Privacy Policy (GDPR)
This is a courtesy translation. In case of any discrepancy, the Czech version prevails.
Hyperbaric s.r.o., a Czech limited liability company, registered office: Kateřinská 493/8, Nové Město, 128 00 Prague 2
IČ: 09125043 | DIČ: CZ09125043
Registered with the Municipal Court in Prague, file no. C 331308/MSPH
Designated contact person for GDPR matters: Tomáš Valeška, Managing Director
Email: info@kyslikovaterapie.cz
1. Introductory provisions
1.1. This Privacy Policy describes how Hyperbaric s.r.o. (the “Controller”) processes the personal data of clients, people interested in our services, business partners and users of the website.
1.2. The Controller processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and related legislation.
1.3. By using the Controller’s services or website, the Client confirms that they have read this Privacy Policy.
2. What data we process
The Controller processes only the data necessary to provide its services, to communicate, or to meet legal obligations.
2.1. Client data
- name and surname,
- phone number, email,
- information about bookings and the sessions provided,
- payment details (to the extent necessary for accounting),
- any information about health that the client provides voluntarily (for example contraindications, allergies).
Note: Information about health is not mandatory. The client provides it voluntarily, so that risks can be prevented and the session carried out safely.
2.2. Data from contact forms and emails
- name and contact details,
- the content of the message or enquiry.
2.3. Data from the booking system
- booking history, appointment dates, preferred services,
- information about the use of vouchers or packages.
2.4. Website and cookie data
- anonymised analytics data,
- IP address, device identifiers,
- data needed for the website to work correctly.
3. Purposes of personal data processing
We process data for the following purposes:
3.1. Providing services
- booking appointments,
- keeping records of the sessions carried out,
- handling the client’s requests.
3.2. Meeting legal obligations
- accounting and tax obligations,
- obligations under the občanský zákoník (Act No. 89/2012 Coll., the Civil Code) and other regulations.
3.3. Communication with the client
- booking confirmations,
- practical information,
- answers to enquiries.
3.4. Legitimate interests of the Controller
- protection against fraudulent conduct,
- internal analysis of our services,
- basic marketing (for example news for existing clients).
3.5. Marketing based on consent
- sending the newsletter (only with active consent),
- the use of cookies beyond those necessary to run the website.
4. Legal bases for processing
We process personal data on the basis of:
- Performance of a contract – providing the service, bookings,
- Compliance with a legal obligation – accounting, archiving,
- Legitimate interest – security and protection of the Controller’s rights,
- The client’s consent – marketing, newsletter, some cookies.
5. How long we keep personal data
We keep data only for as long as it is necessary:
- booking data: 3 years,
- accounting documents: 10 years (as required by law),
- marketing purposes: until consent is withdrawn,
- voluntary notes about health: a maximum of 1 year from the last visit.
Once the period has passed, the data is securely deleted.
6. Recipients of personal data
The Controller may pass personal data only to the following parties:
- our accounting firm,
- the provider of the booking system,
- providers of email and IT services,
- public authorities, where required by law.
We do not sell personal data, nor do we pass it to third parties for marketing purposes.
7. Client rights (rights of the data subject)
The client has the right to:
- access their data,
- have inaccurate data corrected,
- erasure (the “right to be forgotten”),
- restriction of processing,
- data portability,
- object to the processing,
- withdraw consent at any time,
- lodge a complaint with the ÚOOÚ (the Czech data protection authority).
Requests can be sent by email to: info@kyslikovaterapie.cz.
8. How data is processed and secured
8.1. The Controller applies technical and organisational measures that protect personal data against loss, misuse or unauthorised access.
8.2. Data is stored in secured systems with restricted access.
8.3. Only trained members of our team have access to personal data.
9. Cookies
The website uses cookies for:
- the correct functioning of the website (necessary cookies),
- anonymous analysis of traffic,
- marketing, only on the basis of consent.
10. Processing of data about health
10.1. The client may voluntarily provide information about their health so that the session can be carried out safely (for example contraindications, allergies, implants).
10.2. This information is not medical documentation within the meaning of the zákon o zdravotních službách (Act No. 372/2011 Coll., on Health Services).
10.3. The information is kept separately and is accessible only to the members of our team who carry out the session.
11. Final provisions
11.1. The Controller reserves the right to update this Privacy Policy. The valid version is always published on the website.
11.2. This Privacy Policy takes effect on the day it is published.