I. Introductory Provisions and Definitions
1.1. These terms and conditions (the "Terms") govern the rights and obligations between the provider: Jonáš Bláha, Company ID No. (IČO): 71772618, VAT ID (DIČ): CZ8701225830, with registered office at Dolní hejčínská 298/19, 779 00 Olomouc, Czech Republic, a natural person doing business under the Czech Trade Licensing Act (živnostenský zákon), registered in the Trade Register (the "Provider"), and the customer in connection with the use of the Flotello software service available at flotello.app (the "Service").
1.2. For the purposes of these Terms, the following terms have the following meanings:
- "Service" — the Flotello web application provided as software as a service (SaaS), intended for managing the operations of rental companies renting out trailers, cars, carts, machines and similar equipment, including all of its components, updates and additional features.
- "Customer" — an entrepreneur (a natural person doing business or a legal entity) who has entered into the Agreement with the Provider; typically the operator of a rental company.
- "Agreement" — the agreement on the provision of the Service concluded between the Provider and the Customer in the manner set out in Article II of these Terms, of which these Terms and their annexes form an integral part.
- "User Account" — the Customer's account in the Service through which the Customer and the persons authorised by the Customer use the Service.
- "Renter" — a customer of the Customer, i.e. a person to whom the Customer rents out vehicles or other equipment and whose data the Customer records in the Service. The Renter is not a party to the Agreement and no direct contractual relationship arises between the Renter and the Provider.
- "Plan" — a subscription variant of the Service under the Provider's current price list, tiered in particular by the number of managed vehicles.
- "Price List" — the current price list of the Service published at flotello.app.
- "Customer Content" — all data entered into the Service by the Customer or its users, in particular data on vehicles, reservations and Renters, texts and templates of rental agreements, protocols, photographs and other documents.
1.3. The Service includes in particular: management of vehicles and availability calendars, reservation management, records of Renters, generation of rental agreements from templates and their electronic signing, handover and return protocols including photo documentation, payment management through a third party (Stripe), and other features which the Provider adds on an ongoing basis (e.g. a public booking page, a booking widget, e-mail notifications, multilingual versions). The specific scope of features may vary depending on the selected Plan.
1.4. The Service is provided exclusively to entrepreneurs in the course of their business activities (B2B). By entering into the Agreement, the Customer confirms that it is an entrepreneur and is entering into the Agreement in the course of its business. Consumer-protection provisions of legal regulations shall not apply to the Agreement.
II. Conclusion of the Agreement, Registration and Trial Period
2.1. The Agreement is concluded at the moment the Customer completes registration in the Service, in the course of which the Customer expresses consent to these Terms (including their annexes) by ticking the relevant box. Registration cannot be completed without consent to the Terms.
2.2. The Customer is obliged to provide true, accurate and up-to-date identification, contact and billing details upon registration and throughout the term of the Agreement.
2.3. Upon registration, the Customer is entitled to a free trial period of 7 days (the "Trial Period"). No payment card or other means of payment is required for the Trial Period. If the Customer does not choose a paid Plan by the end of the Trial Period, the Provider is entitled to suspend access to the Service; the Customer's data will be retained for the period set out in Article VIII and then deleted.
2.4. The User Account is intended exclusively for the Customer. The Customer is liable for the conduct of all persons to whom it grants access to its User Account as if it were the Customer's own conduct, and is obliged to protect the access credentials against misuse.
2.5. The Provider is entitled to refuse registration, in particular where it has reasonable grounds to suspect misuse of the Service or where the applicant has materially breached the Agreement in the past.
III. Subscription, Prices and Payment Terms
3.1. The Service is provided for a fee in the form of a subscription under the selected Plan. Plans are tiered in particular by the number of managed vehicles; their current parameters and prices are set out in the Price List.
3.2. The subscription may be paid monthly or annually; annual payment carries a discount as set out in the Price List.
3.3. All prices in the Price List are final and stated inclusive of VAT, unless expressly stated otherwise. The Provider is a VAT payer.
