PRIVACY POLICY
of the Gift Podcast service
of the company XPE Group s.r.o., ID: 17179173,
with registered office at Ve Smečkách 595/28, Nové Město, 110 00 Prague 1,
registered in the Commercial Register administered by the Municipal Court in Prague
under file no. C 367791
OPENING PROVISIONS
The protection of personal data is a priority for us. We have prepared this Privacy Policy to inform you, as a user of the Gift Podcast platform (giftpodcast.com) — whether in the role of buyer (Buyer) or recipient of the gift (Recipient) — about how XPE Group s.r.o. (also referred to as the “Company”, the “Controller”, or “we”) obtains, stores, protects, and further processes your personal data in connection with the provision of the Gift Podcast service and related activities.
Because our service involves the processing of voice data of Recipients, which is inherently sensitive, we pay particular attention to its protection and to keeping retention times as short as possible. Audio data is permanently and irrevocably deleted no later than 64 days from the completion of the conversation.
We process your personal data for the purposes set out in this Privacy Policy, in particular for the performance of contractual obligations, the fulfilment of legal obligations, and on the basis of explicit consents that you have granted to us.
Through this Privacy Policy we want to inform you about how we process your personal data, who our processors are, how long we retain the data, and about your rights and how you can exercise them.
We recommend that you read this Privacy Policy carefully. If you have any questions, you can contact us at any time using the contact details set out below.
PERSONAL DATA CONTROLLER AND CONTACT DETAILS
The controller of your personal data is XPE Group s.r.o., with its registered office at Ve Smečkách 595/28, Nové Město, 110 00 Prague 1, registered in the Commercial Register maintained by the Municipal Court in Prague under file no. C 367791, ID: 17179173.
Contact details of the Controller for any matters relating to personal data protection are:
Address: XPE Group s.r.o., Ve Smečkách 595/28, Nové Město, 110 00 Prague 1, Czech Republic
Email: [email protected]
Up-to-date contact details (including any data protection officer, where appointed) are also published on the Platform at www.giftpodcast.com.
CATEGORIES OF DATA SUBJECTS AND CATEGORIES OF PROCESSED DATA
In connection with the provision of the service, we process data of the following categories of data subjects:
(a) Buyer (purchaser of the Gift Link)
The Buyer is the person who pays the price via the Platform and receives the Gift Link. We process the following categories of data about the Buyer in particular:
- identification data: first name and last name;
- contact details: email address and any other contact information that the Buyer voluntarily provides;
- transactional and billing data: order identifier, date and amount of payment, payment method; we do not process payment card numbers or bank account details ourselves — these are processed exclusively by our payment service provider (in particular Stripe);
- technical data: IP address, browser and device data, activity on the Platform, server logs;
- communication content: the content of your emails or other communications you send us in connection with the service.
(b) Recipient (participant in the conversation)
The Recipient is the person who, on the basis of the Gift Link, takes part in the conversation with the AI host. We process the following categories of data about the Recipient in particular:
- identification data: first name and/or nickname, where the Recipient provides them to the Buyer or via the Platform;
- contact details: email address, where provided by the Recipient (e.g. to deliver the link to the Recording);
- voice and audio data: the audio recording of the conversation with the AI host (the “Recording”); biometric voice characteristics are processed in real time by the conversational AI provider (ElevenLabs, Inc.) during the conversation only and are not used for the purpose of unique identification of a natural person within the meaning of Article 9(1) GDPR;
- content of statements: the transcript and content shared by the Recipient during the conversation (personal memories, life stories, relationships, etc.); in some cases this may include data of special categories within the meaning of Article 9 GDPR (e.g. health information, religious beliefs, sexual orientation), provided that the Recipient voluntarily shares such information;
- technical data: IP address, device and browser data, timestamps, and metadata about the conversation.
The selection of topics by the Recipient before the conversation begins, and the content shared during the conversation, are entirely voluntary. The Recipient may pause or end the conversation at any time.
(c) Visitor using the free demonstration
A visitor to the Platform may try a short demonstration conversation with the AI host without buying anything and without creating an account. We process the following data about such a Visitor:
- voice data: the visitor's speech is processed in real time by our processor ElevenLabs, Inc. solely in order to conduct the conversation. The demonstration is configured so that no audio recording and no transcript is retained, neither by us nor by the processor, and nothing is linked to any gift or order;
- technical data: the visitor's IP address, processed briefly and only to limit how many free demonstrations can be started from one connection (abuse prevention).
