I. Introduction and Definitions
1.1. These Terms of Service (the "Terms") govern the rights and obligations between the provider: Jonáš Bláha, a sole trader established under the laws of the Czech Republic, Company ID (IČO): 71772618, VAT ID: CZ8701225830, with registered office at Dolní hejčínská 298/19, 779 00 Olomouc, Czech Republic (the "Provider"), and the customer, in connection with the use of the Flotello software service available at flotello.app (the "Service").
1.2. For the purposes of these Terms, the following capitalised terms have the meanings set out below:
- "Service" — the Flotello web application provided on a software-as-a-service (SaaS) basis, designed for managing the operations of businesses renting out trailers, cars, carts, machinery and similar equipment, including all of its components, updates and additional features.
- "Customer" — a business (a natural person acting in the course of business, or a legal entity) that has entered into the Agreement with the Provider; typically the operator of a rental business.
- "Agreement" — the contract for the provision of the Service concluded between the Provider and the Customer in the manner set out in Article II, of which these Terms and their annexes form an integral part.
- "User Account" — the Customer's account in the Service through which the Customer and the persons it authorises use the Service.
- "Renter" — a customer of the Customer, i.e. a person to whom the Customer rents out vehicles or other equipment and whose data the Customer records in the Service. The Renter is not a party to the Agreement, and no direct contractual relationship arises between the Renter and the Provider.
- "Plan" — a subscription tier of the Service under the Provider's current price list, differentiated in particular by the number of managed vehicles.
- "Price List" — the current price list for the Service published at flotello.app.
- "Customer Content" — all data entered into the Service by the Customer or its users, including in particular data concerning vehicles, reservations and Renters, texts and templates of rental agreements, protocols, photographs and other documents.
1.3. The Service includes, in particular: management of vehicles and availability calendars, reservation management, records of Renters, generation of rental agreements from templates and their electronic signing, handover and return protocols including photo documentation, payment management through a third-party provider (Stripe), and further features which the Provider adds from time to time (for example a public booking page, a booking widget, e-mail notifications and multilingual versions). The specific scope of features may vary depending on the selected Plan.
1.4. The Service is provided exclusively to business customers for use in the course of their trade, business or profession (B2B). By entering into the Agreement, the Customer represents and warrants that it is acting in the course of its business and not as a consumer. Consumer-protection rules do not apply to the Agreement.
II. Formation of the Agreement, Registration and Free Trial
2.1. The Agreement is formed at the moment the Customer completes registration in the Service, in the course of which the Customer accepts these Terms (including their annexes) by ticking the corresponding box. Registration cannot be completed without acceptance of the Terms.
2.2. The Customer shall provide true, accurate and up-to-date identification, contact and billing details upon registration and shall keep them up to date throughout the term of the Agreement.
2.3. Upon registration, the Customer is entitled to a free trial of the Service for a period of 7 days (the "Trial Period"). No payment card or other payment method is required for the Trial Period. If the Customer does not subscribe to a paid Plan by the end of the Trial Period, the Provider may suspend access to the Service; the Customer's data will be retained for the period set out in Article VIII and thereafter deleted.
2.4. The User Account is intended solely for the Customer. The Customer is responsible for the acts and omissions of all persons to whom it grants access to its User Account as if they were its own, and shall protect the access credentials against misuse.
2.5. The Provider may refuse registration, in particular where it has reasonable grounds to suspect misuse of the Service or where the applicant has materially breached the Agreement in the past.
III. Subscription, Fees and Payment
3.1. The Service is provided for a fee in the form of a subscription under the selected Plan. Plans are tiered in particular by the number of managed vehicles; their current parameters and fees are set out in the Price List.
3.2. The subscription may be paid monthly or annually; annual payment carries a discount as set out in the Price List.
3.3. Fees are stated in the Price List. Where value added tax or a similar tax applies, it is charged in accordance with applicable law; for business customers established outside the Czech Republic, the reverse-charge mechanism may apply, in which case the Customer accounts for the tax under the law of its own jurisdiction. The Provider is registered for VAT.