3.4. The subscription renews automatically for the next billing period (month or year, as applicable) until the Customer cancels the subscription or terminates the Agreement. Payment for the renewed period is charged to the Customer's means of payment via the Stripe payment gateway. The Customer may switch off automatic renewal at any time in the User Account settings; the subscription then ends upon expiry of the period already paid for.
3.5. The Customer may switch to a higher Plan at any time; the upgrade takes effect immediately and the price difference is charged pro rata. A switch to a lower Plan takes effect from the beginning of the following billing period. The subscription is not refunded for the unused part of the period in the event of a switch to a lower Plan or termination of the Agreement by the Customer, unless agreed otherwise.
3.6. If the Customer exceeds the limits of its Plan (in particular the number of vehicles), the Provider will invite the Customer to switch to the appropriate Plan. If the Customer does not switch to the appropriate Plan within a reasonable period, the Provider is entitled to restrict the addition of further vehicles or features beyond the scope of the Plan.
3.7. Consequences of non-payment. If the subscription is not paid by the due date, the Provider will notify the Customer by e-mail and attempt to retry the payment. If payment is not made within 14 days after the due date, the Provider is entitled to suspend access to the Service. If payment is not made within 30 days after the due date, the Provider is entitled to withdraw from the Agreement; the Customer's data will be handled in accordance with Article VIII. Suspension of access is without prejudice to the Provider's right to payment of the amounts due.
3.8. The Provider is entitled to change the Price List. A price change applies to an existing Customer no earlier than from the following billing period, and the Provider will announce it at least 30 days in advance by e-mail. If the Customer does not agree to the price change, the Customer is entitled to terminate the Agreement by notice effective as of the date the change takes effect.
3.9. Tax documents are issued electronically and made available in the Service or sent by e-mail, to which the Customer consents.
IV. Renter Payments and the Role of Stripe
4.1. The Service enables the Customer to accept payments from Renters (advances, security deposits, rent, balance payments) and to manage them (including charging or refunding a security deposit). These payments are processed exclusively by the Stripe payment service (Stripe Payments Europe, Ltd., or other companies of the Stripe group) on the basis of a separate contractual relationship between the Customer and Stripe, the terms of which the Customer is obliged to comply with.
4.2. The Provider is not a payment institution or a payment service provider; it does not accept Renter payments and does not hold or manage funds of the Customer or of Renters. In the Stripe Connect mode, Renter payments flow directly to the Customer's account held with Stripe.
4.3. The legal relationship arising from the rental of a vehicle or other equipment, including payments, advances and security deposits, exists exclusively between the Customer and the Renter. The Provider bears no liability for these transactions or for their proper execution; in particular, it is not liable for disputes between the Customer and the Renter, for refunds of payments, complaints, chargebacks or Stripe fees, or for damage arising in connection with payment transactions or their failure.
4.4. The Provider is not liable for the availability or functionality of Stripe services. Any claims relating to payment services shall be raised by the Customer directly with Stripe.
V. Rights and Obligations of the Provider, Availability of the Service
5.1. The Provider undertakes to provide the Service with professional care. The Service is provided on an "as is" and "as available" basis. The Provider does not guarantee that the Service will be available continuously and free of defects; no contractual availability guarantee (SLA) is agreed.
5.2. The Provider is entitled to carry out both planned and unplanned maintenance of the Service. The Provider will endeavour to carry out planned maintenance that substantially restricts the availability of the Service outside usual business hours and to announce it in advance.
5.3. The Provider is entitled to develop, change and modify the Service on an ongoing basis, in particular to add, modify or remove individual features and to change the user interface and the technical solution. The Provider will give advance notice of any substantial restriction of key features of the Service used by the Customer; in such a case, the Customer is entitled to terminate the Agreement by notice effective as of the date the change takes effect.
5.4. The Provider is entitled to suspend access to the Service or a part thereof if: (a) the Customer is in default of payment under Article 3.7; (b) the Customer materially breaches the Agreement; (c) it is necessary for security or technical reasons; or (d) it is required by a legal regulation or a decision of a public authority.