Legal basis: steps taken at the request of the data subject prior to entering into a contract (Article 6(1)(b) GDPR) and our legitimate interest in preventing abuse of a free service (Article 6(1)(f) GDPR).
PURPOSES OF PROCESSING AND LEGAL BASES
We process your personal data for the following purposes and on the following legal bases (Article 6 GDPR, and for special categories of data Article 9(2) GDPR):
Performance of the contract and provision of the service. Processing of data of the Buyer and the Recipient necessary to conclude the contract, deliver the Gift Link, conduct the conversation with the AI host, create the Recording, and make it available to the entitled persons. Legal basis: performance of the contract (Article 6(1)(b) GDPR); for the Recipient also legitimate interest in providing the service to the third party for whose benefit the contract was concluded (Article 6(1)(f) GDPR).
Processing of voice data and conversation content. Recording, processing, and storage of the Recording. Legal basis: performance of the contract (Article 6(1)(b) GDPR) together with the Recipient’s explicit consent granted via browser microphone permission and the click of the start button (Article 6(1)(a) GDPR); for any special-category data the Recipient voluntarily shares during the conversation, the legal basis is the Recipient’s explicit consent within the meaning of Article 9(2)(a) GDPR.
Accounting and tax obligations. Issuance and retention of invoices, payment records, and related accounting documents. Legal basis: compliance with a legal obligation of the Controller (Article 6(1)(c) GDPR), in particular under the Czech Accounting Act and the VAT Act; the statutory retention period may be up to 10 years.
Handling of complaints and requests. Processing of data contained in customer complaints or requests. Legal basis: performance of the contract and compliance with legal obligations.
Establishment, exercise, and defence of legal claims. After the end of the contractual relationship, we may retain certain data (in particular transactional data and the content of communications) for the duration of the relevant limitation periods to defend against potential claims. Legal basis: legitimate interest (Article 6(1)(f) GDPR).
Security of the Platform and prevention of abuse. Processing of technical data (logs, IP addresses) to prevent fraud, system attacks, and misuse of the service. Legal basis: legitimate interest (Article 6(1)(f) GDPR).
Marketing communications. If the Buyer grants us explicit consent (e.g. when placing an order or registering), we may use their contact details to send information about our services and news. Legal basis: consent (Article 6(1)(a) GDPR), which can be withdrawn at any time. If the Buyer has already used the service, we may also send communications about similar services on the basis of legitimate interest (Section 7(3) of Czech Act No. 480/2004 Coll.); the Buyer always has the right to unsubscribe free of charge.
Unfinished orders. If you begin an order and provide your email address without completing the purchase, we may send you up to two reminder messages about that unfinished order, the second of which may contain a personal discount. Legal basis: our legitimate interest in completing a transaction you started (Article 6(1)(f) GDPR). Every such message contains a one-click unsubscribe link, which we honour permanently and immediately.
SPECIAL NOTE ON VOICE DATA
Given the heightened sensitivity of voice recordings, we have implemented the following measures:
- voice data of the Recipient is streamed in real time to our processor — ElevenLabs, Inc. (the conversational AI provider, USA) — which processes the input via API and generates the AI host’s responses; under our contractual integration with this processor, and to the extent technically possible, we have opted out of the use of conversation content for training the foundation models of such processor. The conversational AI provider retains the conversation recording after the call so that we can produce the finished episode; we delete that copy from the provider once the episode has been archived in our own storage, and in any event during the retention purge described below;
- the resulting Recording is stored in encrypted form on Cloudflare R2 cloud storage (provider: Cloudflare, Inc., region Eastern North America);
- access to the Recording is granted only to the Buyer and the Recipient via an unlisted link;
- after the expiry of 30 days from the completion of the conversation, the Recording moves into an unavailable state (soft-delete) and no later than 64 days from the completion of the conversation it is permanently and irrevocably deleted from all of our servers and storage (hard-delete);
- the Recipient may at any earlier point request immediate deletion of the Recording by contacting the Controller at [email protected].
