Skip to content

Legal

Privacy Policy

How Czech Your Way collects, uses and protects your personal data — what we hold, who we share it with, how long we keep it, and the rights you have over it.

Effective from EFFECTIVE DATEVersion 1.0

On this page

Draft for review. The tools listed here are the ones planned for launch — Meta Ads, Google Analytics 4, Google Tag Manager, Hotjar, Stripe, Supabase and Vercel. Fill every highlighted gap, delete anything you end up not using, and have the result checked before it goes live. A policy that lists a tool you do not run is as much of a problem as one that omits a tool you do.

In short

  • We collect what we need to run your account and your learning, to take payment, and — only with your consent — to measure and advertise the service.
  • We do not sell your personal data.
  • We never see your full card number. Payments run through Stripe.
  • Analytics and advertising cookies load only after you allow them, and you can change your mind at any time.
  • You can ask us for a copy of your data, or to delete it, at PRIVACY E-MAIL.

1. Who is responsible for your data

The controller of your personal data — the one who decides why and how it is processed — is:

Controller
Kristýna Zuzaňáková
Company ID (IČO)
17309743
Registered address
sídliště Pod lesem 860/14, 742 35 Odry, Czech Republic
E-mail for data protection
PRIVACY E-MAIL

We have not appointed a Data Protection Officer — we are not required to, because our core activity does not involve large-scale monitoring or special categories of data. Write to the address above with anything about your data and it reaches the person who decides.

2. What personal data we process

Data you give us

  • Account data — name or first name only, e-mail address, password (stored only as a cryptographic hash, never in readable form), language and country of the interface.
  • Learning profile — the goals, level, topics and situations you choose so the service can be built around them.
  • Billing data — billing name, billing address or country, and, for VAT purposes, whatever the tax rules require. Card details go straight to Stripe; we only see the card brand, the last four digits and the outcome.
  • Messages — what you write to support, and anything you send us in feedback.

Data created as you use the service

  • Learning activity — lessons opened, exercises completed, answers given, results, streaks, time spent.
  • Membership data — plan, term, renewal date, payment history, invoices.
  • Technical data — IP address, browser and device type, operating system, language, referring page, timestamps, error and access logs.
  • Behavioural analytics — with your consent: pages viewed, clicks, scrolling, and anonymised session recordings and heatmaps (see section 5).

Data we receive from others

  • From Stripe — confirmation that a payment succeeded or failed, the payment method type, and fraud-prevention signals.
  • From Meta and Google — with your consent: aggregated reports about how our ads performed. We do not receive lists of individuals from them.

We do not intentionally collect special categories of data (health, religion, political opinions and so on). Please do not enter such data into exercises or support messages.

3. Why we process it, and on what legal basis

PurposeData usedLegal basis (GDPR Art. 6)
Creating and running your account, giving you the lessons and exercises, saving your progressAccount data, learning profile, learning activityPerformance of a contract — Art. 6(1)(b)
Taking payment, renewals, refunds, issuing invoicesBilling data, membership dataContract — Art. 6(1)(b), and legal obligation — Art. 6(1)(c) for accounting and tax records
Support, answering your questions, handling complaints and withdrawalsAccount data, messages, membership dataContract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) for statutory complaint handling
Keeping the service secure — detecting abuse, shared logins, fraud and attacksTechnical data, account data, membership dataLegitimate interest — Art. 6(1)(f): protecting the service and paying members
Service e-mails you cannot opt out of — order confirmations, renewal reminders, security notices, changes to the termsAccount data, membership dataContract — Art. 6(1)(b), and legal obligation — Art. 6(1)(c)
Measuring how the site and the app are used, so we can improve them (Google Analytics 4, Hotjar)Technical data, behavioural analytics, cookie identifiersConsent — Art. 6(1)(a), given in the cookie banner
Advertising — measuring campaigns, building audiences and showing ads on Meta platformsCookie identifiers, technical data, hashed e-mail if you enable the Conversions APIConsent — Art. 6(1)(a)
Marketing e-mails about Czech Your WayAccount data, membership dataLegitimate interest — Art. 6(1)(f) towards our own customers, under § 7(3) of Act No. 480/2004 Coll., with an opt-out in every message; consent — Art. 6(1)(a) for everyone else
Establishing, exercising or defending legal claimsAny of the above, as relevantLegitimate interest — Art. 6(1)(f)
Keeping accounting, tax and invoicing recordsBilling data, membership dataLegal obligation — Art. 6(1)(c)

Where we rely on consent, you may withdraw it at any time — that does not affect what we did lawfully before you withdrew it. Where we rely on legitimate interest, you may object; section 10 explains how.

4. Cookies and similar technologies

Under § 89(3) of Act No. 127/2005 Coll. we may only store or read anything on your device with your consent, apart from what is strictly necessary to deliver the service you asked for. So when you first arrive, everything except the necessary category stays switched off until you turn it on. No cookie banner button pre-selects analytics or marketing, and refusing is exactly as easy as accepting.

