Privacy Policy
Last updated: 14 June 2026
This Privacy Policy explains how Denha Nexus s.r.o. ("Tsoden", "we", "us", "our") collects, uses, shares and protects personal data in connection with the Tsoden website check service, our website at https://quicko.tsoden.ai, and our business-to-business (B2B) outreach. We have written it to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR and Data Protection Act 2018, the ePrivacy Directive / PECR, and applicable Slovak data-protection law (Act No. 18/2018 Coll. on the Protection of Personal Data).
It should be read together with our Terms of Service, our Disclaimer, our Audit Practices page, and our Anti-Spam & Outreach Policy.
1. Who we are — the data controller
The controller responsible for your personal data is:
- Legal entity: Denha Nexus s.r.o.
- Registered address: Pekná cesta 2459/19, 831 52 Bratislava, Slovak Republic (EU)
- Brand: Tsoden
- Website: https://quicko.tsoden.ai
- Privacy / data-protection contact: support@tsoden.ai
We have assessed that we are not legally required to appoint a Data Protection Officer (DPO) under Article 37 GDPR, because our core activities do not consist of large-scale processing of special-category data or large-scale systematic monitoring of individuals. You can nevertheless raise any privacy matter with us at the contact above. If our processing changes such that a DPO becomes mandatory, we will appoint one and update this section.
2. Scope
This policy covers personal data we process in three contexts:
- (a) Outreach recipients — business contacts we email to offer the free audit.
- (b) Service users / visitors — people who request an audit on our website, view a report, or sign up for a paid service.
- (c) Email engagement — delivery, open and click events relating to emails we send.
Most data we handle is role-based business contact data (for example, a company role-based email such as info@ or contact@, a company address, and a publicly listed business website) — we prioritise role inboxes over personal mailboxes wherever possible. Where business contact data identifies or relates to an identifiable individual (for example, a named person at a small business), it is treated as personal data and protected accordingly.
3. What personal data we process, and where it comes from
| Category | Examples | Source |
|---|---|---|
| Business contact data | Business name, business email address, business website URL, business postal address/location, business phone, country/market | Public sources only: the business's own public website, OpenStreetMap, public business registries, and public listings such as Hacker News / Product Hunt |
| Audit input data | The website URL submitted for audit (by us or by the user), and the publicly available content of that homepage | Submitted by the user, or derived from the public contact data above |
| Audit / report data | The generated score and recommendations, and (for paid services) the verified findings | Generated by our automated analysis of public pages |
| Site-visitor technical data | IP address, approximate location, browser/user-agent, pages viewed, the check/audit you ran, timestamps | Collected automatically when you use our website |
| Email engagement data | Whether an email was delivered, opened, or its links clicked; bounce/complaint signals; opt-out status | Collected via our email service provider (Resend) using a tracking pixel and link wrapping, and via a webhook |
| Customer & billing data | Name, billing email, country, transaction and subscription records, the services purchased | Provided by you when you buy a paid service; payment-card data is handled by Stripe, not stored by us |
| Correspondence | Emails and messages you send us, including opt-out / "stop" requests and data-rights requests | Provided by you |
We do not intentionally collect special categories of personal data (Article 9 GDPR) and we ask you not to send them to us. We do not access any non-public, password-protected, or access-controlled data; see our Audit Practices page.
4. Why we process your data, and our lawful bases
Under Article 6 GDPR we rely on the following lawful bases:
4.1 B2B outreach — legitimate interests (Article 6(1)(f))
We send a limited volume of plain-text, individually relevant emails to business addresses to introduce our free audit. We rely on our legitimate interests in promoting our business to other businesses. As required by Article 6(1)(f) and Recital 47, we have carried out a legitimate-interests assessment (LIA) using the three-part test:
- (1) Purpose test — is there a legitimate interest? Yes. Direct marketing of relevant B2B services is expressly recognised as a legitimate interest in Recital 47 GDPR. Promoting our service to businesses that plausibly benefit from website-conversion improvements is a genuine, lawful commercial interest.
