Privacy Policy

pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR)

Effective from: 18 May 2026

Introductory Provisions

Under these policies, the company

DLOUHY TECHNOLOGY s.r.o. Company Registration No. (IČ): 28498712 Registered office: Jinonická 759/24, Košíře, 150 00 Praha 5 Registered in the Commercial Register maintained by the Municipal Court in Prague, file no. C 146026 Contact e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it. Phone: +420 226 800 800 Data box (datová schránka): uh8y9zh

(hereinafter the "Controller")

informs data subjects about the processing of personal data of natural persons in connection with the provision of services, business cooperation, marketing activities and visits to the company's website.

These policies govern the processing of personal data of customers, business partners, prospective clients, applicants for cooperation and visitors to the Controller's website, always to the extent corresponding to their relationship with Dlouhy Technology s.r.o.

"Personal data" means any information relating to an identified or identifiable natural person within the meaning of Article 4(1) GDPR.

I. Data Protection Officer

The Controller has not appointed a Data Protection Officer, as it does not fall within the categories of entities subject to the obligation under Article 37 GDPR.

For matters concerning personal data protection, the exercise of data subject rights and other related queries, please contact the Controller's contact e-mail address stated at the beginning of these policies.

II. Purposes of Processing and Legal Bases

The Controller processes personal data always on a legal basis under Article 6 GDPR, in particular to the extent necessary for the purposes set out below.

A) Performance of a contract - Article 6(1)(b) GDPR

Processing in particular for the purpose of:

·       negotiating a contract and taking steps prior to its conclusion at the request of the data subject,

·       performance of the contract and provision of the agreed services,

·       communication with the customer within the contractual relationship,

·       invoicing, settlement of payments and handling of complaints.

The provision of these personal data is a contractual requirement. Without such provision it would not be possible to conclude or perform the contract.

B) Compliance with legal obligations - Article 6(1)(c) GDPR

Processing in particular for the purpose of:

·       maintaining accounts and bookkeeping in accordance with applicable legal regulations,

·       fulfilling tax obligations in accordance with applicable legal regulations,

·       fulfilling archiving obligations in accordance with applicable legal regulations,

·       fulfilling obligations towards public authorities.

C) Legitimate interests of the Controller - Article 6(1)(f) GDPR

Processing in particular for the purpose of:

·       recording and managing business cooperation and business contacts,

·       debt collection, assertion and defence of legal claims,

·       maintaining internal records of communication with customers and partners,

·       ensuring the security of the network, information systems and website,

·       direct marketing towards existing customers in the scope of offering the Controller's own similar products and services (in accordance with applicable legal regulations).

The legitimate interests of the Controller consist in particular of the proper conduct of business activities, the protection of the Controller's assets, rights and good name, ensuring the security of the IT infrastructure and effective customer care.

The data subject has the right to object at any time to processing based on legitimate interests.

D) Consent of the data subject - Article 6(1)(a) GDPR

Processing for the purpose of:

·       sending commercial communications and marketing information to persons who are not customers of the Controller,

·       marketing surveys and questionnaire research,

·       taking and publishing photographic and video documentation from organised events,

·       analytical evaluation of website traffic,

·       remarketing and targeted online advertising,

·       recording enquiries and price quotations beyond the statutory obligation.

The granting of consent is entirely voluntary and its non-granting has no impact on the provision of services or performance of the contract. Consent may be withdrawn at any time in the same simple manner in which it was granted - in particular:

·       by e-mail sent to the Controller's contact address,

·       via the unsubscribe link in each commercial communication,

·       by changing the settings in the cookie bar (for cookies-based processing).

The withdrawal of consent does not affect the lawfulness of processing prior to its withdrawal.

III. Scope of Personal Data Processed

For the above purposes, the Controller processes in particular the following categories of personal data:

·       identification data: first name, surname, title, date of birth (only where necessary),

·       professional data: job position, employer's name, company registration number (Business ID / IČO), tax identification number (VAT number / DIČ),

·       contact data: registered office or residential address, delivery address, e-mail address, telephone number,

·       payment data: bank account details, payment data,

·       data arising from cooperation: content of communications, data on the course of business cooperation, order history, complaints,

·       electronic identifiers: IP address, cookies, device identifier, website behaviour data (only with consent),

·       signature (in the case of contractual documentation).

IV. Sources of Personal Data

The Controller obtains personal data:

·       directly from the data subject - during contract negotiations, upon ordering, completion of a contact form, registration for an event, etc.,

·       from public registers and sources - in particular the Commercial Register, the Trade Register, the VAT payers' register, the insolvency register, publicly available professional networks (e.g. LinkedIn),

·       from third parties - only in cases where the Controller has a legal basis for doing so (e.g. from business partners in joint projects).

V. Online Marketing and Use of Cookies

The Controller's website uses analytical and marketing tools, in particular:

·       Google Analytics 4 (Google Ireland Ltd.),

·       Google Ads including remarketing (Google Ireland Ltd.),

·       Sklik (Seznam.cz, a.s.),

·       LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company).

