Privacy Policy

Last updated: 14 June 2026

This Privacy Policy explains how Denha Nexus s.r.o. ("Tsoden", "we", "us", "our") collects, uses, shares and protects personal data in connection with the Tsoden revenue-readiness audit service, our website at https://quicko.tsoden.ai, and our business-to-business (B2B) outreach. We have written it to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR and Data Protection Act 2018, the ePrivacy Directive / PECR, and applicable Slovak data-protection law (Act No. 18/2018 Coll. on the Protection of Personal Data).

It should be read together with our Terms of Service, our Disclaimer, our Audit Practices page, and our Anti-Spam & Outreach Policy.

1. Who we are — the data controller

The controller responsible for your personal data is:

We have assessed that we are not legally required to appoint a Data Protection Officer (DPO) under Article 37 GDPR, because our core activities do not consist of large-scale processing of special-category data or large-scale systematic monitoring of individuals. You can nevertheless raise any privacy matter with us at the contact above. If our processing changes such that a DPO becomes mandatory, we will appoint one and update this section.

2. Scope

This policy covers personal data we process in three contexts:

Most data we handle is role-based business contact data (for example, a company role-based email such as info@ or contact@, a company address, and a publicly listed business website) — we prioritise role inboxes over personal mailboxes wherever possible. Where business contact data identifies or relates to an identifiable individual (for example, a named person at a small business), it is treated as personal data and protected accordingly.

3. What personal data we process, and where it comes from

CategoryExamplesSource
Business contact data Business name, business email address, business website URL, business postal address/location, business phone, country/market Public sources only: the business's own public website, OpenStreetMap, public business registries, and public listings such as Hacker News / Product Hunt
Audit input data The website URL submitted for audit (by us or by the user), and the publicly available content of that homepage Submitted by the user, or derived from the public contact data above
Audit / report data The generated revenue-readiness score and recommendations, and (for paid services) the verified findings Generated by our automated analysis of public pages
Site-visitor technical data IP address, approximate location, browser/user-agent, pages viewed, the check/audit you ran, timestamps Collected automatically when you use our website
Email engagement data Whether an email was delivered, opened, or its links clicked; bounce/complaint signals; opt-out status Collected via our email service provider (Resend) using a tracking pixel and link wrapping, and via a webhook
Customer & billing data Name, billing email, country, transaction and subscription records, the services purchased Provided by you when you buy a paid service; payment-card data is handled by Stripe, not stored by us
Correspondence Emails and messages you send us, including opt-out / "stop" requests and data-rights requests Provided by you

We do not intentionally collect special categories of personal data (Article 9 GDPR) and we ask you not to send them to us. We do not access any non-public, password-protected, or access-controlled data; see our Audit Practices page.

4. Why we process your data, and our lawful bases

Under Article 6 GDPR we rely on the following lawful bases:

4.1 B2B outreach — legitimate interests (Article 6(1)(f))

We send a limited volume of plain-text, individually relevant emails to business addresses to introduce our free audit. We rely on our legitimate interests in promoting our business to other businesses. As required by Article 6(1)(f) and Recital 47, we have carried out a legitimate-interests assessment (LIA) using the three-part test:

You have the right to object to this processing at any time (Article 21). For direct marketing, your objection is absolute: we will stop immediately and suppress your address. See section 7 and our Anti-Spam & Outreach Policy. Where local law (for example, ePrivacy/PECR rules on corporate vs. individual subscribers, or stricter national rules) requires a different basis or prior consent for a given recipient, we follow that stricter rule for that recipient.

4.2 Providing the free audit and running our website — legitimate interests (Article 6(1)(f))

When you request an audit or browse the site, we process the submitted URL, the report we generate, and basic technical/visitor data to deliver the service you asked for, to operate and secure the site, and to prevent abuse. Our legitimate interest is in providing and protecting a functioning service. Strictly necessary processing of this kind is balanced against your interests and limited to what the service requires.

4.3 Paid services — performance of a contract (Article 6(1)(b))

When you purchase a one-off audit, a 48-hour fix pack, or monthly monitoring, we process your customer and billing data to perform that contract, take payment, and deliver and support the service.

