Skip to content
Visork
Request pilot access

Privacy Policy

Last updated: August 9, 2026

This Privacy Policy explains how Filip Šedivý ("Company", "we", "us", or "our") processes personal data in connection with the Visork website and services, and what rights you have.

This Policy is provided as an information notice under Articles 13 and 14 of the EU General Data Protection Regulation ("GDPR"). It is not a contract, and we do not ask you to "accept" it. Where we rely on your consent for a specific processing operation, we will ask for it separately.


1. Controller Information

The data controller responsible for the processing described in this Policy is:

Filip Šedivý, sole trader (OSVČ), registered in the Czech Trade Licensing Register (živnostenský rejstřík) Business ID (IČ): 05435561 Address: Hledíková 3008/2, Praha 10, 106 00, Czech Republic Email: hello@visork.com


2. Our Two Roles: Controller and Processor

Visork is a B2B service, and we process personal data in two distinct roles.

2.1 Where We Act as Controller

For the website, inquiries and communications, customer accounts, and billing, we decide the purposes and means of processing and act as the data controller. This Policy governs that processing.

2.2 Where We Act as Processor

When a business customer submits content to our API for analysis ("Customer Content"), we process that content on the customer's documented instructions as a data processor. The customer — typically the platform whose users created the content — is the controller of that data.

That processing is governed by our Data Processing Agreement (DPA), not by this Policy. Key commitments from the DPA include: Customer Content is analysed in volatile memory and deleted after analysis by default; it is retained only in the specific cases the DPA defines (human review of flagged content, legally justified preservation for competent authorities, or a configuration or written agreement of the customer); training on it is off by default on paid tiers and happens only where the customer enables it, while a free tier, where offered, may have retention and training use enabled by default, stated at sign-up and switchable off at any time; and it is processed on EU-based infrastructure.

If your personal data was submitted to Visork by a platform you use, that platform is responsible for informing you and handling your requests. Please direct requests to the platform; we will support it in responding, as required by the DPA and the GDPR.


3. Personal Data We Collect as Controller

3.1 Data You Provide

  • details submitted through our contact form: name, email address, company name, company website, optional information about your platform (approximate content volume and content type), and your message,
  • the content of email or other correspondence with us,
  • account registration and billing information (once account features launch).

3.2 Data Collected Automatically

When you visit the website, our hosting infrastructure automatically records technical data in server logs:

  • IP address,
  • date and time of access,
  • browser type and version,
  • operating system,
  • pages requested and actions performed,
  • referring URL.

We use these logs to operate and secure the website and to prevent abuse.

If you consent to statistical measurement (Section 4), PostHog additionally collects:

  • an analytics identifier, stored in a ph_ cookie and in your browser's local storage on your device,
  • the pages you view and the actions you take on them, such as clicks and which links and buttons you use,
  • a session recording: a reconstruction of the pages as they were displayed to you, including scrolling and cursor movement. Everything you type into a form field is masked before it leaves your browser, so the recording never contains the text you enter,
  • device and browser characteristics such as type, version, screen size, and language,
  • page performance measurements and JavaScript errors that occurred while you were using the site,
  • approximate location, typically at city level, derived from your IP address. The IP address itself is used to derive that location on arrival and is then discarded — it is not stored with the collected data.

We do not combine this data with the details you provide under Section 3.1, we do not use it for advertising, and we do not attempt to identify you from it. If you decline, none of it is collected — the software that would collect it is not loaded into your browser at all.


4. Cookies and Local Storage

The website sets no advertising or cross-site tracking cookies, and we do not use third-party advertising technologies of any kind.

Asking you first. On your first visit, a banner asks whether you consent to statistical measurement. It is provided by Cookiebot, operated by Usercentrics A/S (Denmark) as our processor, and is served from Cookiebot's European infrastructure. It stores your answer in a CookieConsent cookie on your device, valid for twelve months, and keeps a record of that answer so we can demonstrate consent was obtained. This cookie is strictly necessary — its only function is to remember what you decided, including a refusal — and is therefore exempt from the consent requirement. You can change or withdraw your answer at any time, with effect for the future, using the consent link on this website.

What runs without consent. For basic audience measurement we use Vercel Web Analytics, which is cookieless: it writes nothing to your device and reads nothing from it. It records aggregate page views and derives a short-lived, non-reversible hash from request metadata (IP address, user agent) to distinguish one visit from another. That hash cannot be traced back to you, is not combined with any other data we hold, and is not used to follow you across sessions or across other websites. Because it neither stores nor accesses information on your device, it needs no consent and runs on the legal basis given in Section 5.

