Privacy Policy
This policy applies to the application at https://traffic.axonflow.cz (the "service"). Rules for using the service are set out in the Terms of Use.
Who processes your data
axnflw s.r.o., company ID (IČO) 24457442, Příčná 1892/4, 110 00 Prague 1, Czech Republic ("we"). Contact for anything related to personal data: info@axonflow.cz. We have no data protection officer; write directly to this contact.
We process the personal data described in this document as a controller. Where we act on your organisation's instructions for some processing operations (as a processor), that processing is governed by the contract with your organisation.
Who this policy covers
Users of the service. There is no public sign-up — we create accounts under the contract with your organisation (your employer or the organisation that engaged you). Your organisation provides the account data (name, e-mail, role) and decides who gets an account.
What data we hold about you
| Category | Specifically | Why |
|---|---|---|
| Account | name, e-mail, avatar URL, role, interface language, flags for two-factor authentication and account blocking; when you sign in with a Microsoft account, Entra ID identifiers — OID and TID (Microsoft's internal identifiers of your account and your organisation) | operating your account |
| Sign-in | password hash (we never store the password itself), OAuth tokens of sign-in providers | verifying your identity |
| Two-factor authentication | TOTP secret, backup codes | second sign-in factor, if you enable it |
| Sessions | IP address, browser and OS (user agent), time of sign-in and last activity | securing sign-ins; a session lasts 7 days, activity extends it (at most once per 24 hours) |
| Web server logs | records of requests to the server: IP address, time, request method and URL, status code, browser (user agent) and referring page | operating the service and resolving incidents |
| Analytics and diagnostics | your actions in the app, session recordings (session replay) including screen content, browser console logs and application logs; identified by e-mail — details below under Analytics | finding where the app fails and reproducing bugs |
| Admin audit log | who changed what in the service administration, and when | permanent record of administrative actions (details under How long we keep data) |
| Feedback | report text, page URL, device and browser parameters, time zone and a screenshot (the original and the version with your annotations) | handling your report — the screenshot shows us exactly what you see |
Traffic data is not personal data
The core of the service is traffic data — speeds, travel times and queue lengths, aggregated per road segment. It contains no vehicle identifiers, no licence plates and no GPS traces of individual trips. It is not personal data and this policy does not apply to it.
The data source is NDIC (the Czech National Traffic Information Centre, operated by the Road and Motorway Directorate of the Czech Republic, ŘSD). The source of digitised road traffic information is NDIC.
Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Operating accounts and sign-in | legitimate interest — providing your organisation the contracted service and managing its user accounts |
| Security (sessions, 2FA, audit log) | legitimate interest in protecting accounts and proving administrative actions |
| Analytics and diagnostics of app behaviour | legitimate interest — seeing where the app fails or confuses users, and reproducing bugs |
| Web server logs | legitimate interest in operating the service and resolving incidents |
| Feedback | handling your report (legitimate interest) |
You can object to any processing based on legitimate interest at info@axonflow.cz. We make no automated decisions about you, and we never use analytics data to evaluate you or your work performance — only to find bugs in the app.
Analytics: what exactly we record
We use PostHog (EU cloud, eu.i.posthog.com). It records:
- your actions in the app (clicks, navigation between screens),
- session recordings (session replay) — a recording of the app screen including its content, i.e. also the map, zones and analysis results you have open,
- your browser's console logs (application error messages),
- server-side application logs.
In PostHog you are identified by your e-mail — when you report a bug, we find your exact session instead of asking you for reproduction steps.
We handle objections to analytics within one month. If we uphold your objection, we stop recording your account and delete the records we already hold.
