This is an English translation for your convenience. Only the Czech version is legally binding.
This policy describes how we process the personal data of visitors to dontpanic.cz, people who contact us, and our customers and business partners.
We process personal data in line with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, “GDPR”) and the Czech Act No. 110/2019 Coll., on the processing of personal data, as amended.
1. Who is the controller of personal data
The controller of your personal data is:
Registered office: Riegrovy sady 28, 120 00 Prague 2 - Vinohrady
Email: hello@dontpanic.cz
Phone: +420 606 606 597
For any questions about data protection, contact us at the email above.
2. What data we process, why and for how long
A. Communication and handling your enquiry
If you send us a message through the contact form, by email or by phone, we mainly process the data you give us. This is typically your first name, last name, email, phone number, address, payment and billing details, company name, data about your use of the website (IP address, cookies and similar technologies), the content of your message and records of our communication.
Purpose: answering your question, handling your enquiry and follow-up communication.
Legal basis: our legitimate interest in communicating with people interested in our services; for steps before a contract, the need to take steps at your request before entering into a contract.
Retention: for as long as the communication takes, up to 12 months, unless we need to keep the data longer to enter into or perform a contract or to protect legal claims.
B. Entering into and performing a contract
If you become our customer or business partner, we process the data needed to enter into, perform and manage the contract. This mainly includes identification, contact and billing details, order details and communication about the service.
Purpose: entering into and performing the contract, customer support, invoicing and making or defending legal claims.
Legal basis: performance of a contract; compliance with legal obligations; where relevant, our legitimate interest in protecting legal claims.
Retention: for the duration of the contract and then for as long as needed to meet legal obligations and protect legal claims. We keep accounting and tax documents for the periods set by law.
C. Marketing messages
We only send marketing messages when the law allows it or when you have given us your consent.
Purpose: informing you about our services, news and offers.
Legal basis: consent, or legitimate interest where the law allows it.
Retention: until you withdraw consent or object, for a maximum of 12 months. You will be able to unsubscribe in every marketing message or via our contact email.
D. Website operation and security
When you visit the website, technical information may be processed automatically, for example your IP address, device and browser details, the date and time of access, the pages you visit and technical logs needed to keep the website secure and running properly.
Purpose: keeping the website working and secure and protecting it from misuse.
Legal basis: our legitimate interest in running the website securely.
Retention: as long as needed for the purpose, usually 6 months.
3. Cookies and similar technologies
The website may use cookies and similar technologies. We use technically necessary cookies to make the website work properly; they do not need consent. For analytics, preference and marketing cookies, if we use them, we ask for your verifiable consent in advance.
In the cookie bar you can choose which optional categories to allow, and change your choice at any time with the “Cookie settings” button, which is always available in the website footer.
| Category | Purpose | Legal basis | Retention |
|---|---|---|---|
| Necessary cookies | Functionality, security and basic operation of the website | legitimate interest / exemption for technically necessary storage or access | 12 months |
| Analytics cookies | Measuring traffic and improving the website | consent | 12 months |
| Marketing cookies | Personalising and measuring ad campaigns | consent | 90 days |
Third-party tools we use:
| Tool | Provider | Category and purpose | Retention and transfers outside the EEA |
|---|---|---|---|
| Google Analytics 4 | Google Ireland Limited, Ireland | analytics: measuring traffic and improving the website | 12 months; transfer to the USA based on the European Commission adequacy decision (EU-US Data Privacy Framework) and standard contractual clauses (Google LLC, USA) |
| Google Ads | Google Ireland Limited, Ireland | marketing: conversion tracking and remarketing | 90 days; transfer to the USA based on the European Commission adequacy decision (EU-US Data Privacy Framework) and standard contractual clauses (Google LLC, USA) |
| Meta Pixel | Meta Platforms Ireland Limited, Ireland | marketing: conversion tracking and ad targeting | 90 days; transfer to the USA based on the European Commission adequacy decision (EU-US Data Privacy Framework) and standard contractual clauses (Meta Platforms, Inc., USA) |
4. Who may receive your data
We share personal data only as far as necessary:
- with our employees and contractors who need it for their work;
- with providers of IT infrastructure, hosting, website management, email and other support services;
- with providers of accounting, legal or payment services, if we use them;
- with public authorities, if the law requires it.
We have proper contracts in place with suppliers who process personal data for us. You can ask for the current list of recipient categories at the contact email above.
5. Transfers outside the European Economic Area
As a rule, we process personal data in the European Economic Area. We transfer it to third countries only when this is necessary for a specific supplier and the legal requirements are met, especially on the basis of an adequacy decision or with appropriate safeguards.
For traffic measurement and advertising, we use Google Analytics 4 and Google Ads, provided by Google Ireland Limited, and Meta Pixel, provided by Meta Platforms Ireland Limited. In this context, data may be accessed by Google LLC and Meta Platforms, Inc., based in the United States. The transfer is based on the European Commission adequacy decision (EU-US Data Privacy Framework), supplemented by standard contractual clauses.
Meta Pixel and joint controllership
Our website uses Meta Pixel, provided by Meta Platforms Ireland Limited (“Meta”).
Meta Pixel mainly lets us measure how well our ad campaigns on Meta services work, analyse traffic and conversions, and run remarketing.
When data is collected on the website and sent to Meta, we and Meta are joint controllers under Article 26 GDPR. Joint controllership only covers this stage of processing, not automatically any later processing of personal data by Meta for its own purposes.
The data processed may include information about your use of the website, the pages you visit, the actions you take, technical data about your device and browser, your IP address and online identifiers (e.g. cookies).
The legal basis is your consent given in the cookie bar. You can withdraw it at any time by changing this setting. Without your consent, we do not run Meta Pixel for these marketing purposes.
We have a joint controller agreement with Meta. In short, we are mainly responsible for informing you about this processing and for getting your consent, while Meta mainly handles the exercise of data subject rights and the security of processing on its side. You can still use your GDPR rights against either joint controller.
Meta may also process personal data outside the European Economic Area. Information about further processing by Meta, its recipients, retention periods and how to use your rights is in Meta’s privacy policy.
The terms of joint controllership are set out in Meta’s “Controller Addendum”. For questions about this processing, you can also contact Meta Platforms Ireland Limited directly.
6. Your rights
Under the conditions set by law, you have the right to:
- access your personal data;
- have inaccurate data corrected or incomplete data completed;
- have your personal data deleted;
- restrict processing;
- object to processing based on legitimate interest, especially direct marketing;
- receive your data for data portability, if processing is based on consent or a contract and is automated;
- withdraw consent at any time, if processing is based on consent; this does not affect the lawfulness of processing before withdrawal;
- file a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů).
You can use your rights by emailing hello@dontpanic.cz. We may ask you to reasonably confirm your identity so that data is not disclosed to the wrong person.
7. Automated decision-making
We do not use automated individual decision-making or profiling that has legal effects on you or affects you in a similarly significant way.
8. Data security
We have taken appropriate technical and organisational measures to protect personal data against unauthorised access, loss, change, destruction or other misuse. Only people who need the data for the stated purposes have access to it.
9. Changes to this policy
We may update this policy when needed, especially when the way we process data or legal requirements change. The current version will always be published on this website.