Privacy Policy — Kemp Černá Louže
Data controller: Pukoře, s.r.o., Černokostelecká 1777/107, 100 00 Prague 10 — Strašnice Company ID (IČO): 08084807 Contact for personal data matters: [email protected] · +420 604 575 751
Effective from: [date of website launch] Version: 2026-launch-v1
1. Who we are and why we process your data
1.1. Pukoře, s.r.o. (the "operator" or "we") is the operator of Kemp Černá Louže and the controller of personal data within the meaning of Regulation (EU) 2016/679 (GDPR) and Act No. 110/2019 Coll. on the processing of personal data.
1.2. We process your personal data so that we can:
- Receive and handle reservations
- Communicate with you about the course of your stay (confirmations, instructions, invoices)
- Comply with legal obligations (accounting documents, reporting of foreign guests to the Czech Police)
- Where applicable, inform you about our news — only if you grant separate consent to this
1.3. We do not sell your data to anyone, we do not profile you and we do not use it for automated decision-making with legal effects for you.
2. What data we process about you
2.1. When booking accommodation
| Data | Why we need it | Legal basis |
|---|---|---|
| First name and surname | Handling the reservation, identifying the guest | Performance of a contract (Art. 6(1)(b) GDPR) |
| E-mail address | Sending the confirmation, invoice, instructions for the stay | Performance of a contract |
| Phone number | Contact in case of a necessary change to the reservation | Performance of a contract |
| Arrival and departure dates, number of persons, accommodation type | The actual content of the reservation | Performance of a contract |
| Address (optional) | Issuing an invoice | Performance of a contract + accounting obligation |
| Nationality (for foreign guests) | Reporting to the Czech Police under Act No. 326/1999 Coll. | Legal obligation |
2.2. Additional data
| Data | Purpose | Legal basis |
|---|---|---|
| IP address, browser, time of visit | Security and protection against misuse (anti-spam, anti-fraud) | Legitimate interest |
| Communication with you (e-mails, phone calls) | Handling an enquiry or request | Legitimate interest / performance of a contract |
| Consent to marketing e-mails | Sending news and offers (max. 4× per year) | Consent (Art. 6(1)(a) GDPR) |
| Review (if you write one) | Publication on the website after approval | Consent |
2.3. What we do NOT process
- The identity document numbers (ID card, passport) of foreign guests are NOT stored in our system. On arrival you only present the document for inspection; the operator fills the details in manually on a paper form for the Czech Police.
- Payment details (card numbers) — we do not hold them; payment is made on arrival, in cash or by bank transfer.
- Special-category data (state of health, political opinions, religious beliefs, etc.) — we do not process these.
3. To whom we pass on your data (processors)
To operate the website and communicate, we use the following processors, which are contractually bound to protect your data in the same way as we do:
| Processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Website hosting, database, photo storage | EU edge servers (Europe) |
| Resend, Inc. | Sending transactional e-mails (reservation confirmations, cancellations, reviews) | EU |
| Sentry (Functional Software, Inc.) | Monitoring technical website errors (without your content data) | EU |
| Seznam.cz, a.s. (Mapy.cz) | Displaying the interactive map of the surroundings — when the tiles load, your IP address is transmitted | Czech Republic / EU |
Some processors (Cloudflare, Resend, Sentry) are companies based in the USA that process the data on servers in the EU. For any transfer of data outside the European Economic Area (EEA), EU Standard Contractual Clauses (SCC) are in place, or the EU-US Data Privacy Framework applies. Beyond these safeguards, we do not transfer your data.
4. How long we keep the data
| Category | Retention period |
|---|---|
| Reservation data (name, contact, dates of stay) | 6 years from the last reservation (accounting obligation under Act No. 563/1991 Coll.) |
| Tax documents (invoices) | 10 years from the end of the accounting year (legal obligation) |
| Marketing consent and related e-mail data | Until consent is withdrawn, max. 5 years from the last contact |
| Reviews (after approval and publication) | For as long as the website is operated, or until a deletion request |
| Technical records (IP, browser) | 30 days in the active log, 1 year in backups, then deleted |
After these periods, we anonymise the data (name → "[anonymised]", e-mail/phone deleted, only the necessary accounting links retained).
5. Your rights
As a data subject, you have the following rights under the GDPR:
- Right of access — you can request at any time what data we hold about you
- Right to rectification — if your data is incorrect or incomplete
- Right to erasure ("right to be forgotten") — if the data is no longer needed, except for data we are required to keep by law
- Right to restriction of processing — you can request that we merely store your data but no longer work with it
- Right to data portability — you can obtain your data in a structured, machine-readable format
- Right to object to processing based on legitimate interest
- Right to withdraw consent to marketing e-mails at any time (link at the end of every newsletter)
- Right to lodge a complaint with the Office for Personal Data Protection (www.uoou.cz)
How to exercise your rights
Simply contact us by e-mail at [email protected] or by post at the address above. We will handle your request within 30 days.
To verify your identity, we may ask for additional information (e.g. confirmation by e-mail from the address you used for the reservation).
6. Cookies and tracking
The rules for using cookies are governed by a separate document, the "Cookie Policy" (/en/cookies).
In brief: on the website we use anonymous Cloudflare web analytics (without storing cookies in your browser) and a Turnstile security cookie (protection against spam in the reservation form). We have no Google Analytics or advertising trackers on the website.
7. Security
7.1. Your data is encrypted in transit (HTTPS/TLS) and at rest (backups encrypted with AES-256).
7.2. Access to the administration is held only by the operator and the website developer, with authentication via a one-time login link sent by e-mail (no static password).
7.3. We back up the database regularly; backups remain within Cloudflare's infrastructure on servers in the EU.
7.4. In the event of a personal data breach, we will inform you without undue delay and report it to the Office for Personal Data Protection within 72 hours in accordance with the GDPR.
8. Changes to this policy
We may update this policy from time to time. The current version is always available on this page.
If a change materially affects you (e.g. an expansion of processing, new processors), we will notify you by e-mail (if you have provided it to us) at least 30 days in advance.
This is a courtesy translation. In the event of any discrepancy, the Czech version of this document is legally binding.
Pukoře, s.r.o. Černokostelecká 1777/107, 100 00 Prague 10 — Strašnice Company ID (IČO): 08084807
Contact: [email protected] · +420 604 575 751