5.5. The Provider performs regular data backups. Backups serve to restore the operation of the Service as a whole; they do not give the Customer any right to the restoration of individual records deleted by the Customer.
VI. Rights and Obligations of the Customer
6.1. The Customer is responsible for the accuracy, completeness and lawfulness of the Customer Content. The Provider does not review the Customer Content and is not responsible for it.
6.2. The Customer is responsible in particular for: (a) the wording and lawfulness of its rental agreements, terms and conditions and other documents which it creates or stores in the Service (contract templates in the Service are merely a technical tool, not a legal service); (b) its legal relationship with Renters, including the settlement of payments, security deposits and any disputes; (c) compliance with its own statutory obligations related to its business (trade licensing, tax, record-keeping and other obligations); (d) compliance with its obligations as a controller of personal data towards Renters and other data subjects under Annex No. 1 (Data Processing Agreement), in particular for the existence of a legal basis for processing and the fulfilment of information obligations towards Renters.
6.3. The Customer must not: (a) use the Service in violation of legal regulations or for unlawful purposes; (b) interfere with or circumvent the technical measures of the Service, test its vulnerabilities without the Provider's consent, or interfere with the Service in a manner that may damage or overload it; (c) make the Service available to third parties beyond the scope of the Agreement, in particular resell it or provide it as its own service; (d) upload content into the Service that infringes the rights of third parties; (e) store in the Service special categories of personal data (Article 9 GDPR), national identification (birth) numbers, or copies/scans of identity documents, unless agreed otherwise with the Provider in writing.
6.4. The Customer is obliged to ensure that it uses the electronic signing of documents in the Service (signature on a touchscreen) in a manner that meets the legal requirements applicable to the contracts it concludes; the assessment of the legal suitability of this form of signature for the Customer's specific legal acts is the Customer's responsibility.
6.5. The Customer is obliged to notify the Provider without undue delay of any discovered defects of the Service and of any suspected misuse of the User Account.
VII. Liability for Damage
7.1. The Provider is liable to the Customer for damage caused by a breach of its obligations under the Agreement only up to the amount of the actual damage and up to a maximum of the subscription fees paid by the Customer in the 12 months preceding the event giving rise to the damage. This limitation is agreed with regard to the nature and price of the Service, and the Customer acknowledges and agrees to it.
7.2. The Provider is not liable for: (a) indirect and consequential damage, lost profit, loss of business opportunities, damage to reputation, or loss of data caused by the Customer; (b) damage arising from the Customer Content or from its inaccuracy or unlawfulness; (c) damage arising from use of the Service in violation of the Agreement or the documentation; (d) damage arising from the unavailability or defects of third-party services (in particular Stripe, hosting and infrastructure services), internet connection outages, or circumstances excluding liability (force majeure); (e) transactions between the Customer and the Renter under Article IV.
7.3. The limitations under this Article shall not apply to the extent that liability cannot be limited under mandatory provisions of legal regulations (in particular damage caused intentionally or through gross negligence and harm to a person's natural rights).
VIII. Term and Termination of the Agreement, Fate of Data
8.1. The Agreement is concluded for an indefinite period.
8.2. The Customer may terminate the Agreement at any time by cancelling the User Account in the Service or by written notice (including by e-mail). The notice takes effect on the last day of the billing period already paid for, unless agreed otherwise. Paid subscription fees are non-refundable.
8.3. The Provider may terminate the Agreement with a notice period of 3 months, even without stating a reason; in such a case, it will refund to the Customer a pro-rata part of the subscription for the unused period.
8.4. Either party may withdraw from the Agreement in the event of a material breach of the Agreement by the other party which has not been remedied even within an additional reasonable period (of at least 15 days) after a written request to do so. The Provider may also withdraw in the cases set out in Article 3.7.
