Legal
Privacy Policy
How Czech Your Way collects, uses and protects your personal data — what we hold, who we share it with, how long we keep it, and the rights you have over it.
Effective from EFFECTIVE DATEVersion 1.0
On this page
- In short
- 1. Who is responsible for your data
- 2. What personal data we process
- 3. Why we process it, and on what legal basis
- 4. Cookies and similar technologies
- 5. Who else sees your data
- 6. Joint controllership with Meta
- 7. Transfers outside the EEA
- 8. How long we keep it
- 9. Personalisation and automated decisions
- 10. Your rights
- 11. Marketing e-mails
- 12. How we protect your data
- 13. Children
- 14. Changes to this policy
Draft for review. The tools listed here are the ones planned for launch — Meta Ads, Google Analytics 4, Google Tag Manager, Hotjar, Stripe, Supabase and Vercel. Fill every highlighted gap, delete anything you end up not using, and have the result checked before it goes live. A policy that lists a tool you do not run is as much of a problem as one that omits a tool you do.
In short
- We collect what we need to run your account and your learning, to take payment, and — only with your consent — to measure and advertise the service.
- We do not sell your personal data.
- We never see your full card number. Payments run through Stripe.
- Analytics and advertising cookies load only after you allow them, and you can change your mind at any time.
- You can ask us for a copy of your data, or to delete it, at PRIVACY E-MAIL.
1. Who is responsible for your data
The controller of your personal data — the one who decides why and how it is processed — is:
- Controller
- Kristýna Zuzaňáková
- Company ID (IČO)
- 17309743
- Registered address
- sídliště Pod lesem 860/14, 742 35 Odry, Czech Republic
- E-mail for data protection
- PRIVACY E-MAIL
We have not appointed a Data Protection Officer — we are not required to, because our core activity does not involve large-scale monitoring or special categories of data. Write to the address above with anything about your data and it reaches the person who decides.
2. What personal data we process
Data you give us
- Account data — name or first name only, e-mail address, password (stored only as a cryptographic hash, never in readable form), language and country of the interface.
- Learning profile — the goals, level, topics and situations you choose so the service can be built around them.
- Billing data — billing name, billing address or country, and, for VAT purposes, whatever the tax rules require. Card details go straight to Stripe; we only see the card brand, the last four digits and the outcome.
- Messages — what you write to support, and anything you send us in feedback.
Data created as you use the service
- Learning activity — lessons opened, exercises completed, answers given, results, streaks, time spent.
- Membership data — plan, term, renewal date, payment history, invoices.
- Technical data — IP address, browser and device type, operating system, language, referring page, timestamps, error and access logs.
- Behavioural analytics — with your consent: pages viewed, clicks, scrolling, and anonymised session recordings and heatmaps (see section 5).
Data we receive from others
- From Stripe — confirmation that a payment succeeded or failed, the payment method type, and fraud-prevention signals.
- From Meta and Google — with your consent: aggregated reports about how our ads performed. We do not receive lists of individuals from them.
We do not intentionally collect special categories of data (health, religion, political opinions and so on). Please do not enter such data into exercises or support messages.
3. Why we process it, and on what legal basis
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Creating and running your account, giving you the lessons and exercises, saving your progress | Account data, learning profile, learning activity | Performance of a contract — Art. 6(1)(b) |
| Taking payment, renewals, refunds, issuing invoices | Billing data, membership data | Contract — Art. 6(1)(b), and legal obligation — Art. 6(1)(c) for accounting and tax records |
| Support, answering your questions, handling complaints and withdrawals | Account data, messages, membership data | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) for statutory complaint handling |
| Keeping the service secure — detecting abuse, shared logins, fraud and attacks | Technical data, account data, membership data | Legitimate interest — Art. 6(1)(f): protecting the service and paying members |
| Service e-mails you cannot opt out of — order confirmations, renewal reminders, security notices, changes to the terms | Account data, membership data | Contract — Art. 6(1)(b), and legal obligation — Art. 6(1)(c) |
| Measuring how the site and the app are used, so we can improve them (Google Analytics 4, Hotjar) | Technical data, behavioural analytics, cookie identifiers | Consent — Art. 6(1)(a), given in the cookie banner |
| Advertising — measuring campaigns, building audiences and showing ads on Meta platforms | Cookie identifiers, technical data, hashed e-mail if you enable the Conversions API | Consent — Art. 6(1)(a) |
| Marketing e-mails about Czech Your Way | Account data, membership data | Legitimate interest — Art. 6(1)(f) towards our own customers, under § 7(3) of Act No. 480/2004 Coll., with an opt-out in every message; consent — Art. 6(1)(a) for everyone else |
| Establishing, exercising or defending legal claims | Any of the above, as relevant | Legitimate interest — Art. 6(1)(f) |
| Keeping accounting, tax and invoicing records | Billing data, membership data | Legal obligation — Art. 6(1)(c) |
Where we rely on consent, you may withdraw it at any time — that does not affect what we did lawfully before you withdrew it. Where we rely on legitimate interest, you may object; section 10 explains how.
