Legal

Privacy Policy

Last updated: June 2026

This Privacy Policy explains how we process personal data. It does not describe our full confidentiality obligations, which may also be covered by our Terms of Service, NDA, statement of work, or client agreement.

This Privacy Policy explains how Eudoc.online ("Eudoc", "we", "us" or "our") collects, uses, stores and protects personal data when you visit our website, contact us, create an account, request a document review, upload supplier documents, or use our services.

Eudoc provides expert-led EU import compliance documentation review with smart automation support. Our service helps clients assess supplier documents before shipment or before paying the supplier balance. This Privacy Policy explains how we process personal data in that context.

Eudoc is not a certification body, notified body, law firm, laboratory, or market surveillance authority. Our privacy practices are separate from the scope and limitations of our compliance review services.

If you have any questions, contact us at: hello@eudoc.cz

1. Who is responsible for your personal data

The data controller is:

BohemiAsia s.r.o.
Operating the Eudoc.online service
Legal form: společnost s ručením omezeným / limited liability company
Company registration number / IČO: 09700978
Tax ID / DIČ: CZ09700978
VAT payer status: Not registered as a VAT payer
Registered address: Školská 660/3, Nové Město, 110 00 Praha 1, Czech Republic
Data box / Datová schránka: cq9tfjj
Represented by: Huy Nguyen, Managing Director / jednatel

If a data protection officer or EU representative is appointed in the future, we will update this Privacy Policy with the relevant contact details.

2. What this Privacy Policy covers

This Privacy Policy applies to personal data processed when you:

  • visit our website;
  • contact us by email, form, or other communication channel;
  • request a free preview, expert review, consultation, or quote;
  • create or use an account or client portal;
  • upload supplier documents or product compliance files;
  • receive review findings, reports, recommendations, or follow-up questions;
  • interact with our marketing, resources, or support communications.

This Privacy Policy does not apply to third-party websites or services linked from our website. Those third parties are responsible for their own privacy practices.

3. Personal data we collect

We collect only the personal data that is necessary for our website, communication, account management, document review, service delivery, security, and legal obligations.

3.1 Contact and account data

We may collect:

  • full name;
  • work email address;
  • phone number, if provided;
  • company name;
  • job title or role;
  • billing or business address;
  • account login details;
  • communication preferences;
  • information you provide in forms, emails, or support requests.

3.2 Product and supplier review data

When you request a review or upload documents, we may process information related to:

  • product category and product description;
  • supplier or manufacturer name;
  • country of origin;
  • target EU/EEA market;
  • shipment timing or balance payment timing;
  • applicable regulations or document types;
  • review notes, findings, risk summaries, and supplier follow-up questions.

3.3 Uploaded documents

You or your supplier may upload documents such as:

  • CE Declarations of Conformity;
  • certificates;
  • test reports;
  • RoHS and REACH declarations;
  • EMC, RED, LVD, GPSR, WEEE, battery, or packaging documents;
  • technical files;
  • manuals and instructions;
  • product labels, packaging artwork, and photos;
  • supplier letters, declarations, or emails;
  • other compliance-related evidence.

These documents may contain personal data such as names, signatures, job titles, email addresses, phone numbers, company addresses, or contact details of supplier, manufacturer, laboratory, certification body, or client representatives.

Uploaded documents may also contain confidential business, supplier, product, or technical information. We treat such information with care and restrict access as described below.

3.4 Website and technical data

When you visit our website, we may collect:

  • IP address;
  • browser type and version;
  • device type;
  • operating system;
  • pages visited;
  • approximate location based on IP address;
  • timestamps;
  • referral source;
  • cookie identifiers;
  • usage and security logs.

3.5 Payment and billing data

If paid services are ordered, we may process:

  • billing contact details;
  • invoice details;
  • payment status;
  • transaction references;
  • VAT or tax details, where applicable.

We do not intend to store full card numbers. Payment processing, if enabled, should be handled by a secure third-party payment provider.

3.6 Marketing data

If you subscribe to updates or request resources, we may process:

  • email address;
  • name;
  • company;
  • consent status;
  • marketing preferences;
  • engagement with emails or website resources.

You can unsubscribe from marketing communications at any time.

