Legal
Privacy Policy
In short
- This website uses no cookies, analytics or tracking tools and loads nothing from third parties.
- We use the details from the contact form only to reply to your message.
- We process data in the EU and do not transfer it outside the EU/EEA.
1. Data controller
Nxtrum s.r.o.
Company ID (IČO): 29533783
Commercial Register entry: C 151755 vedená u Krajského soudu v Brně
K Pasekám 2984/45, 760 01 Zlín
E-mail: info@nxtrum.com
Phone: +420 910 920 772
We process personal data as a controller under Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 Coll. on personal data processing.
2. Data protection contact
Given the nature and scope of our activities, we are not required to appoint a Data Protection Officer (GDPR Art. 37). Please send any data protection questions to gdpr@nxtrum.cz.
3. What data we process and why
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Replying to a message from the contact form or by email | Name, email, message text; optionally company name and subject | Legitimate interest in replying to your enquiry (GDPR Art. 6(1)(f)); where it concerns entering into a contract, Art. 6(1)(b) | While the enquiry is handled and then at most 3 years from the last contact |
| Protecting the form against abuse | IP address, sender email and time of sending in the server log; a hash of the IP address to limit the number of submissions | Legitimate interest in secure operation (Art. 6(1)(f)) | Server log 6 months, IP address hash 1 hour |
| Operating and securing the website | Technical data recorded by the hosting provider’s server when you visit (IP address, time, requested address, browser type) | Legitimate interest in secure operation (Art. 6(1)(f)) | Only as long as necessary to operate and secure the server |
| Performing a contract and providing services | Identification and contact details, details of ordered services | Contract (Art. 6(1)(b)) | For the duration of the contract; afterwards only to the extent required by law |
| Accounting and tax | Billing and payment details | Legal obligation (Art. 6(1)(c)), Czech Accounting Act and tax laws | For the period required by these laws, at most 10 years |
We do not use the data for marketing, we do not sell it and we do not build profiles from it.
4. Who receives the data
We entrust data only to processors with whom we have a data processing agreement (GDPR Art. 28) and who provide sufficient security guarantees.
| Recipient | Purpose | Location |
|---|---|---|
| WebSupport s.r.o. | Web hosting and sending messages from the form | EU |
| Email mailbox provider | Delivering and storing email communication | EU |
| Accounting firm | Bookkeeping and tax matters | Czech Republic |
5. Transfers outside the EU/EEA
The website and all its files, including fonts, are served from our server in the EU. The website loads no third-party content such as Google Fonts, analytics or advertising scripts, so visiting it does not involve any transfer of data to third countries. We do not transfer data outside the EU/EEA. Should this change, we will state the legal basis for the transfer under Chapter V of the GDPR here in advance.
6. Automated decision-making and profiling
We do not carry out automated individual decision-making or profiling within the meaning of GDPR Art. 22.
7. Children
Our services are not intended for children under 16 and we do not knowingly process their data. If we find out that we have obtained such data, we will delete it without undue delay.
8. Your rights
- Access (Art. 15): find out whether and what data we process about you and get a copy.
- Rectification (Art. 16): have inaccurate data corrected.
- Erasure (Art. 17): have data erased that is no longer needed or was processed unlawfully.
- Restriction (Art. 18): temporarily restrict processing.
- Portability (Art. 20): receive data in a machine-readable format where processing is based on a contract or consent.
- Objection (Art. 21): object to processing based on legitimate interest.
- Complaint with the Czech Office for Personal Data Protection, uoou.gov.cz, Pplk. Sochora 27, 170 00 Praha 7.
How to submit a request is described on the page Exercising your GDPR rights. We will reply without undue delay and within one month at the latest; in complex cases this period may be extended by two further months, and we will let you know in time.
9. Security
We protect data with appropriate technical and organisational measures under GDPR Art. 32, including an encrypted connection (HTTPS) and access limited to the people who need the data for their work.
In the event of a personal data breach, we will notify the Czech Office for Personal Data Protection without undue delay and within 72 hours of becoming aware of it (GDPR Art. 33). Where there is a high risk to your rights, we will also inform you (GDPR Art. 34).
10. Cookies and browser storage
The website sets no cookies and uses no analytics. It keeps only four technical values in your browser’s session storage (sessionStorage); they contain no personal data, are never sent anywhere and disappear when you close the tab. Details are in our Cookies and browser storage.
11. Changes to this policy
We will update this policy when our activities, services or the law change. The current version is always on this page with its effective date.