CategoryWhat it doesExamplesLifetime
Necessary (no consent needed)Keeps you logged in, remembers your cookie choices, protects the checkout against fraudsb-<project-ref>-auth-token (Supabase, login), cyw_consent (your cookie choices), __stripe_mid / __stripe_sid (Stripe, fraud prevention)Session to 1 year
Analytics (consent)Tells us which pages and lessons are used, where people get stuck, and whether a change helped_ga, _ga_<container-id> (Google Analytics 4), _hjSessionUser_<site-id>, _hjSession_<site-id> (Hotjar)30 minutes to 14 months
Marketing (consent)Measures which ads led to a registration, and lets us show ads to people who visited the site_fbp, _fbc (Meta pixel). Add _gcl_au here if you ever run Google Ads.Up to 90 days

Google Tag Manager

We load our measurement and advertising tags through Google Tag Manager. GTM itself does not set cookies or store your data; it is the mechanism that decides which of the tools above is allowed to run, based on the choice you made in the banner. Tags in the analytics and marketing categories stay blocked until you consent, and are unloaded when you withdraw consent.

Hotjar — session recordings

With your consent, Hotjar records how you move through the site — clicks, scrolling and mouse movement — and builds heatmaps and anonymised replays of that. Recording is configured to mask text input by default, so what you type into forms, and anything inside your account, is not captured. Hotjar does not identify you by name, and we do not use it to make decisions about individuals.

Changing your mind

Open “Cookie settings” in the footer at any time to change or withdraw your consent. You can also delete cookies in your browser, or block them entirely — the necessary ones cannot be blocked without breaking the login. We honour the Global Privacy Control signal where your browser sends one.

Build requirement

This section only becomes true once a consent management platform is actually wired up: nothing in the analytics or marketing categories may load before consent, Google Consent Mode v2 must be signalled to GTM/GA4, and Meta’s pixel must run in consent-gated mode. Consents must be logged — when, what wording, which version — because under GDPR Art. 7(1) you have to be able to prove them.

5. Who else sees your data

We use a small number of service providers to run Czech Your Way. Most of them act as our processors: they only handle your data on our instructions, under a data processing agreement required by GDPR Art. 28. Where a provider decides things for itself, it is named as a separate or joint controller below.

ProviderWhat it does for usRoleWhere it goes, and on what safeguard
Vercel Inc.privacyHosting of the website and application, content delivery, server and error logsProcessorUSA, with EU region processing where configured — EU–US Data Privacy Framework and/or Standard Contractual Clauses
Supabase Inc.privacyDatabase, user authentication, file storage — where your account and learning data liveProcessorEU region — confirm your project region; Standard Contractual Clauses where support access happens from outside the EEA
Stripe Payments Europe, Ltd. / Stripe, Inc.privacyCard payments, subscriptions, invoices, fraud preventionProcessor for the payment we ask it to take; independent controller for its own fraud-prevention, anti-money-laundering and regulatory purposesIreland and USA — Data Privacy Framework and Standard Contractual Clauses
Google Ireland LimitedprivacyGoogle Analytics 4 and Google Tag ManagerProcessor, under Google’s Ads Data Processing TermsEU and USA — Data Privacy Framework and Standard Contractual Clauses
Meta Platforms Ireland LimitedprivacyMeta pixel, campaign measurement and advertising on Facebook and InstagramJoint controller with us for the collection and transmission of the data — see section 6Ireland and USA — Data Privacy Framework and Standard Contractual Clauses
Hotjar Ltd.privacyHeatmaps, behavioural analytics and anonymised session recordingsProcessorMalta / EU — processing stays in the EEA; SCCs for any sub-processor outside it
E-MAIL PROVIDERTransactional e-mails and, where you have asked for them, newslettersProcessorWHERE, AND ON WHAT SAFEGUARD
ACCOUNTANT / TAX ADVISERBookkeeping and tax filingsProcessorCzech Republic

Beyond that, we may disclose data to public authorities, courts or our legal advisers where the law requires it or where we need to defend a claim. If the business is ever sold or reorganised, data may pass to the successor, who is bound by this policy until it tells you otherwise.

Paperwork to have on file

Each processor above needs a signed DPA: Stripe’s is part of the Services Agreement, Google’s Data Processing Amendment is accepted in the GA4 admin, and Vercel, Supabase and Hotjar publish theirs. Keep a record of the sub-processor lists you were shown — you have to notify users of changes that matter.

6. Joint controllership with Meta

When you consent to marketing cookies, the Meta pixel on our site collects certain data about your visit and transmits it to Meta. For that collection and transmission, we and Meta Platforms Ireland Limited are joint controllers under GDPR Art. 26. The essence of our arrangement, which follows Meta’s Controller Addendum, is:

  • We are responsible for giving you this information and for obtaining your consent before the pixel fires.
  • Meta is responsible for the rights you exercise over the data once it has it — access, erasure and the rest — and for the security of its own systems.
  • You may exercise your rights against either of us. Whichever you contact, we will pass your request to the other where that is needed.
  • Meta’s own later processing of that data — for its advertising across its platforms — is Meta’s alone, and this policy does not cover it.