5. Who else sees your data
We use a small number of service providers to run Czech Your Way. Most of them act as our processors: they only handle your data on our instructions, under a data processing agreement required by GDPR Art. 28. Where a provider decides things for itself, it is named as a separate or joint controller below.
| Provider | What it does for us | Role | Where it goes, and on what safeguard |
|---|---|---|---|
| Vercel Inc. — privacy | Hosting of the website and application, content delivery, server and error logs | Processor | USA, with EU region processing where configured — EU–US Data Privacy Framework and/or Standard Contractual Clauses |
| Supabase Inc. — privacy | Database, user authentication, file storage — where your account and learning data live | Processor | EU region — confirm your project region; Standard Contractual Clauses where support access happens from outside the EEA |
| Stripe Payments Europe, Ltd. / Stripe, Inc. — privacy | Card payments, subscriptions, invoices, fraud prevention | Processor for the payment we ask it to take; independent controller for its own fraud-prevention, anti-money-laundering and regulatory purposes | Ireland and USA — Data Privacy Framework and Standard Contractual Clauses |
| Google Ireland Limited — privacy | Google Analytics 4 and Google Tag Manager | Processor, under Google’s Ads Data Processing Terms | EU and USA — Data Privacy Framework and Standard Contractual Clauses |
| Meta Platforms Ireland Limited — privacy | Meta pixel, campaign measurement and advertising on Facebook and Instagram | Joint controller with us for the collection and transmission of the data — see section 6 | Ireland and USA — Data Privacy Framework and Standard Contractual Clauses |
| Hotjar Ltd. — privacy | Heatmaps, behavioural analytics and anonymised session recordings | Processor | Malta / EU — processing stays in the EEA; SCCs for any sub-processor outside it |
| E-MAIL PROVIDER | Transactional e-mails and, where you have asked for them, newsletters | Processor | WHERE, AND ON WHAT SAFEGUARD |
| ACCOUNTANT / TAX ADVISER | Bookkeeping and tax filings | Processor | Czech Republic |
Beyond that, we may disclose data to public authorities, courts or our legal advisers where the law requires it or where we need to defend a claim. If the business is ever sold or reorganised, data may pass to the successor, who is bound by this policy until it tells you otherwise.
Paperwork to have on file
Each processor above needs a signed DPA: Stripe’s is part of the Services Agreement, Google’s Data Processing Amendment is accepted in the GA4 admin, and Vercel, Supabase and Hotjar publish theirs. Keep a record of the sub-processor lists you were shown — you have to notify users of changes that matter.
6. Joint controllership with Meta
When you consent to marketing cookies, the Meta pixel on our site collects certain data about your visit and transmits it to Meta. For that collection and transmission, we and Meta Platforms Ireland Limited are joint controllers under GDPR Art. 26. The essence of our arrangement, which follows Meta’s Controller Addendum, is:
- We are responsible for giving you this information and for obtaining your consent before the pixel fires.
- Meta is responsible for the rights you exercise over the data once it has it — access, erasure and the rest — and for the security of its own systems.
- You may exercise your rights against either of us. Whichever you contact, we will pass your request to the other where that is needed.
- Meta’s own later processing of that data — for its advertising across its platforms — is Meta’s alone, and this policy does not cover it.
Meta explains what it does with the data in its Data Policy and in the Controller Addendum. You can withdraw consent at any time in our cookie settings, and manage ad personalisation in your Meta account settings.
7. Transfers outside the EEA
Some of the providers above are based in the United States. Where data reaches them, the transfer rests on one of the safeguards in Chapter V of the GDPR: the EU–US Data Privacy Framework, where the provider is certified under it, or the European Commission’s Standard Contractual Clauses together with the technical and organisational measures the provider applies.