RECIPIENTS OF PERSONAL DATA (PROCESSORS)
To fulfil the purposes set out above, we use carefully selected processors with whom we have entered into data processing agreements pursuant to Article 28 GDPR. The current list of our main processors:
- ElevenLabs, Inc. (USA) — conversational AI provider; operation of the AI host and real-time processing of voice data. Transfers outside the EEA are safeguarded by Standard Contractual Clauses (SCCs) under Article 46(2)(c) GDPR and, to the extent ElevenLabs is certified under the EU-US Data Privacy Framework, by an adequacy decision of the European Commission under Article 45 GDPR;
- Cloudflare, Inc. (USA) — Cloudflare R2 cloud storage where Recordings and related technical data are stored (region Eastern North America). Transfers outside the EEA are safeguarded by SCCs and, where Cloudflare is certified, by the EU-US Data Privacy Framework adequacy decision;
- Sevalla (Kinsta Inc., USA) — hosting and database platform; operation of the application layer and database (PostgreSQL, region us-east4 — Ashburn, Virginia). Sevalla runs on Google Cloud Platform infrastructure (Google LLC). Transfers outside the EEA are safeguarded by SCCs and the EU-US Data Privacy Framework adequacy decision under which Google and other subprocessors are certified;
- Stripe Payments Europe, Limited (Ireland) — payment processing; payment card and bank account data is processed by Stripe in its own capacity as a controller in respect of its financial-regulatory obligations. Processing takes place within the EEA and no further transfer safeguards are required;
- Brevo SA (France) — transactional email provider; sending order confirmations, the Gift Link, the reminder to download the Recording, and marketing communications. Processing takes place within the EEA and no further transfer safeguards are required;
- TikTok Technology Limited (Ireland) — advertising measurement; receives page and purchase events from the TikTok pixel and, for paid orders, a hashed form of the Buyer's email address. Processing takes place within the EEA, with any onward transfer safeguarded by Standard Contractual Clauses;
- Functional Software, Inc. (Sentry, USA) — technical error monitoring; receives error reports from the Platform, configured to exclude IP addresses, cookies and request contents. Transfers outside the EEA are safeguarded by Standard Contractual Clauses;
- External providers of IT, legal, tax, and accounting services — only to the extent necessary for the performance of their contractual role and always under confidentiality obligations.
We may also disclose data to public authorities where we are required to do so by law (e.g. in connection with cooperation with law-enforcement bodies, tax authorities, or courts).
We will provide you with an up-to-date detailed list of our processors upon request via the contact details set out in the section “Personal data controller and contact details”.
INTERNATIONAL DATA TRANSFERS OUTSIDE THE EEA
Some of our processors — specifically ElevenLabs, Inc. (conversational AI provider), Cloudflare, Inc. (Cloudflare R2 cloud storage), and Sevalla / Google LLC (hosting and database platform) — process personal data in the United States. Our other main processors (Stripe Payments Europe, Brevo SA) process data within the European Economic Area.
In such cases, transfers are safeguarded by one of the mechanisms set out in Chapter V GDPR, in particular:
- a European Commission adequacy decision under Article 45 GDPR (e.g. UK Adequacy Decision; the EU-US Data Privacy Framework, where the processor is certified under it);
- Standard Contractual Clauses (SCCs) approved by the European Commission under Article 46(2)(c) GDPR, supplemented where necessary by additional measures (transfer impact assessment);
- Binding Corporate Rules (BCR), where applied by the relevant processor.
A copy of, or information about, the safeguards used will be provided to you on request sent to [email protected].
RETENTION PERIODS
We retain your data only for as long as necessary for the purposes for which it was collected, or for as long as required by law:
- voice data and conversation content (the Recording): no later than 64 days from completion of the conversation, after which it is irrevocably deleted; in the meantime, the Recording moves into an unavailable state on day 30 (soft-delete);
- order and Gift Link data: for the validity period of the Gift Link (max. 1 year), and for as long as necessary to settle rights and obligations under the contract;
- accounting and tax documents: for the period required by Czech tax and accounting law, typically up to 10 years;
- data needed for the establishment, exercise, and defence of legal claims: for the duration of the relevant limitation periods;
- marketing data (based on consent): until the consent is withdrawn or the Buyer unsubscribes;
- logs and technical data: typically for 12 months, unless a longer period is justified by security or incident-investigation needs.
Once the relevant retention period expires, we delete or anonymise your data so that you can no longer be identified.
