Updated: 10 September 2026
Privacy Policy
This policy describes how the data controller processes personal data of visitors to this website and of persons interested in cooperation, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Czech legislation.
1. Data controller
Matěj Kratochvíl
place of business: Rostoklaty 173, 281 71 Rostoklaty, Czech Republic
business identification number (IČO): 23974486
not registered as a VAT payer
e-mail: matej.kratochvil33@seznam.cz
2. Categories of personal data processed
The contact form sends your name, email, message and, if supplied, website address and budget to the controller’s inbox through Seznam.cz. The website does not store enquiries in its own database and does not use marketing cookies or third-party analytics tools.
Your name, email and brief are required to submit the form and respond to your enquiry. Your current website and budget are optional. Providing data is not a statutory obligation; the form cannot be submitted without its required fields. Please do not include sensitive data or unnecessary information about other people. Attachments are not accepted.
Enquiry content is not written to application logs. Delivery status and a technical message identifier are processed to check delivery and limit duplicates. No profiling or automated decisions producing legal or similarly significant effects take place.
The controller may process in particular the following categories of personal data:
- identification and contact details (name, e-mail address, telephone number, if provided) and the content of a message or inquiry, only if the data subject contacts the controller (through the form, by e-mail or via LinkedIn),
- data related to cooperation (project brief, communication, billing details), only where cooperation has been established,
- technical data (such as IP address, browser type, device, time of access) may arise automatically in operational logs of the hosting provider or related infrastructure. The controller does not actively collect, store, or evaluate these data in the website application for analytics or marketing purposes,
- display preferences (light / dark mode) are stored only in the visitor's browser (localStorage) and are not sent to or stored on the controller's server.
3. Purposes and legal bases for processing
- handling enquiries from individuals acting on their own behalf, at their request before entering into a contract under Art. 6(1)(b) GDPR. For company representatives and other questions, the basis is the legitimate interest in business communication under Art. 6(1)(f) GDPR. Consent is not required to handle an enquiry,
- performance of a contract and provision of services under Art. 6(1)(b) GDPR,
- compliance with accounting and tax obligations under Art. 6(1)(c) GDPR,
- protection of legal claims, operation and security of the website (including any operational hosting logs) based on the legitimate interest of the controller under Art. 6(1)(f) GDPR.
4. Retention periods
- inquiries and communication: usually for up to 3 years from the last contact,
- contractual and billing records: for the period required by accounting and tax legislation, usually 5 to 10 years,
- operational hosting or infrastructure logs: for as long as necessary for operation and security according to the relevant provider’s settings. A technical message fingerprint and delivery state are held temporarily in application memory to limit duplicates. A successful record is valid for 10 minutes and is removed on a subsequent request, or disappears when the server instance stops. This period does not apply to the enquiry in the mailbox or to operational logs,
- browser preferences: until deleted or changed by the user on their device.
5. Recipients and transfers of data
Vercel Inc. provides hosting and server-side form processing. Seznam.cz, a.s. sends and delivers enquiries and processes their content and delivery metadata. Enquiries are then held in the controller’s email inbox provided by Seznam.cz, a.s. The visitor’s email is used as the reply-to address. Personal data may be disclosed to IT and hosting providers, accountants, and other processors only to the extent necessary and, where required, on the basis of a data processing agreement. Operational logs may be processed directly by the hosting or infrastructure provider.
Vercel hosting may process data outside the European Economic Area, particularly in the USA. Safeguards for applicable transfers include the European Commission’s Standard Contractual Clauses. Details and the safeguards are available from Vercel.
6. Rights of the data subject
The data subject has the right to:
- request access to their personal data,
- request rectification or completion of inaccurate data,
- request erasure where the conditions under the GDPR are met,
- request restriction of processing,
- request data portability where GDPR conditions are met,
- object to processing based on legitimate interest,
- withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
Requests to exercise these rights may be sent to matej.kratochvil33@seznam.cz. The controller will respond without undue delay, and no later than one month. For complex requests, this may be extended by two further months; the controller will explain the reasons within the first month.
Where erasure is requested, the controller will, as applicable, delete available communication (for example e-mail) and, within technical possibilities, arrange deletion or anonymisation of relevant operational hosting records. Data required for legal obligations or the establishment, exercise or defence of legal claims may be retained. Preferences in localStorage are stored only in the data subject's browser; the controller has no remote access to them, and the data subject may delete them by clearing the website's data in the browser.
7. Right to lodge a complaint
If the data subject considers that the processing of their personal data infringes the GDPR, they have the right to lodge a complaint with the supervisory authority, which is the Office for Personal Data Protection (www.uoou.cz).
8. Security of personal data
The controller implements appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, or other unlawful handling.
9. Changes to this policy
The controller may update this policy. The current version is always published on this page.