Privacy Policy

Data controller

Majme, s. r. o.
Hradská 124, 821 07 Bratislava, Slovakia
Company ID (IČO): 36844837
VAT ID (IČ DPH): SK2022465016
Email: contact@trafixi.com
Web: www.trafixi.com · www.trafixi.sk

This Privacy Policy explains how Majme, s. r. o. processes personal data when you visit TraFixi websites or use the TraFixi product. It is a separate document from the Terms of Service.

1. Who this policy is for

This policy applies if you:

  • visit www.trafixi.com or www.trafixi.sk;
  • buy or enquire about TraFixi;
  • hold a TraFixi licence (Licence Key, email, billed customer);
  • install the TraFixi WordPress plugin and connect it to our Hub (api.trafixi.com).

It applies to consumers and business customers in Slovakia, the EU/EEA and worldwide.

It does not cover WordPress.org, WooCommerce, Rank Math, Google Site Kit, or your own shop’s customers — except where their data appears in content you send through TraFixi (see Section 3).

Contract terms for buying TraFixi are in the separate Terms of Service.

2. Plain-language summary

  • We store what we need to run the licence: your email, domain, plan, credit, billing identifiers, and technical heartbeat (plugin / WordPress / PHP versions).
  • We store AI usage (what kind of action, tokens, model, cost, time) so we can bill Credit. We do not keep a full archive of every product description in the Hub.
  • When you run AI (text, images, voice), the relevant content is sent to AI providers (currently including OpenAI and Google) so the feature can work.
  • Payments are handled by Stripe. We do not store full card numbers.
  • Google Search Console data used in the plugin stays on your WordPress site via Site Kit. We do not copy your full Search Console property into the Hub.
  • We do not sell your personal data.

3. Controller and processor

We are the controller for data about you as a TraFixi customer or website visitor: account email, licence, billing, support messages, Hub logs, and website logs.

You are the controller, and we are the processor, for Your Content that we process on your instructions to provide AI and related features — for example product titles and descriptions, images, prompts, and voice input you send through the Plugin. That content may include personal data if you put it there (an author’s name, a customer story, a face in a photo).

We do not want, and do not try to collect, personal data of your shop’s end customers. If such data is inside Your Content, you must have a legal basis to send it through TraFixi.

Business customers who need a GDPR Article 28 data processing agreement can request one at contact@trafixi.com.

4. Data we process

Category Examples
Identity and contact Email address (licence owner), billing name, company name, postal address, country, VAT ID.
Licence and account Licence Key (stored hashed / encrypted on the Hub), plan name, credit balances, licence status, activation dates, pending plan changes.
Licensed site Domain name, TraFixi plugin version, WordPress version, PHP version, last heartbeat time, preferred AI language.
Usage / billing metrics Activity type (for example AI Fix, image generation), token counts, AI model name, duration, images generated, euro cost, WordPress entity type and numeric ID (for example a product ID — not the product title in this log).
Payments Stripe customer, subscription and invoice IDs, invoice links, payment-failure flags. Card data is handled by Stripe, not stored by us in full.
AI content (in transit) Prompts, selected product/post text, reference images, voice audio during a voice session. Sent to AI providers to generate Output. Not stored as a full content archive on the Hub.
Support Emails and attachments you send to us.
Website / security Server logs that typically include IP address, date/time, requested URL, browser user-agent. Needed to operate and secure the sites and Hub API.

We do not intentionally collect special-category data (health, religion, political opinions, and similar). Please do not put that kind of data into prompts or product text you send to AI.

5. Why we process it (legal bases)

Under the GDPR (and UK GDPR where it applies) we rely on:

Purpose Legal basis
Create and run your licence, Hub heartbeats, updates, Credit metering, AI features you request Performance of a contract (GDPR Art. 6(1)(b))
Take payment, invoices, VAT, accounting Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) — Slovak tax and accounting rules
Security, abuse prevention (shared keys, duplicate domains), fraud, chargebacks Legitimate interests (Art. 6(1)(f)); for Consumers we balance this against your rights
Answer support questions Contract (Art. 6(1)(b)) and/or legitimate interests (Art. 6(1)(f))
Service emails (licence issued, payment failed, subscription status) Contract (Art. 6(1)(b))
Optional marketing emails, if we ever send them and you have opted in Consent (Art. 6(1)(a)) — we do not currently run a newsletter as a default
Non-essential website analytics or advertising cookies, if we add them later Consent (Art. 6(1)(a) and ePrivacy), after we update this policy
Your Content processed as a processor (AI on your shop content) We act on your documented instructions (the Product). You need your own legal basis toward your data subjects

You may refuse to provide account or billing data, but then we cannot sell or operate a licence.

6. Where data comes from

  • You — purchase, licence form in the Plugin (key + email), support, billing details.
  • Your WordPress site — domain, versions, AI language, usage metrics, and the content you choose to send to AI.
  • Stripe — payment status, tax calculation, invoice identifiers.
  • Automatically — heartbeats about twice a day while the Plugin is active; website/API server logs.

