Effective from 1 July 2026
An annex to the creatorbox platform's Terms of Service. Concluded by accepting the Terms.
Controller (správce): the Creator (identified in their account). Processor (zpracovatel): ANAX HOLDING, s.r.o., Company ID (IČO) 10876197.
1.1 The Operator (Provozovatel), acting as processor (zpracovatel), processes Buyers' personal data on behalf of the Creator (Tvůrce), acting as controller (správce), exclusively for the purpose of operating the platform and fulfilling the Creator's sales. Processing continues for the duration of the Creator's account.
2.1 The Operator processes personal data only on the Creator's documented instructions, which consist of the Terms and the Creator's use of the platform's features. Absent an instruction, the Operator does not transfer data to a third country unless required by EU or Czech law; in that case it will inform the Creator in advance, unless prohibited by law.
3.1 Persons authorised to process the data are bound by confidentiality. 3.2 The Operator implements appropriate technical and organisational measures under Art. 32 GDPR (Annex 2).
4.1 The Creator grants the Operator general authorisation to engage sub-processors. The current named list (identifying each provider, its seat, purpose, location of processing, and a link to its DPA/SCCs) is publicly available on the Processors page (creatorbox.cz/zpracovavame) and forms an integral part of this Agreement. 4.2 The Operator will impose on each sub-processor obligations corresponding to this Agreement (in particular confidentiality, security under Art. 32, purpose limitation, and deletion on termination). 4.3 The Creator will be informed of an intended change (adding or replacing a sub-processor) at least 30 days in advance by email to the primary contact address, by an in-app notice, and by an update to the Processors page. The Creator may, for serious data-protection reasons, raise a written objection within 14 days of the notice; if the Operator does not accommodate the objection (e.g. by offering an equivalent alternative), the Creator is entitled to terminate the service agreement effective as of the date the change takes effect, and the Operator will refund the proportionate part of any prepaid fee for the unused period.
5.1 The Operator provides the Creator with reasonable assistance in handling Buyers' requests (access, rectification, erasure, portability, objection) and in fulfilling the obligations under Art. 32-36 GDPR.
6.1 The Operator will notify the Creator of a personal data security breach without undue delay and no later than 48 hours after becoming aware of it; at the same time it will provide the information required under Art. 33(3) GDPR (the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken), so that the Creator can meet its own obligation to notify the supervisory authority within 72 hours (Art. 33) and the data subjects (Art. 34).
7.1 Where a transfer takes place outside the EEA (e.g. in connection with payment or infrastructure services), the Operator will ensure appropriate safeguards under Art. 46 GDPR (in particular the Standard Contractual Clauses under Commission Decision 2021/914) or certification under the EU-US Data Privacy Framework. The specific mechanism used for each provider outside the EU/EEA is listed on the Processors page.
8.1 After termination of the agreement, the Creator's account enters an "export only" mode for 30 days (see the Terms of Service, Art. 10.6). After this period, the Operator will delete the data or, on request, return it in a machine-readable format (CSV/JSON), unless its retention is required by EU or Czech law (in particular § 31 of Act No. 563/1991 Coll., on Accounting, and § 47 of Act No. 280/2009 Coll., the Tax Code (daňový řád)). Deletion from operational backups will occur within the normal backup rotation cycle (no later than 90 days). 8.2 Audit. On request, the Operator will provide the Creator with information and documents evidencing compliance with this Agreement (in particular a description of security measures, a list of sub-processors, and, once available, SOC 2 / ISO 27001 attestations). An on-site physical audit is possible by prior arrangement (generally 30 days' notice), at most once a year, to the extent necessary and in a manner that does not disrupt operations or the confidentiality of other customers' data. The Creator bears the cost of the audit, unless the audit reveals a material breach of this Agreement by the Operator.
9.1 Commitment: data belonging to the Creator and its Buyers will NOT be used to train the AI provider's or the Operator's models, nor to improve the AI provider's or the Operator's models. 9.2 Where the Service provides AI features (e.g. suggested product descriptions, generated cover images, review summaries), personal data will be transmitted to an external AI provider (listed on the Processors page) only for the purpose of generating the specific output (inference); the AI provider may not retain the data any longer than technically necessary and may not make it available to others. 9.3 The Operator will impose on each AI provider a contractual prohibition on training and contractual security guarantees corresponding to Annex 2. 9.4 The Creator may disable the use of AI features on its account in settings; disabling takes effect for newly generated output. Existing output already on record remains available as the Creator's data. 9.5 For the purposes of the EU Regulation on Artificial Intelligence (2024/1689), the current AI features are classified as minimal-risk systems. The Operator monitors developments in this classification and, should any features become classifiable in a higher risk category, will notify the Creator in advance under Art. 4.
10.1 This Agreement is governed by the law of the Czech Republic. On data-protection matters, this Agreement prevails in the event of a conflict with the Terms. 10.2 Contact for data-protection matters: hello@creatorbox.cz. 10.3 Governing language version. The Czech-language version of this Agreement is authoritative; any translations are provided for information only.
Subject matter: operation of the platform and fulfilment of the Creator's sales. Duration: for the duration of the Creator's account. Nature and purpose: storage, delivery of products, order fulfilment, transactional emails, support, and, where applicable, AI inference under Art. 9. Categories of data subjects: the Creator's Buyers. Categories of data: identification and contact data (name, email), order data, IP address; payment data is processed by Stripe as an independent controller.
Encryption in transit (TLS 1.2+) and encryption at rest (AES-256). Access control and authorisation; multiple user roles; multi-factor authentication (TOTP/WebAuthn) mandatory for accounts with an administrator role. Environment separation (production / staging / test) and restricted access to production data limited to necessary roles. Regular backups (daily incremental, weekly full, 30-day retention). Access monitoring and logging (audit log); 90-day log retention. Contractual imposition of corresponding obligations on sub-processors (DPA + SCCs for US-based providers). A vulnerability management process and security updates for dependencies. Hosting on servers within the EU/EEA. A security incident response plan, with an obligation to notify the Creator within 48 hours (Art. 6).
The named list and description is publicly available on the Processors page (creatorbox.cz/zpracovavame). The current list (as of the effective date of this DPA) includes only providers to whom the Creator's Buyers' personal data is actually transferred: hosting (Hetzner Online GmbH, EU/EEA), CDN and network protection (Cloudflare), file storage (Cloudflare R2), payment services (Stripe Payments Europe, Ireland), email (Mailgun, EU region), and, if the Creator activates an optional AI feature, an AI inference provider. The Operator's internal tools (its own email, chat, anonymous analytics) are not processors within the meaning of Art. 28(4) GDPR. Changes are governed by Art. 4.