Genexy Privacy Policy
Version: 1.0
Effective from: 26 August 2026
This Privacy Policy (the “Policy”) explains how U:BIT s. r. o. processes personal data in connection with Genexy.
Genexy is designed so that a significant part of work with source code, projects, and files takes place locally on the user’s device. Merely opening or editing a local project does not mean that it is automatically sent to U:BIT.
U:BIT does not use the user’s source code, projects, or conversations with artificial intelligence to train artificial intelligence models, nor does it sell them for advertising purposes.
Certain data may nevertheless be processed when using online services, remote access, support, a user account, first-party analytics, or third-party services, as explained below.
1. Controller
The controller of personal data is:
U:BIT s. r. o.
Karpatské námestie 10A
831 06 Bratislava – Rača Borough
Slovak Republic
Company ID No. (IČO): 54 772 877
Tax ID No. (DIČ): 2121781981
Registered in the Commercial Register of the Municipal Court Bratislava III, Section: Sro, Insert No. 162715/B.
Privacy / legal matters: legal@genexy.io
Support: support@genexy.io
2. Legal Framework
We process personal data primarily in accordance with:
- Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”),
- Act No. 18/2018 Coll. on Personal Data Protection,
- Act No. 452/2021 Coll. on Electronic Communications,
- Act No. 431/2002 Coll. on Accounting to the extent applicable to accounting documentation,
- and other applicable laws.
3. What Data We May Process
The scope of personal data processed depends on the features used by the user or authorized seller.
3.1 Account and Authentication
When creating or using an account, we may process, in particular:
- name or display name,
- email address,
- profile picture,
- internal account identifier,
- information about creation and use of the account,
- email verification status,
- information about FREE or PRO entitlement,
- security and authentication data.
If the user uses a password, we do not store it in readable form and protect it using appropriate cryptographic measures.
When signing in through a third party, we may receive data necessary for authentication, such as a user identifier, email address, name, or profile picture.
3.2 Licenses
When managing licenses, we may process:
- the license key,
- its status and validity,
- license type and period,
- activation date,
- the account on which the license was activated,
- information necessary to prevent fraud or unauthorized use.
An authorized seller normally provides the end customer with a license key, and the customer then adds or activates it in their own Genexy account.
3.3 Billing and Order Data of Authorized Sellers
U:BIT sells license keys to authorized sellers within a business-to-business relationship. In connection with this, we may process data necessary for orders, invoicing, accounting, and management of the commercial relationship, including in particular:
- business name or name of the entrepreneur,
- registered office or place of business,
- Company ID No. (IČO), Tax ID No. (DIČ), and, where applicable, VAT ID No. (IČ DPH),
- contact details and details of a contact person,
- information about orders for license keys,
- information contained in issued invoices and accounting records,
- order and payment status in the relationship between U:BIT and the authorized seller.
Such data constitutes personal data only to the extent that it relates to an identified or identifiable natural person.
Under the current distribution model, U:BIT does not process payment or billing data of the end consumer in connection with the purchase of a license. Payment and invoicing toward the end customer are handled by the authorized seller. U:BIT does not operate a payment gateway for the sale of licenses to end customers.
3.4 Technical Data and Operational Logs
When online or internet services are used, we may process technical data necessary for their operation and security, such as:
- IP address,
- time of the request,
- information about the device or browser,
- session identifiers,
- technical result of the request,
- error and security events.
We use this data primarily for operation, diagnostics, account protection, fraud prevention, and handling security incidents.
3.5 Support and Communications
If a user or authorized seller contacts support, we may process:
- identification and contact data,
- content of the message or request,
- communications with support,
- screenshots,
- operational logs,
- crash reports,
- files or other attachments voluntarily provided by the person.
Users should not send passwords, private keys, API keys, or other secret access credentials to support unless this is necessary and has been securely agreed.
3.6 First-Party Analytics
Genexy may use its own analytics to understand use of the website and product, improve features, identify technical issues, and measure basic service usage.
