All policies

Privacy Policy

Updated: 31 August 2026

This Privacy Policy describes how Vision Thing, s.r.o. processes personal data in connection with the Vision Thing AI web application.

1. Data Controller

The controller of personal data is:

Vision Thing, s.r.o.
Na Pankráci 1618/30
140 00 Prague - Nusle
Company ID No.: 06958133
VAT ID No.: CZ06958133
Email: info@visionthing.cz
Website: https://visionthing.cz

The Company has not appointed a Data Protection Officer because, based on its assessment, it does not meet the conditions for mandatory appointment of a Data Protection Officer under the GDPR.

2. Who the Processing Concerns

This Privacy Policy applies in particular to:

  • registered users of the application,
  • visitors who use the public sections of the application,
  • persons who create, edit or submit an advertising campaign proposal,
  • persons who communicate with the AI assistant,
  • persons whose data are entered into the application by a user,
  • internal users and administrators of the application.

If a user enters another person’s personal data into the application, we obtain such data from that user. The user is responsible for ensuring that they are authorised to enter such data into the application and that they have fulfilled any applicable information or other obligations towards the person concerned. We process such data only to the extent necessary to provide the service, prepare a campaign proposal, provide customer support, ensure security, resolve incidents and protect legal claims.

3. Personal Data We Process

We may process the following categories of data in the application:

  • identification and contact details, in particular first name, surname and email address,
  • user account data, in particular the password in securely hashed form, registration date, role, language preference, preferred planning mode and profile settings,
  • data related to login through an external provider, in particular the provider, the account identifier held by the provider, email address and, where applicable, avatar,
  • security data, in particular two-factor authentication data, recovery codes in secured form, password reset tokens, remember tokens, session identifiers, IP address, user agent and data required to protect the account,
  • campaign data, in particular campaign date, budget, selected advertising inventory, requested budgets for individual items, media categories, estimated results and campaign notes,
  • uploaded campaign materials, in particular logos, brand elements, images, texts, product materials, briefs or other files uploaded by the user,
  • generated or edited creatives, previews, prompts, creative variants and related metadata,
  • the content of communications with the AI assistant, in particular user inputs, assistant responses, related campaign context, system and technical context, technical conversation records, tool calls, tool outputs, AI-generated conversation summaries, metadata and usage data,
  • technical and operational data, in particular logs, error information, request data, broadcast/stream identifiers, and data required for rate limiting and security,
  • marketing communication data, in particular email address, records of consent or another legal basis, subscription and unsubscribe dates, subscription preferences and basic technical delivery data,
  • data stored in cookies, sessions or the browser’s local storage,
  • data contained in internal business or operational notifications.

The application is not intended for the processing of special categories of personal data under Article 9 of the GDPR, in particular health data, biometric data, data concerning political opinions, religious beliefs, sex life or sexual orientation. Users should not enter sensitive personal data, personal data of third parties or confidential information into the application unless this is necessary for use of the service. The Operator may restrict, delete or otherwise process such content only to the extent necessary where required for security, compliance with legal obligations or protection of legal claims.

4. Purposes and Legal Bases of Processing

We process personal data for the following purposes:

Account Creation and Management

We process data required for registration, login, email verification, password recovery, profile management, two-factor authentication and account deletion.

Legal basis: performance of a contract or steps taken prior to entering into a contract.

Login Through an External Provider

If a user uses login through an external provider, we process the data required to verify the user’s identity, create or link an account and secure the login process.

Legal basis: performance of a contract; for security checks, also legitimate interest.

Use of the Application and Preparation of an Advertising Campaign Proposal

We process the data entered or created by the user when planning a campaign, selecting advertising inventory, working with the budget and reviewing the proposal.

Legal basis: performance of a contract or steps taken prior to entering into a contract.

Communication With the AI Assistant

We process user messages, AI assistant responses and the related campaign context in order to provide AI-based planning, maintain the conversation, display the conversation history, synchronise the campaign proposal, resolve errors and improve the quality of the service.

Legal basis: performance of a contract; for bug fixes, quality control, security and proportionate improvement of the service, also legitimate interest.

