Privacy policy (GDPR)
Uralská 689/7, Bubeneč, 160 00 Prague 6, Czechia
Company ID 29712840
registered in the Commercial Register kept by the Municipal Court in Prague, file no. C 451181
email: [email protected]
(the „Controller“)
This is an English translation provided for convenience. The binding version is the Czech one; if the two differ, the Czech text prevails.
I. Key terms
The Controller operates the website www.maiaform.eu, the online services and social media pages connected to it and any further projects on the internet, and provides business mentoring, business consulting and related services (together the „Services“). In running these and providing the Services, the Controller processes personal data of data subjects who have given it to the Controller when using the Services or on another legal basis.
Personal data are identifiers a user has given to the Controller which, alone or together with other identifiers, can identify a specific user (a natural person).
A data subject is, for the purposes of this policy, a user - a natural person whose data the Controller processes while running the Services.
Processing of personal data means a single operation or a set of operations that systematically occur when handling personal data. This includes in particular collecting, organising, storing, retrieving, using, sorting and filtering in databases, blocking and so on. The Controller processes personal data in line with applicable data protection law, namely Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data (the „GDPR“) and Czech Act No. 110/2019 Coll., on personal data processing.
A processor is a person (natural or legal) whom the Controller has entrusted with processing personal data for purposes the Controller has set.
Special categories of data are personal data revealing a data subject's health, and also for example data about religious belief or philosophical conviction, sex life or sexual orientation, which the data subject gives to the Controller in order to use its services. In providing its services the Controller does not primarily process special categories of data.
II. Purpose and manner of processing
1. Personal data are processed so that the Services provided by the Controller can be used. The legal basis for processing is a concluded contract, an order, consent given by the data subject or legitimate interest; the reasons for processing may also be imposed on the Controller by law.
2. The Controller sends email newsletters only on the basis of separate consent, or where the statutory conditions for using customer contacts for commercial communications under Czech Act No. 480/2004 Coll., on certain information society services, are met.
3. The Controller processes personal data to the extent the user provided them, and only for the purposes above (buying the Services / concluding a contract or otherwise using the Services, and sending information in the form of email newsletters).
4. The Controller processes personal data by carrying out in particular the following operations: storing them in a user database, amending them where users ask for additions or corrections, retrieving them within the database, sorting them by individual criteria, and erasing them once the processing period above has passed or once the data subject withdraws consent.
5. The Controller processes special categories of data only where the data subject voluntarily provides such data when using the services; the Controller does not request such data from the user in advance unless it is necessary in order to provide the Services. The Controller notes that for some Services it is necessary to obtain information from the data subject about, for example, their health, without which the service could not be provided well and safely.
6. The data subject is informed in advance within the contractual relationship with the Controller, and agrees, that where the service or product provided by the Controller includes a group online lesson or online workshop held through a digital platform (Zoom and similar), the Controller may record that lesson or workshop and use the recording for its further purposes, including distributing it over the internet or by email as part of its business. The Controller always gives more detail at the start of such a service and, through the technical recording settings, asks the data subjects for explicit consent.
7. The data subject is informed in advance within the contractual relationship with the Controller, and agrees, that the Controller may take a reasonable amount of photographic material at events it organises and distribute it over the internet (in particular through the Controller's website and social media accounts). Where such material could interfere with the personal rights of data subjects, the Controller will also ask for written consent to its use.
III. How long data are kept
The Controller keeps the personal data provided for the following period:
- Where a contractual relationship exists, for its duration and for 5 years after it ends (because of possible complaints or other claims between the parties).
- For 5 years from the user's last use of a service.
- Or until consent is withdrawn, or until a similar act by the user withdrawing the Controller's ability to process their personal data.
IV. Rights of data subjects
In connection with the processing of personal data, the Controller guarantees data subjects the following rights arising from the GDPR:
1. Data subjects have the right of access to their personal data. They also have the right to have them corrected and/or completed or erased, or to ask for processing to be restricted, as well as the right not to be subject to automated individual decision-making (including profiling).
2. Data subjects have the right to object to the processing of their personal data.
3. Data subjects have the right to data portability in a structured, commonly used and machine-readable format.
4. Data subjects may withdraw consent to the processing of personal data at any time. To withdraw consent, the Controller recommends using the contact email given at the top of this policy.
5. Data subjects have the right to lodge a complaint with the supervisory authority, which is the Office for Personal Data Protection (www.uoou.cz), Pplk. Sochora 27, 170 00 Prague 7, Czechia, email [email protected], data box qkbaa2n.
V. Cookies
1. The Controller uses cookies or similar technologies on the website. Cookies are small files used to store and receive identifiers and other information about the devices from which users access the Controller's website.
2. The Controller uses essential technical cookies as well as analytics and marketing cookies. Technical cookies help with viewing the pages and, where relevant, with registering for the Controller's Services. Analytics cookies are used to analyse data in order to improve how the Controller's Services work. Marketing cookies are used to track the preferences of website users in order to target advertising. The Controller uses analytics and marketing cookies together with third-party tools (in particular Google Analytics and Meta Pixel) and only on the basis of the user's prior consent.
3. Users may refuse cookies in their browser settings, or allow only some of them; the cookie bar on the Controller's website serves the same purpose.
4. Information about cookies and the cookie bar are part of the Controller's website.
VI. Final provisions
1. Where the Controller uses a processor for its activities, it undertakes to bind that processor to the same protection of personal data it guarantees to data subjects under this policy. The Controller notes that part of its services run on, and part of its content is provided through, the Facebook and Instagram platforms, which set their own rules for processing personal data.
2. In its activities the Controller does not transfer personal data outside the EU.
3. The Controller reserves the right to change this policy if things change on its side or if the law in this area changes.
4. This privacy policy is effective from 2 July 2026.
Kateřina Halenka, managing director