Who receives your data
Exactly these recipients and no others:
| Recipient | What it receives | Where processing runs |
|---|---|---|
| PostHog | behavioural analytics, session recordings including screen content, browser console logs and application logs; identified by e-mail | EU cloud (eu.i.posthog.com) |
| Grafana Cloud (Loki) | web server logs, 14-day retention | EU |
| Hetzner Online GmbH | hosting of both the application and the database | Nuremberg data centre, Germany |
| Microsoft Entra ID / Google | only if you sign in through them; they run the sign-in process as independent controllers under their own terms | per their terms, may include transfers outside the EU |
| OpenStreetMap Nominatim | the text you type into address search, and your IP address | the request goes from your browser directly to their servers; their processing is governed by their terms and may include transfers outside the EU |
| CARTO | map tile requests and your IP address | tiles load directly from your browser; their processing is governed by their terms and may include transfers outside the EU |
We do not sell personal data. Beyond the recipients above, we may disclose it only to public authorities where the law requires us to. An expansion of the recipient list is a material change to this policy (see Changes to this policy).
Nominatim and CARTO requests go directly from your browser — they never pass through our servers, and (as with any web request) the provider sees your IP address. Only what the feature needs is sent: the search text, or the map tile request.
Cookies and local storage
| Name | Purpose | Lifetime | Note |
|---|---|---|---|
__Secure-better-auth.session_token |
keeps you signed in | 7 days | httpOnly — not readable by scripts |
| two-factor cookies (better-auth family) | the 2FA sign-in step | only for the duration of signing in | httpOnly |
fcd-locale |
your interface language | ~400 days | readable by JavaScript |
In the browser's local storage we also keep: fcd-theme (dark/light mode),
fcd:last-zone-id (last opened zone) and PostHog's storage (analytics; PostHog
sets no cookies of its own).
The service shows no cookie consent banner. The sign-in and language cookies are necessary for the service to work; analytics runs on our legitimate interest (see above) and you can object to it at info@axonflow.cz.
How long we keep data
| Data | Period |
|---|---|
| Session records (IP, user agent) | 7 days from last activity |
| Web server logs | copy in Grafana Cloud 14 days; we rotate the original on the server by file size, with no fixed period |
| Analytics data, session recordings and application logs (PostHog) | no automatic period set by us; deleted on request |
| Admin audit log | never deleted — so we can prove who changed what in administration |
| Account and feedback | no automatic period; deleted on request by you or your organisation |
| Measured traffic data | no retention period — not personal data |
When your organisation's contract ends, its users lose access. We delete user data on the organisation's request via info@axonflow.cz; on request we hand over the organisation's content (zones and their settings) in the format we hold it in, or delete it.
Your rights
You have the right to access your data, to rectification, erasure, restriction of processing, and to object to processing based on legitimate interest.
How: write to info@axonflow.cz. We respond within one month.
There is no self-service account deletion or data export in the app. Your organisation's administrator can deactivate an account and remove it from the organisation; we carry out account deletion or data export manually on your request.
Exception: we do not delete admin audit log records (see How long we keep data).
Think we process your data unlawfully? Complaints are handled by the Czech data protection authority (Úřad pro ochranu osobních údajů / Office for Personal Data Protection, uoou.gov.cz).
Security and incidents
Communication with the service is encrypted (HTTPS). Passwords are stored only as hashes. The sign-in cookie is httpOnly and Secure. You can protect your account with two-factor authentication. Both the application and the database run in the EU (Germany).
When resolving an incident, our administrator may temporarily sign in under your account (impersonation). Only the operator's superadmin can do this, every such sign-in is written to the audit log and the record is never deleted; we provide your organisation a list of impersonations on request.
If a personal data breach occurs, we follow the GDPR: we notify the Office for Personal Data Protection within 72 hours of becoming aware (where notification is required) and inform the affected organisation no later than 72 hours after becoming aware — with a description of the scope of the incident and of the measures taken. If the incident poses a high risk to you personally, we inform you directly.
Changes to this policy
We publish changes on this page and update the date below. We notify your organisation of material changes — an expanded recipient list, a new processing purpose, a restriction of your rights — at least 30 days in advance: with an in-app notice and an e-mail to your organisation's contact person.
This policy exists in Czech and English; in case of conflict, the Czech version prevails.
Last updated: 30 July 2026