PRIVACY POLICY
Surplus Food Studio s.r.o.
Last updated: June 2026
This Privacy Policy explains how Surplus Food Studio s.r.o., registration number 57147361 (the Company, we, us, our) collects, uses, discloses, and protects personal data when you use our website surplusfoodstudio.com (the Website) and our membership learning platform and mobile app (the Platform and App, together with the Website, the Services). This Privacy Policy applies to both B2C users (consumers) and B2B users (business customers, including multi-seat plans).
ARTICLE I. ABOUT US AND HOW THIS POLICY WORKS
1.1Data Controller.
Surplus Food Studio s.r.o., is the data controller for personal data processed through the Services, meaning we determine the purposes and means of processing.
1.2Contact Details.
You can contact us regarding privacy matters at:
(a) Email: hello@surplusfoodstudio.com
(b) Postal address: Karpatske Namestie 10A, Bratislava, 83106, Slovakia
1.3 Scope of This Privacy Policy.
This Policy covers processing of personal data in connection with:
(a) account creation and administration;
(b) subscriptions, billing, and payments;
(c) access to and delivery of digital learning content, including offline access features;
(d) customer support;
(e) communications and service updates;
(f) security, fraud prevention, and enforcement of terms;
(g) analytics and performance measurement; and
(h) legal and compliance obligations.
1.4Relationship to Terms and Conditions.
This Policy should be read together with our Terms and Conditions. If there is a conflict, this Policy governs how we process personal data, and the Terms govern platform usage and contractual rights.
1.5 Services Supported by Third Parties.
Our Services rely on third-party providers, including:
(a) Stripe for payment processing; and
(b) GroupApp for platform infrastructure.
We remain responsible for our processing as controller. These providers may act as processors or independent controllers depending on the specific service.
ARTICLE II. DEFINITIONS
2.1Definitions.
For purposes of this Policy:
2.2 “Personal Data.”
Any information relating to an identified or identifiable natural person, as defined under the EU General Data Protection Regulation (GDPR).
2.3 “Processing.”
Any operation performed on personal data, such as collection, storage, use, disclosure, or deletion.
2.4 “User.”
Any person who visits the Website, creates an account, purchases a subscription, accesses the Platform, uses the App, or otherwise interacts with the Services.
2.5 “B2B User” and “B2C User.”
A B2B User is a user accessing the Services via a business subscription or on behalf of a company. A B2C User is a user purchasing and using the Services personally.
2.6 “Processor.”
A party that processes personal data on behalf of the controller.
2.7 “EEA.”
The European Economic Area.
ARTICLE III. CATEGORIES OF PERSONAL DATA WE COLLECT
3.1Personal Data You Provide Directly.
When you create an account, subscribe, purchase add-ons, or communicate with us, you may provide:
(a) Identity and contact data: name, email address;
(b) Professional data: job position, company name (especially for B2B Users);
(c) Account credentials: login identifiers and authentication tokens (passwords are typically stored as hashed values by the relevant platform provider);
(d) Support communications: messages and correspondence you send to us.
3.2Payment and Transaction Data.
Payments are processed by Stripe. We typically receive limited payment-related data necessary to administer subscriptions, such as:
(a) subscription status and plan type;
(b) billing cycle, renewal date, and payment confirmation;
(c) partial payment identifiers (for example, last four digits of a card) where provided by Stripe;
(d) invoice references, payment timestamps, and refund status (note: our policy is no refunds except where mandatory law applies or where we refuse registration or terminate an Account without cause as described in our Terms and Conditions).
We do not intentionally collect full payment card numbers. Stripe processes payment details under its own security standards.
3.3Device and Technical Data.
When you use the Website or App, we may collect technical data such as:
(a) device type, operating system version, app version;
(b) browser type and settings;
(c) IP address (may be used for security and approximate location for compliance and fraud prevention);
(d) identifiers necessary for service functionality (for example, session IDs, device IDs, push notification tokens, or app instance identifiers);
(e) time zone and language settings.
3.4UsageData.
We may collect data about how you interact with the Services, including:
(a) pages or screens viewed;
(b) features used;
(c) course progress and completion signals;
(d) access times and duration;
(e) interactions needed for offline access functionality (for example, content caching events);
(f) access logs for security and enforcement.
