Terms of use Personal data processing Cookies
Effective from 17 September 2026 · version 1.1
These terms govern the use of the responsiblo.com website, the academies on its subdomains and the certification services operated by responsiblo s.r.o. They become part of your contract with us when you expressly accept them while creating an account; for simply browsing the website they apply as the rules under which we make the content available. You can read, print and save their wording on this page at any time. If you do not agree with these terms, please do not use the service.
01
Who operates the service
The service is operated by responsiblo s.r.o., company registration number (IČO) 19428588, VAT number CZ19428588, registered office Varšavská 715/36, Vinohrady, 120 00 Prague 2, Czech Republic, registered in the Commercial Register kept by the Municipal Court in Prague, file number C 386401. Our contact email address is info@responsiblo.com, our Czech data box is edyk5ss and our postal address is the registered office. In the text below we refer to ourselves as "we" and to the user of the service as "you".
02
Scope of the service
On responsiblo.com you will find information about our educational programmes, contact and enquiry forms, and access to the academies where the learning takes place. A programme consists of chapters, a practical part and a final quiz. The free AI Act Literacy programme is intended for individuals and for personal use: once you register, we enrol you in it and the account remains free of charge. Company accounts are ordered by organisations on the basis of an enquiry, the prices in the price list are shown excl. VAT and we handle each order individually, including the invoice. Within its company account an organisation invites people by email, an invitation is valid for 30 days from the moment it is sent, and inside its own academy the organisation can see how the invited people are progressing and whether they hold a valid certificate. The organisation is a separate controller of its own list of invited people and is responsible for having a lawful basis for passing that list to us. Accounts, learning records, issued certificates and the register of those certificates are processed by us as the controller; we make the overview of the progress and certificates of the invited people available to the organisation only to the extent necessary, on the basis of our contract with the organisation and the legitimate interest of both parties in keeping records of training. Who is responsible for which data, and what an organisation can see inside its academy, is set out in the Personal data processing tab.
03
Account and access
An account may be created by an individual who is at least 18 years old. Please provide true and current details: the first name and surname held in your account are carried over to the certificate and cannot be changed on a certificate once it has been issued. The account is personal and non-transferable, you must protect your sign-in details and must not share them with anyone else. You are responsible for activity carried out through your account; you are not responsible for it where someone else misused your account without any fault on your part. As soon as you find that someone else has gained access to your account, tell us at info@responsiblo.com and we will block the account. The link that completes your registration and the link for resetting your password are valid for 24 hours from the moment they are sent. If you create your account or sign in using the Google button, we take your email address, name and account identifier from your Google account; in that case you have no password with us. If we have reasonable grounds to suspect a breach of these terms, misuse of an account or a threat to the security of the service, we may temporarily restrict or block the account.
04
The certificate and its validity
We issue a certificate to anyone who meets the conditions of the particular programme, that is, works through the prescribed content and passes the final quiz with the required score. The certificate is issued in the first name and surname held in the account; these details are stored in the certificate in unchangeable form at the moment of issue, so that the document cannot be altered afterwards. Every certificate carries its own number in the form RSP-XXXX-XXXX-XXXX, the date on which the conditions were met and the validity period. How long a certificate remains valid is set by the programme and is stated on the certificate itself. Unless the programme states otherwise, a certificate is valid for 24 months. You can download your certificate as a PDF from your account. The certificate confirms that you completed our programme and met its conditions; it is not a public authorisation, a state accreditation or a certification under the EU AI Act.
05
Verification and withdrawal of a certificate
Anyone can verify that a certificate is genuine by entering its number on the Certificate verification page at responsiblo.com; the link printed on the certificate takes the form responsiblo.com/verify/NUMBER. For a valid certificate we publish the holder's name, the name of the programme, the issuer, any organisation named on the certificate, the date on which the conditions were met, the validity, the certificate number and a fingerprint of the issued document; we do not show the email address, the quiz results or any other details on the verification page. For an expired certificate we publish the holder's name, the name of the programme, the date on which the conditions were met and the expiry date, and for a withdrawn certificate only its number and the date of withdrawal, because we publish neither the holder's name nor the reason for withdrawal. We may withdraw a certificate if it was obtained fraudulently, on the basis of false information or in breach of these terms. The record of an issued certificate and the ability to verify it remain in place even after an account is closed, as verification would otherwise lose its meaning; how long we keep the register of issued certificates is set out in the Personal data processing tab. Where a certificate was obtained by an individual outside a company account, both the certificate and the verification page state that it is a personal certificate and that it is not a record of staff training for an organisation.
