GDPR Compliance
Last updated: July 2025
Our Role Under GDPR
Webito Future Tech s.r.o. (Registration Number: 232 40 911, Plzeňská 3352/156, Smíchov, 150 00 Prague 5, Czech Republic) acts as the data controller for personal data of platform users (merchants and their team members). With respect to your customers' data that you process through your Webito-powered store, Webito acts as a data processor on your behalf, and you are the data controller.
Legal Bases for Processing
We process personal data of merchants on the following legal bases: (1) Performance of a contract — to deliver the Webito platform services you have subscribed to; (2) Legitimate interests — to prevent fraud, ensure platform security, and improve our service; (3) Legal obligation — to comply with Czech and EU financial and tax record-keeping requirements; (4) Consent — for optional analytics cookies and non-essential marketing communications, which you may withdraw at any time.
Data Processing Agreement
When you process your customers' personal data through the Webito platform (for example, storing customer names, addresses, and purchase history in order management), Webito acts as your data processor. A Data Processing Agreement (DPA) that meets GDPR Article 28 requirements is available upon request at [email protected] and will be entered into with any Merchant who requires one.
Your Rights as a Data Subject
Under GDPR, individuals have the right to: access a copy of their personal data (Article 15); correct inaccurate data (Article 16); request erasure of data where there is no overriding legal obligation to retain it (Article 17); restrict processing in certain circumstances (Article 18); receive data in a portable format (Article 20); object to processing based on legitimate interests (Article 21); and not be subject to solely automated decision-making that produces legal effects (Article 22).
Exercising Your Rights
To exercise any of your GDPR rights, submit a written request to [email protected] with sufficient information to verify your identity. We will respond within 30 days. In complex cases, we may extend this period by a further 60 days with notification. There is no charge for exercising your rights unless requests are manifestly unfounded or excessive.
International Data Transfers
Webito is headquartered in the Czech Republic, an EU member state, and primarily stores and processes data within the European Economic Area. Where any data transfer occurs outside the EEA (for example, through certain cloud infrastructure or analytics sub-processors), we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.
Sub-Processors
We use a limited number of sub-processors to deliver our service, including cloud infrastructure, email delivery, and payment providers. We maintain a current list of sub-processors and notify Merchants of any additions or changes with at least 14 days' notice, giving them an opportunity to object. All sub-processors are contractually required to process data only on our documented instructions and to implement appropriate technical and organizational security measures.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Where the breach is likely to result in a high risk, we will also notify affected individuals without undue delay. As your data processor, we will notify you of any breach affecting your customers' data promptly to allow you to meet your own notification obligations.
Supervisory Authority
The supervisory authority for Webito Future Tech s.r.o. is the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů — ÚOOÚ), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, www.uoou.cz. You also have the right to lodge a complaint with the supervisory authority in your EU member state of residence.