3.4. The subscription renews automatically for successive billing periods (monthly or annual, as applicable) until the Customer cancels the subscription or the Agreement is terminated. The fee for each renewed period is charged to the Customer's payment method through the Stripe payment platform. The Customer may switch off automatic renewal at any time in the User Account settings; the subscription then ends upon expiry of the period already paid for.
3.5. The Customer may upgrade to a higher Plan at any time; the upgrade takes effect immediately and the difference in fees is charged pro rata. A downgrade to a lower Plan takes effect from the beginning of the following billing period. No refund is given for the unused part of a billing period upon a downgrade or upon termination of the Agreement by the Customer, unless agreed otherwise.
3.6. If the Customer exceeds the limits of its Plan (in particular the number of vehicles), the Provider will invite the Customer to move to the appropriate Plan. If the Customer does not do so within a reasonable period, the Provider may restrict the addition of further vehicles or features beyond the scope of the Plan.
3.7. Consequences of non-payment. If the subscription fee is not paid when due, the Provider will notify the Customer by e-mail and will attempt to retry the payment. If payment is not received within 14 days after the due date, the Provider may suspend access to the Service. If payment is not received within 30 days after the due date, the Provider may terminate the Agreement with immediate effect; the Customer's data will then be handled in accordance with Article VIII. Suspension of access is without prejudice to the Provider's right to payment of all amounts due.
3.8. The Provider may change the Price List. A price change applies to an existing Customer no earlier than from the following billing period, and the Provider will give at least 30 days' prior notice of it by e-mail. If the Customer does not accept the price change, it may terminate the Agreement with effect from the date the change takes effect.
3.9. Invoices and tax documents are issued electronically and made available in the Service or sent by e-mail, to which the Customer consents.
IV. Renter Payments and the Role of Stripe
4.1. The Service enables the Customer to accept payments from Renters (advance payments, security deposits, rent and balance payments) and to manage them (including charging or refunding a security deposit). These payments are processed exclusively by the Stripe payment service (Stripe Payments Europe, Ltd., or other companies of the Stripe group) on the basis of a separate contractual relationship between the Customer and Stripe, the terms of which the Customer shall comply with.
4.2. The Provider is not a payment institution or a payment service provider; it does not accept Renter payments and does not hold, control or manage any funds of the Customer or of Renters. Under the Stripe Connect model (direct charges), Renter payments flow directly to the Customer's own account held with Stripe.
4.3. The legal relationship arising from the rental of a vehicle or other equipment, including all payments, advances and security deposits, exists exclusively between the Customer and the Renter. The Provider assumes no liability for these transactions or for their proper performance; in particular, the Provider is not liable for disputes between the Customer and the Renter, for refunds, complaints, chargebacks or Stripe fees, or for any loss arising in connection with payment transactions or their failure.
4.4. The Provider is not liable for the availability or functionality of Stripe's services. Any claims relating to payment services shall be raised by the Customer directly with Stripe.
V. Provider's Rights and Obligations; Availability of the Service
5.1. The Provider undertakes to provide the Service with professional skill and care. The Service is provided on an "as is" and "as available" basis. The Provider does not warrant that the Service will be available without interruption or free of defects; no contractual service-level commitment (SLA) is agreed.
5.2. The Provider may carry out both scheduled and unscheduled maintenance of the Service. The Provider will endeavour to carry out scheduled maintenance that materially restricts the availability of the Service outside usual business hours and to announce it in advance.
5.3. The Provider may develop, change and modify the Service on an ongoing basis, in particular by adding, modifying or removing individual features and by changing the user interface and the underlying technical solution. The Provider will give advance notice of any material restriction of key features of the Service used by the Customer; in such a case, the Customer may terminate the Agreement with effect from the date the change takes effect.
5.4. The Provider may suspend access to the Service or any part of it if: (a) the Customer is in default of payment as set out in Article 3.7; (b) the Customer is in material breach of the Agreement; (c) suspension is necessary for security or technical reasons; or (d) suspension is required by law or by a decision of a public authority.
5.5. The Provider performs regular data backups. Backups serve to restore the operation of the Service as a whole; they do not entitle the Customer to the restoration of individual records deleted by the Customer.