Generation and Editing of Advertising Creatives

If a user uses features for generating or editing creatives, we process the entered prompts, briefs, uploaded logos, images, texts, brand elements, product materials, resulting creatives, previews and related technical metadata. We process these data in order to create the creatives, display them to the user, edit them, perform quality control, resolve errors, ensure security and protect legal claims.

Legal basis: performance of a contract; for quality control, security, bug fixes and protection of legal claims, also legitimate interest.

AI-Generated Summaries for the Sales Team and Quality Control

We may create a concise AI-generated summary from a conversation with the AI assistant and from campaign data. The summary may be made available to authorised persons of the Operator, in particular the sales team, support staff, administrators, developers and external technical contractors, so that they can assess the campaign proposal, follow up on an enquiry, verify the quality of the AI assistant’s recommendations, resolve errors and improve the service.

Legal basis: legitimate interest in handling enquiries, quality control, customer support and proportionate improvement of the service.

Submission of a Non-Binding Campaign Proposal

After a campaign proposal is submitted, we process the data required to create a record, perform an internal review of the proposal and conduct subsequent business communication. Submission of the proposal does not automatically constitute an order, reservation of advertising inventory or payment.

Legal basis: steps taken prior to entering into a contract; legitimate interest in handling the enquiry and internal business follow-up.

Customer Support, Internal Review and Development

Authorised persons may access data in the application for the purposes of customer support, review of submitted proposals, correction of technical errors, improvement of AI tools, improvement of the advertising inventory database, business analysis, security and prevention of misuse.

Legal basis: legitimate interest.

Application Security and Prevention of Misuse

We process technical data, session data, IP addresses, user agents, logs and rate-limiting data in order to secure the application, protect accounts, prevent attacks, resolve incidents and maintain service stability.

Legal basis: legitimate interest; in some cases, compliance with a legal obligation.

Compliance With Legal Obligations and Protection of Claims

We may process certain data in order to comply with legal obligations, maintain records, resolve disputes and protect legal claims.

Legal basis: compliance with a legal obligation or legitimate interest.

Marketing

We may send newsletters, product updates, commercial communications or other direct marketing communications. Such communications will be sent only on the basis of consent or to the extent permitted by law, in particular when communicating with existing customers or users about similar services. Users will be able to unsubscribe at any time, in particular by using the link in the email or by contacting the Operator.

Legal basis: consent or legitimate interest to the extent permitted by law.

Where processing is based on legitimate interest, we pursue in particular the following legitimate interests: securing the application and protecting accounts, preventing misuse and attacks, handling enquiries and business follow-up, correcting errors and ensuring service stability, proportionate internal improvement of the service, protecting legal claims and protecting the Operator, users and third parties.

5. AI Service Providers

The application uses external AI services to process user messages, generate AI assistant responses, generate or edit creatives, analyse materials and create internal summaries. Data sent to an AI service may include, in particular, user messages, the conversation history, campaign parameters, selected advertising inventory, budget, campaign dates, notes, uploaded logos or other materials, prompts, generated or edited creatives, outputs of internal tools and the technical context required for the assistant to function.

The Operator may use different providers of AI models and AI infrastructure, including text, image, multimodal or fallback AI services. The specific provider may change depending on availability, quality, security, price, technical requirements or development of the service. Recipients of personal data are therefore described in this Privacy Policy primarily by the category “AI service providers”. If a change of provider would result in a material change to the processing of personal data or a new significant risk to users, the Operator will update this Privacy Policy accordingly.

Data retention conditions at an AI provider depend on the specific API endpoint and service settings. For some AI API endpoints, customer data may be retained for security, abuse prevention and service operation purposes, for example for up to 30 days, unless a different setting or legal basis for longer retention applies.

We may use user content and related metadata for quality control, evaluations, prompt tuning and improvement of the application’s tools.

Data sent to AI services are not intended to contain sensitive personal data, personal data of third parties or confidential business information unless this is necessary.

