Privacy Policy

Effective date: 1 June 2026 Version: 2026-06-01

This Privacy Policy describes how PMG Capital s.r.o. processes the personal data of users of the PMGclub platform (pmgclub.com) and the related portal miroslavpekarek.com.

This Policy is prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation, "GDPR") and Czech Act No. 110/2019 Coll., on Personal Data Processing.


1. Data Controller

The controller of your personal data is:

PMG Capital s.r.o. Bohuslava Niederleho 1018, 272 04 Kladno, Czech Republic Company ID (IČO): 06998771 VAT ID (DIČ): CZ06998771 Email: info@pmgclub.com Web: pmgclub.com

The controller is not required to appoint a Data Protection Officer (DPO) under Article 37 GDPR. For all enquiries and to exercise your rights, please contact the email address above.

2. Personal Data We Process

2.1 Registration data

  • email address (required, for sign-in)
  • password (stored as a secure hash — the controller has no access to the plaintext)
  • first and last name
  • username (handle, visible to other users)

2.2 Profile data (optional)

  • avatar and cover image
  • bio, headline, location, website, company name, role/position
  • answers to profile questions

2.3 Billing data (for paid subscriptions)

  • billing name / company name
  • address, city, postal code, country
  • Company ID and VAT ID (for business entities)
  • payment and invoice history
  • we do not store payment card numbers or banking credentials — payments are processed by Mo.one or by the user's bank directly

2.4 Content data

  • posts, comments, reactions (likes)
  • private messages between users
  • created presentations, AI notebooks (Pekari), QLive events
  • uploaded files (images, documents, audio)
  • poll responses

2.5 Relationship data

  • connections with other users and their status
  • participation in QLive presentations
  • game results (Games)

2.6 AI usage data

  • type of AI operation performed (text, translation, image, voice)
  • provider and model used (OpenAI / Anthropic / ElevenLabs)
  • tokens / characters consumed
  • credits spent and approximate cost
  • timestamps of usage

2.7 Technical and operational data

  • IP address (logged in the billing audit log and in server logs for security)
  • browser and device type (User-Agent, in server logs only)
  • timestamps of sign-in and key actions
  • language preference
  • Content Security Policy (CSP) violation reports
  • post impression records used for the recommendation algorithm

2.8 Consents

  • timestamp and version of acceptance of the Terms of Service and this Privacy Policy
  • cookie preferences

3. Purposes and Legal Bases of Processing

Purpose Legal basis (GDPR) Retention period
Operating the account, providing services, authentication Art. 6(1)(b) — performance of a contract for the duration of the account
Issuing and archiving invoices Art. 6(1)(c) — legal obligation (§ 35 Czech VAT Act) 10 years from the end of the tax period
Accounting and taxes Art. 6(1)(c) — legal obligation (Czech Accounting Act) 5–10 years
Billing audit log (incl. IP address) Art. 6(1)(c) + (f) — legal obligation + legitimate interest 5 years
Platform security and abuse prevention Art. 6(1)(f) — legitimate interest (security) 30 days (server logs), 90 days (CSP reports)
Recommendation algorithm and feed personalisation Art. 6(1)(f) — legitimate interest for the duration of the account
Service communication (operational emails) Art. 6(1)(b) — performance of a contract for the duration of the account
Marketing communication (newsletter, offers) Art. 6(1)(a) — consent until consent is withdrawn
Service improvement based on anonymised analytics Art. 6(1)(f) — legitimate interest aggregated, indefinitely

Legitimate interest — the controller has performed a legitimate interest assessment (LIA) and considers that its legitimate interests are not overridden by the rights and freedoms of users. You may object to processing based on legitimate interest at any time (Art. 21 GDPR).

4. Recipients of Personal Data (Third-Party Processors)

To operate the platform, we use the following providers who, acting as processors, process your personal data exclusively under our instructions and on the basis of Data Processing Agreements (DPAs):

4.1 Infrastructure and hosting

Provider Purpose Data location Transfer mechanism
Supabase, Inc. Database, authentication, file storage EU — Dublin (eu-west-1) Data remain in the EU
Vercel, Inc. Application hosting, CDN USA (edge nodes in the EU) Standard Contractual Clauses (SCCs), EU-US Data Privacy Framework
Cloudflare, Inc. (R2) File storage (images, video) Global distribution Standard Contractual Clauses (SCCs)

4.2 AI services

Provider Purpose Location Note on AI training
OpenAI, L.L.C. Text generation (GPT-4o-mini), translations, embeddings, TTS, image generation USA Data are not used to train models (API tier)
Anthropic, PBC Advanced text processing, AI Vision (Claude) USA Data are not used to train models (API tier)
ElevenLabs Inc. Text-to-speech voice generation for presentation narration USA Per ElevenLabs terms

Transfers to the USA: All US providers are either certified under the EU-US Data Privacy Framework, or transfers are conducted on the basis of Standard Contractual Clauses (SCCs) approved by the European Commission.