06
Rights to the content
The content of the service, that is the texts, videos, graphics, practical scenarios, final quiz questions, the design of the certificate and the responsiblo brand, is protected by copyright and other intellectual property rights. We grant you a non-exclusive, non-transferable and revocable right to use the content for your own purposes and to the extent needed to complete a programme. Without our prior written consent, the content must not be copied, downloaded beyond the functions of the service, redistributed, made available to other people, modified, used for training outside our platform or otherwise exploited commercially. Automated harvesting of the content and circumventing the technical measures that protect it are also not permitted.
07
Liability and the limits of a programme
Our programmes are educational content, not legal advice. Completing a programme is one of the measures through which an organisation can support the AI literacy of its people under Article 4 of the EU AI Act; on its own it does not mean that an individual or an organisation meets the obligations arising from the AI Act or from other legislation, because those depend on how the particular organisation uses AI. AI Act Literacy is an independent educational product of responsiblo s.r.o. It is not a programme of the European Union, nor is it endorsed by the European Union. We make reasonable efforts to keep the service available and the content in line with the current wording of the legislation, but we do not guarantee uninterrupted or error-free operation, nor that the service will meet every expectation. We are not liable for the decisions you make in practice on the basis of the content, nor for problems caused by a connection failure or incompatible equipment on your side. Nothing in this limits our liability for damage caused intentionally or by gross negligence, or for harm to a person's life, health or other personality rights, and nothing in it affects rights that cannot be waived under the law, in particular your rights as a consumer.
08
Ending the service and changes to these terms
You can close your account at any time, simply write to info@responsiblo.com. Once the account is closed we delete the records of your learning; we keep only the record of an issued certificate and its public verification, as described in the paragraph on verification and withdrawal of a certificate. We may restrict or end the service in the event of a serious breach of these terms, in particular misuse of an account or of the certification, infringement of the rights of others or a security incident. We may amend and supplement these terms, for example when the scope of the service or the legislation changes. We publish the new wording on this page together with the version and the effective date; if you do not agree with a change, you can stop using the service and close your account.
09
Governing law and consumers
The relationship between you and us is governed by the law of the Czech Republic; this does not affect the rights that mandatory legislation of your country of residence gives you as a consumer. The free programme for individuals is not paid for, so no purchase arises that could be withdrawn from. Company accounts are ordered by organisations acting as businesses, prices are shown excl. VAT and an order is handled on the basis of an enquiry and an invoice. We do not currently accept online payments. If you order a paid service as a consumer, you will receive the full pre-contractual information under Section 1820 of the Czech Civil Code (Act No. 89/2012 Coll.) before the contract is concluded: you have 14 days to withdraw from the contract (Section 1829) and, for digital content that we do not supply on a tangible medium, that right ends once we begin performance with your express consent and you confirm that you thereby lose the right to withdraw (Section 1837(l)). Send any withdrawal to info@responsiblo.com or to our registered office. We deal with disputes primarily by agreement, and a consumer may turn to the body for the out-of-court settlement of consumer disputes, which is the Czech Trade Inspection Authority (Česká obchodní inspekce), Central Inspectorate, ADR Department (oddělení mimosoudního řešení spotřebitelských sporů), Gorazdova 1969/24, 120 00 Prague 2, Czech Republic, https://coi.gov.cz/informace-o-adr/. These terms are published in Czech and in English; if the versions differ, the Czech wording prevails.
Here you will find what personal data we process, why we process it, who we share it with, how long we keep it and what rights you have. Processing is governed by the General Data Protection Regulation (GDPR) and by Czech Act No. 110/2019 Coll., on personal data processing.
01
Who the controller is and how to contact us
The controller of your personal data is responsiblo s.r.o., company registration number (IČO) 19428588, VAT number CZ19428588, registered office at Varšavská 715/36, Vinohrady, 120 00 Prague 2, Czech Republic, registered in the Commercial Register kept by the Municipal Court in Prague, file number C 386401. For anything to do with data protection, contact us at info@responsiblo.com, through the Czech data box edyk5ss, or by post to our registered office. We have not appointed a data protection officer because the law does not require us to; your questions and requests are handled at the contact details above.
02
Website visitors and people who fill in our forms
If you are only browsing the website, our web server keeps operational records containing your IP address, the time of access and details of your browser; we use them to run and secure the site and we do not link them to your identity. No third-party measurement or advertising tools run on this website. If you fill in the contact form, we process your name, the name of your organisation, your email address, a phone number if you give one, the topic you select and the text of your message; the message is sent to our support team by email and is not stored in a database. If you request the checklist or send a company enquiry, we store your name, work email address, company name and number of employees, and for an enquiry also the plan you select, the text of your message and whether you would like a call, together with your IP address, the time of submission and the exact wording of the consent you ticked. We protect our forms against misuse with a hidden field, a timing trap and limits on how many submissions we accept from one IP address and from one email address. The forms are additionally protected by the Cloudflare Turnstile service; during the check, the IP address and technical details about the browser are sent to Cloudflare, the contents of the form are not. If you study in a public academy on one of our subdomains, the rspVisitor cookie with a random number is stored in your browser and we keep your learning progress against that number, that is completed chapters, video playback and the quiz result. The number holds no name or contact details of yours, but it is a persistent identifier of your browser, so we treat these records as personal data.