What runs only with your consent. If you agree to statistics, we additionally use PostHog, hosted on PostHog's European infrastructure in Frankfurt, Germany. It then sets a ph_ cookie and a matching local storage entry, valid for twelve months, to recognize a returning visit, and it measures how the site is used as described in Section 3.3 — including a session recording with all form input masked. We do not use PostHog for advertising, remarketing, or cross-device profiling.

This is not a tag that starts in a restricted mode and expands once you agree. Until you accept, PostHog is not present on the page: its software is never downloaded, no request is made to it, and nothing is written to your device. If you later withdraw consent, capture stops and the data PostHog stored on your device is deleted.

No tag manager. The consent banner and PostHog are the only third-party components this website loads, and it loads them directly. There is no tag management platform in between, which means the list above is complete and cannot be added to without a change to the website itself.

What we no longer use. We previously used Google Analytics 4 for statistical measurement and Google Tag Manager to load it. Both have been removed. No Google Analytics cookie is set, no request is made to Google Tag Manager, and the Content Security Policy this website sends to your browser no longer permits a connection to either — so neither can be re-enabled without a visible change to the website.

Everything else. The only other browser storage we use is technically necessary: your theme preference (light/dark mode), which is stored in your browser's local storage and stays on your device. Our hosting provider may set strictly necessary cookies required to deliver the website securely.


We process personal data for the following purposes, on the following legal bases:

  • Responding to inquiries (contact form, email) — Article 6(1)(b) GDPR (steps taken at your request prior to entering into a contract) and Article 6(1)(f) (our legitimate interest in responding to business inquiries).
  • Operating and securing the website (server logs) — Article 6(1)(f) (our legitimate interest in network and information security and abuse prevention).
  • Measuring website audience without cookies (Vercel Web Analytics, aggregate and cookieless) — Article 6(1)(f) (our legitimate interest in understanding which pages are useful and improving the site). No profiling, no cross-site tracking, and no advertising use is involved.
  • Statistical measurement and session recording with PostHog — Article 6(1)(a) (your consent), together with Section 89(3) of Czech Act No. 127/2005 Coll. on Electronic Communications for storing and accessing information on your device. You may withdraw consent at any time; withdrawal does not affect the lawfulness of processing carried out before it.
  • Recording your consent decision (Cookiebot) — Article 6(1)(c) (our legal obligation to demonstrate that consent was obtained) and Article 6(1)(f) (our legitimate interest in honoring a refusal on later visits).
  • Providing accounts and the Service — Article 6(1)(b) (performance of a contract).
  • Invoicing, accounting, and tax compliance — Article 6(1)(c) (legal obligation).
  • Establishing, exercising, or defending legal claims — Article 6(1)(f) (our legitimate interest).
  • Direct marketing to existing customers or with your consent — Article 6(1)(f) or Article 6(1)(a); you can opt out at any time.

We do not sell personal data.


6. Recipients and Processors

We share personal data only with:

  • Vercel Inc. (USA) — website hosting, content delivery, and cookieless audience measurement (Vercel Web Analytics). Transfers are safeguarded as described in Section 7.
  • PostHog, Inc. (USA) — statistical measurement and session recording, where you have consented to it. The data is stored on PostHog's European infrastructure in Frankfurt, Germany; transfers to PostHog, Inc. are safeguarded as described in Section 7.
  • Google Ireland Limited (Ireland) and Google LLC (USA) — Google Sheets only, where the details you submit through our contact form are recorded so that an inquiry cannot be lost if delivery fails. This is a server-side record: visiting the website sends nothing to Google. We no longer use Google Analytics or Google Tag Manager. Transfers to Google LLC are safeguarded as described in Section 7.
  • Usercentrics A/S (Denmark) — consent management (Cookiebot): displaying the consent banner, storing your decision, and keeping the record that proves it. Both the script delivery and the consent records stay on European infrastructure.
  • Railsware Products Studio LLC, trading as Mailtrap (USA) — delivery of the internal notification email that tells us a contact-form inquiry has arrived. Transfers are safeguarded as described in Section 7.
  • Email service providers — for handling correspondence.
  • Professional advisers (e.g., accounting) — where necessary for our legal and tax obligations.
  • Public authorities — where required by law or a binding order.
  • Payment processors — once paid plans launch; this Policy will be updated with details.

All service providers acting as processors are bound by data processing agreements consistent with Article 28 GDPR. Sub-processors involved in processing Customer Content are listed in the DPA.


