Privacy Policy
Last Updated: 29 July 2026
This Privacy Policy describes how Buzomu (operating at buzomu.info, hereinafter "we", "us", or "the Controller") collects, processes, stores, and protects personal data. This policy applies to all visitors and users of the website buzomu.info and to individuals who contact us for information about our services. Processing is conducted in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation, "GDPR") and the applicable Czech national implementing legislation, including Act No. 110/2019 Coll., on the Processing of Personal Data, as amended.
1. Identity and Contact Details of the Controller
The controller of personal data collected through this website is Buzomu, with its registered place of business at Rybná, Praha, Czech Republic. The controller can be contacted by email at [email protected] or by telephone at +420 777 601 969. As a controller, Buzomu determines the purposes and means of processing personal data. We have not appointed a Data Protection Officer, as the scale and nature of our processing does not meet the threshold requiring such appointment under Article 37 of the GDPR. Inquiries regarding data protection matters should be directed to the contact details above.
2. Categories of Personal Data Collected
We collect personal data that you provide to us directly through the contact form on this website. This includes your full name, email address, telephone number, and the content of any message you submit. We also collect technical data automatically when you visit our website, including your IP address, browser type and version, operating system, referring URL, pages visited, and the date and time of your visit. This technical data is collected through standard web server logs and, where applicable, through cookies and similar tracking technologies. We do not collect special categories of personal data as defined in Article 9 of the GDPR (such as health data, racial or ethnic origin, political opinions, or biometric data) through this website.
3. Purposes and Legal Bases for Processing
Personal data submitted through the contact form is processed for the purpose of responding to your inquiry and communicating with you about the services described on this website. The legal basis for this processing is Article 6(1)(b) of the GDPR (processing necessary for the performance of a contract or to take steps at the request of the data subject prior to entering into a contract) and, where applicable, Article 6(1)(f) (legitimate interests of the controller in maintaining business communications). Technical data collected automatically is processed for the purpose of operating and maintaining the security of the website, on the legal basis of Article 6(1)(f) of the GDPR, being our legitimate interest in ensuring the proper technical functioning of the website. Where processing is based on your consent (for example, in relation to non-essential cookies), you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
4. Data Retention Periods
Personal data submitted through the contact form is retained for a period of three years from the date of the last contact, unless a longer retention period is required by applicable law or is necessary for the establishment, exercise, or defence of legal claims. Technical log data is retained for a period of twelve months from collection. Data stored in cookies is retained for the period specified in our Cookie Policy. At the end of the applicable retention period, personal data is securely deleted or anonymised in a manner that prevents re-identification. We periodically review the personal data we hold to ensure it remains accurate, relevant, and not held longer than necessary.
5. Recipients and Transfers of Personal Data
We do not sell, rent, or otherwise transfer your personal data to third parties for their own marketing purposes. Personal data may be shared with third-party service providers who assist us in operating this website and communicating with you, including hosting providers and email service providers. Such providers act as data processors on our behalf and are bound by data processing agreements that require them to process personal data only on our documented instructions and to implement appropriate technical and organisational security measures. Where any transfer of personal data to a third country outside the European Economic Area takes place, we ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR, such as standard contractual clauses adopted by the European Commission. Personal data may also be disclosed to competent authorities where required by applicable law.
6. Your Rights as a Data Subject
Under the GDPR and applicable Czech law, you have the following rights in relation to your personal data: the right of access (Article 15 GDPR) to obtain confirmation of whether we process your personal data and, if so, to receive a copy; the right to rectification (Article 16 GDPR) to have inaccurate data corrected; the right to erasure (Article 17 GDPR) to request deletion of your data in circumstances specified by law; the right to restriction of processing (Article 18 GDPR); the right to data portability (Article 20 GDPR) where processing is based on consent or contract and carried out by automated means; the right to object (Article 21 GDPR) to processing based on legitimate interests; and the right not to be subject to solely automated decision-making with legal or similarly significant effects (Article 22 GDPR). To exercise any of these rights, please contact us at [email protected]. We will respond within one month of receiving your request, as required by Article 12 of the GDPR. We may need to verify your identity before processing your request.
7. Right to Lodge a Complaint
If you believe that our processing of your personal data infringes the GDPR or applicable Czech data protection law, you have the right to lodge a complaint with the competent supervisory authority. In the Czech Republic, the supervisory authority is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, UOOU), with its registered seat at Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, website: www.uoou.cz. You may also lodge a complaint with the supervisory authority of the EU member state in which you habitually reside, work, or where the alleged infringement occurred. We encourage you to contact us first at [email protected] so that we can attempt to resolve any concerns directly.
8. Security of Personal Data
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in accordance with Article 32 of the GDPR. These measures include the use of encrypted connections (HTTPS/TLS) for data transmission, access controls limiting data access to authorised personnel, and regular review of our security practices. No method of transmission over the internet or method of electronic storage is completely secure; however, we take reasonable steps to protect personal data using commercially acceptable means. In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority within 72 hours of becoming aware, as required by Article 33 of the GDPR.
9. Cookies and Tracking Technologies
This website uses cookies and similar tracking technologies. Detailed information about the cookies we use, their purposes, and how you can manage your cookie preferences is set out in our Cookie Policy, which is available at cookies.html. Where cookies require your consent under applicable law, we collect that consent through our cookie consent mechanism before placing such cookies. You can withdraw or modify your cookie consent at any time by accessing the cookie settings through the cookie consent tool on this website.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or for other operational reasons. The date of the most recent revision is indicated at the top of this document. We encourage you to review this Privacy Policy periodically. Where changes are material, we will take reasonable steps to inform you, which may include posting a prominent notice on the website. Continued use of the website following the posting of changes constitutes your acknowledgement of those changes.