VI. Customer's Rights and Obligations; Acceptable Use
6.1. The Customer is responsible for the accuracy, completeness and lawfulness of the Customer Content. The Provider does not review the Customer Content and assumes no responsibility for it.
6.2. The Customer is responsible in particular for: (a) the wording and lawfulness of its rental agreements, terms and conditions and other documents which it creates or stores in the Service (contract templates in the Service are a technical tool only and do not constitute legal advice or a legal service); (b) its legal relationship with Renters, including the settlement of payments, security deposits and any disputes; (c) compliance with its own statutory obligations connected with its business (licensing, tax, record-keeping and other obligations under the law applicable to the Customer); (d) compliance with its obligations as a controller of personal data towards Renters and other data subjects under Annex 1 (Data Processing Agreement), in particular for maintaining a valid legal basis for the processing and for providing the required information to Renters.
6.3. The Customer shall not: (a) use the Service in breach of applicable law or for unlawful purposes; (b) interfere with or circumvent the technical measures of the Service, probe or test its vulnerabilities without the Provider's consent, or interfere with the Service in a manner that may damage or overload it; (c) make the Service available to third parties beyond the scope of the Agreement, in particular resell it or offer it as its own service; (d) upload into the Service any content that infringes the rights of third parties; (e) store in the Service special categories of personal data within the meaning of Article 9 GDPR, national identification numbers (such as birth numbers), or copies or scans of identity documents, unless otherwise agreed with the Provider in writing.
6.4. The Customer shall ensure that its use of electronic signing of documents in the Service (signature on a touchscreen) complies with the legal requirements applicable to the contracts it concludes; the assessment of the legal suitability of this form of signature for the Customer's specific transactions is the Customer's own responsibility.
6.5. The Customer shall notify the Provider without undue delay of any defects of the Service it discovers and of any suspected misuse of its User Account.
VII. Limitation of Liability
7.1. The Provider's aggregate liability to the Customer for any and all loss or damage arising out of or in connection with the Agreement, whether in contract, tort (including negligence) or otherwise, is limited to direct damage actually suffered and shall not exceed the total subscription fees paid by the Customer for the Service in the 12 months immediately preceding the event giving rise to the claim. The Customer acknowledges that this limitation reflects the nature and price of the Service and forms part of the agreed allocation of risk.
7.2. To the maximum extent permitted by applicable law, the Provider is not liable for: (a) indirect or consequential loss, loss of profit, loss of business opportunity, loss of goodwill or reputational harm, or loss of data caused by the Customer; (b) loss arising from the Customer Content or from its inaccuracy or unlawfulness; (c) loss arising from use of the Service in breach of the Agreement or the documentation; (d) loss arising from the unavailability or defects of third-party services (in particular Stripe and hosting and infrastructure services), internet connectivity outages, or events beyond the Provider's reasonable control (force majeure); (e) transactions between the Customer and the Renter as described in Article IV.
7.3. Nothing in these Terms excludes or limits either party's liability for: (a) damage caused intentionally or through gross negligence; (b) death or personal injury; or (c) any other liability which cannot be excluded or limited under applicable mandatory law. The limitations in this Article apply only to the extent permitted by such law.
VIII. Term, Termination and Treatment of Data
8.1. The Agreement is concluded for an indefinite period.
8.2. The Customer may terminate the Agreement at any time by cancelling its User Account in the Service or by written notice (including by e-mail). Termination takes effect on the last day of the billing period already paid for, unless agreed otherwise. Subscription fees already paid are non-refundable.
8.3. The Provider may terminate the Agreement for convenience on 3 months' notice; in that case, it will refund to the Customer a pro-rata part of the subscription fee for the unused period.
8.4. Either party may terminate the Agreement with immediate effect in the event of a material breach by the other party which is not remedied within a reasonable additional period (of at least 15 days) after a written notice requiring the breach to be remedied. The Provider may also terminate the Agreement in the cases set out in Article 3.7.