DATA SECURITY
We have implemented and maintain appropriate technical and organisational measures, internal controls, and information security processes designed to protect your personal data against accidental loss, destruction, alteration, unauthorised disclosure, or access. These measures include in particular:
- encryption of data in transit (TLS) and encryption of Recordings at rest;
- access management based on the least-privilege principle and multi-factor authentication for administrator accounts;
- separation of production, testing, and development environments;
- regular backups and procedures for data recovery and security incident management;
- contractual confidentiality obligations and training of persons with access to the data.
In the event of a personal data breach that is likely to result in a high risk to the rights and freedoms of data subjects, we will inform you without undue delay in accordance with Articles 33 and 34 GDPR.
YOUR RIGHTS AS A DATA SUBJECT
In accordance with applicable law, you have the right:
- to access your personal data (Article 15 GDPR), i.e. to obtain information about whether and which data we process about you, and to receive a copy;
- to rectification of inaccurate or incomplete data (Article 16 GDPR);
- to erasure (“right to be forgotten” — Article 17 GDPR), in particular where the data is no longer necessary for the original purpose, where you have withdrawn consent, or where we have processed it unlawfully;
- to restriction of processing (Article 18 GDPR);
- to data portability of data you have provided to us and which we process on the basis of contract or consent (Article 20 GDPR);
- to object to processing based on legitimate interest or for direct marketing purposes (Article 21 GDPR);
- not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you (Article 22 GDPR); we clarify that, although our service uses automated processing (the AI host), it does not produce automated decisions with legal effects on the Recipient;
- to withdraw any consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
- to lodge a complaint with the supervisory authority (see below).
You can exercise your rights by sending an email to [email protected] or a letter to the Controller’s registered address. To verify your identity, we may request additional information. We will respond to your request without undue delay, and no later than one (1) month from its receipt; this period may be extended by a further two (2) months in justified cases.
If you exercise your right to erasure of the Recording, we will delete it without undue delay, including from our processors, except for data we are required to retain by law (e.g. tax records).
CHILDREN
The gift may be given to a Recipient of any age, including a child. Where the Recipient is a child under the age of 13, or under the age of digital consent applicable in their country if that age is higher, the interview must be arranged and set up by their parent or legal guardian, who must remain present for it and who consents to the processing described in this Privacy Policy on the child's behalf. By arranging the gift, the Buyer confirms that they hold that authority or that the parent or legal guardian has given that consent.
We do not knowingly process a child's voice recording without such consent. A parent or legal guardian may at any time ask us what we hold about their child, obtain a copy of the Recording, or have it deleted immediately, by contacting us at [email protected]. We act on such a request without undue delay and in any case within 30 days. We do not use children's data for advertising, profiling or any form of automated decision-making, and we never sell personal data.
COMPLAINT TO THE OFFICE FOR PERSONAL DATA PROTECTION
You have the right to file a complaint regarding our processing of your personal data with the Czech Office for Personal Data Protection, with its registered office at Pplk. Sochora 27, 170 00 Prague 7, website: www.uoou.gov.cz.
COOKIES AND SIMILAR TECHNOLOGIES
On the Platform www.giftpodcast.com we use strictly necessary cookies that are required for the basic functioning of the service (in particular for maintaining the session, securing the order flow, and protecting against abuse). These cookies do not require your consent under applicable law.
For measuring our advertising we use the TikTok pixel and the TikTok Events API (TikTok Technology Limited), which set cookies and receive usage events such as page views and completed purchases. For paid orders we transmit a hashed (SHA-256) form of the Buyer's email address to TikTok so that the purchase can be attributed to the advertisement that led to it; TikTok does not receive the address in readable form from us. We further store advertising click identifiers (such as gclid, ttclid, fbclid and utm parameters) and a random visitor identifier in your browser's local storage for up to 90 days, for the same attribution purpose. For technical error monitoring we use Sentry (Functional Software, Inc.), configured so that it does not receive IP addresses, cookies or request contents.
The legal basis for these advertising and monitoring technologies is our legitimate interest in measuring and improving our advertising and in keeping the service reliable (Article 6(1)(f) GDPR). You may object to this processing at any time using the contact details above, and you can prevent these technologies from running by using your browser's tracking protection or an ad blocker.
UPDATES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time, in particular when there are changes to the scope of processing, the processors used, or applicable law. The current version is always published on the Platform with the effective date. We will inform you of any material changes in an appropriate manner (e.g. by email or by notice on the Platform).
This Privacy Policy takes effect on 7 May 2026, as amended on 9 August 2026.
In Prague.
XPE Group s.r.o.
Daniel Izák, Managing Director