Policy
Patronito Platform Privacy Policy
Effective date: 1. 1. 2026
1. Introductory provisions and connection with the Terms of Use
This Privacy Policy (hereinafter referred to as the “Policy”) constitutes an integral part of Terms of use of the Patronito platform and other contractual documents, including the Code of Ethics and Grant Agreement. Our goal is to provide you with a completely transparent, understandable and comprehensive overview of how we handle your personal data within our international ecosystem, how we protect it and what your rights are.
By enabling global funding for socially beneficial projects, the Patronito platform is subject to the strictest privacy standards, both under the European General Data Protection Regulation (GDPR) and the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA). In the event of any interpretative ambiguity for users from the European Union (EU) and the European Economic Area (EEA), the Czech language version of this document is always decisive.
2. Data controllers and determination of primary jurisdiction
Due to the international nature of the platform, which seamlessly connects donors (Patrons) and project implementers (Guarantors) from different continents, your personal data is managed by two cooperating entities. The management of your basic data is governed by the jurisdiction in which you have registered:
For users outside the EU/EEA and for international projects: Your primary administrator is a Canadian organization United Patrons (BN: 708235551TZ0001, OCN: 1001025182, located at: 7030 Woodbine Avenue, Markham ON, Canada). The processing of your information is subject to Canadian law, primarily PIPEDA.
For users from the EU/EEA and for local Czech projects: Your primary administrator is Patroni Česka (IČ: 23301660, with registered office: Křižíkova 661, 256 01 Benešov, Czech Republic). The processing of your data is fully subject to the GDPR and the legal order of the Czech Republic.
Both of the above organizations operate within this ecosystem as joint administrators (within the meaning of Article 26 of the GDPR). This means that they jointly participate in determining the purposes and means of data processing to ensure the uniform operation of the platform and are contractually bound to comply with identical, maximum strict data protection standards.
3. Data sharing across jurisdictions (International data flows for projects)
The basic function of the Patronito platform is to remove geographical barriers to supporting projects. In order for you, as a user registered in one country, to be able to safely and transparently support a project managed in another country, targeted data sharing takes place between both organizations (Cross-Border Interaction). You acknowledge and agree to the following principles of your data flow:
Localization of registration data:Your basic identification data (name, email, account settings) is managed exclusively by the organization under which you fall according to your place of registration.
Sharing project data:If you decide to support a specific project that falls under the administration of a "second" organization (for example, if a Czech citizen supports a Canadian project administered by United Patrons), your home organization will provide the second organization with access to your data that is necessary for the administration of this donation.
Purpose of sharing between organizations:This handover is absolutely necessary for the conclusion and performance of the contract, monitoring the flow of funds, preventing fraud (e.g. applying the Donor Guarantee) and for fulfilling the tax and accounting obligations of the organization that physically provides the project.
4. Categories of data processed and legal grounds for processing
We do not collect any unnecessary information about you.All processing is transparent and has a clearly defined purpose and legal basis. The following table serves as a central register of our processing activities:
5. Legal safeguards for international data transfers (EU – Canada)
Operating a global platform with headquarters in Canada and the Czech Republic naturally requires the transfer of personal data across the borders of the European Economic Area (EEA). To ensure that your data is protected, we employ a two-tier security mechanism:
Adequacy Decision: For most common data flows between the EU and Canada, we rely on the European Commission Decision (2002/2/EC) which recognizes Canada's PIPEDA law as providing an adequate level of protection consistent with the GDPR.
Standard Contractual Clauses (SCCs): Given that the Canadian adequacy decision is so-called “partial” and covers only entities carrying out “commercial activities” (which may create legal uncertainty for certain forms of non-profit grant administration), and for any further transfers to countries outside the adequacy regime, we have signed Standard Contractual Clauses approved by the European Commission with our partners (including the Canadian organization United Patrons). These strict contractual arrangements ensure absolute legal certainty and protection of your data under all circumstances.
6. Who else do we share data with?
Access to your personal data is strictly limited. We generally do not sell data to third parties and only share it to the extent necessary with the following entities:
Payment transaction processors: Your payments and payouts are processed exclusively by certified partners Stripe, PayPal and Findby. These partners meet the strictest security standards (PCI-DSS). We do not have access to your credit card numbers themselves.
Project Guarantors: If you support a project, your name and contact email may be shared with the Guarantor (project leader) solely for the purpose of fulfilling the contract - specifically for sending progress reports on the implementation of the project you funded.
Technology suppliers: Cloud hosting and security providers with whom we have processing agreements that oblige them to confidentiality and compliance with GDPR regulations.
7. Your rights as a data subject
Regardless of the country in which the organization that currently manages your data is located, the Patronito platform grants all users a uniform package of rights based on the stricter European GDPR regulation. You have the right to:
Right of access: Request a detailed overview and copy of all personal data we hold about you.
Right to rectification: Update your information in your profile settings at any time if it is inaccurate.
Right to erasure ("Right to be forgotten"): Request permanent account deletion and removal of data for which the purpose of processing has ceased (with the exception of transaction data, which we must retain for 7 years for tax purposes, and public records of supported projects to maintain platform transparency).
Right to restriction of processing and data portability: Request your data in a machine-readable format for transfer elsewhere or request suspension of its processing in the event of dispute resolution.
To object or withdraw consent: In particular, for processing based on legitimate interest, or to withdraw consent to the use of marketing cookies.
File a complaint: If you believe that we are processing your data unlawfully, you have the right to contact the supervisory authority (in the EU these are the relevant national authorities, in the Czech Republic, for example, the Office for Personal Data Protection - ÚOOÚ).
You can easily exercise all your rights by sending an email to our Data Protection Officer (DPO) at: info@patronito.com.
8. Security and use of cookies
Infrastructure security: For maximum data protection from cyber threats, all communication with the Patronito platform is encrypted using the TLS (Transport Layer Security) protocol. User passwords are securely hashed and only a narrow circle of verified employees has access to the databases.
Cookies: The platform uses cookies to operate.Strictly necessary cookies, without which you cannot make a donation or log in to your account, work automatically. In contrast, all other cookies (functional, analytical and marketing) are subject to your explicit consent through a user-friendly "cookie banner" that does not contain any pre-ticked boxes. You can revise your choices at any time in the user interface.
9. Child protection and age restrictions
Due to the nature of the handling of funds and the obligations defined in the Terms and Conditions, we do not allow young children to use the platform. The following age limits have been implemented:
To register as a user and set up an account for the purpose of supporting projects (Patron role), the minimum age required is 16 years of age.
To be able to start your own project and apply for funding (Guarantor role), you must be of legal age, i.e. at least 18 years of age. Funds raised from persons under the age of 16 without documented supervision by legal guardians, or projects led by persons under the age of 18, will be immediately suspended and personal data deleted upon discovery.
