GDPR
Privacy Policy
Last updated: February 8, 2026
1. Data Controller
The controller of your personal data is:
Lázně Pramen s.r.o.
Dejvická 255/18
160 00 Praha 6 – Dejvice
Czech Republic
Email: info@laznepramen.cz
Phone: +420 728 059 770
2. What Data We Collect
2.1 Data from Contact Forms
When you fill in a form on our website (contact, franchise, investor, or newsletter), we collect:
- First and last name
- Email address
- Phone number
- City and country (for franchise and investor forms)
- Financial capabilities / budget (for investor forms)
- Message or comment
2.2 Automatically Collected Data
- IP address
- Browser and operating system type
- Date and time of visit
- Pages visited
- Cookies (see our Cookie Policy)
3. Purposes and Legal Basis for Processing
| Purpose | Legal Basis | Retention Period |
|---|---|---|
| Responding to inquiries (contact form) | Legitimate interest (Art. 6(1)(f) GDPR) | 2 years |
| Processing franchise applications | Performance of contract / pre-contractual measures (Art. 6(1)(b) GDPR) | 3 years |
| Processing investor applications | Performance of contract / pre-contractual measures (Art. 6(1)(b) GDPR) | 3 years |
| Sending newsletters | Consent (Art. 6(1)(a) GDPR) | Until consent is withdrawn |
| Web analytics | Consent (Art. 6(1)(a) GDPR) | See Cookie Policy |
4. Data Recipients (Third Parties)
Your data may be shared with the following third parties:
| Service | Purpose | Location |
|---|---|---|
| Web3Forms | Form data processing | USA |
| Resend | Sending email notifications and auto-replies | USA |
| Netlify | Website hosting, serverless functions | USA |
| Google Maps | Displaying map on the Contact page | USA |
| Matterport | 3D virtual tour | USA |
| Trustindex | Reviews widget | Hungary |
| Yandex Metrica | Web analytics (with consent only) | Russia |
| flagcdn.com | Flag icons for language switcher | Netherlands |
Data transfers to third countries outside the EEA (USA, Russia) are carried out on the basis of Standard Contractual Clauses (SCCs) or adequacy decisions.
5. Your Rights
Under the GDPR, you have the following rights:
- Right of access – obtain information about whether and what data we process about you
- Right to rectification – request correction of inaccurate data
- Right to erasure – request deletion of your data ("right to be forgotten")
- Right to restriction of processing – request limitation of your data processing
- Right to data portability – obtain your data in a structured format
- Right to object – object to processing based on legitimate interest
- Right to withdraw consent – withdraw your consent at any time (newsletter, cookies)
To exercise your rights, contact us at info@laznepramen.cz.
6. Right to Lodge a Complaint
If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the supervisory authority:
Úřad pro ochranu osobních údajů (ÚOOÚ) – Czech Data Protection Authority
Pplk. Sochora 27
170 00 Praha 7
www.uoou.cz
7. Data Security
We have implemented appropriate technical and organizational measures to protect your personal data, including:
- SSL/TLS encryption (HTTPS)
- Content Security Policy (CSP)
- HTTP Strict Transport Security (HSTS)
- Honeypot spam protection in forms
- Server-side data validation
8. Changes to This Policy
This policy may be updated from time to time. We will inform you of significant changes on this page. We recommend regularly checking the date of the last update.