The Data Privacy Framework adequacy decision is currently in force; it was upheld by the EU General Court in September 2025 and an appeal is pending. If it were annulled, we would fall back on Standard Contractual Clauses and reassess each transfer. You may ask us for a copy of the safeguards that apply to a specific transfer at PRIVACY E-MAIL.
8. How long we keep it
| Data | Kept for | Why |
|---|---|---|
| Account and learning data | For as long as your account exists, then 3 years | The limitation period for claims arising from the contract |
| Invoices, payment records and accounting documents | 10 years from the end of the tax period | Act No. 235/2004 Coll. on VAT and Act No. 563/1991 Coll. on accounting |
| Contracts, orders and consents to immediate delivery | 4 years from the end of the contract | Proof of what was agreed, and of the statutory pre-contract information |
| Support correspondence | 3 years | Handling complaints and defending claims |
| Server and security logs | 30 days | Security and troubleshooting |
| Google Analytics 4 data | 14 months | Configured retention limit |
| Hotjar data | 365 days | Configured retention limit |
| Marketing consents and records of cookie consent | 3 years after withdrawal | Proving consent under GDPR Art. 7(1) |
When a period ends we delete the data, or irreversibly anonymise it so it can still be counted in statistics without being about anyone.
9. Personalisation and automated decisions
The service adapts what it shows you to the goals, level and topics you chose and to how you have been doing — that is what makes it personal, and it is part of what you are buying. It produces no legal effect for you and nothing comparable to one, so it is not automated decision-making of the kind GDPR Art. 22 restricts.
If you consent to marketing cookies, Meta and Google build advertising profiles using data from many sites, including ours. That happens under their own rules; you can turn it off for our site by withdrawing consent, and in their own settings for everywhere else.
10. Your rights
Under the GDPR you have the right to:
- Access — get confirmation of whether we process your data, and a copy of it (Art. 15).
- Rectification — have anything inaccurate corrected or completed (Art. 16).
- Erasure — have your data deleted where there is no longer a reason to keep it (Art. 17). We cannot delete what accounting and tax law requires us to keep.
- Restriction — have processing paused while a dispute about it is resolved (Art. 18).
- Portability — receive the data you gave us, in a structured, machine-readable format, or have it sent to another controller (Art. 20).
- Objection — object at any time to processing based on our legitimate interest, including profiling; and object to direct marketing, which we then stop unconditionally (Art. 21).
- Withdraw consent — at any time, as easily as you gave it (Art. 7(3)).
- Complain — to a supervisory authority (Art. 77).
How to use them
Write to PRIVACY E-MAIL from the address registered to your account, or from another address if you can identify yourself another way. We answer within one month, and may extend that by two further months for complex requests, telling you why. It is free, unless a request is manifestly unfounded or repetitive.
Complaining to the regulator
If you believe we are handling your data wrongly, please tell us first — and you can complain to the Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, uoou.gov.cz. If you live in another EU member state, you may complain to your own supervisory authority instead.
11. Marketing e-mails
If you buy from us, we may send you occasional e-mails about Czech Your Way itself — new content, features and offers on the service you already use. Czech law allows this to our own customers under § 7(3) of Act No. 480/2004 Coll., and we tell you about it when we collect your address. Every message has a one-click unsubscribe, and unsubscribing costs nothing and changes nothing about your Membership. If you are not a customer, we only e-mail you marketing after you ask us to.
12. How we protect your data
- All traffic runs over HTTPS, and data is encrypted in transit and at rest with our infrastructure providers.
- Passwords are stored only as salted cryptographic hashes and are never readable by us.
- Access to production data is limited to the people who need it, protected by multi-factor authentication.
- We never store full card numbers — the card form is Stripe’s, and it is Stripe that handles the number.
- We keep backups, and we review our providers and their sub-processors as the service grows.
- If a breach ever put your rights at serious risk, we would notify the ÚOOÚ within 72 hours and tell you without undue delay.
13. Children
Czech Your Way is meant for adults. We do not knowingly process the data of children under 15 — the age at which a child can consent to information society services under § 7 of Act No. 110/2019 Coll. Anyone between 15 and 18 needs their parent or guardian to conclude the contract. If you believe a child has given us data, write to PRIVACY E-MAIL and we will delete it.
14. Changes to this policy
We update this policy when the service, our providers or the law change. The current version and its effective date are always at the top of this page, and we keep the earlier ones. If a change materially affects how we use your data, we will e-mail you before it takes effect — and where the change needs your consent, we will ask for it rather than assume it.
Version 1.0, effective from EFFECTIVE DATE.