4. We do not intentionally request special category data

Our services are intended for product compliance documentation, not for processing sensitive personal data.

Please do not upload special category personal data unless strictly necessary. Special category data includes information about health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, sex life, or sexual orientation.

If such data is accidentally included in uploaded documents, we will process it only as necessary to provide the service, protect confidentiality, comply with legal obligations, or delete it upon request where appropriate.

5. How we use personal data

We use personal data for the following purposes:

5.1 To provide our services

We use personal data to:

  • create and manage accounts;
  • receive uploaded documents;
  • review supplier compliance documents;
  • assess whether documents appear complete, current, relevant, or mismatched;
  • prepare review findings and reports;
  • identify missing or outdated documents;
  • create supplier follow-up questions;
  • communicate with you about the review;
  • provide support and respond to questions.

5.2 To communicate with you

We use contact data to:

  • respond to enquiries;
  • schedule consultations;
  • send service updates;
  • send review results;
  • provide administrative messages;
  • handle complaints or support requests.

5.3 To improve our website and services

We may use website and service usage data to:

  • understand how users interact with our website;
  • improve usability and content;
  • improve document upload and review workflows;
  • develop new features;
  • maintain internal quality control.

5.4 To protect security and prevent misuse

We may process technical and account data to:

  • detect suspicious activity;
  • prevent unauthorized access;
  • protect uploaded documents;
  • maintain logs;
  • troubleshoot errors;
  • prevent fraud, abuse, or misuse of our services.

5.5 To comply with legal and accounting obligations

We may process personal data to:

  • issue invoices;
  • maintain business records;
  • comply with tax and accounting rules;
  • respond to lawful requests;
  • establish, exercise, or defend legal claims.

5.6 Marketing, where permitted

We may send marketing communications where:

  • you have consented; or
  • we are allowed to do so under applicable law for similar business services.

You can opt out at any time.

6. Legal bases for processing

Under the GDPR, we rely on the following legal bases:

6.1 Contract or pre-contractual steps

We process personal data where necessary to provide services, respond to review requests, prepare quotes, manage accounts, or deliver reports.

6.2 Legitimate interests

We may process personal data based on our legitimate interests, including:

  • operating and improving our website and services;
  • communicating with business contacts;
  • protecting security;
  • preventing misuse;
  • keeping business records;
  • developing and improving review workflows;
  • handling claims or disputes.

We balance these interests against your rights and expectations.

6.3 Legal obligation

We process personal data where required by law, including accounting, tax, regulatory, or legal record-keeping obligations.

6.4 Consent

We rely on consent where required, for example for certain cookies, analytics, or optional marketing communications. You may withdraw consent at any time.

7. Uploaded documents and confidentiality

Uploaded documents are central to our service. We understand that supplier documents, test reports, technical files, labels, product photos, and related correspondence may contain confidential business information.

We use uploaded documents only to:

  • provide the requested review;
  • prepare findings and recommendations;
  • communicate with you about the review;
  • maintain service records;
  • protect legal or contractual interests;
  • improve quality and internal processes, where permitted and appropriately protected.

We do not sell uploaded documents.

We do not publish uploaded documents.

We do not share uploaded documents with unrelated third parties for their independent marketing purposes.

Access to uploaded documents is restricted to people and service providers who need access to provide, secure, maintain, or support the service.

If a separate NDA or client agreement applies, it may provide additional confidentiality protections.

8. Expert review and smart automation support

Eudoc uses expert-led review with smart automation support. Automation may help organize documents, extract text, identify document types, flag missing information, or support internal review workflows.

However, our review findings are not intended to be based solely on automated decision-making. Human expertise remains part of the review process.

We do not use automation to make legal, certification, or official market access decisions about you. Our findings are practical document review outputs and do not replace certification, legal advice, laboratory testing, or authority decisions.

9. Cookies and analytics

Our website may use cookies and similar technologies to:

  • keep the website functional;
  • remember preferences;
  • improve performance;
  • understand website usage;
  • protect security;
  • support analytics or marketing, where enabled.

Where required by law, we will ask for your consent before placing non-essential cookies.

More information may be provided in our separate Cookie Policy.