- (2) Necessity test — is the processing necessary? Yes. Contacting a business by its own published business email is a targeted and proportionate way to offer a relevant service; there is no materially less intrusive means of making a relevant business aware of it.
- (3) Balancing test — do our interests override the recipient's rights? On balance, yes, because: we contact businesses at business addresses (typically role-based), not consumers in a personal capacity; the data is already public and was published by the business for contact purposes; the content is relevant to the recipient's commercial activity; the volume is low and the intrusion minimal (a single plain email, with at most a short follow-up); we identify ourselves clearly; and we provide a one-click unsubscribe and an immediate, honoured opt-out, so the recipient retains full control. We do not profile individuals, sell data, or use the data for unrelated purposes.
You have the right to object to this processing at any time (Article 21). For direct marketing, your objection is absolute: we will stop immediately and suppress your address. See section 7 and our Anti-Spam & Outreach Policy. Where local law (for example, ePrivacy/PECR rules on corporate vs. individual subscribers, or stricter national rules) requires a different basis or prior consent for a given recipient, we follow that stricter rule for that recipient.
4.2 Providing the free audit and running our website — legitimate interests (Article 6(1)(f))
When you request an audit or browse the site, we process the submitted URL, the report we generate, and basic technical/visitor data to deliver the service you asked for, to operate and secure the site, and to prevent abuse. Our legitimate interest is in providing and protecting a functioning service. Strictly necessary processing of this kind is balanced against your interests and limited to what the service requires.
4.3 Paid services — performance of a contract (Article 6(1)(b))
When you purchase a one-off audit, a 48-hour fix pack, or monthly monitoring, we process your customer and billing data to perform that contract, take payment, and deliver and support the service.
4.4 Email engagement analytics — legitimate interests, with consent where required (Article 6(1)(f) / 6(1)(a))
We process delivery/open/click events to understand whether our emails reach and interest recipients, to manage deliverability, to honour opt-outs, and to suppress bounced or complaining addresses. Where the applicable ePrivacy rules require consent for tracking technologies (for example certain cookies or device-storage), we obtain consent as described in section 10.
4.5 Legal obligations (Article 6(1)(c))
We process certain data to comply with legal obligations such as tax, accounting, and responding to lawful requests, and to keep a suppression list (which is itself a compliance measure required to honour opt-outs).
5. Who we share data with — sub-processors and recipients
We do not sell your personal data and we do not share it for others' independent marketing. We use the following service providers (sub-processors), each bound by a data-processing agreement and acting on our instructions:
| Provider | Purpose | Data involved |
|---|---|---|
| Resend | Sending email and measuring delivery/opens/clicks | Recipient email, message content, engagement events |
| Stripe | Payment processing for paid services | Billing details, transaction data (card data handled directly by Stripe) |
| OpenAI | Generating and translating audit/report and content text | Audit input (public page content/URL) and generated text; we do not send special-category data |
| Our hosting provider | Hosting the website, application, and data storage | All service data in transit/at rest on our infrastructure |
We may also disclose data where required by law, to enforce our Terms, to protect our rights, safety, or property, or in connection with a corporate transaction (merger, acquisition, or asset sale), in which case we will require the recipient to honour this policy.
6. International data transfers
Some of our sub-processors (for example Stripe and OpenAI) are based in, or process data in, the United States or other countries outside the EEA/UK. Where personal data is transferred outside the EEA or UK, we rely on an appropriate safeguard under Chapter V GDPR, namely:
- an adequacy decision where one applies (for example transfers to providers certified under the EU–US Data Privacy Framework, and the UK extension, where applicable); or
- Standard Contractual Clauses (SCCs) approved by the European Commission (and the UK International Data Transfer Addendum for UK transfers), together with supplementary technical and organisational measures where needed.
You can request information about the specific safeguard relied on for a given transfer by contacting support@tsoden.ai.