8.5. Data export and deletion. After termination of the Agreement, the Customer has the right, for a period of 30 days, to export the Customer Content in a machine-readable format (to the extent of the export functions of the Service, or upon request to the Provider). After this period, the Provider will delete the Customer Content, except for data which it is obliged to retain under legal regulations (in particular accounting and tax documents) and backups, which are overwritten in regular cycles (within 90 days at the latest). The handling of Renters' personal data after termination of the Agreement is governed by Annex No. 1.
IX. Intellectual Property and Licence
9.1. All intellectual property rights to the Service, its source code, design, documentation, trademarks and the "Flotello" designation belong to the Provider. Conclusion of the Agreement does not transfer any intellectual property rights to the Customer.
9.2. The Provider grants the Customer, for the term of the Agreement, a non-exclusive, non-transferable and non-assignable licence to use the Service within the scope of the selected Plan, exclusively for the Customer's own business activities. The Customer is not entitled to grant sublicences, to reproduce or modify the Service, to reverse engineer it (beyond mandatory statutory exceptions), or to make it available to third parties beyond the scope of the Agreement.
9.3. The Customer Content remains the property of the Customer. The Customer grants the Provider the right to store, process, back up and display the Customer Content exclusively to the extent necessary for the provision of the Service.
9.4. If the Customer provides the Provider with feedback or suggestions for improving the Service, the Provider is entitled to use them free of charge.
X. Changes to the Terms
10.1. The Provider is entitled to amend these Terms to a reasonable extent, in particular due to the development of the Service or changes in legal regulations or third-party terms (within the meaning of Section 1752 of Act No. 89/2012 Coll., the Civil Code).
10.2. The Provider will notify the Customer of an amendment to the Terms at least 30 days before it takes effect, by e-mail to the address stated in the User Account or by a notice in the Service. If the Customer does not agree to the amendment, the Customer is entitled to terminate the Agreement in writing no later than as of the date the amendment takes effect; otherwise, the Customer is deemed to agree to the amendment and, from its effective date, the Agreement is governed by the new wording of the Terms.
10.3. The current and previous versions of the Terms are available at flotello.app.
XI. Final Provisions
11.1. The Agreement and all legal relationships arising from it are governed by the law of the Czech Republic, in particular Act No. 89/2012 Coll., the Civil Code, to the exclusion of conflict-of-law rules. The United Nations Convention on Contracts for the International Sale of Goods shall not apply.
11.2. The courts of the Czech Republic have jurisdiction to resolve disputes arising from the Agreement; the court with local jurisdiction is the Provider's general court, where permitted by legal regulations.
11.3. If any provision of the Terms is or becomes invalid, putative (null) or unenforceable, the validity and enforceability of the remaining provisions shall not be affected. The parties undertake to replace such a provision with a valid provision that best corresponds to its economic purpose.
11.4. The Customer is not entitled to assign the Agreement or any receivables arising from it without the Provider's prior written consent. The Customer assumes the risk of a change of circumstances within the meaning of Section 1765(2) of the Civil Code.
11.5. Annex No. 1 — the Data Processing Agreement (DPA) — forms an integral part of these Terms. By agreeing to these Terms upon registration, the Customer simultaneously enters into the Data Processing Agreement with the Provider.
11.6. Provider contact: info@flotello.app, flotello.app.
Annex No. 1 — Data Processing Agreement (DPA)
concluded pursuant to Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation, "GDPR") between the Customer as controller and the Provider as processor (the "DPA").
1. Introductory Provisions
1.1. This DPA forms an integral part of the Terms and is concluded electronically together with the Agreement (by ticking the box confirming consent to the Terms upon registration). The parties expressly agree that this form satisfies the written-form requirement under Article 28(9) GDPR (electronic form).
1.2. In providing the Service, the Provider processes for the Customer personal data of which the Customer is the controller — in particular the data of Renters. This DPA governs the terms of such processing. In the event of a conflict between the DPA and other parts of the Terms, the DPA prevails with respect to the processing of personal data.
1.3. For the avoidance of doubt: with respect to the personal data of the Customer itself and of its users (contact, billing and accounting data), the Provider acts as an independent controller; such processing is governed by the Personal Data Processing Policy available at flotello.app.