10. Who we share personal data with

We may share personal data only where necessary and appropriate with:

  • hosting and cloud infrastructure providers;
  • document storage providers;
  • authentication and account management providers;
  • email and communication tools;
  • analytics providers, if enabled;
  • payment processors, if paid services are enabled;
  • professional advisers such as accountants, lawyers, or auditors;
  • contractors, reviewers, or technical specialists involved in providing the service;
  • authorities, courts, or regulators where legally required.

All service providers should process personal data under appropriate contractual, confidentiality, and security obligations.

We do not sell your personal data.

11. International transfers

We aim to store and process personal data in the EU/EEA where practical.

Some service providers may process data outside the EU/EEA. Where this happens, we use appropriate safeguards required by GDPR, such as:

  • European Commission adequacy decisions;
  • Standard Contractual Clauses;
  • data processing agreements;
  • additional technical and organizational safeguards where appropriate.

12. How long we keep personal data

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy.

Typical retention periods include:

  • enquiry and contact data: for as long as needed to respond and maintain reasonable business records;
  • account data: for the duration of the account and a reasonable period afterward;
  • uploaded documents and review files: for the duration needed to provide the service and maintain service records, unless deletion is requested or a longer retention period is agreed;
  • billing and accounting records: for the period required by tax and accounting law;
  • security logs: for a limited period necessary to protect the service;
  • marketing data: until you unsubscribe or withdraw consent.

Clients may request deletion of uploaded documents, subject to legal, contractual, accounting, security, or dispute-related retention needs.

Where possible, we will delete or anonymize data that is no longer needed.

13. Security

We use reasonable technical and organizational measures to protect personal data and uploaded documents against unauthorized access, loss, misuse, alteration, or disclosure.

These measures may include:

  • access controls;
  • restricted reviewer access;
  • secure hosting;
  • encryption in transit;
  • secure document storage;
  • logging and monitoring;
  • confidentiality obligations;
  • account authentication;
  • internal handling procedures.

No online service can guarantee absolute security. You are responsible for keeping your account credentials confidential and for ensuring that uploaded documents are appropriate to share with us.

14. Your GDPR rights

If GDPR applies to your personal data, you may have the following rights:

  • right of access;
  • right to rectification;
  • right to erasure;
  • right to restriction of processing;
  • right to data portability;
  • right to object to processing based on legitimate interests;
  • right to withdraw consent;
  • right not to be subject to solely automated decisions with legal or similarly significant effects, where applicable;
  • right to lodge a complaint with a supervisory authority.

To exercise your rights, contact us at hello@eudoc.cz.

We may need to verify your identity before responding. We will respond within the timeframe required by applicable law.

15. Supervisory authority

If you believe that we process your personal data unlawfully, you have the right to lodge a complaint with a data protection supervisory authority.

If Eudoc is established in the Czech Republic, the relevant authority is:

Úřad pro ochranu osobních údajů

You may also contact the supervisory authority in your country of residence, workplace, or where the alleged infringement occurred.

16. Business clients, suppliers, and third-party personal data

Our clients may upload documents that contain personal data of supplier, manufacturer, laboratory, certification body, or other third-party representatives.

If you upload documents containing third-party personal data, you are responsible for ensuring that you have a lawful basis to share those documents with us for review.

We process such third-party personal data only as necessary to provide the requested service, protect confidentiality, comply with legal obligations, or handle related claims.

17. Children

Our services are intended for businesses and professional users. They are not directed to children.

We do not knowingly collect personal data from children. If you believe that a child has provided personal data to us, contact us at hello@eudoc.cz.

18. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal requirements, or business operations.

The updated version will be posted on this page with a revised "Last updated" date.

Material changes may be communicated by email or website notice where appropriate.

19. Contact

For privacy questions, requests, or concerns, contact:

BohemiAsia s.r.o.
Operating the Eudoc.online service
Company registration number / IČO: 09700978
Tax ID / DIČ: CZ09700978
VAT payer status: Not registered as a VAT payer
Registered address: Školská 660/3, Nové Město, 110 00 Praha 1, Czech Republic
Data box / Datová schránka: cq9tfjj
Represented by: Huy Nguyen, Managing Director / jednatel

Last updated: June 2026