7. Your rights
Subject to the conditions in the GDPR/UK GDPR, you have the right to:
- Access — obtain confirmation of whether we process your data and a copy of it (Article 15);
- Rectification — correct inaccurate or incomplete data (Article 16);
- Erasure — have your data deleted in certain circumstances ("right to be forgotten") (Article 17);
- Restriction — limit how we use your data in certain circumstances (Article 18);
- Portability — receive data you provided in a structured, machine-readable format, and have it transmitted to another controller where technically feasible (Article 20);
- Object — object to processing based on legitimate interests, including an absolute right to object to direct marketing, in which case we stop immediately (Article 21);
- Withdraw consent — where we rely on consent, withdraw it at any time without affecting prior processing (Article 7(3));
- Not be subject to solely automated decisions producing legal or similarly significant effects (Article 22). Note: our audit score is an informational estimate and is not a decision that produces legal or similarly significant effects about you.
How to exercise your rights: email support@tsoden.ai, or use the one-click unsubscribe link (for marketing) or reply "stop" to any email. We respond within one month (extendable by two further months for complex requests, with notice). We may need to verify your identity. Exercising your rights is free unless a request is manifestly unfounded or excessive.
8. How long we keep data (retention)
- Outreach contact data & audit results: kept while the contact may be relevant to our outreach and for a reasonable period thereafter, and reviewed periodically; deleted or anonymised when no longer needed, unless you object/opt out sooner.
- Suppression / opt-out list: retained indefinitely on a minimised basis (email address and opt-out flag only) because we must keep it to ensure we do not contact you again — this is a compliance record, not marketing use.
- Site-visitor & engagement logs: retained for a limited period for security, abuse-prevention and analytics, then deleted or aggregated.
- Customer & billing records: retained for the duration of the service and for as long as required by tax/accounting law (commonly up to 10 years under Slovak law), then deleted.
Our records are stored on an append-only basis for integrity; "deletion" on an append-only store is implemented by suppression/anonymisation and removal from active use so the data is no longer accessible or usable.
9. Security
We apply appropriate technical and organisational measures under Article 32, including encryption in transit (TLS), access controls and least-privilege access, reputable sub-processors bound by DPAs, minimisation (we collect only what we need and do not collect non-public data), and monitoring. No method of transmission or storage is perfectly secure, but we work to protect your data and will notify you and the competent supervisory authority of a personal-data breach where legally required.
10. Cookies, tracking pixels and similar technologies
On our website we use only the cookies/storage necessary to operate the site, plus any analytics we describe in a cookie notice; where consent is legally required, we request it before setting non-essential cookies and you can withdraw it at any time. In our emails we use a tracking pixel and link wrapping (via Resend) to measure delivery, opens and clicks, as described in section 4.4. You can prevent open-tracking by disabling remote images in your email client, and you can opt out of all our emails at any time.
11. Children
Our service is a B2B service intended for businesses and is not directed to children. We do not knowingly process the personal data of children under 16. If you believe a child's data has been provided to us, contact support@tsoden.ai and we will delete it.
12. Automated processing
The audit score is produced by automated analysis of public web pages. It is an informational estimate about a website, not a decision that produces legal or similarly significant effects about an individual, and it does not involve profiling of individuals. See our Disclaimer.
13. Complaints and supervisory authority
If you have a concern, please contact us first at support@tsoden.ai so we can try to resolve it. You also have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is:
- Úrad na ochranu osobných údajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic)
- Hraničná 12, 820 07 Bratislava 27, Slovak Republic
- Website: dataprotection.gov.sk
If you are in the UK you may complain to the Information Commissioner's Office (ICO); if you are elsewhere in the EEA you may complain to your local data-protection authority.
14. Changes to this policy
We may update this policy from time to time. We will change the "Last updated" date above and, where changes are material, take reasonable steps to notify affected individuals.
15. Contact
Privacy questions and data-rights requests: support@tsoden.ai. Postal: Denha Nexus s.r.o., Pekná cesta 2459/19, 831 52 Bratislava, Slovak Republic.
This document is provided for transparency. It is general information, not legal advice to you, and should be reviewed by qualified local counsel before being relied upon.