What data we process about you, why, who can access it, and your rights. Compliant with GDPR (EU 2016/679).
Data Controller: Signal Core s.r.o., Prague. DPO contact: [email protected].
We collect only the data we need to operate the platform: contact details, invoices, payouts, conversion tracking, tax reports (DAC7). We never sell your data to third parties for advertising.
You have the right to access, rectification, erasure, and to object to processing. You can lodge a complaint with the Czech Office for Personal Data Protection (ÚOOÚ), uoou.gov.cz.
Signal Core s.r.o., Rybná 716/24, 110 00 Prague 1, Czech Republic · Reg. No: 24460354 · VAT ID: CZ24460354
Registered: Municipal Court in Prague, section C, file 198765
GDPR queries: [email protected] · general support: [email protected]
We have appointed a Data Protection Officer responsible for GDPR compliance. The DPO is independent and reports directly to management.
Contact: [email protected] · post: Signal Core s.r.o., for the attention of DPO, Rybná 716/24, Prague 1
Depending on user type and purpose, we process the following categories:
For each data category we know clearly why we process it and under which clause of GDPR Art. 6:
| Purpose | Legal basis | Example data |
|---|---|---|
| Performance of contract | Art. 6(1)(b) | Account, invoicing, payouts |
| Legal obligation | Art. 6(1)(c) | DAC7, AML, tax reporting |
| Legitimate interest | Art. 6(1)(f) | Anti-fraud, security logs, analytics |
| Consent | Art. 6(1)(a) | Marketing newsletter, non-essential cookies |
You may withdraw consent anytime (email, in-app settings) without affecting processing performed before withdrawal.
We share data with carefully selected processors, all under DPA per GDPR Art. 28:
List is public and updated in Settings → Privacy → Subprocessors.
Some data flows outside the EU/EEA (USA — Stripe, Cloudflare, Polygon, etc.). For each transfer we have:
| Category | Retention | Reason |
|---|---|---|
| Active account | For account lifetime | Performance of contract |
| Invoices, accounting data | 10 years | § 31 of CZ Accounting Act |
| DAC7 reporting data | 5 years after last report | International cooperation law |
| KYC documents | 5 years after relationship ends | CZ AML Act 253/2008 |
| Login logs | 12 months | Security audit |
| Conversion tracking | 3 years | Statute of limitations for disputes |
| Marketing consent | Until withdrawn | Consent |
You have the right to:
Settings → Privacy → Download dataWe respond within 30 days of the request. Complex cases may extend by 60 days with notice.
We use automated decision-making only in a limited scope:
We do not use automated decision-making with legal effects under Art. 22 GDPR.
Tandemio is not intended for children under 18. We verify age at registration via KYC (Creator) or company ID (Brand).
If we detect a minor’s registration, we close the account and delete data immediately. Parents who discover their child uses Tandemio should email [email protected].
We implement technical and organisational measures per GDPR Art. 32:
In case of a data breach:
Public status: tandemio.app/security (planned).
We may amend this Policy. For material changes (new data categories, new recipients) we notify you at least 30 days in advance by email.
The current version is always on this page with effective date. Historical versions are archived.
DPO: [email protected] · General: [email protected]
Post: Signal Core s.r.o., for the attention of DPO, Rybná 716/24, 110 00 Prague 1
Authority complaint: Czech Office for Personal Data Protection (ÚOOÚ), Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz
This Policy describes our current practice. In case of conflict, the Czech version prevails.