Privacy Policy for the Resio Service
Controller: VisionEdge s. r. o., 29. augusta 1503/1A, 958 01 Partizánske, Slovak Republic Company ID (IČO): 51962161, Tax ID (DIČ): 2120848521 (not a VAT payer) Registration: Commercial Register of the District Court Trenčín, Section Sro, Insert No. 37109/R Data protection contact: info@visionedge.sk
Version: 1.0 · Effective date: 21 June 2026
1. Introduction
This policy explains how VisionEdge s. r. o. ("we" or the "Provider") processes personal data in connection with Resio — a tool for preparing and validating the register of information under Regulation (EU) 2022/2554 (DORA) and generating it into the xBRL-CSV format. Processing is carried out in accordance with Regulation (EU) 2016/679 (GDPR) and Act No. 18/2018 Coll. on personal data protection.
2. Dual role in processing
2.1 Controller: With respect to data about user accounts, billing and operation of the Service, we are the controller and we decide on the processing. This is governed by this policy.
2.2 Processor: With respect to personal data contained in the content that a customer enters into the Service (in particular in the uploaded template and the saved register of information — for example contact persons of ICT service providers, or suppliers who are natural persons), we are a processor. The controller of that data is the customer, and the processing is governed by the Data Processing Agreement (DPA). If you are a person whose data the customer processes in Resio, please address your rights to the relevant customer (the controller).
2.3 The register of information under DORA is by its nature predominantly a set of data about entities and contractual arrangements; however, it may contain limited personal data. Special categories of personal data under Art. 9 GDPR are not to be entered into the Service.
3. What data we process (as controller)
- Account and user data: first name and surname, email, organisation name, role, sign-in identifiers (when used with an account).
- Billing and identification data: business name, registered office, Company ID, Tax ID, VAT ID and data needed to issue documents (where a paid plan is introduced).
- Technical and operational data: IP address, device and browser data, access and activity logs, cookies (see the separate Cookie Policy).
- Communication: the content of communications during support and handling of requests.
4. Account-free (transient) processing
4.1 When the Service is used without an account (uploading a template, validation and package generation), we process the content of the uploaded template transiently, solely for the purpose of performing validation and generating the package. We do not store this content in a persistent (living) register and we delete it after processing or after the session ends.
4.2 Even in account-free use, we may process technical and operational data (in particular the IP address and logs) for the purposes of security, abuse prevention and operation of the Service.
5. Purposes and legal bases (as controller)
| Purpose | Legal basis (GDPR) |
|---|---|
| Provision and administration of the Service, account management | Art. 6(1)(b) — performance of a contract |
| Performing validation and package generation | Art. 6(1)(b) — performance of a contract / Art. 6(1)(f) for account-free use |
| Billing and bookkeeping | Art. 6(1)(c) — legal obligation |
| Security, abuse prevention, logs | Art. 6(1)(f) — legitimate interest |
| Improving and supporting the Service | Art. 6(1)(f) — legitimate interest |
We do not carry out marketing communications and do not process personal data for those purposes.
6. Retention period
- Content of the uploaded template in account-free use: only transiently, during processing; deleted thereafter.
- Account data and saved registers: for the duration of the agreement and a reasonable period after its termination (see Terms, Art. 11.5 — export available for 30 days after termination).
- Accounting and tax documents: for the period required by law (usually 10 years).
- Logs and technical data: 12 months, unless needed longer for security purposes.
7. Recipients and processors
To provide the Service we use trusted providers (processors) with whom we have concluded processing agreements:
| Processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | infrastructure hosting (servers) | European Union |
| Clerk, Inc. | authentication and user management (with an account) | USA |
| Resend, Inc. | sending transactional emails | USA |
| MinIO (self-hosted) | storage of documents and packages (within our infrastructure) | European Union |
We may also disclose data to the competent authorities where required by law.
Operational note: the list of processors corresponds to VisionEdge's standard infrastructure; before publishing, we recommend verifying that it fully matches Resio's actual technical architecture.
8. Transfers to third countries
The processors Clerk and Resend are based in the USA. We safeguard transfers of personal data to third countries with appropriate safeguards under the GDPR, in particular the standard contractual clauses (SCC) adopted by the European Commission.
9. Rights of data subjects
In accordance with the GDPR, you have the right to: access your data, rectification, erasure, restriction of processing, data portability, to object to processing based on a legitimate interest, and to withdraw consent at any time (without affecting the lawfulness of processing before withdrawal).
You may exercise your rights at info@visionedge.sk. You also have the right to lodge a complaint with the supervisory authority:
Office for Personal Data Protection of the Slovak Republic
Hraničná 12, 820 07 Bratislava 27
https://dataprotection.gov.sk
10. Cookies
We operate the Service and the website using cookies. We use only strictly necessary cookies. Details are set out in the separate Cookie Policy.
11. Security of processing
We apply appropriate technical and organisational measures, in particular: encrypted transmission (HTTPS/TLS), security HTTP headers (HSTS and others), logical isolation of individual customers' data, access and permission management, separated operational roles, regular encrypted backups of stored data, and monitoring. We review the measures on an ongoing basis.
12. Changes to this policy
We may update this policy, in particular when the Service, processors or legislation change. We will inform you of material changes in an appropriate manner. The current version is always available on the Service's website.
13. Contact
VisionEdge s. r. o., 29. augusta 1503/1A, 958 01 Partizánske, info@visionedge.sk, https://visionedge.sk