4.4 Email engagement analytics — legitimate interests, with consent where required (Article 6(1)(f) / 6(1)(a))

We process delivery/open/click events to understand whether our emails reach and interest recipients, to manage deliverability, to honour opt-outs, and to suppress bounced or complaining addresses. Where the applicable ePrivacy rules require consent for tracking technologies (for example certain cookies or device-storage), we obtain consent as described in section 10.

4.5 Legal obligations (Article 6(1)(c))

We process certain data to comply with legal obligations such as tax, accounting, and responding to lawful requests, and to keep a suppression list (which is itself a compliance measure required to honour opt-outs).

5. Who we share data with — sub-processors and recipients

We do not sell your personal data and we do not share it for others' independent marketing. We use the following service providers (sub-processors), each bound by a data-processing agreement and acting on our instructions:

ProviderPurposeData involved
ResendSending email and measuring delivery/opens/clicksRecipient email, message content, engagement events
StripePayment processing for paid servicesBilling details, transaction data (card data handled directly by Stripe)
OpenAIGenerating and translating audit/report and content textAudit input (public page content/URL) and generated text; we do not send special-category data
Our hosting providerHosting the website, application, and data storageAll service data in transit/at rest on our infrastructure

We may also disclose data where required by law, to enforce our Terms, to protect our rights, safety, or property, or in connection with a corporate transaction (merger, acquisition, or asset sale), in which case we will require the recipient to honour this policy.

6. International data transfers

Some of our sub-processors (for example Stripe and OpenAI) are based in, or process data in, the United States or other countries outside the EEA/UK. Where personal data is transferred outside the EEA or UK, we rely on an appropriate safeguard under Chapter V GDPR, namely:

You can request information about the specific safeguard relied on for a given transfer by contacting support@tsoden.ai.

7. Your rights

Subject to the conditions in the GDPR/UK GDPR, you have the right to:

How to exercise your rights: email support@tsoden.ai, or use the one-click unsubscribe link (for marketing) or reply "stop" to any email. We respond within one month (extendable by two further months for complex requests, with notice). We may need to verify your identity. Exercising your rights is free unless a request is manifestly unfounded or excessive.

8. How long we keep data (retention)

Our records are stored on an append-only basis for integrity; "deletion" on an append-only store is implemented by suppression/anonymisation and removal from active use so the data is no longer accessible or usable.

9. Security

We apply appropriate technical and organisational measures under Article 32, including encryption in transit (TLS), access controls and least-privilege access, reputable sub-processors bound by DPAs, minimisation (we collect only what we need and do not collect non-public data), and monitoring. No method of transmission or storage is perfectly secure, but we work to protect your data and will notify you and the competent supervisory authority of a personal-data breach where legally required.

10. Cookies, tracking pixels and similar technologies

On our website we use only the cookies/storage necessary to operate the site, plus any analytics we describe in a cookie notice; where consent is legally required, we request it before setting non-essential cookies and you can withdraw it at any time. In our emails we use a tracking pixel and link wrapping (via Resend) to measure delivery, opens and clicks, as described in section 4.4. You can prevent open-tracking by disabling remote images in your email client, and you can opt out of all our emails at any time.

11. Children

Our service is a B2B service intended for businesses and is not directed to children. We do not knowingly process the personal data of children under 16. If you believe a child's data has been provided to us, contact support@tsoden.ai and we will delete it.

12. Automated processing

The audit score is produced by automated analysis of public web pages. It is an informational estimate about a website, not a decision that produces legal or similarly significant effects about an individual, and it does not involve profiling of individuals. See our Disclaimer.

13. Complaints and supervisory authority

If you have a concern, please contact us first at support@tsoden.ai so we can try to resolve it. You also have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is:

If you are in the UK you may complain to the Information Commissioner's Office (ICO); if you are elsewhere in the EEA you may complain to your local data-protection authority.

14. Changes to this policy

We may update this policy from time to time. We will change the "Last updated" date above and, where changes are material, take reasonable steps to notify affected individuals.

15. Contact

Privacy questions and data-rights requests: support@tsoden.ai. Postal: Denha Nexus s.r.o., Pekná cesta 2459/19, 831 52 Bratislava, Slovak Republic.

This document is provided for transparency. It is general information, not legal advice to you, and should be reviewed by qualified local counsel before being relied upon.