8.5. Data export and deletion. After termination of the Agreement, the Customer may, for a period of 30 days, export the Customer Content in a machine-readable format (to the extent of the export functions of the Service, or on request to the Provider). After this period, the Provider will delete the Customer Content, except for data which the Provider is required to retain under applicable law (in particular accounting and tax records) and backups, which are overwritten in regular cycles (within 90 days at the latest). The treatment of Renters' personal data after termination of the Agreement is governed by Annex 1.
IX. Intellectual Property; Licence
9.1. All intellectual property rights in and to the Service, its source code, design, documentation, trademarks and the "Flotello" name and branding belong to the Provider. Nothing in the Agreement transfers any intellectual property rights to the Customer.
9.2. The Provider grants the Customer, for the term of the Agreement, a non-exclusive, non-transferable and non-sublicensable licence to use the Service within the scope of the selected Plan, solely for the Customer's own business operations. The Customer shall not grant sublicences, copy or modify the Service, reverse engineer it (except to the extent such restriction is prohibited by applicable mandatory law), or make it available to third parties beyond the scope of the Agreement.
9.3. The Customer Content remains the property of the Customer. The Customer grants the Provider the right to store, process, back up and display the Customer Content solely to the extent necessary for the provision of the Service.
9.4. If the Customer provides the Provider with feedback or suggestions for improving the Service, the Provider may use them without restriction and free of charge.
X. Changes to these Terms
10.1. The Provider may amend these Terms to a reasonable extent, in particular to reflect the development of the Service, changes in applicable law, or changes in the terms of third-party providers.
10.2. The Provider will notify the Customer of any amendment to these Terms at least 30 days before it takes effect, by e-mail to the address recorded in the User Account or by a notice in the Service. If the Customer does not accept the amendment, it may terminate the Agreement in writing with effect no later than the date the amendment takes effect; otherwise, the Customer is deemed to have accepted the amendment and, from its effective date, the Agreement is governed by the amended Terms.
10.3. The current and previous versions of these Terms are available at flotello.app.
XI. Governing Law, Jurisdiction and Final Provisions
11.1. The Agreement and all rights and obligations arising out of or in connection with it are governed by the laws of the Czech Republic, to the exclusion of its conflict-of-laws rules. The United Nations Convention on Contracts for the International Sale of Goods (CISG) does not apply.
11.2. This choice of law is without prejudice to any mandatory provisions of the law of the jurisdiction in which the Customer is established or habitually resident that cannot be derogated from by agreement, including mandatory protections under the law of the European Union, which remain unaffected.
11.3. The courts of the Czech Republic have jurisdiction over any dispute arising out of or in connection with the Agreement; venue lies with the court having general jurisdiction over the Provider's registered office, to the extent permitted by applicable law.
11.4. If any provision of these Terms is or becomes invalid or unenforceable, the validity and enforceability of the remaining provisions is not affected. The parties shall replace such a provision with a valid provision that most closely reflects its economic purpose.
11.5. The Customer shall not assign the Agreement or any claims under it without the Provider's prior written consent. Each party bears its own commercial risk of a change of circumstances; a change of circumstances does not entitle either party to demand renegotiation of the Agreement or to refuse performance, except as expressly provided in these Terms or required by applicable mandatory law.
11.6. These Terms are drawn up in the English language and are binding in their own right. Where the Provider publishes its terms in other languages, each language version independently governs the agreements concluded under it.
11.7. Annex 1 — the Data Processing Agreement (DPA) — forms an integral part of these Terms. By accepting these Terms upon registration, the Customer simultaneously enters into the Data Processing Agreement with the Provider.
11.8. Provider contact: info@flotello.app, flotello.app.
Annex 1 — Data Processing Agreement (DPA)
concluded pursuant to Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation, "GDPR") between the Customer as controller and the Provider as processor (the "DPA").
1. Introductory Provisions
1.1. This DPA forms an integral part of the Terms and is concluded electronically together with the Agreement (by ticking the box confirming acceptance of the Terms upon registration). The parties expressly agree that this form satisfies the requirement of written form, including in electronic form, under Article 28(9) GDPR.
