Routario Privacy Policy
Effective date: 8 June 2026
This Privacy Policy explains how JM Ventures s.r.o. processes personal data when operating the Routario website, sales process, customer relationship, billing, support, and related business activities.
This Privacy Policy does not primarily govern personal data that customers upload into their Routario workspaces. For that data, the customer is generally the controller and the Provider acts as processor under the Data Processing Agreement.
1. Controller
Controller: JM Ventures s.r.o.
Company ID: 07458240
Registered office: Pod Havránkou 656/10a, Troja, 171 00 Prague 7, Czech Republic
Contact: hello@routario.com
2. Data We Process as Controller
We may process:
- website visitor data, including cookies, analytics data, device data, and log data;
- demo request and contact form data;
- prospect and sales CRM data;
- customer billing and contract contact data;
- admin user account data;
- support communications;
- marketing consent and communication preferences;
- security and fraud-prevention data.
3. Purposes and Legal Bases
We process personal data for the following purposes:
| Purpose | Legal basis |
|---|---|
| Responding to enquiries and demo requests | pre-contractual steps / legitimate interest |
| Providing Routario customer accounts | contract / legitimate interest |
| Billing, accounting, and tax records | legal obligation / contract |
| Customer support | contract / legitimate interest |
| Website analytics and improvement | consent where required / legitimate interest |
| Direct marketing to business contacts | consent where required / legitimate interest |
| Security, fraud prevention, and service integrity | legitimate interest / legal obligation |
| Legal claims and compliance | legitimate interest / legal obligation |
4. Customer Workspace Data
Customers may upload personal data into Routario workspaces, including CRM records, project notes, documents, relationship context, and business contact information.
For such Customer Data, the customer determines the purposes and legal basis of processing. Routario processes the data as processor according to the Data Processing Agreement and customer instructions.
Individuals whose data is stored by a Routario customer should normally contact that customer directly to exercise data protection rights.
5. Recipients and Service Providers
We may share personal data with service providers that help us operate Routario, including hosting providers, cloud infrastructure, email providers, analytics, monitoring, CRM, support tools, payment/accounting tools, and AI service providers where applicable.
A customer-facing list of subprocessors is maintained separately for Customer Data.
We may also disclose personal data where required by law, regulators, courts, auditors, professional advisors, or to protect rights and security.
6. International Transfers
Where personal data is transferred outside the European Economic Area, we use appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, or other lawful mechanisms under GDPR.
7. Retention
We retain personal data only for as long as necessary for the purposes described above, unless longer retention is required by law or legitimate business needs.
Typical retention examples:
- enquiry and demo data: 24 months;
- customer contract and billing records: for the period required by accounting and tax law;
- support records: 24 months;
- marketing contacts: until opt-out or inactivity cleanup;
- security logs: 90 days, unless needed for investigation.
8. Cookies and Analytics
The Routario website may use cookies or similar technologies for essential website operation, analytics, performance, and marketing where enabled.
Where required by law, non-essential cookies are used only with consent. Cookie preferences can be managed through the website cookie banner or browser settings.
9. Data Subject Rights
Subject to GDPR conditions, individuals may have the right to:
- access their personal data;
- correct inaccurate data;
- request deletion;
- restrict processing;
- object to processing;
- receive data portability;
- withdraw consent where processing is based on consent;
- lodge a complaint with a supervisory authority.
Requests can be sent to hello@routario.com.
The Czech supervisory authority is the Office for Personal Data Protection / Úřad pro ochranu osobních údajů.
10. Security
We use reasonable technical and organizational measures to protect personal data. No system is perfectly secure, but we work to protect data against unauthorized access, loss, misuse, and alteration.
11. Changes to this Policy
We may update this Privacy Policy from time to time. The latest version will be published on the Routario website with its effective date.