3.5Offline Access Data.
If offline access is enabled, we may process:
(a) records of content made available for offline use;
(b) device verification and token validation events;
(c) time-limited entitlement data to ensure the user remains subscribed and authorized.
3.6Cookies and Similar Technologies.
On the Website, we may use cookies and similar technologies for functionality, security, analytics, and preferences (see ARTICLE VI).
3.7Data We Do Not Intend to Collect.
We do not intend to collect sensitive categories of personal data (special categories under GDPR, such as health data) through normal operation of the Services. You should not provide such data in support tickets or community features. If you do, we will process it only to the extent necessary to respond, and we may delete or redact it where appropriate.
ARTICLE IV. PURPOSES OF PROCESSING AND LEGAL BASES (GDPR)
4.1Overview.
Under GDPR, we must have a lawful basis for processing. We process personal data for the purposes below on one or more of these legal bases:
(a) Contract: processing necessary to provide Services under our Terms;
(b) Legal obligation: compliance with applicable laws (for example, accounting and tax);
(c) Legitimate interests: operating, securing, and improving the Services;
(d) Consent: where required for certain cookies, marketing, or optional features.
4.2Account Creation and Administration.
Purpose: to register you, create and manage your account, authenticate access, and provide core service functionality.
Legal basis: Contract (performance of the contract) and Legitimate interests (secure operation and fraud prevention).
4.3Subscription Management and Billing.
Purpose: to process subscriptions, renewals, invoicing, payment confirmation, and account entitlements.
Legal basis: Contract and Legal obligation (accounting, tax compliance).
4.4Delivery of Digital Content and Features.
Purpose: to deliver Platform content, enable course progress, enable offline access features, and provide user experience functions.
Legal basis: Contract and Legitimate interests (service operation and improvement).
4.5Customer Support and Communications.
Purpose: to respond to requests, provide support, send service messages (billing notices, security alerts, platform updates).
Legal basis: Contract and Legitimate interests (customer service, quality improvement).
4.6Security, Fraud Prevention, and Content Protection.
Purpose: to protect accounts, prevent credential sharing, detect abusive usage, protect intellectual property, enforce Terms, and maintain service integrity.
Legal basis: Legitimate interests (security and protection of business assets) and, where relevant, Contract.
4.7Analytics and Service Improvement.
Purpose: to understand performance, diagnose errors, improve features, and maintain stability.
Legal basis: Legitimate interests and, where required for non-essential cookies or tracking, Consent.
4.8Legal Claims and Compliance.
Purpose: to comply with lawful requests, enforce rights, prevent unlawful activity, and establish, exercise, or defend legal claims.
Legal basis: Legal obligation and Legitimate interests.
4.9Marketing Communications.
Purpose: to send marketing communications where permitted by law.
Legal basis: Consent where required, or Legitimate interests where permitted for existing customer communications, subject to opt-out rights and applicable ePrivacy rules.
ARTICLE V. B2B AND B2C SPECIFICS
5.1B2C Users.
If you are a consumer, we process your data primarily to provide the subscription service, manage billing, secure the platform, and comply with legal obligations.
5.2B2B Users and Business Customer Contacts.
For B2B subscriptions, we process business-related contact data, such as job position and company name, to:
(a) manage seat access and business subscriptions;
(b) provide admin and billing communications;
(c) verify authorized use under multi-seat plans; and
(d) prevent misuse such as credential sharing beyond purchased seats.
Legal basis: Contract and Legitimate interests.
5.3Multi-Seat Administration Data.
If a business plan includes multiple seats, we may process:
(a) seat assignment identifiers;
(b) user lists or seat rosters;
(c) usage signals relevant to enforcing seat limits.
This is processed to provide the service to the Business Customer and to prevent misuse.
5.4B2B Customer Responsibilities.
Business Customers are responsible for ensuring that authorized users receive appropriate notices about processing under this Policy and that they use the Services in compliance with the Terms.
ARTICLE VI. COOKIES, SDKs, AND SIMILAR TECHNOLOGIES
6.1Cookies on the Website.