4.3 Payments

Provider Purpose Location Role
Mo.one (operated by Z-net Technologies s.r.o., znpay.tech) Processing bank transfer payments (CZ only) Czech Republic Independent controller — Mo.one processes payment data under its own privacy policy

4.4 Communication

Provider Purpose Location Mechanism
Resend (Resend, Inc.) Transactional email delivery (registration confirmation, invoices, notifications) USA + EU SCCs

4.5 Optional integrations

Provider Purpose Activation
LinkedIn (Microsoft Ireland Operations Limited) Sharing content from the platform to the user's LinkedIn account Only if the user connects their LinkedIn account (OAuth)

4.6 Statutory recipients

Where required by law, we may disclose data to: - tax and financial authorities - law enforcement authorities - courts and public prosecutors

5. Retention Periods

Data category Retention
Account and profile for the duration of the registration
Content (posts, comments, messages) for the duration of the account; after account deletion, content is anonymised or deleted
Invoices and tax documents 10 years (§ 35 of Czech Act No. 235/2004 Coll., on VAT)
Accounting records 5 years (§ 31 of the Czech Accounting Act)
Billing audit log (incl. IP address) 5 years
AI usage log 12 months
Credit transaction records for the duration of the account + 3 years
Server logs (IP, User-Agent) 30 days
CSP reports 90 days
Consent records 3 years after withdrawal or account termination

Upon account deletion the following occurs: - immediate removal of publicly visible profile data - anonymisation of content (author = "deleted user") or its complete deletion - retention of invoices and related data for the statutory period with detachment from the identifiable person where possible (Art. 17(3)(b) GDPR — processing necessary for compliance with a legal obligation)

6. Your Rights

Under the GDPR you have the right to:

  • Right of access (Art. 15 GDPR) — obtain confirmation of whether we process your personal data, and a copy of those data.
  • Right to rectification (Art. 16 GDPR) — correct inaccurate data or complete incomplete data. Most profile data can be edited directly in your account settings.
  • Right to erasure / "right to be forgotten" (Art. 17 GDPR) — request deletion of your account and related data. Erasure is available in your profile settings. Data we are legally required to retain (invoices, accounting) will remain archived for the statutory period.
  • Right to restriction of processing (Art. 18 GDPR) — request the temporary halting of processing.
  • Right to data portability (Art. 20 GDPR) — receive your data in a machine-readable format (JSON). Export is available in your profile settings.
  • Right to object (Art. 21 GDPR) — object to processing based on legitimate interest, including the recommendation algorithm and personalisation.
  • Right to withdraw consent (Art. 7(3) GDPR) — withdraw consent for processing based on consent (e.g. marketing communication) at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
  • Right not to be subject to automated decision-making (Art. 22 GDPR) — the controller does not engage in automated decision-making with legal effect on users.

6.1 How to exercise your rights

  • In-app — account deletion, data export, and profile editing are available in settings
  • By email — at info@pmgclub.com

We will respond to requests within 30 days. In justified cases (complexity, volume of requests) this period may be extended by a further two months, of which you will be informed.

We reserve the right to verify the identity of the requester by reasonable means (e.g. confirmation from the registered email address).

6.2 Right to lodge a complaint

If you believe that we process your personal data unlawfully, you have the right to lodge a complaint with the Czech Office for Personal Data Protection:

Úřad pro ochranu osobních údajů Pplk. Sochora 27, 170 00 Prague 7, Czech Republic www.uoou.cz Phone: +420 234 665 111 Email: posta@uoou.cz

Citizens of other EU Member States may also lodge a complaint with the supervisory authority in their country.

7. Cookies and Similar Technologies

The platform uses cookies and similar technologies (localStorage). For details, please refer to our separate Cookie Policy.

8. AI Features — Specific Processing

When you use AI features (text generation, translation, AI images, voice narration), the inputs (prompts, uploaded documents, text for translation) are transmitted for processing to the AI providers listed in section 4.2.

Important information:

  • Inputs to AI features are not used to train the models of providers who offer this guarantee at the API level (OpenAI, Anthropic).
  • We strongly advise against entering sensitive personal data (health information, data about minors, passwords, financial details of third parties) into AI features — the user is solely responsible for the content of inputs.
  • AI outputs may contain inaccuracies. The controller does not warrant the accuracy of AI outputs (see Terms of Service, Article 10).

Detailed information about AI features is available in the AI Policy.

9. Children and Age Restriction

The platform is intended for persons aged 16 and over. We do not knowingly process data of persons under 16. If we learn that an account has been created by a person under 16, we will delete it without delay.

If you are a parent or legal guardian and believe that your child is using the platform contrary to this rule, please contact us at info@pmgclub.com.

10. Data Security

The controller implements appropriate technical and organisational measures to protect personal data, in particular:

  • encryption in transit (HTTPS / TLS)
  • encryption of sensitive data in the database (passwords are hashed, not reversibly encrypted)
  • Row Level Security (RLS) in the Supabase database, ensuring users can only see their own data
  • authentication via Supabase Auth with strong password support
  • limited employee access to the database (only essential personnel)
  • Content Security Policy (CSP) to prevent XSS attacks
  • regular updates of dependencies and infrastructure
  • automatic database backups

However, no measure can guarantee 100% security. In the event of a personal data breach likely to result in a risk to the rights and freedoms of users, we will notify users without undue delay, and no later than 72 hours after becoming aware of it (Art. 33–34 GDPR).

11. Changes to this Policy

This Policy may be updated from time to time. We will notify users of material changes:

  • by email to the registered address, at least 14 days in advance,
  • via in-app notification.

In case of a material change (different processing purpose, new processor, extended retention period), re-confirmation of consent may be required.

The version history of this Policy is archived and available upon request. The version you accepted at registration or at the last consent update is stored in your profile (gdpr_consent_version).

12. Contact

For any questions, requests to exercise your rights, or complaints, please contact:

PMG Capital s.r.o. Bohuslava Niederleho 1018, 272 04 Kladno, Czech Republic Email: info@pmgclub.com


Effective from: 1 June 2026 PMG Capital s.r.o. · Company ID: 06998771 · VAT ID: CZ06998771