Privacy policy
This policy explains how TORLIN processes personal data when you use the website, mobile application and related services.
Effective 8 September 2026Data controller
The data controller is HEADSOFT s.r.o., Durychova 101/66, 142 00 Prague 4, Czech Republic, Company ID: 05451507, VAT ID: CZ05451507. The company operates the TORLIN service. Contact info@headsoft.cz for questions or to exercise your rights.
Data we process
We process account and sign-in data (such as username, email and session details), technical device and app data, and data required to deliver notifications.
When you use a camera system, events may include images and metadata made available by your system operator.
How we use data
We use data to authenticate users, operate and secure the service, deliver requested alerts, provide support and meet legal obligations. We do not use it for advertising profiling.
Retention and security
We retain data only as long as needed for these purposes or as required by law. Access is permission-controlled and protected with safeguards appropriate to the data. Your system settings determine the specific retention period for camera recordings.
Cloud camera recordings
If a client chooses cloud storage, camera recordings and related metadata are transferred to and stored in cloud infrastructure provided by HEADSOFT. To the extent that the client determines the purpose and retention period, HEADSOFT processes these recordings as a processor on the client’s documented instructions.
Cloud recordings are accessible only to the client’s authorised users and to personnel providing support or operating the service, and only to the extent necessary. The client can delete recordings and set their retention period. After the service ends, recordings are deleted in accordance with the contract and technical possibilities, except data that must be retained by law.
Sharing
We may share data with infrastructure and push-notification providers only as needed to operate the service and subject to contractual and security safeguards. We do not sell personal data.
Your rights
You may request access, correction, deletion, restriction or portability of your data, and you may object to processing. You may also complain to your local data protection authority.
Website and application analytics
Without consent, the public website records only an anonymous view of the specific page. We do not attach an IP address, visitor or device identifier, traffic source, or location to this record.
After consent, we may additionally measure sessions and repeat visits, active time, sections viewed, scroll depth, selected buttons and forms, device type, traffic source, and an approximate city derived on the server using a local DB-IP database. We do not store the raw IP address in analytics, send it to a third-party geolocation service when deriving the city, use the data for advertising, or override Do Not Track. Public analytics data is retained for no more than 365 days.
In the signed-in application, we record visited areas, the application session, and the user account to improve, support, and secure the service. Successful data and settings changes are kept in a separate audit log without form contents. Product analytics is retained for no more than 395 days and audit records for no more than three years.
Cookies
We store the analytics choice in a necessary cookie for no more than 12 months. Only after consent do we create an analytics visitor identifier valid for up to 12 months and a session identifier renewed during activity and expiring after 30 minutes of inactivity. You can change your choice at any time using “Analytics settings” in the website footer; rejecting analytics removes these identifiers. We do not use marketing cookies or advertising profiling.
For questions about personal data, contact us at info@headsoft.cz.
