Privacy Policy

Information on the processing of personal data pursuant to Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council, the General Data Protection Regulation (the "GDPR")

1. Data Controller

Company name: RKR Estate Group, s. r. o.Company ID (IČ): 11731362Registered office: Varšavská 715/36, 120 00 Prague, Czech RepublicContact person: Radim KovářE-mail: info@rockspa.czPhone: +420 773 972 699

(the "controller")

2. Personal Data We Process

  1. The controller processes the personal data of its customers, i.e. persons who conclude a contract with the controller for the use of a private relaxation space or purchase a voucher, as well as persons who contact the controller or subscribe to the newsletter. These persons are data subjects within the meaning of Article 4(1) GDPR.
  2. The controller processes the following categories of personal data:
    • identification and contact data: first name and surname, address, company ID (for self-employed persons), phone number, e-mail,
    • order and reservation data: purchased services and vouchers, selected premises, reservation date, changes and cancellations of reservations,
    • payment and billing data: amount and date of payment, details on the tax document (the controller does not process payment card details; these are processed exclusively by the payment gateway provider),
    • customer account data: login e-mail and purchase history in the "My Purchases" section,
    • communication data: content of e-mails, phone requests and complaints,
    • photographs and written references (only with consent),
    • technical data: IP address, browser information and data obtained through cookies (see the Cookie Policy for details).

3. Purposes and Legal Basis of Processing

  1. Conclusion and performance of the contract: We process identification, contact, order and payment data to handle orders, book reservations, provide the service, manage customer accounts, handle changes, cancellations and complaints, and communicate with the customer in connection with the contract. The legal basis is the performance of a contract under Article 6(1)(b) GDPR. Providing this data is necessary to conclude the contract; without it, the order cannot be processed.
  2. Compliance with legal obligations: We process billing data for accounting and tax purposes. The legal basis is compliance with a legal obligation under Article 6(1)(c) GDPR.
  3. Protection of the controller's rights: We process order and communication data to the necessary extent for debt collection, dispute resolution and website security. The legal basis is the controller's legitimate interest under Article 6(1)(f) GDPR.
  4. Commercial communications: We process your name and e-mail to send commercial communications (e.g. newsletters), exclusively on the basis of your consent under Article 6(1)(a) GDPR. You can unsubscribe at any time using the link in every e-mail.
  5. Promotion: We process photographs, first name and surname in connection with written references to promote the controller's business (e.g. publication on social media or the website), exclusively on the basis of your consent under Article 6(1)(a) GDPR.
  6. Website analytics: We process technical data from cookies to measure traffic and improve the website, exclusively on the basis of your consent under Article 6(1)(a) GDPR. Details can be found in the Cookie Policy.
  7. The controller does not carry out automated decision-making or profiling that would have legal effects on you.

4. Data Retention

  1. Data processed for the performance of a contract is kept for the duration of the contractual relationship and subsequently for the period necessary to establish, exercise or defend legal claims, for no longer than 10 years after the end of the contractual relationship.
  2. Customer account data is kept until the account is deleted.
  3. Data processed to comply with legal obligations (e.g. accounting and tax documents) is kept for the period required by the applicable legislation.
  4. Data processed on the basis of consent (commercial communications, promotion) is kept until the consent is withdrawn, but for no longer than 5 years after the end of the last contractual relationship.
  5. The retention period for cookie data is stated in the Cookie Policy.

5. Recipients of Personal Data

  1. Personal data may be disclosed to the following processors, who provide the controller with technical and administrative services needed to operate the website, the reservation system and related activities:
    • Lovable – website operation and hosting,
    • Supabase – database, customer accounts and reservation data,
    • payment gateway provider – processing of online payments,
    • Resend – sending confirmation and service e-mails about orders and reservations,
    • SMSbrána.cz – sending text messages about reservations,
    • Google – website analytics (Google Analytics) and e-mail and office services,
    • WEDOS – domain management and related services,
    • MailerLite – sending newsletters.
  2. If a customer fails to meet their obligations, the controller may provide the necessary data to legal service providers for the purpose of debt collection.
  3. We also provide personal data to public authorities where required by law.
  4. Some of the processors listed above may process personal data outside the European Economic Area, in particular in the USA. Such transfers take place only on the basis of a European Commission adequacy decision (EU-U.S. Data Privacy Framework) or standard contractual clauses approved by the European Commission.

6. Data Security

  1. The controller protects personal data using technical and organisational measures corresponding to the current state of the art, which prevent its misuse, damage or destruction. These include in particular:
    • encrypted communication on the website (valid HTTPS certificate),
    • secured access to the website administration, reservation system and database (username and password, restricted access rights),
    • secured access to the controller's computers and phones (password, biometric authentication),
    • secured access to e-mail accounts, e-mail marketing applications and billing systems,
    • regular software updates.
  2. Personal data is processed electronically by automated means or in paper form by non-automated means.

7. Your Rights

  1. In accordance with the GDPR, you have the right to:
    • request access to your personal data,
    • request rectification of inaccurate personal data,
    • request erasure of your personal data,
    • request restriction of processing,
    • object to processing based on legitimate interest,
    • request the transfer of your personal data to another controller,
    • withdraw your consent to processing at any time, without affecting the lawfulness of processing carried out before the withdrawal,
    • lodge a complaint with the supervisory authority, the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, www.uoou.gov.cz.
  2. You can exercise your rights, including withdrawing your consent, by e-mail at info@rockspa.cz. We will respond to your request without undue delay and no later than one month after receiving it.

8. Final Provisions

  1. The controller may update this policy. The current version is always published on this page.
  2. This policy is also available in Czech. In the event of any discrepancy between the language versions, the Czech version prevails.
  3. This policy is effective from 23 September 2026.