DR DR-files

Политика конфиденциальности

Документ доступен на английском и чешском языках. Юридическую силу имеет чешская версия.

This document describes which personal data we process when operating the website https://www.dr-files.com and providing the ECU file modification service, why we process it, to whom we disclose it and what rights you have. Processing complies with Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 Coll., on personal data processing.

1. Data controller

The controller is DR CARS services s.r.o., Holická 117/49a, 77900 Olomouc, Company ID 17677297. For any matter concerning personal data, contact us at info@dr-files.com. We have not appointed a data protection officer, as we are not required to do so.

2. Which data we process

  • Identification and contact data – name, email, phone; for businesses the company name, company ID, VAT ID and billing address.
  • Vehicle and ECU data – make, model, engine, year, ECU type, HW/SW number, reading tool and method, and optionally the VIN.
  • Uploaded files – the original and the modified ECU file. The file may contain the VIN or other vehicle identifiers.
  • Order and payment data – ordered services, price, currency, status, invoice number, payment identifier at the payment gateway. We neither see nor store card details; they are processed by Stripe.
  • Communication – messages and attachments you send us via the contact form, order messages or email.
  • Account data – for registered customers the login email, password (stored only in a secure hashed form), two-factor authentication and passkey settings, saved billing details.
  • Evidence of consent – the time the terms and declarations were confirmed, their version, IP address and browser identification.
  • Technical data – IP address, browser type, access time, error and security logs, cookies (see the Cookie policy).
  • Visitor statistics (without cookies) – IP address, device and browser type, pages viewed, time on page and where you came from. The IP address and browser let us recognise a repeat visit.
  • Data for verifying the welcome offer – VIN, a fingerprint (checksum) of the uploaded file, email and phone in a comparable form, company ID, the IP address at registration and order, and a card fingerprint from Stripe (an anonymous identifier, not the card number). Only with your consent when claiming the offer, also a random device identifier stored in a cookie and a browser fingerprint – a summary value calculated from technical properties of the device (e.g. screen resolution, time zone, graphics card, installed fonts).

We obtain the data directly from you. Providing contact data, vehicle data and the file is necessary to conclude and perform the contract; without them the service cannot be provided.

3. Why we process the data and on what legal basis

  • Performance of a contract (Art. 6(1)(b) GDPR) – receiving and processing the order, modifying the file, communicating about the order, delivering the file, maintaining the customer account, handling complaints and refunds.
  • Compliance with legal obligations (Art. 6(1)(c) GDPR) – issuing and retaining tax documents, bookkeeping, obligations under tax and consumer protection law.
  • Legitimate interest (Art. 6(1)(f) GDPR) – securing the website and preventing misuse, visitor statistics, verifying that the welcome offer is used only once per person and per vehicle (comparing the VIN, file, contact details, IP address and card fingerprint with earlier orders), proving the conclusion of the contract and the consents given, defending legal claims, internal records and improving the service. You may object to processing on this basis.
  • Consent (Art. 6(1)(a) GDPR) – analytics cookies (withdraw consent in the cookie settings) and the device identifier with browser fingerprint when claiming the welcome offer (without consent the offer cannot be claimed, an order at the regular price is always possible; you may ask us to erase data already stored at any time).

We do not use the data for automated decision-making with legal effects or for marketing without your consent.

4. To whom we disclose the data

We disclose data only to recipients who need it to provide the service, and only to the necessary extent:

  • Stripe Payments Europe, Ltd. (Ireland) – processing payments and refunds; we pass on the email, amount, currency and order number. From Stripe we receive a card fingerprint (an anonymous identifier that is the same for the same card) to verify the welcome offer.
  • External file modification specialists (subcontractors) – for some modifications we pass on the uploaded file and the technical vehicle and ECU data. We do not pass on your name, contact or billing details.
  • Hosting and email service providers – operating the server, file storage and sending emails.
  • Accountant and tax adviser – bookkeeping and tax documents.
  • Google Ireland Ltd. – website analytics, only if you have consented to analytics cookies.
  • Public authorities where required by law.

We do not sell data. Where data is transferred outside the European Economic Area (e.g. for payment processing or analytics), this is done on the basis of a European Commission adequacy decision or standard contractual clauses.

5. How long we keep the data

  • Files of unpaid orders are deleted after 48 hours; the remaining data of an unpaid order after 90 days.
  • Files of completed orders are kept for the duration of the customer account, but no longer than until you request deletion.
  • Order data, invoices and evidence of consent are kept for 10 years from the end of the year in which the order was completed (accounting and VAT law, limitation periods).
  • Messages and attachments are kept for 3 years from the last message.
  • The device identifier, browser fingerprint, card fingerprint and the IP address at registration are deleted 3 years after the order or registration.
  • Visitor statistics records including the IP address are deleted after 12 months.
  • Customer account data is kept until the account is deleted. After deletion, orders and invoices remain stored for the period above but are no longer linked to the account.
  • Technical logs are kept for a maximum of 12 months.

6. Your rights

You have the right:

  • to access your personal data and obtain a copy of the data we process about you,
  • to rectification of inaccurate or completion of incomplete data (billing details can be edited in your account),
  • to erasure of data that is no longer needed, unless a legal obligation prevents it (e.g. retention of invoices),
  • to restriction of processing and to portability of the data you have provided to us,
  • to object to processing based on legitimate interest,
  • to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal,
  • to lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, www.uoou.cz, or with the supervisory authority in your country of residence.

Send requests to info@dr-files.com. We will respond without undue delay and within one month at the latest. To protect your data we may verify your identity before handling the request (e.g. by confirmation from the email address used in the order).

7. Security

The website is served exclusively over an encrypted connection (HTTPS). Uploaded files are stored outside the publicly accessible part of the server and can be downloaded only by their owner, by a person with a signed link from the email, and by the administrator. Access to the administration is protected by two-factor authentication. Passwords are stored only as hashes.

8. Cookies

The use of cookies and similar technologies is described in the separate Cookie policy.

9. Changes to this document

We may update this document, for example when processors or the scope of the service change. The current version is always available on this page. This version is effective from 28 September 2026.