Version 1.0 · August 20, 2026

Privacy Policy

How the Acquisition Management System (AMS) handles account, CRM, research, onboarding, and integration data.

Who is responsible

The Visart operates AMS and is responsible for the processing described in this policy. Privacy questions and requests can be sent to info@thevisart.cz.


What AMS is

AMS is a restricted internal business application used to manage approved access, customer relationships, lead acquisition, client onboarding, and authorized external integrations. It is not a public social network or an advertising platform. The public client questionnaire is served on a separate, hostname-isolated origin and does not expose the internal AMS shell or database credentials.


Account and administration data

AMS may process administrator names, email addresses, account status, access roles, invite and setup state, authentication and security records, rate-limit identifiers, and limited technical audit information. Passwords, invite tokens, OAuth codes, and access-token values are not returned to the browser or stored in application logs.


CRM and contact data

CRM records may contain a person's name, email address, phone number, profile URL, job title, company details, source and provenance information, workflow stage, response timestamps, external identifiers, and safe records of authorized administrator activity. Contacts are managed as the organization's business records and are not exposed through direct browser access to the database.


Meta Lead Ads and Ads reporting

For the Meta Lead Ads integration, AMS may process the connecting account's Meta identifier and name, the selected Page and its forms, granted permissions, field mappings, webhook and delivery evidence, submitted lead answers, Meta identifiers, original submission times, processing attempts, CRM links, and response evidence. Only explicitly selected forms are activated. Meta user and Page access tokens are encrypted on the server and are never returned to the browser.

For the separate, read-only Meta Ads reporting workflow, AMS may process connection identities, business and ad-account metadata, campaign metadata, account currency and timezone, daily reporting metrics, objective-specific outcomes, sync checkpoints, and audit or failure state. The reporting workflow does not create, edit, or delete Meta ad objects. Reporting history is designed for a bounded period of up to 24 months, subject to the organization's accepted configuration and applicable provider requirements.


Google Contacts and Google Calendar

When an active AMS user explicitly connects their own Google account, AMS may process the shared connection identity, encrypted authorization envelope, Google resource mappings, scheduled Calendar event projections, CRM call matches, sync jobs, and structured audit metadata. Contacts and Calendar are independently enabled from one shared authorization. AMS copies only approved CRM fields, such as a name, phone, email, profile URL, company, job title, company website, and an AMS record link, into a separate AMS-managed Google Contacts group. The Contacts integration is one-way: AMS does not import Google contacts or alter unrelated personal contacts. Calendar access is read-only and AMS never creates or changes provider events. Google refresh tokens remain server-side, and Google integration audit metadata expires within one year.


Lead acquisition and research data

The lead-acquisition workflow may store saved-search settings, internal result and service-limit reservations, run and source-attempt state, actionable or incomplete candidates, source evidence, public business and professional contact methods, public social-profile URLs, dispositions, archives, provenance, failure details, and CRM import references. Sources can include Meta Ads Library, Google Maps, Firmy.cz, company websites, and related approved research providers. Public availability does not by itself make collection or outreach permitted; source restrictions, lawful basis, objections, and retention rules remain applicable.


Client onboarding and questionnaire data

Client onboarding may process published form revisions, link metadata, client-detail values, questionnaire answers, delivery email addresses, exact consent evidence, progress and bounded presence, submitted-response history, and delivery attempts. Administrators may upload intentionally public link preview images. Generated PDF artifacts are stored privately and are available only through an authenticated, record-bound route. Respondent voice recordings are bounded and discarded after server-side transcription; only transcript text accepted by the respondent can enter the ordinary answer workflow. Bearer tokens are hashed at rest, and the raw link is exposed only when a link is created.


Why we process data

We process data to operate and secure AMS, control approved access, administer accounts, maintain CRM records, respond to incoming leads, conduct bounded lead and company research, connect approved business accounts, synchronize explicitly enabled Google Contacts and Calendar services, provide read-only Meta Ads reporting, collect and deliver client onboarding questionnaires, generate requested PDFs and messages, troubleshoot failures, and maintain necessary security and audit evidence.


Legal basis and responsibility

Depending on the workflow and the people involved, processing may rely on requested service performance, legitimate interests in operating a secure business workflow, legal obligations, or consent where consent is required. The organization decides the applicable legal basis and required notices for its business activities; AMS does not replace those notices or provide formal legal advice.

The organization publishing a Meta instant form is responsible for the form's notice, consent language, targeting, and legal basis for collecting each lead's information. AMS processes that information for the authorized organization's CRM workflow and preserves the source and consent evidence it receives.


Service providers and transfers

Depending on the enabled workflow, data may be processed by Supabase for authentication, database, and storage services; Vercel for hosting and operational delivery; Meta and Google for connected services; the private scraping service for bounded lead-acquisition research; the Visart PDF service for requested PDF rendering; Resend for configured message delivery; and OpenRouter for server-side voice transcription. Provider-specific data may be transferred to the locations used by those services. Where processing occurs outside the European Economic Area, the responsible organization relies on applicable safeguards and relevant provider agreements.


Security

AMS restricts protected access to active approved administrators, keeps application credentials and integration tokens server-side, encrypts stored access-token envelopes, validates bearer tokens, verifies signed webhook requests, isolates the public questionnaire hostname, keeps PDFs private, rate-limits public operations, and records limited audit evidence. No internet service can guarantee absolute security, but these measures are designed to reduce unauthorized access, alteration, and disclosure.


Retention

Retention differs by data category. Account, CRM, lead, and imported business records are retained for as long as needed for the organization's workflow, account administration, security, audit, and legal or contractual obligations. Meta Ads reporting history follows its bounded reporting configuration, currently designed for up to 24 months. Google integration audit metadata expires within one year. Completed onboarding responses, private PDFs, and delivery attempts form immutable operational history until authorized deletion or the applicable retention limit. Rejected or duplicate research candidates should be removed when no longer needed. Temporary provider URLs are not stored as AMS artifacts, and voice recordings are discarded after transcription.


Cookies and browser storage

AMS uses necessary cookies and browser storage for authentication, onboarding, security, and application operation. Draft testing values and questionnaire progress may remain in browser memory where the workflow describes it, but they do not grant access to AMS data. AMS does not use marketing cookies unless they are introduced later with an appropriate notice and, where required, consent.


Your rights

Subject to applicable law, individuals may request access, correction, deletion, restriction, portability, or object to processing. They may also lodge a complaint with their competent data-protection authority. We may need to verify a requester's identity before acting and may retain information where required by law or necessary to protect legal claims or the organization's legitimate business records.


Deletion and integration disconnection

To request deletion of data associated with AMS or one of its integrations, email info@thevisart.cz with the subject “AMS Data Deletion Request.” Include enough information to locate the relevant account or record, such as an account email, Facebook Page, lead form, Google connection, onboarding link, or approximate submission date. Do not send passwords, access tokens, OAuth codes, bearer URLs, or other secrets.

We will confirm receipt, verify the request where necessary, and delete or anonymize eligible personal data. If information must remain for legal, security, audit, or lawful CRM recordkeeping reasons, we will explain the applicable limitation. Disconnecting Meta stops future imports, revokes or destroys stored connection credentials, and preserves imported business records under the organization's retention requirements. Disconnecting Google removes AMS-managed copies before revoking authorization and does not alter unrelated Google contacts. An authorized administrator can permanently delete a revoked onboarding link and its associated draft, responses, PDFs, delivery attempts, and link-owned preview asset.


Changes and contact

We may update this policy when AMS or its data practices change. The version date above identifies the current policy. Questions, rights requests, and deletion requests can be sent to info@thevisart.cz.