Meta explains what it does with the data in its Data Policy and in the Controller Addendum. You can withdraw consent at any time in our cookie settings, and manage ad personalisation in your Meta account settings.

7. Transfers outside the EEA

Some of the providers above are based in the United States. Where data reaches them, the transfer rests on one of the safeguards in Chapter V of the GDPR: the EU–US Data Privacy Framework, where the provider is certified under it, or the European Commission’s Standard Contractual Clauses together with the technical and organisational measures the provider applies.

The Data Privacy Framework adequacy decision is currently in force; it was upheld by the EU General Court in September 2025 and an appeal is pending. If it were annulled, we would fall back on Standard Contractual Clauses and reassess each transfer. You may ask us for a copy of the safeguards that apply to a specific transfer at PRIVACY E-MAIL.

8. How long we keep it

DataKept forWhy
Account and learning dataFor as long as your account exists, then 3 yearsThe limitation period for claims arising from the contract
Invoices, payment records and accounting documents10 years from the end of the tax periodAct No. 235/2004 Coll. on VAT and Act No. 563/1991 Coll. on accounting
Contracts, orders and consents to immediate delivery4 years from the end of the contractProof of what was agreed, and of the statutory pre-contract information
Support correspondence3 yearsHandling complaints and defending claims
Server and security logs30 daysSecurity and troubleshooting
Google Analytics 4 data14 monthsConfigured retention limit
Hotjar data365 daysConfigured retention limit
Marketing consents and records of cookie consent3 years after withdrawalProving consent under GDPR Art. 7(1)

When a period ends we delete the data, or irreversibly anonymise it so it can still be counted in statistics without being about anyone.

9. Personalisation and automated decisions

The service adapts what it shows you to the goals, level and topics you chose and to how you have been doing — that is what makes it personal, and it is part of what you are buying. It produces no legal effect for you and nothing comparable to one, so it is not automated decision-making of the kind GDPR Art. 22 restricts.

If you consent to marketing cookies, Meta and Google build advertising profiles using data from many sites, including ours. That happens under their own rules; you can turn it off for our site by withdrawing consent, and in their own settings for everywhere else.

10. Your rights

Under the GDPR you have the right to:

  • Access — get confirmation of whether we process your data, and a copy of it (Art. 15).
  • Rectification — have anything inaccurate corrected or completed (Art. 16).
  • Erasure — have your data deleted where there is no longer a reason to keep it (Art. 17). We cannot delete what accounting and tax law requires us to keep.
  • Restriction — have processing paused while a dispute about it is resolved (Art. 18).
  • Portability — receive the data you gave us, in a structured, machine-readable format, or have it sent to another controller (Art. 20).
  • Objection — object at any time to processing based on our legitimate interest, including profiling; and object to direct marketing, which we then stop unconditionally (Art. 21).
  • Withdraw consent — at any time, as easily as you gave it (Art. 7(3)).
  • Complain — to a supervisory authority (Art. 77).

How to use them

Write to PRIVACY E-MAIL from the address registered to your account, or from another address if you can identify yourself another way. We answer within one month, and may extend that by two further months for complex requests, telling you why. It is free, unless a request is manifestly unfounded or repetitive.

Complaining to the regulator

If you believe we are handling your data wrongly, please tell us first — and you can complain to the Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, uoou.gov.cz. If you live in another EU member state, you may complain to your own supervisory authority instead.

11. Marketing e-mails

If you buy from us, we may send you occasional e-mails about Czech Your Way itself — new content, features and offers on the service you already use. Czech law allows this to our own customers under § 7(3) of Act No. 480/2004 Coll., and we tell you about it when we collect your address. Every message has a one-click unsubscribe, and unsubscribing costs nothing and changes nothing about your Membership. If you are not a customer, we only e-mail you marketing after you ask us to.

12. How we protect your data

  • All traffic runs over HTTPS, and data is encrypted in transit and at rest with our infrastructure providers.
  • Passwords are stored only as salted cryptographic hashes and are never readable by us.
  • Access to production data is limited to the people who need it, protected by multi-factor authentication.
  • We never store full card numbers — the card form is Stripe’s, and it is Stripe that handles the number.
  • We keep backups, and we review our providers and their sub-processors as the service grows.
  • If a breach ever put your rights at serious risk, we would notify the ÚOOÚ within 72 hours and tell you without undue delay.

13. Children

Czech Your Way is meant for adults. We do not knowingly process the data of children under 15 — the age at which a child can consent to information society services under § 7 of Act No. 110/2019 Coll. Anyone between 15 and 18 needs their parent or guardian to conclude the contract. If you believe a child has given us data, write to PRIVACY E-MAIL and we will delete it.

14. Changes to this policy

We update this policy when the service, our providers or the law change. The current version and its effective date are always at the top of this page, and we keep the earlier ones. If a change materially affects how we use your data, we will e-mail you before it takes effect — and where the change needs your consent, we will ask for it rather than assume it.

Version 1.0, effective from EFFECTIVE DATE.