7. Who we share data with

We share personal data only as needed to run TraFixi:

Recipient Role
Stripe (Stripe Payments Europe / Stripe, Inc.) Payments, invoices, tax, customer billing portal
OpenAI Text and voice AI features
Google (Gemini / related Google AI APIs) Image generation and related AI features
Hosting and infrastructure providers for our websites and Hub Storage, security, delivery of the Service
Professional advisers (accountant, lawyer) and authorities Where we must or have a legitimate need

We may add or replace providers. We will keep this list honest. Other AI providers will be named here if we start using them for customer traffic.

Your own plugins (WooCommerce, Rank Math, Google Site Kit) process data on your site under their policies. Site Kit / Search Console is a relationship between you and Google, not a TraFixi Hub copy of GSC.

We do not sell personal data. We may transfer data in a company sale or reorganisation of Majme, s. r. o., under the same protections.

8. Transfers outside the EEA

Majme, s. r. o. is established in Slovakia (EU). Some providers — notably Stripe, OpenAI and Google — are in the United States or may process data there.

Where the GDPR requires a transfer tool, we rely on:

  • an adequacy decision (including the EU–US Data Privacy Framework, where the provider is certified); and/or
  • the European Commission’s Standard Contractual Clauses, plus whatever extra measures the provider documents.

If you use AI features, Your Content will typically leave the EEA to those providers. If you do not want that, do not run AI features.

9. Cookies and similar tools

The public TraFixi websites and the Hub are WordPress sites. They may set cookies that are strictly necessary to work (for example a session cookie if you log in to WordPress, or security cookies).

This review draft assumes we are not yet using advertising pixels or a marketing analytics suite on the public site. If we add Google Analytics, Meta Pixel, or similar, we will update this section and, where required, ask for consent.

Stripe may set its own cookies when you pay on Stripe-hosted pages. That is Stripe’s processing; see Stripe’s privacy notice.

The TraFixi Plugin in your wp-admin uses your WordPress login. We do not set extra tracking cookies on your shop’s public storefront.

10. How long we keep data

  • Active licence: account, domain, heartbeat and usage needed to operate the Service, for as long as the licence exists.
  • After cancellation: we may keep licence and billing records as long as Slovak accounting and tax law requires (typically up to 10 years for invoices and related books). Usage logs needed only for operations may be shortened or aggregated earlier.
  • Support emails: for as long as the conversation and a reasonable follow-up period, unless a longer legal hold applies.
  • Server logs: a short operational period (typically weeks, unless we must keep a security incident longer).
  • AI content in transit: we do not keep a Hub archive of full prompts. Providers keep data as described in their policies.

When we no longer need personal data, we delete or anonymise it.

11. Security

We use HTTPS, access control on the Hub, hashed / encrypted storage of Licence Keys on our side, and Stripe for payments. No method of transmission or storage is perfectly secure. You must protect your WordPress admin, Licence Key and email.

If a personal-data breach is likely to result in a high risk to you, we will notify you and the supervisory authority as the GDPR requires.

12. Your rights

If GDPR (or UK GDPR) applies to you, you may ask us to:

  • access your personal data;
  • correct it;
  • delete it (where the law allows — we may keep invoices);
  • restrict or object to certain processing (including legitimate-interest processing);
  • receive data you gave us in a portable format;
  • withdraw consent, where we relied on consent (this does not affect processing already done).

Email contact@trafixi.com. We may need to verify it is you. We will answer within one month, or tell you if we need more time as the law allows.

These rights are not absolute. For example we cannot delete a VAT invoice we must keep, and we cannot erase Your Content from your WordPress database — you control that site.

13. Children

TraFixi is for adults (18+). We do not knowingly collect data from children. If you believe we have, contact us and we will delete it.

14. Automated decisions

We meter Credit and may automatically stop AI when Credit is zero or a payment fails. That is operation of the Service, not a GDPR Article 22 decision that produces a legal effect about you as a person (creditworthiness, hiring, and similar). We do not use your data for automated profiling of that kind.

15. Changes

We may update this Privacy Policy. The new version will show a new effective date. For material changes we will try to email the licence address or show a notice in the Plugin, where reasonably possible.

16. Contact and complaints

Majme, s. r. o.
Hradská 124, 821 07 Bratislava, Slovakia
contact@trafixi.com

We do not currently have a separately appointed Data Protection Officer. The contact above is the right address for privacy requests.

You may lodge a complaint with a supervisory authority. For us as a Slovak company, that is:

Úrad na ochranu osobných údajov Slovenskej republiky
Hraničná 12, 820 07 Bratislava, Slovakia
dataprotection.gov.sk

If you live in another EU/EEA country (or the UK), you may also contact your local authority. You may complain there as well as, or instead of, the Slovak office.