This Privacy Policy explains how Czech Lesson ("we", "us", "our") collects, uses, and protects your personal data in accordance with the EU General Data Protection Regulation (GDPR).
1. Data Controller
Czech Lesson
Email: support@czechlesson.com
Country of operation: Czech Republic
2. Personal Data We Collect
- Name and email address
- Booking and scheduling data (via Calendly)
- Payment status (processed securely by Stripe)
- Messages sent via contact forms or email
- Technical data such as IP address and cookies
3. Purpose and Legal Basis
We process personal data for the following purposes:
- Contract Performance: To provide Czech language lessons you have booked
- Legitimate Interest: To respond to inquiries and improve our services
- Consent: For cookies and marketing communications (where applicable)
- Legal Obligation: To comply with tax and accounting requirements
4. Third-Party Services
We use the following third-party services:
- Calendly: For booking and scheduling (Privacy Policy: calendly.com/privacy)
- Stripe: For secure payment processing (Privacy Policy: stripe.com/privacy)
- Google reCAPTCHA: For spam protection (Privacy Policy: policies.google.com/privacy)
5. Cookies
We use essential cookies for:
- Session management and security (CSRF protection)
- Cookie consent preferences
- Spam protection (reCAPTCHA)
You can manage cookie preferences through your browser settings or our cookie banner.
6. Data Retention
We retain personal data only as long as necessary:
- Contact form data: Up to 2 years
- Booking records: 3 years (for accounting purposes)
- Email communications: Until you request deletion
7. Your Rights (GDPR)
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data
- Restriction: Limit how we process your data
- Portability: Receive your data in a structured format
- Objection: Object to processing based on legitimate interests
- Withdraw Consent: For marketing or optional data processing
To exercise these rights, contact us at: support@czechlesson.com
8. Data Security
We implement appropriate technical and organizational measures to protect your data:
- SSL/TLS encryption for data transmission
- Secure password storage and authentication
- Regular security updates and monitoring
- Access controls and data minimization
9. International Transfers
Your data may be processed by our third-party service providers (Calendly, Stripe, Google) who may transfer data outside the EU. These providers comply with GDPR through Standard Contractual Clauses or other approved mechanisms.
10. Children's Privacy
Our services are intended for adults. We do not knowingly collect data from children under 16 without parental consent.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Significant changes will be communicated via email or website notice.
12. Contact & Complaints
For privacy inquiries or to exercise your rights:
Email: support@czechlesson.com
If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Czech Data Protection Authority (ÚOOÚ): www.uoou.cz