Privacy Policy

Effective date: 27 July 2026 · Last updated: 27 July 2026

This policy explains how the BackProve service processes personal data.

1. Who is the controller

The controller of personal data of BackProve's own users is:

Jan Brožíček · Company ID (IČO): 08764832 · Rižská 1492/2, 102 00 Prague, Czech Republic · legal@backprove.com

2. Two distinct roles of BackProve

BackProve processes personal data in two distinct roles.

2.1 BackProve as controller

BackProve is the controller of personal data of persons who create an account, order the service, communicate with support, or use the BackProve website — in particular email, account, payment, subscription, technical-log, and communication data.

2.2 BackProve as processor

BackProve is a processor in relation to the content of customers' databases and files that the customer backs up through the service. In that case the customer is the controller, or a processor for another controller. BackProve does not determine, select, or actively monitor the content of this data. It processes the data only to provide the service — in particular creating backups, storing backups, verifying restorability, sending operational alerts, deleting data under retention, and assisted restore. Rules for this processing are set out in the Data Processing Agreement.

3. What personal data we process as controller

As controller, we may process the following categories of data:

  • identification and contact data: email address, and possibly name, company name, company ID, billing details;
  • account data: user ID, account creation date, account settings, subscription status;
  • payment and billing data: plan, payments, invoices, customer country, Stripe customer ID and subscription ID;
  • technical data: IP address, user agent, server logs, sign-in time, error and security-event information;
  • communication data: messages sent to support, operational communication, and transactional emails;
  • consents and legal records: versions of the Terms, Privacy Policy, and DPA, and records of consents given when ordering.

4. Purposes and legal bases

We process personal data for the following purposes and legal bases:

  • creating and managing the account — performance of a contract;
  • providing the service — performance of a contract;
  • payments, billing, and accounting — performance of a contract and compliance with legal obligations;
  • security and operational logs — legitimate interest in secure operation of the service;
  • communication with the customer — performance of a contract and legitimate interest;
  • legal defence and record-keeping — legitimate interest and compliance with legal obligations.

5. Customer data processed as processor

Within the service, data from the customer's database and file storage may be backed up. This data may contain personal data of the customer's end users.

BackProve does not determine the content of this data or the purposes of its processing. BackProve processes it only on the customer's instructions and to the extent necessary to provide the service. Typical operations include accessing the customer's database and files, creating an encrypted backup, storing it, verifying restorability, automatic deletion under retention, and assisted restore at the customer's explicit request. Details are set out in the DPA.

6. Customer access credentials

To provide the service, we process the connection details to the customer's database and the access keys to their file storage. These are stored encrypted and are not viewable in the administration interface in plain form.

For backups, access to the customer's production database is used for reading. The exception is assisted restore into a new, empty project at the customer's explicit request.

7. Where data is stored and international transfers

Customer backups are stored on infrastructure in the European Union — specifically in Germany, with the provider Hetzner Online GmbH. The application and backup infrastructure run on European infrastructure.

Some service providers — in particular the payment or email provider — may process selected account, billing, communication, or service-delivery data outside the European Economic Area. Where this happens, we use an appropriate transfer mechanism, such as an adequacy decision, the EU-U.S. Data Privacy Framework where applicable, standard contractual clauses, and supplementary measures where required.

Customer backup artifacts are stored in EU-based storage and are not intentionally transferred outside the EU by BackProve.

8. Sub-processors and recipients

We use in particular the following providers:

A current list of sub-processors and other relevant service providers is available at backprove.com/sub-processors.

  • Hetzner Online GmbH — hosting, servers, and backup storage;
  • Stripe — payment and subscription processing;
  • Resend — sending transactional and operational emails.

9. Retention period

We retain data for the period necessary for each purpose.

  • account data: for the duration of the account and then for a reasonable period for legal, tax, and security purposes;
  • accounting and tax documents: for the period required by law;
  • technical and security logs: for a limited period necessary for security and operation;
  • customer backups: under the retention policy of the selected plan or service settings; after the account ends, backups are retained for 30 days and then permanently deleted, unless earlier deletion is requested or the law requires otherwise.

10. Security

We use technical and organisational measures appropriate to the nature of the service, in particular:

BackProve technically holds the encryption keys necessary to provide the service. The service is therefore not zero-knowledge or end-to-end encrypted in the sense that the customer alone would hold the keys.

  • encryption of backups;
  • encryption of access credentials;
  • storage of backups in the EU;
  • separation of the public-facing web application from the internal component that can access backup storage;
  • restriction of administrator access;
  • monitoring of backups and failures, with alerts;
  • encrypted backup of our own application database.

11. Cookies and localStorage

We use only necessary cookies and similar technologies required for the service to function, in particular for authentication and secure sign-in. We may also use localStorage to store user preferences, such as the appearance of the application. We do not use marketing or advertising cookies unless expressly stated otherwise. See the Cookie Policy.

12. Rights of users

Where we process your personal data as controller, you have in particular the right to:

  • access your personal data;
  • rectify inaccurate data;
  • erasure;
  • restriction of processing;
  • data portability;
  • object to processing based on legitimate interest;
  • lodge a complaint with the Office for Personal Data Protection (Úřad pro ochranu osobních údajů).

Requests can be sent to legal@backprove.com.

If your request concerns data contained in the database or files of a BackProve customer, we are not the controller of that data. In that case, please contact the relevant customer whose service or application you use directly.

13. International customers

BackProve is operated from the Czech Republic and the service is provided digitally, including to customers outside the Czech Republic. If you use the service from a country outside the European Union, you acknowledge that your data may be processed in the Czech Republic, the European Union, and — with selected service providers — in other countries, using appropriate legal mechanisms.

14. Changes to this policy

We may update this policy over time. We will inform you of material changes by a reasonable means, such as email or an in-service notice.

15. Contact

Jan Brožíček · IČO 08764832 · Rižská 1492/2, 102 00 Prague · legal@backprove.com