Such analytics may process, in particular:
- visits to or views of the relevant part of the service,
- events related to use of features,
- date and time of the event,
- Genexy version and platform,
- IP address,
- a pseudonymous session, installation, or account identifier where needed,
- basic technical and performance data,
- type of error or application-crash event.
The analytics are not intended to collect source code, content of user files, commands entered into a local terminal, passwords, API keys, secret access credentials, or the content of conversations with artificial intelligence.
As of the effective date of this Policy, this planned first-party analytics system is not yet active. This section describes processing that may take place after it is introduced. Before activation, the processing will be configured in accordance with this Policy and applicable law.
4. Local Projects and Source Code
U:BIT does not normally collect the content of the user’s local projects automatically.
This includes, in particular:
- source code,
- content of local files,
- local Git repositories,
- content of the local terminal,
- local databases,
- local API or Git credentials,
- local secret access credentials.
Working with a local project in Genexy does not itself mean that the project is uploaded to U:BIT infrastructure.
An exception may arise where the user knowingly sends certain content, for example, to support, a remote service, or a third-party provider.
5. Artificial Intelligence Features
Genexy may enable the use of third-party artificial intelligence services or endpoints configured by the user.
When using artificial intelligence, the user may knowingly send the selected provider, for example:
- an instruction or prompt,
- source code,
- file content,
- project context,
- or other technical information.
Where communication takes place directly with an independent artificial intelligence provider, processing by that provider is governed by its own terms, privacy policy, and user account settings.
U:BIT does not control how an independent provider handles data that the user sends directly to it.
Before sending confidential or personal data, the user should review the rules of the relevant provider.
U:BIT does not use the user’s source code, projects, or conversations with artificial intelligence to train artificial intelligence models.
6. Remote Access
Genexy may enable remote connections between devices or systems.
Depending on the available connection method, communication may be direct or may use U:BIT infrastructure for technical facilitation.
If session content technically passes through U:BIT infrastructure, it is processed to the extent necessary to provide the relevant service.
U:BIT does not normally:
- use such content for advertising profiling,
- use it to train artificial intelligence models,
- or retain it as a recording of the working session,
unless a particular feature expressly states otherwise.
For operation, security, diagnostics, and connection history, we may process technical metadata such as device identifiers, IP addresses, connection times, session duration, or the volume of transmitted data.
Such metadata does not constitute a recording of screen content, terminal content, or transmitted files.
If a business customer uses Genexy in a manner in which U:BIT processes personal data of third parties on the customer’s behalf, the controller-processor relationship is governed by the relevant section of the Genexy Terms of Use.
7. Purposes and Legal Bases
We process personal data only where there is an applicable legal basis for doing so.
| Purpose | Typical data | Legal basis |
|---|---|---|
| account creation and management | email, name, account data | performance of a contract / steps prior to entering into a contract |
| authentication | email, authentication and security data | performance of a contract and legitimate interest in security |
| license activation and management | account, license key, activation status | performance of a contract |
| orders and invoicing for authorized sellers | seller identification and billing data, orders, invoices | performance of a contract and compliance with a legal obligation |
| customer support | account, email, request content, attachments | performance of a contract or legitimate interest |
| operation and diagnostics | IP address, technical data, operational logs | performance of a contract and legitimate interest |
| security and fraud prevention | account, IP address, security events, license | legitimate interest |
| remote features | technical data and necessary transmission | performance of a contract |
| first-party server-side analytics and service improvement | analytics events, IP address, pseudonymous identifiers, technical data | legitimate interest where such processing is permissible; consent where required by law |
| legal and accounting obligations | data required by law | compliance with a legal obligation |
| protection of legal claims | relevant records | legitimate interest |
| marketing | email, record of consent or objection | consent or another legal basis permitted by law |
Where processing is based on legitimate interest, we assess the balance between our interest and the rights and freedoms of the data subject.
If analytics requires storing information on the user’s terminal equipment or accessing information already stored on that equipment, and this is not a technically necessary case, such access will take place only after consent has been obtained where required by law.
8. Cookies and First-Party Analytics
Genexy web services may use cookies, browser local storage, or similar technologies necessary in particular for:
- sign-in and session maintenance,
- account security,
- user settings,
- language or appearance,
- storing a consent-related choice.
