Last updated: 14 June 2026
This Privacy Policy explains how Denha Nexus s.r.o. ("Tsoden", "we", "us", "our") collects, uses, shares and protects personal data in connection with the Tsoden revenue-readiness audit service, our website at https://quicko.tsoden.ai, and our business-to-business (B2B) outreach. We have written it to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR and Data Protection Act 2018, the ePrivacy Directive / PECR, and applicable Slovak data-protection law (Act No. 18/2018 Coll. on the Protection of Personal Data).
It should be read together with our Terms of Service, our Disclaimer, our Audit Practices page, and our Anti-Spam & Outreach Policy.
The controller responsible for your personal data is:
We have assessed that we are not legally required to appoint a Data Protection Officer (DPO) under Article 37 GDPR, because our core activities do not consist of large-scale processing of special-category data or large-scale systematic monitoring of individuals. You can nevertheless raise any privacy matter with us at the contact above. If our processing changes such that a DPO becomes mandatory, we will appoint one and update this section.
This policy covers personal data we process in three contexts:
Most data we handle is role-based business contact data (for example, a company role-based email such as info@ or contact@, a company address, and a publicly listed business website) — we prioritise role inboxes over personal mailboxes wherever possible. Where business contact data identifies or relates to an identifiable individual (for example, a named person at a small business), it is treated as personal data and protected accordingly.
| Category | Examples | Source |
|---|---|---|
| Business contact data | Business name, business email address, business website URL, business postal address/location, business phone, country/market | Public sources only: the business's own public website, OpenStreetMap, public business registries, and public listings such as Hacker News / Product Hunt |
| Audit input data | The website URL submitted for audit (by us or by the user), and the publicly available content of that homepage | Submitted by the user, or derived from the public contact data above |
| Audit / report data | The generated revenue-readiness score and recommendations, and (for paid services) the verified findings | Generated by our automated analysis of public pages |
| Site-visitor technical data | IP address, approximate location, browser/user-agent, pages viewed, the check/audit you ran, timestamps | Collected automatically when you use our website |
| Email engagement data | Whether an email was delivered, opened, or its links clicked; bounce/complaint signals; opt-out status | Collected via our email service provider (Resend) using a tracking pixel and link wrapping, and via a webhook |
| Customer & billing data | Name, billing email, country, transaction and subscription records, the services purchased | Provided by you when you buy a paid service; payment-card data is handled by Stripe, not stored by us |
| Correspondence | Emails and messages you send us, including opt-out / "stop" requests and data-rights requests | Provided by you |
We do not intentionally collect special categories of personal data (Article 9 GDPR) and we ask you not to send them to us. We do not access any non-public, password-protected, or access-controlled data; see our Audit Practices page.
Under Article 6 GDPR we rely on the following lawful bases:
We send a limited volume of plain-text, individually relevant emails to business addresses to introduce our free audit. We rely on our legitimate interests in promoting our business to other businesses. As required by Article 6(1)(f) and Recital 47, we have carried out a legitimate-interests assessment (LIA) using the three-part test:
You have the right to object to this processing at any time (Article 21). For direct marketing, your objection is absolute: we will stop immediately and suppress your address. See section 7 and our Anti-Spam & Outreach Policy. Where local law (for example, ePrivacy/PECR rules on corporate vs. individual subscribers, or stricter national rules) requires a different basis or prior consent for a given recipient, we follow that stricter rule for that recipient.
When you request an audit or browse the site, we process the submitted URL, the report we generate, and basic technical/visitor data to deliver the service you asked for, to operate and secure the site, and to prevent abuse. Our legitimate interest is in providing and protecting a functioning service. Strictly necessary processing of this kind is balanced against your interests and limited to what the service requires.
When you purchase a one-off audit, a 48-hour fix pack, or monthly monitoring, we process your customer and billing data to perform that contract, take payment, and deliver and support the service.
