Privacy Policy
Effective date: November 13, 2025 · Last updated: 2026
1. Data Controller
ZORYX Team s.r.o. is the data controller for all personal data collected through the ZORYX web application (web.zoryx.app) and the ZORYX mobile application.
Data Protection Officer: Yauhen Zorych
Email: yauhen.zorych@zoryx.app
Phone: +420 776 540 503
General inquiries: yauhen.zorych@zoryx.app
2. What Data We Collect
- ▸Clinic reviews: Name (optional, you may use a pseudonym), star rating (1–5), written comment. Stored publicly to help other users.
- ▸Donor leads: Phone number provided voluntarily via the plasma donor popup. Used solely to connect you with A PLAZMA donation center.
- ▸Technical data: IP address, browser type, device type, pages visited, time spent. Collected automatically via Google Analytics (anonymised).
- ▸Cookies: Session cookies for language preference, accessibility settings, and cookie consent. No third-party advertising cookies.
3. Legal Basis for Processing
We process your data under the following legal bases as defined in GDPR Article 6:
- Consent — donor leads, optional review submission
- Legitimate interest — analytics to improve service quality
- Legal obligation — compliance with Czech and EU law
4. Data Storage & Retention
All data is stored on Google Firebase (Firestore), hosted in the European Union (europe-west4, Netherlands). Data is encrypted in transit (HTTPS/TLS) and at rest.
- Reviews: retained indefinitely unless deletion is requested
- Donor leads: retained for 12 months, then deleted
- Analytics: 26-month rolling window (Google Analytics default)
5. Data Sharing
We do not sell your personal data. Data may be shared only with:
- Google LLC — Firebase infrastructure and Google Analytics
- A PLAZMA s.r.o. — donor lead phone numbers, with your explicit consent
- OpenAI — anonymised chat messages for AI assistant responses
- Competent authorities if required by applicable law
6. Your Rights (GDPR)
Under GDPR you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion ("right to be forgotten")
- Restriction — limit how we process your data
- Portability — receive your data in a structured format
- Object — object to processing based on legitimate interest
- Withdraw consent — at any time, without affecting past processing
To exercise any right, email yauhen.zorych@zoryx.app. We will respond within 30 days. You may also lodge a complaint with the Office for Personal Data Protection (ÚOOÚ, Czech Republic): uoou.cz.
7. Cookies
We use strictly necessary cookies (language, accessibility preferences) and analytics cookies (Google Analytics, anonymised IP). You may decline analytics cookies via the cookie banner. Strictly necessary cookies cannot be disabled as they are required for the service to function.
8. Changes to This Policy
We may update this Privacy Policy. Material changes will be communicated via a notice on the website. Continued use after changes constitutes acceptance of the updated policy.