Skip to content

Personal Data Processing Policy

Controller: Techcrowd s.r.o., Company ID 17846218, Pod Nádražím 1204, 286 01 Čáslav, Czech Republic.

Contact: novak@techcrowd.cz · +420 728 826 186 · https://techcrowd.cz/

Effective from: 19 April 2026 · Version: 1.1

1. Introduction

Techcrowd s.r.o. (the “Controller”) provides this information about the processing of personal data in connection with the operation of the website https://techcrowd.cz/.

The website is a company presentation. You contact us through your own active steps (contact form, email, phone, in person). The website contains no registration, newsletter or e-shop.

This policy is issued in accordance with Regulation (EU) 2016/679 (GDPR), Czech Act No. 110/2019 Coll., Act No. 127/2005 Coll. (Section 89 — cookies) and Act No. 480/2004 Coll.

2. Controller contact details

  • Name: Techcrowd s.r.o.
  • Company ID: 17846218
  • Registered office: Pod Nádražím 1204, 286 01 Čáslav, Czech Republic
  • Email: novak@techcrowd.cz
  • Phone: +420 728 826 186

A Data Protection Officer has not been appointed — Art. 37 GDPR does not impose this obligation. Direct any questions to novak@techcrowd.cz.

3. Scope of personal data processed

3.1 When you contact us on your own initiative (contact form, email, phone), we process the data you provide: identification data (name, surname, company and company ID where relevant), contact data (email, phone) and the content of your message. Providing your data is voluntary — without it, however, we cannot reply.

3.2 Automatically when you visit the website: IP address, browser and device data (User-Agent, OS), visit data (date, time, URL, referrer) and data from strictly necessary cookies.

We do not use this data for profiling or to identify specific individuals — it serves to ensure operation, security and attack detection.

4. Purposes and legal bases of processing

A) Handling your enquiry and pre-contractual negotiations · legal basis: steps prior to entering into a contract / legitimate interest — Art. 6(1)(b) or (f) GDPR.

B) Ensuring operation, security and defence of rights (logs, attack detection) · legal basis: legitimate interest — Art. 6(1)(f) GDPR.

C) Compliance with legal obligations (accounting, taxes, archiving in a contractual relationship) · legal basis: legal obligation — Art. 6(1)(c) GDPR.

D) Traffic analytics (when active) · pseudonymised visit data · legal basis: consent — Art. 6(1)(a) GDPR, given through the cookie banner.

You may object at any time to processing based on legitimate interest (see Section 10).

5. Retention periods

  • Enquiries without a contract: 6 months from the last communication
  • Contractual data: contract duration + limitation periods (usually 3 or 10 years)
  • Accounting and tax documents: 10 years from the end of the accounting period
  • Operational logs: max. 6 months
  • Strictly necessary cookies: for the cookie's validity period

After expiry, data is securely destroyed or anonymised.

6. Recipients of personal data

  • Hosting / cloud — Fly.io, Inc.
  • Email communication — Google Ireland Ltd. (Google Workspace), Brevo (contact form delivery)
  • Accounting services — external accounting firm
  • Legal advice — external law firm
  • Public authorities to the extent required by law

We do not sell, rent or otherwise pass your personal data to third parties for their marketing purposes.

7. Transfers to third countries

Some processing may take place with providers outside the EEA, in particular in the USA (Fly.io, Google). Transfers are safeguarded under Art. 44–46 GDPR: the EU–US Data Privacy Framework (for certified recipients), Standard Contractual Clauses approved by the European Commission, and other appropriate safeguards.

8. Cookies

The website uses strictly necessary (essential) cookies. Analytics cookies (Google Analytics) are used only with your consent given through the cookie banner; consent can be withdrawn at any time as easily as it was given. We do not use marketing cookies.

You can block necessary cookies in your browser settings — this may limit the functionality of the website. See the Cookie Policy for details.

9. Automated decision-making and profiling

The Controller does not carry out automated individual decision-making under Art. 22 GDPR or profiling.

10. Data subject rights

Exercise your rights by email at novak@techcrowd.cz or in writing at the Controller's registered office.

  • Access (Art. 15)
  • Rectification (Art. 16)
  • Erasure — “right to be forgotten” (Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Objection (Art. 21) — against processing based on legitimate interest
  • Withdrawal of consent (Art. 7(3))
  • Complaint to the supervisory authority (Art. 77): Office for Personal Data Protection (ÚOOÚ), Pplk. Sochora 27, 170 00 Prague 7, posta@uoou.gov.cz, www.uoou.gov.cz

Requests are handled within 1 month (extendable by 2 further months in exceptional cases with prior notice), free of charge except for manifestly unfounded or repeated requests.

11. Security of personal data (Art. 32 GDPR)

Technical measures include HTTPS / TLS 1.2+, least privilege and MFA for administrator accounts, regular backups with restore testing, monitoring and incident detection, regular software updates and infrastructure segmentation. Organisational measures include confidentiality obligations, regular training, contractual safeguards with processors (Art. 28 GDPR), records of processing activities (Art. 30) and an incident reporting process (Art. 33–34).

12. Data breaches

In the event of a breach likely to result in a risk to the rights and freedoms of natural persons, the Controller will notify the supervisory authority within 72 hours (Art. 33 GDPR) and, where the risk is high, inform the affected data subjects without undue delay (Art. 34 GDPR).

13. Changes to this policy

This policy may be updated from time to time. The current version is always available on the website; visitors will be informed appropriately of any substantial change.