Privacy Policy
pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR)
Effective from: 18 May 2026
Introductory Provisions
Under these policies, the company
DLOUHY TECHNOLOGY s.r.o. Company Registration No. (IČ): 28498712 Registered office: Jinonická 759/24, Košíře, 150 00 Praha 5 Registered in the Commercial Register maintained by the Municipal Court in Prague, file no. C 146026 Contact e-mail:
(hereinafter the "Controller")
informs data subjects about the processing of personal data of natural persons in connection with the provision of services, business cooperation, marketing activities and visits to the company's website.
These policies govern the processing of personal data of customers, business partners, prospective clients, applicants for cooperation and visitors to the Controller's website, always to the extent corresponding to their relationship with Dlouhy Technology s.r.o.
"Personal data" means any information relating to an identified or identifiable natural person within the meaning of Article 4(1) GDPR.
I. Data Protection Officer
The Controller has not appointed a Data Protection Officer, as it does not fall within the categories of entities subject to the obligation under Article 37 GDPR.
For matters concerning personal data protection, the exercise of data subject rights and other related queries, please contact the Controller's contact e-mail address stated at the beginning of these policies.
II. Purposes of Processing and Legal Bases
The Controller processes personal data always on a legal basis under Article 6 GDPR, in particular to the extent necessary for the purposes set out below.
A) Performance of a contract - Article 6(1)(b) GDPR
Processing in particular for the purpose of:
· negotiating a contract and taking steps prior to its conclusion at the request of the data subject,
· performance of the contract and provision of the agreed services,
· communication with the customer within the contractual relationship,
· invoicing, settlement of payments and handling of complaints.
The provision of these personal data is a contractual requirement. Without such provision it would not be possible to conclude or perform the contract.
B) Compliance with legal obligations - Article 6(1)(c) GDPR
Processing in particular for the purpose of:
· maintaining accounts and bookkeeping in accordance with applicable legal regulations,
· fulfilling tax obligations in accordance with applicable legal regulations,
· fulfilling archiving obligations in accordance with applicable legal regulations,
· fulfilling obligations towards public authorities.
C) Legitimate interests of the Controller - Article 6(1)(f) GDPR
Processing in particular for the purpose of:
· recording and managing business cooperation and business contacts,
· debt collection, assertion and defence of legal claims,
· maintaining internal records of communication with customers and partners,
· ensuring the security of the network, information systems and website,
· direct marketing towards existing customers in the scope of offering the Controller's own similar products and services (in accordance with applicable legal regulations).
The legitimate interests of the Controller consist in particular of the proper conduct of business activities, the protection of the Controller's assets, rights and good name, ensuring the security of the IT infrastructure and effective customer care.
The data subject has the right to object at any time to processing based on legitimate interests.
D) Consent of the data subject - Article 6(1)(a) GDPR
Processing for the purpose of:
· sending commercial communications and marketing information to persons who are not customers of the Controller,
· marketing surveys and questionnaire research,
· taking and publishing photographic and video documentation from organised events,
· analytical evaluation of website traffic,
· remarketing and targeted online advertising,
· recording enquiries and price quotations beyond the statutory obligation.
The granting of consent is entirely voluntary and its non-granting has no impact on the provision of services or performance of the contract. Consent may be withdrawn at any time in the same simple manner in which it was granted - in particular:
· by e-mail sent to the Controller's contact address,
· via the unsubscribe link in each commercial communication,
· by changing the settings in the cookie bar (for cookies-based processing).
The withdrawal of consent does not affect the lawfulness of processing prior to its withdrawal.
III. Scope of Personal Data Processed
For the above purposes, the Controller processes in particular the following categories of personal data:
· identification data: first name, surname, title, date of birth (only where necessary),
· professional data: job position, employer's name, company registration number (Business ID / IČO), tax identification number (VAT number / DIČ),
· contact data: registered office or residential address, delivery address, e-mail address, telephone number,
· payment data: bank account details, payment data,
· data arising from cooperation: content of communications, data on the course of business cooperation, order history, complaints,
· electronic identifiers: IP address, cookies, device identifier, website behaviour data (only with consent),
· signature (in the case of contractual documentation).
IV. Sources of Personal Data
The Controller obtains personal data:
· directly from the data subject - during contract negotiations, upon ordering, completion of a contact form, registration for an event, etc.,
· from public registers and sources - in particular the Commercial Register, the Trade Register, the VAT payers' register, the insolvency register, publicly available professional networks (e.g. LinkedIn),
· from third parties - only in cases where the Controller has a legal basis for doing so (e.g. from business partners in joint projects).
V. Online Marketing and Use of Cookies
The Controller's website uses analytical and marketing tools, in particular:
· Google Analytics 4 (Google Ireland Ltd.),
· Google Ads including remarketing (Google Ireland Ltd.),
· Sklik (Seznam.cz, a.s.),
· LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company).