Cookies are small files stored on your device. We may use:
(a) Strictly necessary cookies for site functionality and security;
(b) Preference cookies to remember settings;
(c) Analytics cookies to understand Website usage and improve performance;
(d) Consent management cookies to store your cookie choices.
6.2App Technologies.
Mobile apps often use SDKs or similar tools for functionality, crash reporting, and analytics. We may use such tools to:
(a) keep the App stable and secure;
(b) identify and fix errors;
(c) measure general usage patterns.
6.3Consent Where Required.
Where required under EU ePrivacy rules, non-essential cookies and similar tracking are used only with your consent. You can withdraw consent at any time via cookie settings or device settings, where applicable.
6.4Managing Cookies.
You can control cookies through:
(a) our cookie banner or settings tool (if available); and
(b) your browser settings.
Disabling cookies may affect functionality.
ARTICLE VII. SHARING AND DISCLOSURE OF PERSONAL DATA
7.1General Rule.
We do not sell your personal data. We share it only as necessary to operate the Services, comply with law, and protect our rights.
7.2Service Providers and Processors.
We may share personal data with processors who support our Services, such as:
(a) Stripe for payment processing;
(b) GroupApp for platform infrastructure and app delivery;
(c) hosting and cloud service providers;
(d) email delivery and customer support tools;
(e) analytics and crash reporting providers (where used).
These parties process data under contractual obligations to protect confidentiality and security.
7.3Business Customer Access (B2B).
If you use the Services under a B2B subscription, certain account-level information may be visible to the Business Customer’s administrators for seat management and compliance, such as:
(a) name and email;
(b) seat status;
(c) high-level usage signals relevant to seat compliance.
We aim to limit what is shared to what is reasonably necessary.
7.4Legal and Regulatory Disclosure.
We may disclose personal data if required to do so by law, court order, or valid legal process, or where necessary to protect the rights, property, or safety of the Company, our users, or others.
7.5Professional Advisers.
We may share data with professional advisers (lawyers, accountants, auditors) where necessary for compliance, contractual enforcement, or claims.
7.6Corporate Transactions.
If we undergo a merger, acquisition, reorganization, or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate safeguards.
ARTICLE VIII. INTERNATIONAL TRANSFERS (OUTSIDE THE EEA)
8.1Transfers.
We are based in Slovakia (EEA). Some service providers may process data outside the EEA. When we transfer personal data outside the EEA, we ensure appropriate safeguards.
8.2Safeguards.
Safeguards may include:
(a) an EU adequacy decision for the recipient country, where applicable;
(b) Standard Contractual Clauses (SCCs) approved by the European Commission;
(c) additional technical and organizational measures where appropriate.
8.3Information About Transfers.
You may contact us to request information about international transfers and the safeguards used, subject to legal limits.
ARTICLE IX. DATA RETENTION
9.1General Retention Principle.
We keep personal data only as long as necessary for the purposes described in this Policy, unless a longer retention period is required or permitted by law.
9.2Typical Retention Periods.
We generally retain:
(a) Account data for as long as your account is active and for a reasonable period thereafter to handle reactivation, disputes, or compliance;
(b) Billing and transaction records for the period required by tax and accounting law;
(c) Support communications for as long as needed to resolve issues and maintain quality records;
(d) Security logs for a reasonable period to detect and investigate abuse and protect the Services;
(e) Consent records as needed to demonstrate compliance.
9.3Deletion and Anonymization.
Where feasible, we delete or anonymize data when it is no longer needed. Some data may remain in backups for limited periods, subject to security controls.
ARTICLE X. SECURITY MEASURES
10.1Security Commitment.
We implement reasonable technical and organizational measures to protect personal data and platform integrity, including access controls, encryption in transit where supported, monitoring for suspicious activity, and least-privilege access.
10.2No Absolute Guarantee.
No method of transmission or storage is fully secure. While we take appropriate steps, we cannot guarantee absolute security.
10.3Account Security.
You are responsible for keeping credentials confidential and using secure passwords and device security measures. Unauthorized sharing of access credentials violates the Terms and increases security risk.
10.4Data Breach Response.
If a personal data breach occurs that is likely to result in a risk to individuals’ rights and freedoms, we will notify the relevant supervisory authority and affected individuals where required under GDPR, taking into account legal timelines and requirements.
