Privacy Policy
How Nova Base s.r.o. processes personal data in connection with StellarBase.
General information
This privacy policy provides information about the processing of personal data that Nova Base s.r.o., with its registered office at Na Folimance 2155/15, Vinohrady, 12000 Praha 2, Tax ID 023982721, VAT No. CZ023982721, File No. C 436361, kept by Municipal Court in Prague (“we” or “our company”) process about you as a data subject (“you”).
We operate an AI knowledge management platform available via our application StellarBase (“Application”), available at https://app.stellarbase.ai, as well as the accompanying website (“Website”).
The processing of personal data is governed in particular by Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation) (“GDPR”).
This privacy policy provides you with information about the purposes for which our company processes your personal data and personal data you provided, the extent to which such personal data are processed (i.e., what categories of data are processed), the legal reason we base our right to process your data on (legitimate interest, fulfillment of legal obligations, consent, other legal reason) and for how long we will process them. This privacy policy also contains information about what rights you have in relation to the processing of your personal data and how you can exercise them against our company.
Role of our company
We act as a data controller in relation to personal data processed in connection with:
- account registration and management;
- billing and payment;
- marketing communication;
- provision of Application and/or Website (excluding processing of personal data within the Application on behalf of users);
- customer support;
- operation, security, and analytics of the Application and/or Website.
We act as a data processor when you use the Application to process personal data (e.g., through prompts, inputs, uploads, or interactions with the Application). In such cases you act as the data controller and we process personal data only on your behalf and according to your instructions and only for the purpose of providing the Application. Therefore, you are responsible for ensuring that you have a valid legal basis for processing personal data.
AI processing
When you use the Application, certain features rely on AI services provided by third-party providers.
- Your inputs (including prompts, uploaded data, or queries) and generated outputs may be processed by these providers strictly for the purpose of delivering the requested functionality.
- These providers may temporarily store or process such data for operational purposes such as request handling, security, abuse prevention, and service improvement (subject to their respective privacy policies).
- We contractually restrict such providers from using your data for their own purposes where possible.
- We do not use your data to train AI models unless explicitly agreed with you.
AI-generated outputs are automatically produced and may not always be accurate, complete, or suitable for your specific use case. You remain responsible for reviewing and validating such outputs.
What personal information do we collect?
As data controller, we process various categories of personal data about our Application users and visitors of our Website. Specifically, these categories are:
- identification and contact data (e.g. name, surname, date of birth, bank details, e-mail address);
- login information (e.g. e-mail address, password);
- device information (e.g. IP address, browser used);
- user account data (e.g. data filled in by the user, the date of last login);
- user behaviour data (e.g. Website and/or Application behaviour history, actions taken, features used)
What personal data we process about you, for what purpose and for how long depends on how and why you have provided us with your personal data or how we obtained it from you. In the following overview, you can find information about the processing of your personal data depending on the context in which the personal data is processed.
| Purpose | Scope of processed information | Legal title | Data retention time |
|---|---|---|---|
| Provision of the Application including related services and user support | Identification and contact data, User account data, User behavior data, Login information, Device information, Communication | Pursuant to article 6(1)(b) of the GDPR we may process personal data if it’s necessary for contract performance. | Within 30 days of canceling your account, up to a maximum of 2 years after your last login. |
| Website or Application administration and analysis of the user’s behavior when using the Application or Website | User account data, User behavior data, Login information, Device information | Pursuant to article 6(1)(f) of the GDPR we may process personal data if we have legitimate interest – legitimate interest in improving the Application or Website. | Until a legitimate objection to the processing, no later than 30 days after account cancellation |
| Mutual communication and answering your questions | Identification data, Communication | Pursuant to article 6(1)(f) of the GDPR we may process personal data if we have legitimate interest – legitimate interest in answering the question. | For a period of 3 years after the question is answered or for a period of 3 years after the last communication between our company and you in relation to the relevant question. |
| Sending newsletter | Identification data, Communication | Pursuant to article 6(1)(a) of the GDPR, we may process personal data if we have your consent – for example, your consent to receive our newsletter. | Until you tell us that you no longer wish to receive commercial offers. |
With whom do we share your personal data?
It is not possible to determine in advance which specific person will process your personal data. Therefore, we list here the categories of possible recipients with an explanation of the purposes for which they may be granted access to your personal data.
| Recipient | Reason for disclosure |
|---|---|
| Payment gateway providers | For the purpose of ensuring the proper execution of payment transactions (operation of the payment gateway, payment deductions, payment blocking, etc.), we must transmit your personal data to the entity providing the payment system. Such payment service providers have access to the personal data necessary for the performance of their designated activities, but they are not permitted to use such data for any other purposes. |
| Web statistics providers and social network operators | In order to analyse and improve our Website, we use the services of web statistics providers and social network providers that provide cookies services. These service providers have access to personal data necessary to carry out their specified activities but are not allowed to use it for other purposes. |
| Legal and tax advisors | Occasionally, we may need to consult legal or tax advisors for information about legal relationships with you. These persons are bound by the legal duty of confidentiality. |
| Third-Party service providers | We may use third parties to perform activities on our behalf, including providing administration services, hosting, infrastructure, data processing (including AI-powered functionalities), and communication services. These third-party service providers have access to personal data only to the extent necessary to perform their designated activities. Such providers are contractually bound to process personal data on our behalf. However, certain providers (in particular AI service providers or payment processors) may act as independent data controllers for limited purposes, as defined in their respective privacy policies. |
List of third-party providers
- Amazon Web Services, Inc. (AWS) — Cloud infrastructure provider used to host and operate parts of the Application and store personal data.
