Effective 19 September 2026

Privacy, without
the vague promises.

Who is responsible

Ganado International s.r.o., IČO 19322119, Příčná 1892/4, Nové Město, 110 00 Praha 1, Czech Republic. Contact: info@ganado.cz.

Early-access requests

We store your email address, selected operating system, selected use case, a coarse campaign source (such as GitHub or direct), consent version and signup timestamp. If you later receive an invitation or purchase access, its status may be recorded. We do not ask for payment details, local files, passwords or API keys in the signup form.

With your consent, we use these details to manage the early-access list, understand which workflows to prioritize, and email you about Ganado Bridge access. Joining does not subscribe you to accounting promotions. We do not sell this list.

Hosting and protection

Vercel hosts this website. Supabase stores the signup records in its configured EU West region. These providers process data to operate the site and database; their infrastructure and support arrangements can involve international processing under their terms. The website does not install advertising pixels or analytics cookies. Technical hosting logs may contain IP addresses, request metadata and timestamps under the hosting provider’s controls.

The signup API temporarily uses a hash of the request IP in memory for per-instance rate limiting. It does not write that value into the waitlist. We also use input validation, a honeypot and database admission limits to reduce abuse. Authorized business administrators can access the list; public visitors cannot read it.

Retention and withdrawal

Unconverted waitlist entries are retained for up to 90 days. Maintenance removes expired entries; provider backups may retain deleted data for the provider’s backup period. You can withdraw consent or request removal at any time by emailing us with the subject “Remove me from Bridge”. Withdrawal does not affect processing already performed on the basis of consent.

Your rights

Where applicable, you may request access, correction, deletion, restriction or portability of your personal data, and object to processing. You may complain to the Czech Office for Personal Data Protection (ÚOOÚ) or your competent supervisory authority. We may need proportionate verification that a request comes from the relevant email owner.

The agent is separate from the website

This website has no connection to your local machine. If you later install and authorize the agent, file contents, file paths, images and command output requested by your AI assistant are sent to that assistant through the configured transport. Local operation metadata is described on our security page. Your AI provider’s own privacy terms also apply. Product-specific processing terms will be provided before any broader hosted service is introduced.

General rights information: European Commission — data protection for individuals.

Commercial orders

When checkout is available, purchases are processed by Stripe Managed Payments through Link. Link collects the billing, contact, payment and tax information required for the transaction, provides its own privacy notice, and handles payment-related communication. Ganado receives the order information necessary to establish licence rights, reconcile payments, provide product support and process refunds. We do not receive full card numbers. Order information is processed to perform the contract and meet applicable accounting/legal obligations, not added to marketing lists without consent. Accounting records may need retention beyond the interest-list period; the 90-day waitlist limit does not apply to mandatory transaction records.

The local agent still has no automatic usage telemetry. Download requests on GitHub and merchant checkout events are not proof of installation or active use. A voluntary GitHub activation report is public; do not put personal data, device paths or private logs in it.

Aggregate website measurement

We count page views and clicks to installation, download and licence pages. The stored record contains only a UTC date, a fixed event name, an allowlisted page path, a coarse source such as GitHub, a test flag and an aggregate count. We do not store an analytics cookie, visitor identifier, device fingerprint, raw URL, referrer, email or IP address in these counters. The event API temporarily uses a hashed request IP in memory for rate limiting; it is not added to the aggregate table. Hosting providers still handle ordinary technical request metadata.

These counters cannot identify unique visitors, prove a download finished or establish product activation. Automated and self-test events are marked separately where detected. Measurement is skipped when your browser sends Do Not Track or Global Privacy Control. Aggregate buckets expire after 30 days through daily retention. You may block /api/events without preventing downloads, signup or purchase.