GDPR
Privacy policy
Statement on the processing of personal data under Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).
The data controller, Pension U Lišků, Krasetín 69, 382 03 Křemže, Company ID 68526342, hereby informs you about the processing of personal data.
Scope of processing
We obtain your personal data when you:
- contact us through the website
- send us an accommodation enquiry
- give us your data in person, by e-mail or by phone
We process the following data:
- address and identification data used to uniquely identify the data subject (e.g. first name, surname, title, permanent address, ID card or passport number) and contact details of guests who have stayed with us (e.g. home address, phone number and e-mail address)
- any other information you write in e-mails sent to the address given on this website
Legal grounds for processing ordinary personal data without the guest’s consent
The legal grounds for processing ordinary personal data are: contract, law, vital interest (e.g. emergency), public interest and the legitimate interest of the controller.
The guest acknowledges that the accommodation provider is entitled to request and process the guest’s personal data to the extent required by law without the guest’s consent, namely:
1. Under Act No. 565/1990 Coll. on local fees, the accommodation provider must keep a register recording: first name, surname, permanent address, start and end of the stay, purpose of the stay and ID card or travel document number. Any further details (e.g. date of birth) may not be recorded without the guest’s consent.
2. Under Act No. 314/2015 Coll. amending Act No. 326/1999 Coll. on the residence of foreign nationals in the Czech Republic, the accommodation provider must keep a register of foreign guests recording: first name, surname, date of birth, nationality, ID card or passport number, visa number if stated in the travel document, start and end of the stay, purpose of the stay, permanent address abroad and address in the Czech Republic, if any.
The accommodation provider must keep these data for six years on the basis of this legal obligation and may delete them only after that period.
At the guest’s request, the accommodation provider will provide information about the data it holds about the guest, always only after the person’s identity has been verified. No information is given by phone or e-mail.
The guest further acknowledges that the accommodation provider may, without consent, process the personal data strictly necessary for communicating with the guest and for concluding and performing the contract; an enquiry already constitutes a legitimate interest, as the provider needs e.g. the e-mail address and phone number to communicate. A contract means a firmly confirmed reservation and subsequently the guest’s stay.
In all other cases, the accommodation provider must ask for consent to process ordinary personal data.
Legal grounds for processing sensitive personal data without the guest’s consent
The guest acknowledges that the accommodation provider may process sensitive personal data without consent only if the guest discloses them, e.g. a specific allergy. In that case the provider has a legitimate interest in ensuring the stay goes according to the guest’s wishes.
After the guest’s departure, the accommodation provider must delete such sensitive data without delay unless the guest gives written, explicit and voluntary consent to keep them.
Obligations of the accommodation provider, rights of the guest
The accommodation provider must inform the guest how their personal data are handled, in particular where they are stored, who has access to them, how they are processed and how they are protected.
The guest has the right to access their personal data processed by the provider, to request rectification, restriction of processing or erasure (except for the statutory grounds and periods above), and the right to object to processing.
If the guest believes their personal data are being processed unlawfully, they may lodge a complaint with the supervisory authority, which in the Czech Republic is the Office for Personal Data Protection (www.uoou.cz).