These tools enable the evaluation of website traffic, measurement of the success of advertising campaigns and the display of relevant advertising.
Analytical and marketing cookies are activated exclusively on the basis of consent granted via the cookie bar, in accordance with applicable legal regulations governing electronic communications (opt-in regime).
The Controller implements Google Consent Mode v2, which ensures that without the user's consent no marketing cookies are stored and no data is transmitted for advertising personalisation.
Detailed information on individual cookies, their purpose and retention period is set out in the separate document "Cookie Policy".
VI. Recipients of Personal Data
Personal data is processed primarily by the Controller through its authorised employees.
In justified cases, personal data may be made available to the following categories of recipients - processors who process data on the basis of a contract and instructions from the Controller:
· providers of IT and hosting services,
· providers of accounting, tax and audit services,
· providers of legal services,
· providers of CRM and e-mailing tools,
· providers of marketing and analytical tools (Google, Seznam, LinkedIn),
· transport and logistics companies,
· payment service providers.
Personal data may further be transferred to public authorities in cases where applicable law so requires of the Controller (e.g. tax authorities, courts, law enforcement authorities).
VII. Transfer of Personal Data Outside the EU/EEA
In connection with the use of certain online services (in particular Google and LinkedIn), personal data may be transferred to third countries, primarily to the United States of America.
Such transfer is carried out in accordance with the requirements of the GDPR, in particular on the basis of:
· a decision of the European Commission on an adequate level of protection under the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023), where the recipient is certified under this framework,
· standard contractual clauses approved by the Commission (Commission Implementing Decision (EU) 2021/914),
· or other mechanisms under Article 46 GDPR.
A copy of the safeguards used may be provided upon request via the Controller's contact e-mail.
VIII. Personal Data Retention Periods
The Controller retains personal data for the period necessary to fulfil the purpose of processing, but for no longer than the following periods:
· contracts and commercial documentation: for the duration of the contractual relationship and subsequently for a period corresponding to statutory limitation periods and archiving obligations,
· accounting documents: for the period prescribed by applicable legal regulations governing the keeping of accounts,
· tax documents: for the period prescribed by applicable tax regulations,
· enquiries, price quotations and related communications: for a period corresponding to the Controller's legitimate interest in maintaining records of business communications, generally for a period corresponding to the general limitation period,
· marketing consents: until the withdrawal of consent, but for no longer than a period appropriate to the purpose of processing (with the possibility of renewal),
· cookies: according to the specific tool - see the Cookie Policy,
· job applicant data: for the duration of the selection procedure, and after its conclusion for no longer than a period appropriate for the purposes of potential future cooperation (unless consent for longer retention has been granted).
Upon expiry of the set periods, personal data is securely deleted or anonymised.
IX. Automated Decision-Making and Profiling
No automated decision-making that would have legal effects on data subjects or similarly significantly affect them takes place, nor does profiling within the meaning of Article 22 GDPR.
X. Rights of the Data Subject
The data subject has the following rights in connection with the processing of their personal data:
· right of access to personal data (Article 15 GDPR),
· right to rectification of inaccurate or incomplete data (Article 16 GDPR),
· right to erasure ("right to be forgotten") (Article 17 GDPR),
· right to restriction of processing (Article 18 GDPR),
· right to data portability (Article 20 GDPR),
· right to object to processing based on legitimate interests or for direct marketing purposes (Article 21 GDPR),
· right to withdraw consent at any time where processing is based on consent (Article 7(3) GDPR),
· right not to be subject to automated decision-making (Article 22 GDPR),
· right to lodge a complaint with the supervisory authority.
Data subjects may exercise their rights in writing to the Controller's registered office address or electronically to the contact e-mail address stated at the beginning of these policies. The Controller will respond to requests without undue delay, and no later than one month from receipt.
The supervisory authority in the Czech Republic is:
Czech Data Protection Authority (Úřad pro ochranu osobních údajů) Pplk. Sochora 27 170 00 Praha 7 web: https://uoou.gov.cz/ phone: +420 234 665 111 e-mail:
XI. Security of Personal Data
The Controller has adopted appropriate technical and organisational measures to secure personal data against unauthorised or unlawful processing, accidental loss, destruction, damage or unauthorised disclosure.
Measures adopted include in particular:
· management of access rights and user authentication,
· encryption of data in transit and at rest (where relevant),
· regular data backups and recovery testing,
· system updates and protection against malicious software,
· training and regular education of employees in the area of personal data protection,
· contractual confidentiality obligations and appropriate data processing agreements with suppliers.
XII. Final Provisions
These policies may be updated from time to time, in particular in the event of changes in legal regulations, changes in the tools used or the scope of the Controller's activities. The current version is always available on the Controller's website.
Data subjects for whom it is relevant will be notified of any material changes in an appropriate manner (e.g. by e-mail or notice on the website).
These policies are effective from 18 May 2026.