1.2. In providing the Service, the Provider processes on behalf of the Customer personal data of which the Customer is the controller — in particular the data of Renters. This DPA governs the terms of that processing. In the event of a conflict between this DPA and other parts of the Terms, this DPA prevails with respect to the processing of personal data.
1.3. For the avoidance of doubt: with respect to the personal data of the Customer itself and of its users (contact, billing and accounting data), the Provider acts as an independent controller; that processing is governed by the Privacy Policy available at flotello.app.
2. Subject Matter, Nature, Purpose and Duration of Processing
2.1. Subject matter and nature of the processing: storage, structuring, retention, display, use, export, backup and erasure of personal data within the operation of the Service (a hosted SaaS application for managing rental businesses).
2.2. Purpose of the processing: provision of the Service to the Customer, i.e. in particular keeping records of Renters, managing reservations, generating and storing rental agreements and handover protocols, managing payments and communicating with Renters.
2.3. Duration of the processing: for the term of the Agreement and thereafter for the period set out in Section 9 of this DPA.
2.4. Categories of data subjects: Renters (customers of the Customer), their representatives, drivers and contact persons; and, where applicable, other persons whose data the Customer enters into the Service.
2.5. Categories of personal data: identification data (first name, surname, date of birth, identity document number, driving licence number), address and contact data (address, telephone, e-mail), business identification data (company ID, VAT ID), data concerning reservations and rentals, contractual documents including the electronic signature (the signature is stored as a graphic image only, not as a dynamic biometric template), photo documentation of the condition of vehicles (which may exceptionally capture individuals), and payment metadata (payment status and history; payment card data is processed exclusively by Stripe).
2.6. The Customer undertakes not to enter into the Service special categories of personal data (Article 9 GDPR), data relating to criminal convictions and offences (Article 10 GDPR), national identification numbers (such as birth numbers), or copies or scans of identity documents. The Service is not designed for the processing of such data.
3. Controller's Instructions
3.1. The Provider processes personal data only on documented instructions from the Customer. The Agreement, this DPA and the actions of the Customer and its users performed in the interface of the Service (for example creating, editing, exporting or deleting a record) are deemed to constitute such instructions.
3.2. The Provider shall inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
3.3. The obligation under Section 3.1 does not apply where the processing is required of the Provider by European Union or Member State law; in such a case, the Provider shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
4. Obligations of the Provider (Processor)
4.1. The Provider shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4.2. The Provider shall implement and maintain the technical and organisational measures set out in Section 6 of this DPA.
4.3. The Provider shall assist the Customer, by appropriate technical and organisational measures, in fulfilling the Customer's obligation to respond to requests for the exercise of data subjects' rights (Articles 12 to 23 GDPR), in particular through the features of the Service (searching for, rectifying, exporting and erasing records). If the Provider receives a data subject request concerning processing of which the Customer is the controller, it shall forward the request to the Customer without undue delay and shall not respond to it on the merits itself.
4.4. The Provider shall assist the Customer in ensuring compliance with the obligations under Articles 32 to 36 GDPR (security of processing, breach notification, data protection impact assessments), taking into account the nature of the processing and the information available to the Provider.
4.5. The Provider shall make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and shall allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer. Audits are conducted primarily through the provision of documentation and written answers to questions; an on-site audit may be carried out on at least 30 days' prior notice, during normal business hours, no more than once per year (unless the audit is prompted by a security incident or a requirement of a supervisory authority), and at the Customer's expense.
5. Notification of Personal Data Breaches
5.1. The Provider shall notify the Customer of a personal data breach without undue delay after becoming aware of it, and in any event within 48 hours, by e-mail to the Customer's contact address.
5.2. The notification shall include, to the extent the information is available, at least: a description of the nature of the breach, including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point for further information. The information may be provided in phases.
5.3. Notification of the breach to the supervisory authority and any communication to data subjects are obligations of the Customer as controller; the Provider shall provide the necessary assistance.