6. Recipients of Personal Data

Personal data may be accessed only by persons and suppliers who need such access for the purposes stated above, in particular:

  • authorised persons of the Operator,
  • application administrators,
  • customer support, the sales team and persons handling submitted campaign proposals,
  • developers and external contractors to the necessary extent,
  • providers of hosting, databases, infrastructure, object storage, backups and monitoring,
  • AI service providers, including text, image, multimodal and fallback AI providers,
  • authentication providers, in particular Google, if the user chooses external login through Google,
  • email service providers,
  • providers of internal notification services,
  • legal, accounting or technical advisers, where necessary,
  • public authorities, where required by law.

Internal business notifications or reports for authorised persons may include, in particular, the user’s name and email address, campaign date, budget, selected items, categories, campaign notes, an AI-generated summary of the conversation, information about generated creatives and a link to the proposal overview.

7. Transfers Outside the EU/EEA

The application may use suppliers established or operating technical infrastructure outside the European Union or the European Economic Area, in particular for AI services, authentication services, internal notifications, email services or operational infrastructure. Certain suppliers may process personal data, in particular in the United States or other third countries, in accordance with their contractual and technical terms.

Where personal data are transferred outside the EU/EEA, the Operator uses appropriate legal mechanisms under the GDPR, in particular an adequacy decision where applicable to the relevant supplier, or Standard Contractual Clauses approved by the European Commission together with supplementary technical and organisational measures. Information about the safeguards used may be obtained upon request at info@visionthing.cz.

8. Cookies and Browser Storage

The application uses cookies and browser storage mainly for technical, security and preference-related purposes. These currently include in particular:

Name / Storage Type Purpose Provider / Domain Retention Period Consent
session cookie technical maintaining the session, login and functioning of the application Vision Thing AI application 120 minutes of inactivity no
XSRF-TOKEN security protection against CSRF attacks Vision Thing AI application 120 minutes; renewed while the application is being used no
remember_web_* functional remembering the login if selected by the user Vision Thing AI application approximately 400 days; until logout, a change of login credentials or another security-related change no, where this is a user-selected feature
appearance cookie preference storing the application appearance preference for server-side rendering Vision Thing AI application 365 days from setting or changing the preference no
appearance in localStorage preference storing the application appearance preference in the browser user’s browser until the preference is changed or the browser storage is cleared by the browser or user no
sidebar_state preference storing the state of the sidebar Vision Thing AI application 7 days from a change to the sidebar state no
Session values for language preference, guest AI chat, an in-progress campaign submission and rate limiting technical / preference storing the language, maintaining continuity of the guest AI chat, completing submission after login and protection against misuse Vision Thing AI application 120 minutes of inactivity no

These cookies and similar storage technologies are used for the functioning of the application, login, security and storage of user preferences. If the application uses only these technical and preference-related elements, separate consent for analytics or marketing cookies is generally not required.

If analytics, advertising or other non-technical tools are added to the application, for example traffic measurement, remarketing or marketing pixels, appropriate information and a consent mechanism will need to be added.

9. Retention Periods

We retain personal data only for as long as necessary for the relevant purposes:

Data Category Retention Period
User account for the duration of the account’s existence; when the account is closed, direct identifiers and data required solely for operation of the account will be deleted or anonymised unless another legal basis for retention applies
Password and account security data for the duration of the account’s existence or until changed; when the account is closed, they will be removed or invalidated
Linked external account for the duration of its connection to the user account; when the account is closed, the connection will be removed or anonymised
Session data 120 minutes of inactivity
Password reset tokens 60 minutes from creation
Draft campaign proposals for the duration of the account’s existence or until deleted by the user or the Operator; when the account is closed, they will generally be deleted or anonymised unless they formed part of a submitted or saved campaign
Submitted or saved campaigns for as long as necessary to handle the enquiry, conduct business follow-up, maintain internal records and statistics, perform quality control, protect legal claims or comply with legal obligations; when the account is closed, they may continue to be retained as a separate business, operational or analytical record
Data contained in a campaign for the retention period of the relevant campaign; this may include, in particular, the campaign date, budget, selected advertising inventory, notes, an AI-generated conversation summary, uploaded materials, logos, generated or edited creatives, previews and related metadata
AI conversations and related metadata for the duration of the account’s existence or for as long as necessary for conversation history, quality control, error resolution and protection of legal claims; when the account is closed, they will generally be deleted or anonymised unless they form part of a retained campaign, internal notification or another legitimately retained record
AI-generated conversation summaries for as long as necessary to handle the enquiry, retain the campaign, review the quality of AI recommendations, provide customer support, maintain internal statistics and protect legal claims; if a summary forms part of a campaign, it is retained for the retention period of that campaign
Uploaded materials, logos and files for as long as necessary to provide the service, create or edit creatives, maintain campaign history, perform quality control, resolve errors and protect legal claims; if they form part of a campaign, they are retained for the retention period of that campaign
Generated or edited creatives for as long as necessary for campaign history, further edits, handling the enquiry, quality control, internal statistics and protection of legal claims; if they form part of a campaign, they are retained for the retention period of that campaign
Newsletter and marketing communications for the duration of the subscription or legitimate interest; data required to demonstrate consent or an unsubscribe request may be retained for as long as necessary to protect legal claims
Technical logs for as long as necessary for operation, security and incident resolution
Security incidents for the duration of incident resolution and subsequently for as long as necessary to protect legal claims
Internal business notifications for as long as necessary to handle the enquiry, conduct business follow-up, maintain internal records, perform operational reviews and protect legal claims
Backups for the period resulting from the technical backup and recovery settings, generally for a limited rolling period
Data required for legal claims or obligations for the period required by law or for the duration of the applicable limitation periods

After an account is closed or a deletion request is handled, the user’s direct identifiers may be deleted, anonymised or replaced with a technical identifier. Closing an account does not automatically result in the deletion of submitted or saved campaigns where they continue to be retained for the reasons stated above. Certain data may be retained in pseudonymised form where necessary for legal claims, security, audits, quality control, handling of enquiries or legitimate internal statistics. Pseudonymised data remain personal data if they can be reassociated with a specific person. We may retain anonymised or aggregated statistics from which a specific person can no longer be identified without any time limitation.

Certain data may remain for a limited period in logs, backups, internal notifications, email communications or operational records. The Operator deletes, anonymises or restricts the use of such data according to technical capabilities, retention periods and applicable legal grounds.

10. Security

The Operator protects personal data through technical and organisational measures, in particular:

  • access control,
  • secure login,
  • password hashing,
  • the option to use two-factor authentication,
  • protection against CSRF attacks,
  • rate limiting for selected actions,
  • logging and monitoring,
  • restricting access to production data to authorised persons,
  • backups and operational security measures.

However, no technical measure can guarantee absolute security. If you suspect misuse of your account or a security incident, contact the Operator at info@visionthing.cz.

11. Rights of Data Subjects

Under the GDPR, you have in particular the right to:

  • request access to your personal data,
  • request correction of inaccurate data,
  • request deletion of data,
  • request restriction of processing,
  • object to processing based on legitimate interest,
  • receive data in a portable format where the statutory conditions are met,
  • withdraw consent where processing is based on consent,
  • lodge a complaint with the Czech Office for Personal Data Protection.

You may exercise your rights by email at info@visionthing.cz. The Operator may request reasonable verification of identity where necessary to protect the account and the data.

We handle requests without undue delay, generally within one month. For complex or numerous requests, this period may be extended by up to a further two months; in such a case, the applicant will be informed. Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.

12. Automated Decision-Making

The application uses an AI assistant to support campaign planning. The AI assistant may suggest advertising inventory, budget or other campaign parameters, but it does not itself create a legally binding order, reservation or payment.

Outputs of the AI assistant are not used as the sole basis for decisions that produce legal effects concerning the user or similarly significantly affect the user. The application does not involve automated decision-making that itself produces legal effects concerning the user or similarly significantly affects the user within the meaning of the GDPR.

13. Changes to This Privacy Policy

The Operator may update this Privacy Policy, in particular if the application’s functions, the types of data processed, the purposes of processing, suppliers, retention periods or legal requirements change.

The current version will be available in the application or on the Operator’s website. In the event of significant changes, users may also be informed by email or by a notice in the application.