7. International Data Transfers

Customer Content submitted to the API is processed on EU-based infrastructure. Data relating to the website itself, including the details you submit through our contact form, is processed by the providers named in Section 6, some of which are established in the United States.

Where personal data is transferred outside the EU/EEA — in particular website delivery data processed by Vercel Inc., contact-form records processed by Google LLC, and notification email processed by Railsware Products Studio LLC (Mailtrap), all in the United States — the transfer is safeguarded by the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses. You can request a copy of the relevant safeguards using the contact details below.

Statistical measurement is a deliberate middle case. PostHog stores the data described in Section 3.3 exclusively on European infrastructure in Frankfurt, Germany — we use PostHog Cloud EU, not its United States region. PostHog, Inc. is nevertheless a company established in the United States and its personnel may access that data in order to operate and support the service, so we treat this as a transfer and safeguard it accordingly: PostHog, Inc. participates in the EU–US Data Privacy Framework, and its data processing agreement additionally incorporates the European Commission's Standard Contractual Clauses.

Consent management is not on the list at all. Cookiebot is configured to use its European delivery network, and the consent records it keeps are stored on servers within the EU, so asking you for consent does not itself transfer your data outside the EU/EEA.


8. Data Retention

We retain personal data only as long as necessary for the purposes described above:

  • Contact inquiries: up to 24 months after our last communication, unless we enter into a contract with you.
  • Server and security logs: typically up to 30 days; longer only where needed to investigate a security incident.
  • Account data: for the life of the account and up to 4 years after closure, corresponding to limitation periods for legal claims.
  • Invoicing and tax records: 10 years, as required by Czech accounting and VAT law.
  • Statistical measurement data (PostHog): session recordings are deleted automatically after 30 days, the retention period set on our PostHog project. Event- and visitor-level data is retained for no longer than 14 months. Withdrawing consent stops further collection and deletes what was stored in your browser, but does not by itself erase what was already collected — ask us and we will delete it.
  • Consent records (Cookiebot): 12 months, after which you are asked again.
  • Other consent-based processing: until you withdraw your consent.
  • Customer Content (processor role): deleted promptly after analysis in accordance with the DPA, unless retained for human review of flagged content, preserved where the content's legal qualification or applicable law justifies it, or retained under the customer's configuration or written agreement.

9. Your Rights Under GDPR

You have the right to:

  • access your personal data,
  • request rectification or erasure,
  • request restriction of processing,
  • object to processing based on legitimate interests, and object at any time to direct marketing,
  • receive your data in a portable format,
  • withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.

To exercise your rights, contact us at hello@visork.com. We will respond within one month; for complex requests this may be extended by up to two further months, in which case we will let you know.

You also have the right to lodge a complaint with a supervisory authority, in particular the Czech Office for Personal Data Protection: Úřad pro ochranu osobních údajů (ÚOOÚ), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic, https://uoou.gov.cz — or with the supervisory authority of the EU member state where you live or work.


10. Data Security

We implement technical and organizational measures designed to protect personal data, including encryption in transit, access controls based on least privilege, EU data residency for sensitive workloads, and logging and audit trails. The measures applicable to Customer Content are described in the DPA.

No system is completely secure, and we cannot guarantee absolute security.


11. Children's Privacy

The website and the Service are intended for business users aged 18 or over. We do not target minors, and we do not knowingly collect personal data from minors as users of the website or the Service.

Separately, the nature of our product means that Customer Content submitted by customers for analysis may include personal data relating to minors — including material whose detection is the very purpose of the Service. Where that happens, we act strictly as a processor on the customer's documented instructions, for child-protection purposes, under the safeguards described in the DPA: in-memory analysis with deletion after the verdict by default, model training off by default on paid tiers and otherwise only where the customer enables it (a free tier, where offered, may have it enabled by default, stated at sign-up and switchable off), strict access controls, and preservation or disclosure to competent authorities only where the content's legal qualification or applicable law justifies it.


12. Automated Decision-Making

We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects (Article 22 GDPR).

Detection results we return to customers are probabilistic risk assessments. Our customers remain responsible for their own moderation decisions, including any human review required by applicable law.


Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of such external sites.


14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The current version, with its "Last updated" date, is always available on this page.

If a change is material, we will announce it prominently on the website or notify you by email where appropriate.


15. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

  • Email: hello@visork.com
  • Address: Hledíková 3008/2, Praha 10, 106 00, Czech Republic
Every Visork policy and agreement is indexed on Policies & legal.