We process delivery/open/click events to understand whether our emails reach and interest recipients, to manage deliverability, to honour opt-outs, and to suppress bounced or complaining addresses. Where the applicable ePrivacy rules require consent for tracking technologies (for example certain cookies or device-storage), we obtain consent as described in section 10.
We process certain data to comply with legal obligations such as tax, accounting, and responding to lawful requests, and to keep a suppression list (which is itself a compliance measure required to honour opt-outs).
We do not sell your personal data and we do not share it for others' independent marketing. We use the following service providers (sub-processors), each bound by a data-processing agreement and acting on our instructions:
| Provider | Purpose | Data involved |
|---|---|---|
| Resend | Sending email and measuring delivery/opens/clicks | Recipient email, message content, engagement events |
| Stripe | Payment processing for paid services | Billing details, transaction data (card data handled directly by Stripe) |
| OpenAI | Generating and translating audit/report and content text | Audit input (public page content/URL) and generated text; we do not send special-category data |
| Our hosting provider | Hosting the website, application, and data storage | All service data in transit/at rest on our infrastructure |
We may also disclose data where required by law, to enforce our Terms, to protect our rights, safety, or property, or in connection with a corporate transaction (merger, acquisition, or asset sale), in which case we will require the recipient to honour this policy.
Some of our sub-processors (for example Stripe and OpenAI) are based in, or process data in, the United States or other countries outside the EEA/UK. Where personal data is transferred outside the EEA or UK, we rely on an appropriate safeguard under Chapter V GDPR, namely:
You can request information about the specific safeguard relied on for a given transfer by contacting support@tsoden.ai.
Subject to the conditions in the GDPR/UK GDPR, you have the right to:
How to exercise your rights: email support@tsoden.ai, or use the one-click unsubscribe link (for marketing) or reply "stop" to any email. We respond within one month (extendable by two further months for complex requests, with notice). We may need to verify your identity. Exercising your rights is free unless a request is manifestly unfounded or excessive.
Our records are stored on an append-only basis for integrity; "deletion" on an append-only store is implemented by suppression/anonymisation and removal from active use so the data is no longer accessible or usable.
We apply appropriate technical and organisational measures under Article 32, including encryption in transit (TLS), access controls and least-privilege access, reputable sub-processors bound by DPAs, minimisation (we collect only what we need and do not collect non-public data), and monitoring. No method of transmission or storage is perfectly secure, but we work to protect your data and will notify you and the competent supervisory authority of a personal-data breach where legally required.
On our website we use only the cookies/storage necessary to operate the site, plus any analytics we describe in a cookie notice; where consent is legally required, we request it before setting non-essential cookies and you can withdraw it at any time. In our emails we use a tracking pixel and link wrapping (via Resend) to measure delivery, opens and clicks, as described in section 4.4. You can prevent open-tracking by disabling remote images in your email client, and you can opt out of all our emails at any time.
Our service is a B2B service intended for businesses and is not directed to children. We do not knowingly process the personal data of children under 16. If you believe a child's data has been provided to us, contact support@tsoden.ai and we will delete it.
The audit score is produced by automated analysis of public web pages. It is an informational estimate about a website, not a decision that produces legal or similarly significant effects about an individual, and it does not involve profiling of individuals. See our Disclaimer.
If you have a concern, please contact us first at support@tsoden.ai so we can try to resolve it. You also have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is:
If you are in the UK you may complain to the Information Commissioner's Office (ICO); if you are elsewhere in the EEA you may complain to your local data-protection authority.
We may update this policy from time to time. We will change the "Last updated" date above and, where changes are material, take reasonable steps to notify affected individuals.
Privacy questions and data-rights requests: support@tsoden.ai. Postal: Denha Nexus s.r.o., Pekná cesta 2459/19, 831 52 Bratislava, Slovak Republic.
This document is provided for transparency. It is general information, not legal advice to you, and should be reviewed by qualified local counsel before being relied upon.