03
Registered individuals and certificate holders
When you register, we process your email address, first name and surname, your password stored only in an unreadable form, your country, language and time zone, the record that your email address has been verified, and your learning record, meaning the chapters you have completed, video playback and the result of the final quiz. If you register or sign in with the Google button, we receive your email address, name and Google account identifier from your Google account and no password is created with us; Google will learn that you are signing in to responsiblo.com. The sign-up, sign-in and password recovery forms are protected by the same Cloudflare Turnstile service: your browser loads its script and the service returns a verification token, which we then check with Cloudflare together with your IP address. Once you meet the conditions of the programme, we issue your certificate; the holder's first name, surname and email address are written into an unchangeable record at the moment of issue so that the certificate can be verified at any time. Our programmes are intended for people aged 18 and over; we do not knowingly process children's data or special categories of personal data. An address that Google does not confirm as verified is refused. If you already have an account with us under that address, we link it to your Google account and sign you in, and the password you have on it stays valid. If you do not have an account yet, the first name and surname from Google are only prefilled into the registration form and you can edit them before you submit it.
04
Why we process your data and on what legal basis
We process your account, your access to the programme, your saved progress and the issuing of your certificate so that we can provide the service you asked for; the legal basis is performance of a contract. Answering an enquiry from the contact form and handling a company enquiry rests on steps taken at your request before entering into a contract and on our legitimate interest in replying to someone who has contacted us. Providing you with the checklist and storing your details for that purpose rests on the consent you give by ticking the box on the form. The verifiability of issued certificates, the protection of forms and accounts against misuse, operational security and the defence of legal claims rest on our legitimate interest; we have assessed it on the basis that without public verifiability a certificate would lose its value both for its holder and for whoever checks it, and that without form protection we could not keep the service running. Making the overview of the progress and certificates of invited people available to the organisation that invited them into its company account rests on the performance of our contract with that organisation and on the legitimate interest both we and the organisation have in the organisation holding records of the training of its people; we make available only the data listed in the section on company accounts. Storing your progress in a public academy against a random number in a cookie rests on our legitimate interest in letting you carry on where you left off without having to create an account; you may object to this processing, and deleting the rspVisitor cookie in your browser is enough to stop it. We process accounting and tax records because the law requires it. We do not send marketing messages and we will not start sending them without your explicit consent. Data that Google passes us when you sign in or register with the Google button is processed for the same reason as data from an ordinary registration, that is so that we can create and run your account; the legal basis is the performance of a contract and we neither need nor ask for your consent.
05
Certificates and public verification
A certificate is an unchangeable record. The holder's first name, surname and email address are written into it at the moment of issue and stay in our records even if the holder closes their account; otherwise there would be no way to show that the certificate was genuinely issued. On the public verification page we publish, for a valid certificate, the holder's first name and surname, the name of the programme, the issuer, any organisation named on the certificate, the date the programme was completed, the validity period, the certificate number and a fingerprint of the document. For a certificate that has expired we publish the holder's first name and surname, the programme, the date of completion and the expiry date. For a withdrawn certificate we publish neither the holder's name nor the reason for withdrawal, only the certificate number and the date of withdrawal. The holder's email address is never shown on the verification page or on the certificate, and we do not allow search engines to index verification results.
06
Company accounts and invitations from organisations
An organisation that sets up a company account invites specific people into it, for example its own staff or people it works with. The organisation draws up the list of invitees itself, decides on its own who to invite, and is responsible for having a lawful basis for passing us their name and email address; in relation to that list it is a separate controller. An invitation is valid for 30 days and the link in it can be used once. In such a case we did not obtain your name and email address from you but from the organisation that invited you, so if you want to know why you received the invitation, please ask them. As soon as you accept the invitation, your personal account is created and in relation to that account we are the controller: we decide how the account works, how long we keep the data and how we issue and verify certificates. Within its own academy the organisation sees only what it needs in order to administer the account, that is whether an invitation was sent and accepted, how far you have got in the programme, whether you have completed it and the number and status of your certificate, and it can download that overview as a table. We are the controller of that overview and its export as well; we make available to the organisation only what is necessary, on the basis of our contract with it and of the legitimate interest both it and we have in the organisation holding records of the training of its people. We do not enter into a processor agreement under Article 28 of the GDPR with organisations, because it is we who decide how the account works, how long we keep the data and when a certificate is issued or withdrawn. We do not pass the organisation your quiz answers, the content of your communication with us or your sign-in details. A personal certificate from the free programme is not a company training record; that is created only within a company account.
