← Back to home

Privacy Policy

Last updated: April 15, 2026

Privacy Policy


**Last updated: 2 April 2026**


CZECHtrekker ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains what data we collect, why we collect it, and your rights under the **General Data Protection Regulation (GDPR)** (EU Regulation 2016/679) and applicable Czech law (Act No. 110/2019 Coll. on personal data processing).


---


1. Data Controller


**CZECHtrekker**

Prague, Czech Republic


For all data-related enquiries or to exercise your rights, contact us via the contact form on our website or by the email address provided in your booking confirmation.


---


2. What Personal Data We Collect and Why


We collect personal data only for specific, legitimate purposes. Below is a category-by-category breakdown including the legal basis under GDPR Article 6.


2.1 Booking Data


**Data collected:** Full name, email address, phone number (optional), nationality, number of participants (including children), selected tour and date, any dietary requirements or accessibility needs you disclose.


**Purpose:** To process your reservation, issue a booking confirmation, coordinate the tour, and handle any cancellations or rescheduling.


**Legal basis (GDPR Art. 6(1)(b)):** Processing is necessary for the **performance of a contract** to which you are a party, or to take steps at your request before entering into a contract.


**Retention:** Booking records are retained for **5 years** from the date of the tour, in accordance with Czech accounting law (Act No. 563/1991 Coll.). After that period, data is permanently deleted unless a legal obligation requires longer retention.


---


2.2 Newsletter Subscriptions


**Data collected:** Email address only.


**Purpose:** To send you our newsletter containing travel inspiration, seasonal offers, and new tour announcements.


**Legal basis (GDPR Art. 6(1)(a)):** Processing is based on your **explicit consent**, given when you submit the newsletter sign-up form.


**Withdrawal of consent:** You may unsubscribe at any time by clicking the unsubscribe link in any newsletter email. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.


**Retention:** Your email address is retained until you unsubscribe. Upon unsubscription, it is permanently deleted within **30 days**.


---


2.3 Contact Form Submissions


**Data collected:** Name, email address, and the content of your message.


**Purpose:** To respond to your enquiry.


**Legal basis (GDPR Art. 6(1)(f)):** Our **legitimate interest** in responding to customer enquiries and maintaining good customer relations.


**Retention:** Contact form messages are retained for **12 months** from receipt, then permanently deleted — unless the enquiry converts into a booking (in which case booking retention applies) or a legal dispute arises.


---


2.4 Live Chat Messages


**Data collected:** Any name or contact detail you provide during a chat session, together with the content of the transcript.


**Purpose:** To answer your questions in real time and, where a conversation leads to a booking enquiry, to follow it up.


**Legal basis (GDPR Art. 6(1)(f)):** Our **legitimate interest** in providing customer support and ensuring continuity of service.


**Retention:** Chat transcripts are retained for **90 days** from the date of the conversation, then permanently deleted — unless they relate to an ongoing booking or legal dispute.


---


2.5 Website Analytics


**Data collected:** Anonymised usage data including pages visited, session duration, browser type, device type, approximate geographic location (country/city level), and referring URL, collected via **Google Analytics**.


**Purpose:** To understand how visitors use our website so we can improve it.


**Legal basis (GDPR Art. 6(1)(f) / Art. 6(1)(a)):** Our **legitimate interest** in improving our website. Where required by your browser or local law, we rely on **consent** obtained via the cookie consent mechanism.


**Anonymisation:** IP addresses are anonymised before transmission to Google. We do not enable Google Ads or remarketing features.


**Retention:** Aggregated analytics data is retained for **26 months** (Google Analytics default), then automatically deleted.


---


3. Data Sharing


We do not sell, rent, or trade your personal data. We share data only with trusted processors who act on our instructions:


| Processor | Purpose | Safeguards |

|---|---|---|

| **Stripe** | Processing tour payments | EU Standard Contractual Clauses (SCCs) |

| **Resend** | Sending booking confirmation emails | EU Standard Contractual Clauses (SCCs) |

| **Google Analytics** | Website usage analytics (anonymised) | EU Standard Contractual Clauses (SCCs) |

| **Firebase / Google Cloud** | Secure database and hosting | EU data region where available |

| **Telegram** | Internal admin notifications only — no personal client data transmitted | — |


All processors are bound by data processing agreements and must implement appropriate security measures. We may also disclose your data where required by law, court order, or a competent authority.


---


4. International Transfers


Where data is transferred outside the European Economic Area (EEA) — for example to US-based service providers — we ensure appropriate safeguards are in place, including **EU Standard Contractual Clauses (SCCs)** approved by the European Commission.


---


5. Your Rights Under the GDPR


| Right | What it means |

|---|---|

| **Access** (Art. 15) | Request a copy of all personal data we hold about you |

| **Rectification** (Art. 16) | Request correction of inaccurate or incomplete data |

| **Erasure** (Art. 17) | Request deletion of your data where there is no lawful basis for continued processing |

| **Restriction** (Art. 18) | Request that we pause processing of your data in certain circumstances |

| **Portability** (Art. 20) | Receive your data in a structured, machine-readable format or have it transferred to another controller |

| **Objection** (Art. 21) | Object to processing based on legitimate interests or direct marketing |

| **Withdraw consent** (Art. 7(3)) | Withdraw consent at any time, without affecting the lawfulness of prior processing |


To exercise any right, contact us using the details in Section 1. We will respond within **30 days**. In complex cases, this may be extended by 60 days with prior notice.


**Supervisory authority:** You have the right to lodge a complaint with the **Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů — ÚOOÚ)** at [www.uoou.cz](https://www.uoou.cz), or with the supervisory authority in your country of residence within the EU/EEA.


---


6. Cookies


6.1 What Are Cookies


Cookies are small text files placed on your device by a website. We use them to make our site function correctly, remember preferences, and analyse usage.


6.2 Types of Cookies We Use


| Category | Purpose | Consent required |

|---|---|---|

| **Strictly necessary** | Session management, security, basic functionality | No |

| **Functional** | Remembering language or display preferences | No |

| **Analytics** | Google Analytics — anonymised usage statistics | Yes |


6.3 Managing Cookies


You can control or delete cookies through your browser settings at any time. Disabling cookies may affect certain features of our website. You can also opt out of Google Analytics by installing the [Google Analytics Opt-out Browser Add-on](https://tools.google.com/dlpage/gaoptout).


---


7. Security


We implement appropriate **technical and organisational measures** to protect your data, including:


  • Encrypted storage (Firebase with encryption at rest)
  • HTTPS/TLS encryption for all data in transit
  • Access controls restricted to authorised personnel only
  • Regular review of data handling practices

  • No internet transmission is 100% secure; while we take all reasonable precautions, we cannot guarantee absolute security.


    ---


    8. Children's Privacy


    Our services are not directed to children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us immediately so we can delete it.


    ---


    9. Changes to This Policy


    We may update this Privacy Policy to reflect changes in our practices or legal obligations. The updated version will be posted on our website with a revised "Last updated" date. For material changes, we will notify registered users by email.


    ---


    10. Contact


    **CZECHtrekker** — Prague, Czech Republic

    Contact us via the contact form on our website or by the email address provided in your booking confirmation.

      We use cookies to enhance your experience. By continuing to visit this site you agree to our use of cookies. Read our Privacy Policy.