6. Technical and Organisational Measures
6.1. The Provider has implemented, in particular, the following measures:
- encryption of data in transit (TLS/HTTPS) and encryption of data at rest at the infrastructure level;
- storage of production data in a data centre in the Frankfurt (EU) region (Supabase);
- logical isolation of each Customer's data (separation of data between rental businesses at the application and database level, row-level access control);
- access control: user authentication, access to production data restricted to authorised persons on a need-to-know basis, strong passwords and multi-factor authentication for administrative access to the infrastructure;
- regular automated backups and the ability to restore data;
- logging of access and changes at the infrastructure level;
- updating and hardening of software components, and the use of reputable infrastructure providers holding recognised certifications (for example SOC 2, ISO 27001).
6.2. The Provider may update and improve these measures on an ongoing basis, provided that the level of security is not reduced below the level required by Article 32 GDPR.
7. Sub-processors
7.1. The Customer grants the Provider a general written authorisation to engage sub-processors. The list of sub-processors as of the effective date of this DPA:
| Sub-processor | Registered office | Purpose | Data location / transfer safeguards |
|---|---|---|---|
| Vercel Inc. | USA | hosting and operation of the application | EU-U.S. Data Privacy Framework certification and standard contractual clauses (SCCs) |
| Supabase, Inc. | USA | database and file storage | data stored in the Frankfurt (EU) region; SCCs for any access from third countries |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Ireland / USA | payment processing | EU-U.S. Data Privacy Framework certification and SCCs |
| Resend (Resend, Inc.) | USA | sending transactional e-mails | standard contractual clauses (SCCs) |
| Functional Software, Inc. (Sentry) | USA | application error monitoring | standard contractual clauses (SCCs) |
7.2. The Provider shall give the Customer at least 30 days' prior notice of any intended changes concerning the addition or replacement of a sub-processor, by e-mail or by a notice in the Service. The Customer may object to the change in writing, on reasonable grounds relating to data protection, within 14 days of the notice. If no agreement is reached, the Customer may terminate the Agreement with effect from the date the new sub-processor is engaged; otherwise, the Customer is deemed to have accepted the change.
7.3. The Provider shall impose on each sub-processor, by way of a contract, data protection obligations equivalent to those set out in this DPA, in particular the provision of sufficient guarantees to implement appropriate technical and organisational measures. The Provider remains fully liable to the Customer for the performance of each sub-processor's obligations.
8. Transfers to Third Countries
8.1. Personal data is primarily stored in the EU (Frankfurt region). However, some sub-processors are established in the USA or may access the data from third countries.
8.2. Any transfer of personal data to a third country takes place only in compliance with Chapter V of the GDPR, in particular on the basis of: (a) an adequacy decision under Article 45 GDPR (for sub-processors certified under the EU-U.S. Data Privacy Framework), or (b) standard contractual clauses under Article 46(2)(c) GDPR concluded with the relevant sub-processor, supplemented by additional measures where appropriate.
8.3. The Customer hereby authorises the Provider to put in place, on the Customer's behalf, appropriate transfer safeguards vis-à-vis the sub-processors referred to in Section 7 of this DPA.
9. Erasure and Return of Data after Termination
9.1. After termination of the Agreement, the Customer may, for a period of 30 days, export the personal data in a machine-readable format (in accordance with Article 8.5 of the Terms). At the Customer's choice, the Provider shall return the data (by export) and/or erase it.
9.2. Unless the Customer instructs otherwise, after the expiry of the period under Section 9.1 the Provider shall erase all personal data processed on behalf of the Customer, including all copies, except for: (a) data whose retention is required by European Union or Member State law, and (b) backups, which are erased in regular cycles within 90 days at the latest; until their erasure, the backups remain protected by the measures set out in Section 6.
10. Final Provisions of the DPA
10.1. This DPA is concluded for the term of the Agreement; Sections 4.5, 5 and 9 survive its termination until all obligations have been fully discharged.
10.2. The parties' liability for a breach of this DPA is governed by Article VII of the Terms; this is without prejudice to the mandatory rights of data subjects and the obligations under Article 82 GDPR.
10.3. Amendments to this DPA are governed by Article X of the Terms. The current list of sub-processors is available at flotello.app.
10.4. This DPA is governed by the laws of the Czech Republic and by the GDPR.