07
Who we share data with and transfers outside the European Union
We share data only to the extent necessary and only with those who process it for us or who have a statutory claim to it. The platform runs on the servers of a hosting provider in the Czech Republic, which operates, administers and backs them up for us. Outgoing emails, that is registration confirmations, password resets, invitations and certificate notifications, are delivered by an email service provider and the transfer is encrypted. The fonts used on our pages and in the platform are served from our own servers; your browser does not fetch them from anyone else. For forms protected by the Cloudflare Turnstile service, the data needed to tell automated requests apart is processed by Cloudflare. It may process that data outside the European Union; any such transfer relies on the safeguards set out in the General Data Protection Regulation, in particular the standard contractual clauses approved by the European Commission, and you will find the details in its own privacy policy. Signing in with the Google button works differently. The button is an ordinary link on the page, and until you press it your browser does not contact Google. When you press it, the sign-in takes place directly between your browser and Google; we send Google no data about you and we do not pass it information about your progress in the course. Google thereby learns that you are signing in to responsiblo.com, and it acts as a separate controller under its own privacy policy, not on our instructions; we are not its processor, it is not ours, and we do not enter into a processing agreement with it under Article 28 of the GDPR. Google is responsible for what it does with your data and for whether it processes it outside the European Union, and its own policy sets that out. On request we will provide a copy of the safeguards used, or tell you where they are published, at info@responsiblo.com. We may also disclose data to public authorities where the law or an enforceable decision requires it. We enter into data processing agreements with our processors.
08
How long we keep your data
We keep the details from a checklist request and a company enquiry for at most 3 years from the last contact. For the same period, that is at most 3 years from the last contact, we keep messages from the contact form and other email correspondence in our mailboxes, for as long as is needed to deal with them and to follow up. We keep them for longer only where a contractual relationship arises or another reason for longer retention applies, such as an accounting duty or the defence of a legal claim. We keep account data and your learning record for as long as the account exists; when you close your account, we delete the learning records. We keep the register of issued certificates for the validity period of the certificate and for a further 10 years, so that we can show and verify that it was issued. We keep documents and data that accounting and tax law requires us to retain for the period those rules set, that is 5 years for accounting documents from the end of the accounting period they relate to, and 10 years for tax documents from the end of the tax period in which the supply took place. An invitation to a company account is valid for 30 days and the record of it stays in the company account for as long as that account exists. We keep application logs for 30 days; web server records containing IP addresses are kept for as long as is necessary for operation and security. We keep learning records from the public academies on our subdomains against a random number from the rspVisitor cookie only; they contain no name, email address or IP address, and we delete them once the last activity of a given identifier is more than 24 months old. Data may persist for a limited time in server backups.
09
Your rights
You have the right to know what data we process about you and to obtain access to it. You have the right to have inaccurate data corrected, to erasure, to restriction of processing, to data portability and to object to processing that rests on our legitimate interest. If you have given us consent, you can withdraw it at any time at info@responsiblo.com; this does not affect the lawfulness of processing carried out before the withdrawal. Providing your data is not a statutory obligation, but without an email address, a name and a password we cannot create an account for you or issue a certificate, and without the details from a form we cannot reply to you or provide you with the checklist. We assess each erasure request individually, because we need to keep the record of an issued certificate so that the certificate can be verified; we will always explain what can be restricted and what cannot. We deal with requests as soon as we can and at the latest within one month of receiving them. If a request is complex or if we receive a number of requests from you, we may extend that period by up to two further months; we will tell you about the extension and the reason for it within one month of receiving the request. If you are not satisfied with how we handle your data, you can lodge a complaint with the Czech supervisory authority, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, www.uoou.gov.cz, or with the supervisory authority in the country where you habitually reside.
10
Automated decision-making, security and cookies
We do not carry out profiling or decision-making based solely on automated processing that would have legal effects for you or similarly significantly affect you. The final quiz is marked automatically against a threshold set in advance and the certificate is issued automatically on that result; this is an assessment of whether the conditions of the programme have been met, not a decision about you as a person. We protect your data with appropriate technical and organisational measures, in particular access rights management, encrypted data transfer, passwords stored only in an unreadable form, limits on repeated sign-in and form attempts, and regular backups. Which cookies the website uses and why is described in the Cookies tab; we do not use any third-party analytics or advertising tools. We may update this text; the current version is always on this page and the effective date and version are shown in its header. This text is published in Czech and in English; in the event of any discrepancy between the language versions, the Czech version prevails.