1. Who is responsible for your data
The controller of personal data in the chat service at https://chat.wespner.eu (the “Service”) is Miroslav Grešák, a sole trader doing business under the trade name Wespner.
- Business ID (IČO): 22249371
- Registered address: Husova třída 310, 345 62 Holýšov, Czech Republic
- Privacy requests: [email protected]
- Reports of illegal content and abuse: [email protected], ideally with the subject “Illegal content report”
We process personal data under Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 Coll. on personal data processing. We have not appointed a data protection officer because the law does not require one for our processing.
2. What this policy covers
This policy covers the Service: the web app at chat.wespner.eu, our server and the voice and video infrastructure behind it.
It does not cover:
- the official Fluxer apps and websites, which Fluxer Platform AB runs under its own privacy policy;
- websites and services you open from links in the Service;
- our other Wespner services, such as game and web hosting, which have a separate privacy policy.
The Service runs on the open-source Fluxer software. Our server does not send your data to the developers of Fluxer, except for the push notifications described in Section 6.
3. What data we process
Account data. Your email address, username, display name, password (stored only as a one-way hash) and date of birth. If you turn on two-factor authentication, we also store the data it needs.
Profile. Optional details you add, such as an avatar, banner, bio, pronouns or status. Other users can see them.
Content. Messages, files, images, reactions, custom emoji and stickers, communities, channels, invites, direct and group messages, notes, saved messages and settings.
Calls. Voice and video pass through our media server in real time; we do not record them. When you share your screen, a small preview image may be created so participants can see what you are sharing.
Technical and security data. IP addresses, the approximate country derived from your IP address, device, browser and operating system details, sign-in sessions, IP addresses you have approved for signing in, time of your last activity and security events such as sign-in attempts. We look up the country on our own server in a local database; your IP address is not sent anywhere for this. This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.
Notifications. If you turn on push notifications, the push address of your device or browser.
Reports and moderation. Reports you file and reports about you, including a copy of the reported content with surrounding messages and attachments, our decisions, and community bans, which record the banned account, its email address and its last IP address.
Communication with us. Messages you send to [email protected], our replies, and the service emails we send you, such as verification, password reset and security notices.
Data exports. The archive created when you ask for a copy of your data.
We do not ask for special categories of data, such as health information or political opinions. If you include them in your content, we process them only to deliver that content as you chose.
4. Why we process your data and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Running your account; sending service emails such as verification, password reset and security notices; delivering messages, calls and notifications; search; communities | email address, account, profile, content, technical data, push address | performance of a contract, Art. 6(1)(b) |
| Checking the minimum age and applying age restrictions | date of birth, approximate country | performance of a contract and our legitimate interest in protecting children, Art. 6(1)(b) and (f) |
| Security, preventing spam and abuse, enforcing our Terms and community bans | technical and security data, moderation records | legitimate interest in a safe and secure Service, Art. 6(1)(f) |
| Handling notices of illegal content, statements of reasons, cooperation with authorities | reports, moderation records, data requested by authorities | legal obligation under the Digital Services Act and Czech law, Art. 6(1)(c) |
| Answering your requests | communication with us | performance of a contract or legal obligation, Art. 6(1)(b) and (c) |
| Establishing or defending legal claims | the records concerned | legitimate interest, Art. 6(1)(f) |
You can object to processing based on legitimate interest (Section 10). We do not use your data for advertising, profiling or training AI models, and we do not sell it.
Your email address, username, password and date of birth are required to create an account. Without them, we cannot provide the Service.
5. Who can see your data
- Other users see your profile and the content you send to them or to channels they can access. Communities listed in the directory can be found by any user of the Service.
- Community moderators see the content in their communities and their moderation log, and can remove content and members.
- Our administrators can technically access all data on our server, because the Service does not use end-to-end encryption. We access content only to handle reports, investigate security incidents or abuse, or comply with the law.
Anyone who receives your messages can save or forward them.
6. Service providers and other recipients
| Recipient | Role | Data they receive |
|---|---|---|
| OVH Groupe SAS (France) | server hosting, data centre in Germany | all data stored in the Service |
| Cloudflare, Inc. | storage of backups in the EU | backups encrypted before they leave our server; Cloudflare cannot read them |
| Seznam.cz, a.s. (Czech Republic) | email hosting for [email protected] and sending of service emails | your email address, the service emails we send you, and messages you send us with our replies |
| Fluxer Platform AB (Sweden) | push relay for the official mobile apps | encrypted notifications and your device’s relay address |
| Apple, Google | delivery of notifications to mobile devices | device identifier and encrypted notification |
| Your browser’s push service (e.g. Google, Mozilla, Apple, Microsoft) | delivery of browser notifications | browser push address and encrypted notification |
| Klipy | GIF search | your search terms, sent by our server without your IP address |
| Public authorities | only where the law requires it | the data specified in the request |
Push relay. The official mobile apps can receive notifications from our server only through a relay run by Fluxer Platform AB. Notification content is encrypted for your device, so Fluxer cannot read it; Fluxer records delivery details such as the time and size. The relay is used only if you turn on notifications in the app. See Fluxer’s push relay notice.