2. Subject Matter, Nature, Purpose and Duration of Processing
2.1. Subject matter and nature of processing: storage, structuring, retention, display, use, export, backup and erasure of personal data within the operation of the Service (a hosted SaaS application for managing rental companies).
2.2. Purpose of processing: provision of the Service to the Customer, i.e. in particular keeping records of Renters, managing reservations, generating and storing rental agreements and handover protocols, managing payments and communicating with Renters.
2.3. Duration of processing: for the term of the Agreement and thereafter for the period set out in Article 9 of this DPA.
2.4. Categories of data subjects: Renters (customers of the Customer), their representatives, drivers and contact persons; and, where applicable, other persons whose data the Customer enters into the Service.
2.5. Categories of personal data: identification data (first name, surname, date of birth, identity document number, driving licence number), address and contact data (address, telephone, e-mail), business identification data (company ID number (IČO), VAT ID (DIČ)), data on reservations and rentals, contractual documents including the electronic signature (the biometric image of the signature is not stored as a dynamic biometric template but as a graphic image of the signature), photo documentation of the condition of vehicles (which may exceptionally capture persons), payment metadata (payment status and history; payment card data is processed exclusively by Stripe).
2.6. The Customer undertakes not to enter into the Service special categories of personal data (Article 9 GDPR), data relating to criminal convictions (Article 10 GDPR), national identification (birth) numbers, or copies/scans of identity documents. The Service is not intended for the processing of such data.
3. Controller's Instructions
3.1. The Provider processes personal data only on the basis of documented instructions from the Customer. The Agreement, this DPA and the actions of the Customer and its users performed in the interface of the Service (e.g. creating, editing, exporting or deleting a record) are deemed to be instructions.
3.2. The Provider shall inform the Customer if, in its opinion, an instruction infringes the GDPR or other data protection laws.
3.3. The obligation under Article 3.1 does not apply where the processing is required of the Provider by European Union or Member State law; in such a case, the Provider shall inform the Customer of that requirement before processing, unless that law prohibits such information.
4. Obligations of the Provider (Processor)
4.1. The Provider shall ensure that persons authorised to process personal data have committed themselves to confidentiality or are under a statutory obligation of confidentiality.
4.2. The Provider shall adopt and maintain the technical and organisational measures set out in Article 6 of this DPA.
4.3. The Provider shall assist the Customer, by appropriate technical and organisational measures, in fulfilling the Customer's obligation to respond to requests for the exercise of data subjects' rights (Articles 12–23 GDPR), in particular through the features of the Service (searching for, rectifying, exporting and erasing a record). If the Provider receives a data subject request concerning processing of which the Customer is the controller, it shall forward it to the Customer without undue delay and shall not respond to it on the merits itself.
4.4. The Provider shall assist the Customer in ensuring compliance with the obligations under Articles 32–36 GDPR (security, breach notification, impact assessment), taking into account the nature of the processing and the information available to the Provider.
4.5. The Provider shall make available to the Customer the information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits are conducted primarily in the form of the provision of documentation and answers to questions; an on-site audit may be carried out upon prior notice of at least 30 days, during normal business hours, at most once a year (unless the audit is prompted by a security incident or a requirement of a supervisory authority), and at the Customer's expense.
5. Notification of Personal Data Breaches
5.1. The Provider shall notify the Customer of a personal data breach without undue delay after becoming aware of it, and no later than within 48 hours, by e-mail to the Customer's contact address.
5.2. The notification shall include, to the extent of the information available, at least: a description of the nature of the breach, including the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken and proposed, and a contact point for further information. The information may be provided in phases.
5.3. Notification of the breach to the supervisory authority and any communication with data subjects are obligations of the Customer as controller; the Provider shall provide the necessary assistance.