These tools enable the evaluation of website traffic, measurement of the success of advertising campaigns and the display of relevant advertising.

Analytical and marketing cookies are activated exclusively on the basis of consent granted via the cookie bar, in accordance with applicable legal regulations governing electronic communications (opt-in regime).

The Controller implements Google Consent Mode v2, which ensures that without the user's consent no marketing cookies are stored and no data is transmitted for advertising personalisation.

Detailed information on individual cookies, their purpose and retention period is set out in the separate document "Cookie Policy".

VI. Recipients of Personal Data

Personal data is processed primarily by the Controller through its authorised employees.

In justified cases, personal data may be made available to the following categories of recipients - processors who process data on the basis of a contract and instructions from the Controller:

·       providers of IT and hosting services,

·       providers of accounting, tax and audit services,

·       providers of legal services,

·       providers of CRM and e-mailing tools,

·       providers of marketing and analytical tools (Google, Seznam, LinkedIn),

·       transport and logistics companies,

·       payment service providers.

Personal data may further be transferred to public authorities in cases where applicable law so requires of the Controller (e.g. tax authorities, courts, law enforcement authorities).

VII. Transfer of Personal Data Outside the EU/EEA

In connection with the use of certain online services (in particular Google and LinkedIn), personal data may be transferred to third countries, primarily to the United States of America.

Such transfer is carried out in accordance with the requirements of the GDPR, in particular on the basis of:

·       a decision of the European Commission on an adequate level of protection under the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023), where the recipient is certified under this framework,

·       standard contractual clauses approved by the Commission (Commission Implementing Decision (EU) 2021/914),

·       or other mechanisms under Article 46 GDPR.

A copy of the safeguards used may be provided upon request via the Controller's contact e-mail.

VIII. Personal Data Retention Periods

The Controller retains personal data for the period necessary to fulfil the purpose of processing, but for no longer than the following periods:

·       contracts and commercial documentation: for the duration of the contractual relationship and subsequently for a period corresponding to statutory limitation periods and archiving obligations,

·       accounting documents: for the period prescribed by applicable legal regulations governing the keeping of accounts,

·       tax documents: for the period prescribed by applicable tax regulations,

·       enquiries, price quotations and related communications: for a period corresponding to the Controller's legitimate interest in maintaining records of business communications, generally for a period corresponding to the general limitation period,

·       marketing consents: until the withdrawal of consent, but for no longer than a period appropriate to the purpose of processing (with the possibility of renewal),

·       cookies: according to the specific tool - see the Cookie Policy,

·       job applicant data: for the duration of the selection procedure, and after its conclusion for no longer than a period appropriate for the purposes of potential future cooperation (unless consent for longer retention has been granted).

Upon expiry of the set periods, personal data is securely deleted or anonymised.

IX. Automated Decision-Making and Profiling

No automated decision-making that would have legal effects on data subjects or similarly significantly affect them takes place, nor does profiling within the meaning of Article 22 GDPR.

X. Rights of the Data Subject

The data subject has the following rights in connection with the processing of their personal data:

·       right of access to personal data (Article 15 GDPR),

·       right to rectification of inaccurate or incomplete data (Article 16 GDPR),

·       right to erasure ("right to be forgotten") (Article 17 GDPR),

·       right to restriction of processing (Article 18 GDPR),

·       right to data portability (Article 20 GDPR),

·       right to object to processing based on legitimate interests or for direct marketing purposes (Article 21 GDPR),

·       right to withdraw consent at any time where processing is based on consent (Article 7(3) GDPR),

·       right not to be subject to automated decision-making (Article 22 GDPR),

·       right to lodge a complaint with the supervisory authority.

Data subjects may exercise their rights in writing to the Controller's registered office address or electronically to the contact e-mail address stated at the beginning of these policies. The Controller will respond to requests without undue delay, and no later than one month from receipt.

The supervisory authority in the Czech Republic is:

Czech Data Protection Authority (Úřad pro ochranu osobních údajů) Pplk. Sochora 27 170 00 Praha 7 web: https://uoou.gov.cz/ phone: +420 234 665 111 e-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.

XI. Security of Personal Data

The Controller has adopted appropriate technical and organisational measures to secure personal data against unauthorised or unlawful processing, accidental loss, destruction, damage or unauthorised disclosure.

Measures adopted include in particular:

·       management of access rights and user authentication,

·       encryption of data in transit and at rest (where relevant),

·       regular data backups and recovery testing,

·       system updates and protection against malicious software,

·       training and regular education of employees in the area of personal data protection,

·       contractual confidentiality obligations and appropriate data processing agreements with suppliers.

XII. Final Provisions

These policies may be updated from time to time, in particular in the event of changes in legal regulations, changes in the tools used or the scope of the Controller's activities. The current version is always available on the Controller's website.

Data subjects for whom it is relevant will be notified of any material changes in an appropriate manner (e.g. by e-mail or notice on the website).

These policies are effective from 18 May 2026.