- Google Cloud EMEA Limited (Google Cloud Platform) — Cloud infrastructure provider used to support computing and storage services.
- Microsoft Corporation (Azure) — Cloud services provider used for infrastructure and related services.
- Scaleway S.A.S. — Infrastructure provider operating servers within the European Union used for hosting and storage of personal data.
- OpenAI, L.L.C. — AI service provider used to process user inputs and generate responses within the Application.
- Anthropic, PBC — AI service provider used for processing prompts and generating AI-based outputs.
- Google LLC (Gemini) — AI service provider used to provide language model capabilities.
- Mistral AI SAS — AI provider used for processing natural language inputs.
- xAI Corp. — AI service provider used to support AI-powered features.
- Voyage AI, Inc. — AI provider used for embedding and data processing functionalities.
- OpenRouter, Inc. — Gateway service that enables routing of requests to various AI providers.
- Tavily, Inc. — Search and data enrichment provider used to retrieve external information in response to user queries.
- ActiveCampaign, LLC (Postmark) — Email delivery provider used to send transactional and service-related emails.
- ZonerCloud — Infrastructure provider operating servers within the European Union used for GPU hosting.
Retention of your personal data
We retain personal data only for as long as necessary or legally permitted, based on the purpose(s) for which it was collected. For specific retention periods, please refer to the table above, where each purpose is matched with its corresponding retention timeframe.
Please note that in some circumstances we may store your personal data for longer periods of time, for example (i) where we are required to do so in accordance with legal, regulatory, tax or accounting requirements, or (ii) for us to have an accurate record of your dealings with us in the event of any complaints, or (iii) if we reasonably believe there is a prospect of litigation relating to your personal data.
Transfer of personal data to third countries
We primarily process personal data within the European Economic Area (EEA). However, some of our third-party service providers (in particular AI service providers and cloud providers) may process personal data outside the EEA, including in the United States or other jurisdictions. In such cases, we ensure that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions issued by the European Commission; or other lawful transfer mechanisms under applicable data protection laws. We are responsible for ensuring that any such transfers comply with GDPR requirements and that your personal data remains adequately protected.
What are your rights?
Below is a full list of what you can do in relation to the personal data processed. If you wish to exercise any of your rights, please contact us by email at info@stellarbase.ai.
Right to withdraw consent. If we process your personal data with your consent, it is your right to withdraw your consent to the processing of your personal data. This also applies to your consent to receive the newsletter. You can always withdraw your consent by following the instructions in each consent form.
Right of access. You have the right to access the personal data we process about you, as well as information about what personal data we process about you, for how long, for what purposes, who has access to it and whether we use it for automated decision-making (or how such automated decision-making works).
Right to correction. If you discover that we are processing incomplete or incorrect personal data about you, you have the right to have your personal data corrected or, if the purpose of processing the personal data so requires, completed.
Right to erasure. You have the right to erase your personal data that we store and process about you, provided that the processing is not necessary for compliance with our legal obligations, for maintaining an accurate record of your dealings with us in the event of any complaints, or if we reasonably believe there is a prospect of litigation relating to your personal data.
Right to restriction of processing. In cases where you believe that your personal data processed by us is inaccurate, you have the right to request that we restrict the processing of your personal data for the time necessary to verify the accuracy of your personal data and correct it, if necessary.
Right to data portability. In the case of automated processing or based on your consent or performance of the contract, you have the right to receive the data in a structured, commonly used and machine-readable format and to have them transmitted by us to another personal data controller.
Right to object to the processing of your personal data. You can object to the processing of your personal data by contacting us at email address info@stellarbase.ai.
Right to complain. You can lodge a complaint about how we process your personal data with a supervisory authority, specifically with the Office for Personal Data Protection of the Czech Republic, located at Podplukovníka Sochora 27, 170 00 Prague 7, Czech Republic, tel.: +420 234 665 111, e-mail: posta@uoou.cz.
Newsletter
If you wish to opt-out of receiving our marketing newsletter, you can withdraw your consent any time by clicking on the link at the bottom of every newsletter email. You can also withdraw your consent with receiving newsletter by contacting us at info@stellarbase.ai.
Cookies
Our Website does not currently use cookies or similar tracking technologies.
What else should you know?
Our company does not make decisions based on automated processing or profiling.
Our company has not appointed a data protection officer. We are not obliged to appoint a data protection officer in our company.
Contact information
If you have any questions about the processing of your personal data, please contact us at:
Email: info@stellarbase.ai
Address: Na Folimance 2155/15, Vinohrady, 12000 Praha 2
Changes to the privacy policy
We may update this privacy policy from time to time. The current version will always be listed on our Website.
This privacy policy is effective as of 2026-05-21.