6. Technical and Organisational Measures
6.1. The Provider has adopted in particular the following measures:
- encryption of data in transit (TLS/HTTPS) and encryption of data at rest at the infrastructure level;
- storage of production data in a data centre in the Frankfurt (EU) region (Supabase);
- logical isolation of the data of individual Customers (separation of data between rental companies at the application and database level, row-level access control);
- access control: user authentication, access to production data limited to authorised persons to the extent necessary, strong passwords and multi-factor authentication for administrator access to the infrastructure;
- regular automatic backups and the ability to restore data;
- logging of access and changes at the infrastructure level;
- updating and securing of software components, use of reputable infrastructure providers holding certifications (e.g. SOC 2, ISO 27001).
6.2. The Provider is entitled to update and improve the measures on an ongoing basis, provided that the level of security is not reduced below the level required by Article 32 GDPR.
7. Sub-processors
7.1. The Customer grants the Provider a general authorisation to engage sub-processors. The current list of sub-processors as of the effective date of this DPA:
| Sub-processor | Registered office | Purpose | Data location / transfer safeguards |
|---|---|---|---|
| Vercel Inc. | USA | hosting and operation of the application | EU-U.S. Data Privacy Framework certification and standard contractual clauses (SCCs) |
| Supabase, Inc. | USA | database and file storage | data stored in the Frankfurt (EU) region; SCCs for any access from third countries |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Ireland / USA | payment processing | EU-U.S. Data Privacy Framework certification and SCCs |
| Resend (Resend, Inc.) | USA | sending transactional e-mails | standard contractual clauses (SCCs) |
7.2. The Provider shall notify the Customer of intended changes (the addition or replacement of a sub-processor) at least 30 days in advance by e-mail or by a notice in the Service. The Customer is entitled to object to the change in writing, on justified grounds relating to the protection of personal data, within 14 days of the notification. If no agreement is reached, the Customer is entitled to terminate the Agreement effective as of the date the new sub-processor is engaged; otherwise, the Customer is deemed to agree to the change.
7.3. The Provider shall impose on each sub-processor, by way of a contract, the same data protection obligations as are set out in this DPA, in particular the provision of sufficient guarantees to implement appropriate technical and organisational measures. The Provider is liable to the Customer for the performance of the sub-processors' obligations as if it performed them itself.
8. Transfers to Third Countries
8.1. Personal data is primarily stored in the EU (Frankfurt region). However, some sub-processors are established in the USA or may access the data from third countries.
8.2. Any transfer of personal data to a third country shall take place only if the conditions of Chapter V of the GDPR are met, in particular on the basis of: (a) an adequacy decision under Article 45 GDPR (for sub-processors certified under the EU-U.S. Data Privacy Framework), or (b) standard contractual clauses under Article 46(2)(c) GDPR concluded with the relevant sub-processor, supplemented by additional measures where applicable.
8.3. The Customer hereby authorises the Provider to put in place, on the Customer's behalf, appropriate transfer safeguards vis-à-vis the sub-processors under Article 7 of this DPA.
9. Erasure and Return of Data after Termination
9.1. After termination of the Agreement, the Customer may, for a period of 30 days, export the personal data in a machine-readable format (in accordance with Article 8.5 of the Terms). At the Customer's choice, the Provider shall return the data (by export) and/or erase it.
9.2. Unless the Customer determines otherwise, after the expiry of the period under Article 9.1 the Provider shall erase all personal data processed for the Customer, including copies, except for: (a) data whose storage is required by European Union or Member State law, and (b) backups, which are erased in regular cycles within 90 days at the latest; until erasure, the backups remain protected by the measures under Article 6.
10. Final Provisions of the DPA
10.1. This DPA is concluded for the term of the Agreement; Articles 4.5, 5 and 9 survive its termination until full settlement.
10.2. The parties' liability for a breach of this DPA is governed by Article VII of the Terms; this is without prejudice to the mandatory claims of data subjects and the obligations under Article 82 GDPR.
10.3. Amendments to this DPA are governed by Article X of the Terms. The current list of sub-processors is available at flotello.app.
10.4. This DPA is governed by the law of the Czech Republic and the GDPR.