis | Your consent, Art. 6(1)(a), which you can withdraw at any time. Publishing your likeness also needs your consent under Section 84 and following of Act No. 89/2012 Coll. (Civil Code), which is a separate civil-law consent |
| Retention | Until you withdraw consent, after which we delete the material |
9. Events, seminars and webinars
| Item | Detail |
|---|---|
| Personal data | Registration details (name and title, email, phone, job title); billing and bank details for paid events; photographs and recordings made at the event |
| Data subjects | Customers, partners, distributors and other attendees |
| Purpose | Organising and running the event, informing the public about our work, and keeping an internal archive |
| Legal basis | Performance of a contract, Art. 6(1)(b), and afterwards our legitimate interest in defending claims, Art. 6(1)(f). Legal obligations in tax and accounting for invoices, Art. 6(1)(c). For photographs and recordings, our legitimate interest in documenting and promoting our work, Art. 6(1)(f), together with your consent to the use of your likeness under Section 84 and following of the Civil Code |
| Retention | See section 11. |
We tell you at the entrance when an event is being photographed or filmed, so you can object before it starts. If you would rather not appear, tell the organizer or the photographer on the day, or write to us.
10. Who we share your data with
We do not sell your personal data. We share it only with:
- Professional advisers — lawyers, auditors, accountants, insurers — where needed and under a duty of confidentiality.
- Partner organisations — providers of cloud services, hosting, email delivery and recruitment.
- Organisers, agencies and social platforms, where we run an event or publish something you agreed to.
- Debt collection agencies, credit insurers, lawyers and courts, where we need to recover or defend a claim.
- Authorities, regulators, CERTs, law enforcement and NÚKIB, on lawful request, where we are legally required to disclose, or where we suspect unlawful activity or a security incident.
- A buyer or investor, if we are involved in a merger, acquisition, or financing. We will tell you if your data becomes subject to a different privacy notice.
Your personal data is processed within the European Economic Area. We do not transfer it to countries outside the EEA. If that changes, we will update this notice and put in place one of the safeguards required by Chapter V of the GDPR before any transfer takes place.
11. How long we keep your data
We keep personal data only as long as we need it for the purpose we collected it for, then delete or anonymise it.
| Data | Retention | Why |
|---|---|---|
| Website and server logs | 12 months | Security and troubleshooting |
| Security and audit logs | 12–24 months, or as the customer contract requires | Detecting and investigating incidents |
| Enquiries and demo requests that don't become customers | 24 months from last contact | Legitimate interest in following up |
| Customer contract and account records | Contract duration plus 3 years | General limitation period, Section 629 of Act No. 89/2012 Coll. (Civil Code); up to 10 years where the longer objective period applies |
| Accounting documents | 5 years from the end of the accounting period | Act No. 563/1991 Coll., on accounting |
| Financial statements and audit reports | 10 years | Act No. 563/1991 Coll. |
| Tax documents (VAT) | 10 years from the end of the tax period | Act No. 235/2004 Coll., on value added tax |
| Marketing contacts | Until you unsubscribe, or 24 months of no engagement | Consent or legitimate interest |
| Unsuccessful job applications | 6 months, longer only with your consent | Assessing and defending recruitment decisions |
| Vulnerability reports | 24 months after the issue is closed | Tracking fixes and recurrence |
| Registration data for seminars and webinars, photographs | 12 months | Performance of a contract, Art. 6(1)(b), and afterwards our legitimate interest in defending claims, Art. 6(1)(f) |
Where data is held in backups, it is deleted on the ordinary backup rotation cycle 60 days after deletion from live systems.
12. How we use and protect your data
We apply technical and organisational measures appropriate to the risk, as Article 32 requires. These include encryption in transit and at rest, role-based access control and least privilege, monitoring of access to personal data, secure development practices, vendor security assessment, and staff security and privacy training.
If a breach affecting your personal data is likely to result in a high risk to your rights and freedoms, we will tell you without undue delay, and we will notify the relevant supervisory authority within 72 hours of becoming aware where Article 33 requires it.
To report a security vulnerability, contact us using any of the details in section 17.
13. Your rights
Under the GDPR you have the right to:
- Access your personal data and receive a copy of it (Art. 15).
- Rectification of data that is inaccurate or incomplete (Art. 16).
- Erasure of your data where one of the grounds in Article 17 applies.
- Restriction of processing in the circumstances set out in Article 18.
- Data portability — receive data you gave us in a structured, machine-readable format, or have it sent to another controller, where processing is based on consent or contract and is automated (Art. 20).
- Object to processing based on legitimate interests, on grounds relating to your particular situation (Art. 21). Where you object to direct marketing, we will stop, with no balancing test.
- Withdraw consent at any time, where we rely on it. This does not affect processing carried out before you withdrew.
- Not be subject to solely automated decisions with legal or similarly significant effects (Art. 22).
How to exercise them
Write to info@oryentech.ai, or use any of the contact routes in section 1. We will respond within one month. We may extend by two further months for complex requests and will tell you if we do. We may ask for information to verify your identity, and we will not use that information for anything else.
Requests are free. Where a request is repeated, excessive or manifestly unfounded, we may charge a reasonable fee for the administrative cost or refuse to act on it, and we will tell you which and why. If we cannot identify you from the data we hold and the processing does not require identification, we will say so — Articles 15 to 20 then do not apply unless you give us enough to identify you.
Complaints
You can complain to a supervisory authority, in particular in the member state where you live, work, or where the alleged infringement took place. Ours is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic — uoou.gov.cz. We would appreciate the chance to address your concern first.
14. Automated decision-making and profiling
We do not make decisions that produce legal or similarly significant effects for you based solely on automated processing.
We do not currently use website analytics or lead-scoring tools. When we introduce analytics, it will be used to understand how our website and marketing perform. It will not produce decisions with significant effects on you, and you will be able to object under section 13.
15. Children
Our website is aimed at businesses and is not directed at children. Under Section 7 of Act No. 110/2019 Coll., a child in the Czech Republic can consent to information society services from the age of 15; below that, consent must come from a holder of parental responsibility. We do not knowingly collect personal data from anyone under 15. If you believe a child has given us personal data, contact info@oryentech.ai and we will delete it.
16. Changes to this notice
We update this notice when our processing changes. The date at the top shows the current version. Where a change is material we will tell you directly, by email or an in-product notice, before it takes effect. Previous versions are available on request.
We make this notice available before you send us any personal data through the website. Submitting a web form confirms you have had the chance to read it.
17. Contact us
Questions about this notice or about how we handle your data:
- Email: info@oryentech.ai
- Data box (datová schránka): a294mpy
- Post: Plzeňská 3352/156, 150 00 Praha, Czech Republic
18. Language and governing law
This notice is governed by the law of the Czech Republic and by the GDPR. We publish it in Czech and in English. If the two versions differ, the Czech version prevails.