Technologies necessary for the transmission of a communication or for providing a service expressly requested by the user may be used without separate consent to the extent permitted by law.
If first-party analytics were to use a non-essential cookie, local storage, or another technology that stores or reads information on the user’s terminal equipment, it will be used only after demonstrable consent has been obtained, unless applicable law provides otherwise.
Genexy may also perform first-party server-side analytics that does not require non-essential storage of or access to information on the user’s terminal equipment. Such measurement may include the data described in the first-party analytics section and may be based on the legitimate interest in operating, securing, improving, and understanding use of the service where, after assessment of the circumstances, that legal basis is appropriate under the GDPR.
Genexy does not use project content or conversations with artificial intelligence for advertising profiling, and this Policy does not contemplate the use of third parties to track users across unrelated websites for advertising purposes.
If the way analytical or advertising technologies are used changes materially, we will update this Policy and the relevant consent mechanism before such technologies are used to the extent required by law.
9. Email Communications
9.1 Service Messages
We may send the user messages necessary for or directly related to the service, such as:
- email verification,
- password recovery,
- security alerts,
- account or license information,
- a material operational change,
- a legal notice,
- or a material change to the Terms or this Policy.
Such messages are not marketing where their purpose is to provide or secure the service.
9.2 Newsletter and Marketing
Marketing communications may include information about new features, products, offers, or the development of Genexy.
We send marketing only on a legal basis permitted by applicable law.
Where consent is the legal basis, the user may withdraw it at any time.
Where the law permits marketing without prior consent in a specific case, we may rely on the relevant statutory exception while preserving the user’s right to easily object to the communication.
Opting out of marketing does not affect necessary service messages.
10. How Long We Retain Data
We do not retain personal data longer than necessary for the purpose for which it was obtained or longer than required by law.
Typically:
- active account data is retained for the duration of the account,
- data that we no longer need after account cancellation is removed from active systems without undue delay, usually within approximately 30 days,
- routine technical and security operational logs may generally be retained for up to approximately 12 months,
- identifiable or pseudonymized data from first-party analytics is planned to be retained generally for no more than approximately 12 months and then deleted, aggregated, or anonymized,
- remote-session history metadata is generally retained for approximately 90 days,
- ordinary support history may be retained for approximately 3 years after the case is closed,
- data related to fraud, a security incident, or a legal claim may be retained longer, generally for up to approximately 5 years or for the duration of the relevant proceedings,
- accounting records, invoices, and related accounting documentation concerning business sales to authorized sellers are retained for the period required by applicable law; in the Slovak Republic, generally for ten years following the year to which the relevant accounting record relates,
- data may remain in existing backups until they are overwritten in the ordinary course.
Certain data may be retained longer where necessary to comply with a legal obligation, protect legal claims, or handle a security incident.
Records of marketing consent or objection may be retained to the extent necessary to demonstrate the lawfulness of communications and for the period required by applicable law.
11. Who We May Share Data With
To the extent necessary, we may provide or make personal data available, in particular, to the following categories of recipients:
- providers of technical and operational infrastructure,
- providers of email and communication services,
- authentication providers,
- application distribution platforms,
- providers of security or support services,
- providers of accounting, tax, or legal services to the extent necessary for the performance of their tasks,
- independent services selected or activated by the user,
- competent public authorities where required by law.
If the user independently sends data to an artificial intelligence provider or another third-party service, that provider may act as an independent controller under its own rules.
U:BIT does not sell databases of users’ personal data to advertisers or data brokers for their own advertising purposes.
Under the current distribution model, U:BIT does not provide a payment gateway to the end customer. Therefore, in connection with the purchase of a license key from an authorized seller, the end customer’s payment data is not provided to U:BIT as part of the payment transaction.
12. Reorganization or Transfer of Genexy
If a merger, acquisition, sale of the business, transfer of Genexy, or similar reorganization occurs, relevant personal data may be transferred to a legal successor in accordance with applicable law.
Such a transfer does not in itself terminate obligations relating to the protection of personal data.
