Privacy Policy
Last updated: 4 October 2026. Controller: GP novum s.r.o., Company ID 28155483, Riegrova 1756/51, 370 01 České Budějovice, Czech Republic, info@gpnovum.cz. We have not appointed a data protection officer; write to the address above about anything concerning your data.
The key principle: you never send us your files
The file fingerprint (sha256), the appearance fingerprint and the change grid are computed by your browser or app. Only that fingerprint reaches us, never the file. Photos taken with the Vír Foto app stay on your phone.
What data we process
- Verification (anyone): fingerprints of the files you verify; connection data (IP address, time) in the hosting provider's operational logs for security. We do not profile visitors and use no advertising or analytics cookies.
- User accounts (people who sign in): e-mail address, name (if the sign-in provider sends it), an identifier from the sign-in provider you chose (Google, Microsoft, GitHub or Vír), public keys of your passkeys (never your fingerprint or face — Face ID, Touch ID and Windows Hello stay on your device), membership and role in organisations, and invitations sent to colleagues' e-mail addresses. When you sign in with a link, we send it to your e-mail address.
- Cookies: we use only strictly necessary cookies — a sign-in session cookie (30 days or until you sign out) and a short-lived security cookie during sign-in (10 minutes). No advertising or analytics cookies, so we do not ask for consent.
- Issuers: domain and company name, fingerprints of API keys (not the keys themselves), webhook URL and secret, records of issued seals and usage.
- Seals: file fingerprint, origin declaration, AI tool, time, seal title (stored on our server; only its fingerprint goes to the public log).
- Vír Foto: account name, the phone's public keys, fingerprints of photos taken, and time. When a photo is verified, the name of the account that took it is shown.
A public and permanent log
The public log (RFC 6962, anchored in Bitcoin) records the file fingerprint, the Issuer's domain, the declaration, the time and a fingerprint of the title. This record cannot be deleted — that is what makes it verifiable. We therefore do not put personal data into it; neither Vír Foto account names nor seal titles are in it.
Why (legal basis)
- Performance of the contract with the Issuer and of the account you create (Art. 6(1)(b) GDPR) — signing in, running the account, issuing seals, e-mails needed for the service.
- Legitimate interest in the security of the Service and in the verifiability of seals (Art. 6(1)(f) GDPR).
- Compliance with legal obligations, e.g. accounting (Art. 6(1)(c) GDPR).
How long
Account and Issuer data for as long as the account or contract exists and 3 years after it ends (settlement of claims); accounting records for the period required by law. Sign-in sessions expire after 30 days, sign-in links after 15 minutes. Operational logs of the hosting provider are kept for a short period set by the provider. Seal titles and Vír Foto account names are deleted on request; fingerprints in the public log remain.
Who processes data on our behalf
- Netlify, Inc., USA (hosting of the website, server functions and storage). This involves a transfer to the USA, based on the EU-US Data Privacy Framework (adequacy decision) and, where that does not apply, the European Commission's standard contractual clauses.
- Sendinblue SAS (Brevo), France — sending of sign-in links and service e-mails; data is processed in the EU.
- OpenTimestamps calendars (Bitcoin anchoring) — they receive only fingerprints, no personal data.
- Public DNS resolvers (Google, Cloudflare) — when verifying a domain we query your domain's TXT record.
If you sign in with Google, Microsoft or GitHub, that provider processes your sign-in as an independent controller under its own privacy policy; we receive only the data listed above. We do not sell personal data and do not use it for automated decision-making or profiling.
Your rights
You have the right of access, rectification, erasure (within the limits of the permanent log above), restriction, portability and objection. Write to info@gpnovum.cz. You may lodge a complaint with the Czech data protection authority (Úřad pro ochranu osobních údajů, uoou.gov.cz) or the authority of your country.
The English version of this document is the governing version; any translation is for convenience only.