ARTICLE XI. YOUR RIGHTS UNDER GDPR
11.1Overview of Rights.
If GDPR applies to you, you have rights regarding your personal data, including:
(a) right of access;
(b) right to rectification;
(c) right to erasure (right to be forgotten), in certain circumstances;
(d) right to restriction of processing;
(e) right to data portability, where applicable;
(f) right to object to processing based on legitimate interests;
(g) right to withdraw consent, where processing is based on consent;
(h) right not to be subject to certain automated decision-making, where applicable.
11.2How to Exercise Rights.
You can submit requests using the contact details in ARTICLE I. We may need to verify your identity before fulfilling a request.
11.3Limits and Exceptions.
Your rights are not absolute. We may refuse or limit requests where permitted by law, such as where fulfilling a request would impair others’ rights or conflict with legal obligations.
11.4Right to Lodge a Complaint.
You have the right to lodge a complaint with your supervisory authority. In Slovakia, this is generally the Office for Personal Data Protection of the Slovak Republic (Urad na ochranu osobnych udajov Slovenskej republiky). You may also lodge a complaint in the EU member state of your habitual residence or place of work, as permitted by GDPR.
ARTICLE XII. CHILDREN’S DATA
12.1Not Intended for Children.
The Services are intended for adults and professional users. We do not knowingly collect personal data from children without valid legal basis.
12.2If You Believe a Child Has Provided Data.
If you believe a child has provided personal data to us, contact us. We will investigate and take appropriate steps, including deletion where required.
ARTICLE XIII. THIRD-PARTY WEBSITES, APP STORES, AND SOCIAL MEDIA
13.1Third-Party Links.
The Services may contain links to third-party sites. We are not responsible for their privacy practices. Review their privacy policies before providing data.
13.2App Stores.
If you download the App via an app store, the app store may process certain data as an independent controller. Their processing is governed by their policies. The App is currently expected to be branded as “Surplus”, though the name may change from time to time.
13.3Stripe.
Stripe processes payment data. Stripe’s privacy practices apply to the payment transaction. We encourage you to review Stripe’s privacy notices.
13.4GroupApp.
GroupApp provides platform infrastructure. Depending on the setup, GroupApp may process certain data to provide the platform. Where GroupApp acts as our processor, it is bound by contractual protections.
ARTICLE XIV. AUTOMATED DECISION-MAKING AND PROFILING
14.1No Automated Decisions With Legal Effects.
We do not intend to use automated decision-making that produces legal effects or similarly significant effects on you.
14.2Security and Fraud Signals.
We may use automated tools to detect suspicious access patterns (for example, repeated failed logins or unusual device activity) to protect accounts and Content. Such measures may result in temporary security restrictions. You may contact us if you believe a restriction was applied in error.
ARTICLE XV. CHANGES TO THIS PRIVACY POLICY
15.1Updates.
We may update this Policy to reflect changes in the Services, legal requirements, or processing practices. The “Last updated” date will be revised.
15.2Material Changes.
If changes materially affect your rights or how we process data, we will provide additional notice where appropriate, such as via the Website, App, or email.
15.3Continued Use.
Continued use of the Services after an update becomes effective indicates acknowledgment of the updated Policy, subject to any consent requirements under applicable law.
ARTICLE XVI. PRACTICAL SUMMARY
16.1What We Collect (Core).
Name, email, job position, company name, subscription and payment status details, plus technical and usage data needed to operate and secure the Services.
16.2Why We Collect It.
To provide the membership platform, manage subscriptions, deliver content (including offline access), support users, secure the platform, improve performance, and comply with law.
16.3Who We Share With.
Primarily service providers such as Stripe and GroupApp, plus hosting and support providers, only as necessary. We do not sell personal data.
16.4Your Rights.
You can access, correct, delete (in certain cases), object, and request portability of your data, and complain to a supervisory authority.
ARTICLE XVII. CONTACT FOR PRIVACY REQUESTS
17.1Contact.
For privacy requests or questions, contact:
(a) Email: hello@surplusfoodstudio.com
17.2Response Time.
We aim to respond within GDPR timeframes (typically one month), subject to verification and complexity.