uxpixo Prague
Transparency GDPR Compliance

Data Handling &
User Trust.

We operate a lean, privacy-first architecture. No third-party analytics tracers, no hidden data brokers. This document outlines the specific constraints we place on our own infrastructure to protect the information you entrust to us.

Data Classification

IP Address Ephemeral / Log Only
Contact Forms End-to-End Encrypted
Session Cookies Strictly Necessary
Third-Party Trackers None

Data Minimization by Design

Our legal basis for processing is Article 6(1)(f) GDPR—legitimate interest. We only process data required to deliver the service explicitly requested by the visitor. If a feature doesn't strictly require personal data, we don't collect it.

As a Prague-based studio, we adhere to the strictest interpretation of EU data protection laws. This means our servers are configured to discard connection metadata immediately after the HTTP request lifecycle, and we do not maintain user profiles or marketing lists.

Information We Collect

Technical Data

When you request pages from uxpixo.company, our server logs your IP address, browser type, and timestamp. This data is processed solely for security auditing (DDoS mitigation) and is purged from our active logs within 24 hours. We do not cross-reference this data with any personal identifiers.

Contact Correspondence

Email and phone data submitted via our contact forms at contact.php are encrypted in transit and at rest. We use this information strictly to respond to your inquiry. Once the business inquiry concludes, correspondence is archived offline and deleted from the active system after 12 months.

Pitfall Rail

  • Avoid: Using client IP for behavioral targeting. It is PII and a GDPR violation if used for profiling.
  • Ensure: Any third-party script (e.g., fonts) is hosted locally or via privacy-respecting proxy. We use self-hosted fonts.
  • Check: Forms must have explicit "opt-in" checkboxes for marketing, never pre-checked.

Practitioner's Note

"In the Czech market, trust is currency. We treat every byte of user data as a liability. The goal isn't just compliance; it's operational simplicity. If you can't explain why you're storing it, delete it."

Architectural detail representing structure and privacy
Structural Integrity / Access Control

Your Rights & Controls

Under GDPR, you possess specific rights regarding your personal data held by uxpixo. We have designed our internal processes to facilitate these requests without bureaucratic friction.

Right to Access & Portability

Request a copy of any correspondence or data points we hold. We provide this in a standard, machine-readable format (JSON/CSV) within 30 days.

Right to Erasure

You may demand the deletion of your personal data at any time. This excludes data we are legally required to retain for tax or auditing purposes.

Rectification

If your data is inaccurate, we will correct it immediately upon verification. Contact us at [email protected].

Data Protection Officer & Controller

For all privacy-related inquiries, including data access requests or complaints.

uxpixo s.r.o.

Karlovo nám. 17, 120 00 Praha 2, Czechia

Mon-Fri: 9:00-18:00

[email protected] | +420 222 514 444

Effective Date: Current Year 2026. This policy is reviewed quarterly. Changes to this policy are posted here and, if material, notified via email to active clients. We do not retroactively apply new privacy policies to data collected under previous versions.