1. Controller and contact
The data controller is RedStreak s.r.o., company ID 21693242, with its registered office at Dlouhá 730/35, Staré Město, 110 00 Prague 1, Czech Republic, registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, File 405159. For privacy questions, contact pospisek.michal@redstreak.cz.
The company has not appointed a data protection officer because its current processing activities do not require one.
2. Scope of this policy
This policy covers the RedStreak public website, customer communications and applications operated by RedStreak, particularly ComicCon. External links lead to services operated under their own terms and privacy notices.
3. Data we process
- Account and identity: provider account identifier, name or display name, email address and chosen sign-in provider.
- App choices: selected programme items, preferences and information required for synchronisation.
- Calendar connection: granted permissions, managed calendar and event identifiers, synchronisation status and encrypted access or refresh tokens. We never receive your provider password.
- Apple ICS: a hash of the private subscription token and operational data required to manage it; the token itself is not stored in readable form.
- Communications: your email address, message and related information when you contact us.
- Operational data: IP address, browser type, request time, security and error logs. Logs are designed to exclude OAuth codes, tokens and private ICS URLs.
4. Google, Microsoft and Apple data
Sign-in and calendar connection are separate steps. Google and Microsoft provide basic identity data to create or locate your account. After separate consent, calendar permissions are used only to create, update and delete events in the managed calendar and keep it synchronised.
For Google, we use the narrowest available scope for calendars created by the app. RedStreak's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used for advertising, profiling, credit decisions or training general-purpose AI models.
For Microsoft, we use delegated Calendars.ReadWrite and offline_access permissions. For Apple Calendar, we provide a private ICS subscription and do not access the content of your iCloud Calendar account.
5. Purposes and legal bases
- Providing the service and managing your account - performance of a contract or steps you request under Article 6(1)(b) GDPR.
- Calendar synchronisation - performance of the user-selected service under Article 6(1)(b) GDPR; provider permission can be revoked at any time.
- Security, abuse prevention and diagnostics - our legitimate interest in safe and reliable operations under Article 6(1)(f) GDPR.
- Support and business communications - pre-contractual steps, performance of a contract or our legitimate interest in answering a request.
- Accounting and mandatory records - compliance with a legal obligation under Article 6(1)(c) GDPR.
- Optional technologies or marketing - consent under Article 6(1)(a) GDPR if introduced. The current public website uses no analytics or advertising cookies.
6. Recipients, processors and transfers
We disclose data only as necessary to hosting, backup, security and technical support providers and to the provider you choose for sign-in or calendar access (Google, Microsoft or Apple). These providers may also operate outside the European Economic Area. Transfers rely on an adequacy decision, Standard Contractual Clauses or another lawful GDPR safeguard as applicable.
We do not sell personal data. We disclose it to public authorities only where the law requires us to do so.
7. Retention
- We retain account data, choices and calendar connections while you use the service and delete them after a verified account deletion request unless some records must be retained longer.
- Tokens and connections are removed when the calendar is disconnected or the account is deleted. Inactive or invalid access is cleaned up regularly.
- Operational and security logs are normally kept for no more than 14 days.
- Production backups have a standard 30-day recovery window. Deleted data may remain in encrypted backups until that window expires and is not returned to active use.
- Support communications are normally kept for up to 3 years after closure. Accounting and contractual records are kept as required by law, typically for 10 years.
8. Security
We use encrypted transport, access controls, environment separation, updates, limited logging and backups. Access and refresh tokens are server-side only and stored encrypted. No method is completely secure; we handle incidents according to their risk and applicable notification duties.
9. Your rights
You may request access, correction, erasure, restriction, portability and object to processing based on legitimate interests. You may withdraw consent at any time without affecting earlier lawful processing. Send requests to pospisek.michal@redstreak.cz. We may reasonably verify your identity and will respond without undue delay within the time required by the GDPR.
You may complain to the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, or your local supervisory authority.
10. Automated decisions and children
We do not make decisions producing legal or similarly significant effects based solely on automated processing and do not create advertising profiles. The services are not directed to children under 16 without the involvement of their parent or guardian.
11. Cookies and policy changes
The RedStreak public website uses no analytics or advertising cookies and loads no third-party fonts, measurement scripts or media. If this changes, we will update this notice first and provide consent controls where required.
We may update this policy when services or legal requirements change. The new version will be published at this address with its effective date.