Links and embeds. When you post a link, our server fetches the page to build a preview, so the website sees a request from our server, not from you. If you play an embedded video, for example from YouTube, your device connects to that provider, which processes your data under its own policy.
7. Transfers outside the EU
The Service’s data is stored in the EU: our server is in Germany, and backups are stored in the EU.
Cloudflare, Apple and Google are US companies. Where they or any of our other providers process data outside the EU, the transfer relies on the EU–U.S. Data Privacy Framework (Art. 45 GDPR) or on standard contractual clauses (Art. 46 GDPR).
The push relay runs on Fluxer’s own infrastructure, which according to Fluxer’s privacy policy is located in the United States. Notification content stays encrypted throughout.
8. How long we keep data
| Data | How long we keep it |
|---|---|
| Account and profile | Until you delete your account; deletion takes effect after a 14-day grace period. If you have not used your account for 2 years, we warn you by email and delete it if you do not sign in within 30 days. |
| Messages and files | Until you, the community owner or our moderation delete them. After account deletion, your messages remain as sent by “Deleted User” unless you delete them first. Attachments may expire earlier under our storage settings. |
| Sign-in sessions | While the session exists. You can end sessions in your account settings. |
| Server logs | Up to 30 days. |
| Reports and moderation records | As long as needed to handle the report, any review and possible legal claims, normally up to 1 year after the case is closed; longer only if the law or ongoing proceedings require it. |
| Community bans | Until the ban is lifted or the account is deleted. |
| Data export archives | 7 days. |
| Communication with us | Until the matter is resolved, then up to 3 years for possible legal claims. |
| Backups | Encrypted backups are rotated, usually within 60 days. We restore them only to recover from a failure. |
9. Security
- Connections to the Service are encrypted (TLS).
- Passwords are stored only as one-way hashes.
- You can protect your account with two-factor authentication, and we may ask you to confirm sign-ins from new IP addresses by email.
- Access to our servers is limited to our administrators.
- Backups are encrypted before they leave our server.
The Service does not use end-to-end encryption, so our server can technically read messages and call media while handling them.
If a personal data breach occurs, we notify the Czech Office for Personal Data Protection within 72 hours where the law requires it. If the breach is likely to put you at high risk, we inform you without undue delay by email or in the Service.
10. Your rights
You have the right to:
- access your data and get a copy (Art. 15 GDPR);
- correct inaccurate data (Art. 16);
- have your data erased (Art. 17);
- restrict processing (Art. 18);
- receive your data in a machine-readable format (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- lodge a complaint with a supervisory authority (Art. 77).
You can do much of this yourself in the app: download a copy of your data as a ZIP archive of machine-readable files in your privacy settings, edit your profile, delete your messages and delete your account.
For other requests, write to [email protected]. Please write from the email address on your account so we can verify that the request comes from you. If that is not possible, we may ask for other proof that the account is yours. We reply within one month; in complex cases we may extend this by two more months and tell you why.
The supervisory authority in the Czech Republic is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, https://www.uoou.gov.cz. You can also contact the authority in the country where you live.
11. Cookies and browser storage
The web app does not use cookies for tracking, analytics or advertising. It keeps your sign-in and preferences in your browser’s local storage, which is strictly necessary for the Service to work and does not require consent.
Embedded content from other websites, such as video players, may set its own cookies when you interact with it.
12. Children
The Service is not meant for anyone below the minimum age in Section 3 of our Terms of Service: at least 13 years, or more where the law of your country requires it, for example 15 in the Czech Republic and 16 in Slovakia. At sign-up, we ask for your date of birth and check it against the minimum age for your country. Users under 18 must not access channels marked as age-restricted.
If we learn that an account belongs to a child below the minimum age, we delete it. Parents and guardians can contact us at [email protected].
13. Automated decisions and changes to this policy
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. Automated protections, such as rate limits, a proof-of-work check and blocklists, only stop specific technical actions; restrictions of accounts are decided by our team.
We may update this policy when the Service or the law changes. We announce material changes in the Service at least 30 days in advance, and the date of the last update is shown at the top.
This policy applies from 8 October 2026.