Privacy Policy

Last updated: 19 June 2026

Version Two s.r.o. takes the protection of your personal data seriously. This document explains what personal data we collect, for what purposes we use it, with whom we share it, and what rights you have regarding its processing. We process data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Slovak data protection law.

Data Controller

The data controller is Version Two s.r.o., registered in the Slovak Republic, company ID: [Company ID], entered in the Commercial Register of the Slovak Republic (hereinafter "we" or "the controller"). Contact e-mail: info@versiontwo.sk. Website: https://www.versiontwo.sk.

Personal Data We Process

We process the following categories of personal data: (a) Account data – name, e-mail address, and hashed password provided during registration. (b) Organisation data – organisation name and business sector. (c) CRM data – contacts, leads, deals, notes, and communication records entered by you or your users; you are responsible as a controller for the lawfulness of processing this data in relation to your own contacts. (d) Technical logs – IP address, browser user-agent, login timestamps, and security audit logs for monitoring purposes. (e) Payment data – card numbers are stored exclusively by Stripe, Inc.; we only see the last four digits, card type, and expiry date. (f) Cookies – see our Cookie Policy for details.

Legal Bases for Processing

We process your personal data on the following legal bases: (a) Performance of a contract (Art. 6(1)(b) GDPR) – processing necessary to provide the EasyCRM service under the contract entered into at registration. (b) Legitimate interests (Art. 6(1)(f) GDPR) – system security, fraud detection, abuse prevention, and service improvement; our legitimate interests outweigh the data subjects' interests given the proportionate and transparent nature of the processing. (c) Consent (Art. 6(1)(a) GDPR) – analytics cookies and marketing communications, where you have given explicit consent; consent may be withdrawn at any time. (d) Legal obligation (Art. 6(1)(c) GDPR) – retention of accounting records and invoices under applicable Slovak law.

Purposes of Processing

We process your personal data for the following purposes: (a) Providing and managing the EasyCRM SaaS service – creating and administering your tenant account and enabling access to CRM features. (b) Subscription management and billing – processing payments via Stripe, issuing invoices, and managing plans. (c) Customer communication – sending technical notifications, security alerts, and notices of changes to terms. (d) Product improvement and development – analysing anonymised usage patterns to enhance functionality. (e) Compliance with legal obligations – fulfilling requirements under tax and accounting legislation.

Recipients and Processors

We may share your personal data with the following recipients and processors: (a) Stripe, Inc. (USA) – payment processing; a Data Processing Agreement (DPA) is in place; transfers to the USA are based on EU Standard Contractual Clauses (SCCs) approved by the European Commission. (b) Hosting and infrastructure providers – servers located exclusively within the European Union; access is restricted to essential technical operations. (c) Communication tool providers – SMTP e-mail providers, VoIP providers (e.g. VipTEL), or other integrations activated by your organisation; these providers process data under their own policies, of which you are informed at the point of activation. (d) Internal employees – access is granted only to authorised staff on a need-to-know basis. We do not sell your personal data to third parties.

Retention Periods

We retain your personal data for the following periods: (a) Account data and CRM data – for the duration of the contract and for 30 days after cancellation, during which you may export your data; after this period data is permanently deleted. (b) Billing records and accounting documents – 10 years from the date of issue, in accordance with accounting legislation. (c) Security audit logs – 12 months from the date of the logged event. (d) Backups – a maximum of 90 days from the date the backup was created.

Your Rights

As a data subject you have the following rights under the GDPR: (a) Right of access (Art. 15) – you have the right to obtain confirmation of whether we process your personal data and, if so, to access it. (b) Right to rectification (Art. 16) – you have the right to have inaccurate or incomplete personal data corrected. (c) Right to erasure (Art. 17) – you have the right to request deletion of your personal data where the purpose of processing has ceased or you have withdrawn consent. (d) Right to restriction of processing (Art. 18) – you have the right to request a temporary restriction on the processing of your data. (e) Right to data portability (Art. 20) – you have the right to receive your data in a structured, commonly used, and machine-readable format. (f) Right to object (Art. 21) – you have the right to object to processing based on legitimate interests. You may lodge a complaint with the Office for Personal Data Protection of the Slovak Republic (www.dataprotection.gov.sk). To exercise your rights, please write to us at info@versiontwo.sk.

International Transfers

We transfer personal data to third countries outside the EU/EEA only in connection with payments processed by Stripe, Inc. (USA), and exclusively on the basis of EU Standard Contractual Clauses (SCCs) under Art. 46 GDPR, which ensure an adequate level of protection. All other data is stored and processed solely on servers within the European Union. We do not carry out any other transfers to third countries.

Contact

If you have questions about the processing of your personal data, please write to us at info@versiontwo.sk.