Privacy
Privacy policy
This Privacy Policy explains how personal data is processed when you visit afr-it.com and its associated subdomains, unless a subdomain provides its own privacy notice.
Personal data means any information relating to an identified or identifiable natural person. We process personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection requirements.
This Privacy Policy applies to the public corporate website of AutoFlow Robotics. Separate privacy information may apply to independent software products, platforms or customer applications.
Controller
The controller within the meaning of Article 4(7) GDPR is:
AutoFlow Robotics s.r.o.
Rohanské nábřeží 657/7
186 00 Praha 8
Czech Republic
Email: info@autoflowrobotics.com
Telephone: +420 774 740 032
Privacy contact
For questions concerning the processing of personal data or the exercise of your data protection rights, contact:
Website hosting and delivery
The website is delivered through the infrastructure of Vercel.
When the website is accessed, technically necessary connection and request data is processed. This may include in particular the IP address, the time of access, the requested URL or file paths, HTTP and request metadata, browser and user-agent information, referrer details where transmitted by the browser, and technical security and diagnostic data.
This processing is necessary to deliver the website, to maintain the stability and security of the service, to analyse technical errors and to prevent abusive access.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure, reliable and technically sound operation of our website.
We use Vercel Inc. as our hosting provider.
Contact by email or telephone
We provide email addresses and telephone numbers on the website for direct contact. The website currently does not include a contact form.
If you contact us by email, we process in particular your email address, your name and any further contact details you provide voluntarily, the content of your message, technical email metadata and any attachments you choose to send.
The processing serves to handle your enquiry and to communicate with you.
Where your enquiry relates to entering into or performing a contract, the processing is based on Article 6(1)(b) GDPR.
For other business, technical or organisational enquiries, the processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in handling incoming communication properly and maintaining business contacts.
Where statutory retention obligations apply, further processing may be based on Article 6(1)(c) GDPR.
We use Google Workspace for our corporate email communication. Message content, sender and recipient details, technical metadata and any attachments may therefore be processed by Google.
If you contact us by telephone, we process the information you provide as well as, where applicable, your telephone number and any notes required to handle the enquiry.
No contact form and no website database
afr-it.com currently does not provide a contact form.
Personal data from enquiries is therefore not collected through a website form and is not stored in a contact database operated by afr-it.com.
Contact currently takes place through the email and telephone channels provided on the website.
Cookies, analytics and local storage
According to the current technical state of the site, we do not use any web analytics or marketing services, no personalised advertising, no social-media pixels and no consent-requiring analytics or marketing cookies on afr-it.com.
The language version of the website is selected through the respective URL path. Storing the language choice permanently in an analytics or marketing cookie is not required.
Should services requiring consent be introduced in future, this Privacy Policy will be updated before they are activated and, where legally required, consent will be obtained.
Recipients and service providers
We currently use the following service providers to operate the website and to handle incoming enquiries:
- Vercel Inc.
- Vercel provides hosting, delivery and technical infrastructure services for the website. Technical connection, security and diagnostic data may be processed in this context.
- Google Workspace
- Google Workspace is used for corporate email communication and for handling incoming enquiries. Email content, communication metadata and any attachments may be processed in this context.
International data transfers
When Vercel and Google Workspace are used, personal data may be processed outside the European Economic Area, in particular in the United States.
A transfer takes place only where the requirements of Articles 44 et seq. GDPR are met. Depending on the recipient and the processing, a transfer may in particular rely on an adequacy decision under Article 45 GDPR or on appropriate safeguards such as the European Commission's Standard Contractual Clauses under Article 46 GDPR.
Information on the safeguards used for a specific transfer can be requested through our privacy contact.
Retention
We store personal data only for as long as this is necessary for the respective processing purpose or as long as statutory retention obligations apply.
The following erasure criteria apply in particular to the current processing activities:
- Technical hosting data
- Technical hosting, security and diagnostic data is retained within the respective hosting configuration only for as long as this is necessary for technical operation, error analysis and security.
- General email enquiries
- General enquiries are deleted once they have been handled conclusively and no further business or legal need for storing them remains.
- Contract-related communication
- Communication in connection with entering into a contract or with a contractual relationship may be stored for the duration of the business relationship and beyond, where statutory retention obligations apply or where this is necessary to establish, exercise or defend legal claims.
- Data protection requests
- Data protection requests are stored for the duration of their handling and thereafter for as long as this is necessary to comply with statutory accountability and documentation obligations.
Data security
Taking into account the state of the art, the costs of implementation and the nature, scope and purposes of the processing, we implement appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
Depending on the respective system and risk, these include in particular:
- encrypted delivery of the website via HTTPS,
- restriction of administrative access,
- permissions granted on a need-to-have basis,
- protection of access credentials,
- keeping the software in use up to date,
- organisational rules for handling data protection and security incidents,
- selection and review of the service providers used.
Data subject rights
Subject to the statutory requirements, you have in particular the following rights:
- access under Article 15 GDPR,
- rectification under Article 16 GDPR,
- erasure under Article 17 GDPR,
- restriction of processing under Article 18 GDPR,
- data portability under Article 20 GDPR, where its requirements are met,
- objection under Article 21 GDPR,
- withdrawal of a given consent with effect for the future under Article 7(3) GDPR.
To exercise your rights, you can contact the privacy contact stated above.
Where this is necessary to protect personal data, we may request information to confirm your identity.
Right to object
Where we process personal data on the basis of Article 6(1)(f) GDPR, you have the right to object to that processing at any time on grounds relating to your particular situation.
We will then no longer process the data concerned unless there are compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
Automated decision-making
No solely automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place in connection with this website.
Right to lodge a complaint
You have the right under Article 77 GDPR to lodge a complaint with a data protection supervisory authority. You may in particular contact the supervisory authority of your habitual residence, your place of work or the place of the alleged infringement.
For AutoFlow Robotics s.r.o., the following Czech data protection supervisory authority is particularly relevant — the Office for Personal Data Protection:
Úřad pro ochranu osobních údajů
Pplk. Sochora 27
170 00 Praha 7
Czech Republic
Email: posta@uoou.gov.cz
Changes to this Privacy Policy
We update this Privacy Policy when the website, the services used or the applicable legal framework changes materially.
The version published on this website is the applicable version.
Last updated: August 2026
