01Who is responsible for the product
Developer: DigitalData s.r.o., Company ID 06675867, Jana Masaryka 108/10, 120 00 Prague 2, Czech Republic. Contact for privacy, support and deletion requests: info@digitaldata.cz. Website: www.digitaldata.cz.
The organisation that uses DPSystem WebForms to process its clients’ data determines the purpose, legal basis, recipients and retention period in downstream systems. Installing the extension does not by itself entitle it to process data without an appropriate legal basis. DigitalData does not collect document data on its servers through the extension.
02Purpose and data processed
The extension is used to fill in web forms with data from a document loaded in DPSystem Desktop and to create and run related workflows. It receives the data via a local Native Messaging component on the user’s computer.
Depending on the document provided and the settings, it may process the first name and surname, date and place of birth, sex, nationality, address, document type and number, issuing country, date of issue and expiry, and other items provided by DPSystem and used in the configured form. The scope depends on the data source and the user’s configuration.
To find the correct form, the extension works with the addresses of open pages and with the structure and content of the relevant page elements. When the user starts recording a workflow, it records the necessary interactions, element selections and entered values. It also stores settings, field mappings, conversion tables and workflows. It does not create a browsing history for advertising profiling.
03Where the data goes
Processing in the extension takes place locally in the browser and via a local connection to DPSystem Desktop. The extension does not send document data to DigitalData servers, advertising networks, data brokers or analytics providers.
On the user’s instruction, or through an automated workflow configured by the user, the extension inserts data into the target web form. This makes the data available to that web application; its scripts may process the data as soon as the form is filled in. A workflow may also include submitting the form. The recipient is the operator of the target application and any processors listed in its policy. Therefore, check the target address and configured steps before use.
If the user manually exports or shares a workflow, diagnostic log or file, the user alone determines the recipient of that transfer. Before sharing, any real personal data that such content may include must be removed.
04Storage, retention and deletion
The most recently received set of document data is stored in the browser’s temporary session storage in case the form needs to be filled in again. The user can delete it using the extension’s clear-data action; session storage is removed when the browser is closed. Receiving new data replaces the last stored set.
Settings, schemas, conversion tables and recorded workflows in progress are stored in the extension’s local storage and persist between sessions. If you save a specific piece of personal data into a workflow as a fixed value, it remains part of that workflow until it is edited or deleted. Use test data for recording. The extension’s local data can be removed by uninstalling it; manually exported files must be deleted separately.
Diagnostic messages in the browser’s local console may contain page addresses, field names, values or error messages; with verbose debugging enabled, also the entire received data set. The extension does not send them to DigitalData automatically. When working with real documents, do not use verbose debugging unless necessary, and remove personal data before passing a log to support.
Deleting the extension’s data does not delete data already stored in DPSystem, in the target application or in exported files. Request their deletion from the relevant operator. Any statutory retention obligation, for example for accounting records, applies only to the data and period required by the relevant regulation; it does not imply automatic archiving of loaded documents by the extension.
05Permissions and security
Access to pages, tabs and script execution is used to recognise and fill in forms and to record workflows. The local storage permission stores the configuration; Native Messaging connects the extension to the local application; notifications report the result of an operation. Broad access to web addresses allows use across different customer systems. You can restrict site access in the browser’s extension settings, which may limit its functionality.
The extension uses the browser’s isolated storage and its Native Messaging mechanism. Use HTTPS for target applications and protect your computer and browser profile against unauthorised access. The extension does not add any server-side transfer of document data of its own; the security and location of the target application’s servers are determined by its operator.
06Google APIs and publishing the extension
Regular form filling does not require the user to sign in to a Google account or access their Gmail, Google Drive or contacts. OAuth authorisation for the Chrome Web Store is used in a separate publishing tool operated by an authorised administrator to upload the extension package, check its status and submit a version for review.
The publishing tool processes authorisation tokens, the item identifier, the extension package and Chrome Web Store API responses. Tokens are kept in the environment or local configuration used by the administrator, not in the distributed extension. Transfers to Google take place over HTTPS. The administrator can revoke access in their Google account security settings and delete the local tokens, which removes the ability to publish further through that access. Users’ document data are not part of this publishing process.
07Limited Use
The use of user data in DPSystem WebForms complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. We handle information obtained through Google APIs in accordance with the Google API Services User Data Policy, including the Limited Use requirements.
We use the data only for the functions described above. We do not sell it or use it for advertising, marketing profiling, creditworthiness assessment or training general-purpose artificial intelligence models. DigitalData has no automatic human access to local document data. If a user explicitly provides specific data to resolve a support request, access is limited to that purpose; any other access may occur only to the extent necessary for security or compliance with a legal obligation.
08Your choices, rights and contact
You can stop using the extension at any time by disabling or uninstalling it, restricting its site access and deleting local data. Direct requests for access, rectification, erasure, restriction of processing, portability or objections to the organisation that processes your data. If the processing is carried out by DigitalData, contact info@digitaldata.cz. Rights are exercised under the conditions of the GDPR; you may also contact the Czech Office for Personal Data Protection (uoou.gov.cz).
This page is part of the www.digitaldata.cz website. Operation of the website is separate from the extension’s work with documents; the website does not use analytics or advertising cookies, only a strictly necessary cookie to secure the contact form.
We update this policy when the way data is processed changes; the date of the current version is shown at the top. Before any new purpose or scope of access to user data, we will inform users and request consent where required. This page does not mean that the product has already been approved by Google.