13. International Transfers
Some service providers may have infrastructure or additional suppliers outside the European Economic Area.
If U:BIT transfers personal data to a third country in a manner subject to the GDPR, it will use an appropriate legal mechanism, such as:
- an adequacy decision of the European Commission,
- Standard Contractual Clauses,
- or another mechanism permitted under the GDPR.
Information about the legal mechanism applicable to a specific transfer or about the relevant safeguards may be requested at legal@genexy.io.
If the user independently chooses a third-party service, any international transfer within that service is also governed by the rules of that provider.
14. Security
We use appropriate technical and organizational measures aimed at protecting personal data against:
- unauthorized access,
- loss,
- misuse,
- unauthorized alteration,
- disclosure,
- or destruction.
We adapt these measures to the nature of the processing and the relevant level of risk.
However, no information system can be considered absolutely secure.
If a personal data breach occurs, we proceed in accordance with the GDPR and other applicable laws, including notification obligations where the statutory conditions are met.
15. Rights of the Data Subject
Subject to the conditions laid down by the GDPR, the user may have the right to:
- obtain access to their personal data,
- request correction of inaccurate data,
- request erasure of data,
- request restriction of processing,
- receive portable data in cases provided for by the GDPR,
- object to processing based on legitimate interest,
- object to direct marketing,
- withdraw consent where processing is based on consent.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
The right to erasure is not absolute. We may be required or entitled to retain certain data, for example, to comply with a legal obligation, ensure security, or protect legal claims.
16. Exercising Your Rights
A request may be sent to:
or:
or in writing to the U:BIT address.
Before handling a request, we may reasonably verify the identity of the applicant in order to prevent unauthorized disclosure of data.
We will respond to a valid request within the time limits prescribed by the GDPR.
17. Supervisory Authority
If a data subject believes that we process their personal data in breach of applicable law, they have the right to lodge a complaint or application with the competent supervisory authority.
For U:BIT, the competent supervisory authority is, in particular:
Office for Personal Data Protection of the Slovak Republic.
This does not affect the right to contact another competent supervisory authority in cases provided for by the GDPR.
18. Automated Decision-Making and Advertising Profiling
Genexy does not currently carry out automated individual decision-making based solely on automated processing that would produce legal effects concerning the user or similarly significantly affect the user within the meaning of Article 22 GDPR.
U:BIT does not currently use the content of user projects or communications with artificial intelligence to create profiles for personalized advertising.
19. Minors and Special Categories of Data
Genexy is not generally intended exclusively for adults, and this Policy does not establish a general minimum age for using the developer tool itself.
If, under applicable law, a user cannot independently provide the required consent or accept the terms of the service, the appropriate action of their legal guardian is required. Where processing is based on consent, we respect the age and other conditions laid down by applicable law.
Genexy is not designed for the knowing, systematic collection of special categories of personal data, such as health data, biometric data used for unique identification, political opinions, religious beliefs, or data concerning a person’s sex life.
Users should not provide us with such data unless this is necessary and there is an appropriate legal basis for doing so.
20. Changes to this Policy
The manner in which Genexy is provided may change in the future.
We may update this Policy, in particular, when there is:
- a new service or new type of processing,
- a change in the categories of providers used,
- a material change in analytics,
- a change in legal requirements,
- or a change in the manner in which personal data is processed.
The current version will be published through Genexy or at genexy.io.
For a material change, we may reasonably notify users by email, in the application, or by another appropriate method.
If a new purpose of processing requires new consent, we will not automatically treat existing consent as consent to the new purpose.
21. Language Versions
This Policy may be available in multiple languages.
The Slovak version is the original version.
In the event of a discrepancy between the Slovak and a translated version, the Slovak version will prevail to the extent that doing so does not restrict rights of the data subject under mandatory law.
22. Contact
Questions relating to personal data protection may be sent to:
U:BIT s. r. o.
Karpatské námestie 10A
831 06 Bratislava – Rača Borough
Slovak Republic
Privacy / legal matters: legal@genexy.io
Support: support@genexy.io
Last updated: 26 August 2026