<
GDPR
>

Privacy Policy

Protecting your personal data matters to us — not only because the law requires it, but because it's the foundation of what we do professionally. We help clients collect, process, and protect data correctly — and we apply the same principles to the data we collect from you.

This document describes what personal data we process, what we use it for, how long we retain it, and what rights you have.

Who is the controller of your data

The data controller within the meaning of the GDPR (EU Regulation 2016/679) is:

Signals s.r.o., Hlučkova 813/14, 199 00, Prague 18
Company ID (IČO): 08971251
VAT ID (DIČ): CZ08971251
Email: info@signals.cz
Web: signals.cz

The company is registered in the Commercial Register kept by the Municipal Court in Prague, Section C, Insert 328404.

We have not appointed a Data Protection Officer (DPO), as GDPR does not require it for us. However, you can contact us at any time regarding any questions about your personal data at the email address above.

What data we process and why

We only process what we actually need for a specific purpose. For each group of data below, we state what it is, why we process it, on what legal basis, and for how long.

1. When you contact us via the contact form or email

What data: name, email, optionally phone number and company name, the content of your message.
Purpose: to be able to respond to your inquiry or question and, where relevant, arrange next steps.
Legal basis: steps prior to entering into a contract, and legitimate interest in communicating with a potential client (Art. 6(1)(b) and (f) GDPR).
Retention period: for the duration of the communication, and thereafter for a maximum of 3 years in case you contact us again.

2. When you order a service or product from us

What data: billing details, contacts of your employees, technical access needed to provide the service, records of the course of cooperation.
Purpose: performance of the contract, invoicing, and related obligations (accounting, taxes, archiving).
Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and fulfillment of legal obligations (Art. 6(1)(c) GDPR).
Retention period: for the duration of the contract and thereafter 10 years pursuant to the Accounting Act and the VAT Act.

3. When you visit our website

What data: technical data about your browser and device, pages visited, approximate location, referral source.
Purpose: basic website operation and security (necessary), measuring and improving the website, evaluating marketing campaigns (with your consent).
Legal basis: legitimate interest in website security (Art. 6(1)(f) GDPR) for necessary cookies; consent (Art. 6(1)(a) GDPR) for analytics and marketing cookies.
Retention period: a maximum of 14 months. Specific retention periods for individual cookies can be found in the Cookies document.

4. When you subscribe to our newsletter

What data: email address, optionally name, data on which emails you opened and what you clicked on.
Purpose: sending commercial communications (news, articles, invitations).
Legal basis: consent (Art. 6(1)(a) GDPR), or legitimate interest for existing clients (Art. 6(1)(f) GDPR and Section 7(3) of Act No. 480/2004 Coll.).
Retention period: until you unsubscribe (every email includes an unsubscribe link) or until you withdraw your consent.

5. When you book a meeting with us via an online tool

What data: name, email, meeting time, optionally other details entered in the form.
Purpose: arranging and recording the meeting.
Legal basis: steps prior to entering into a contract (Art. 6(1)(b) GDPR).
Retention period: for as long as necessary to hold the meeting and any follow-up communication, for a maximum of 3 years.

Who we share your data with

We share your data only where necessary, and always under a data processing agreement or equivalent contractual safeguard. Our processors include in particular:

  • Website hosting providers — Webflow, Cloudflare
  • Google Ireland Ltd. / Google LLC — Google Workspace (email, storage), Google Analytics, Google Tag Manager, Google Cloud Platform (BigQuery)
  • Accounting and tax advisor — BKP FINANCE s.r.o.
  • CRM and marketing tools — ClickUp
  • Cookie management tool (CMP) — Consent Studio
  • Invoicing platform — Fakturoid

We do not sell your data or share it with third parties for their own marketing purposes.

Transfer of data outside the EU

Some of our suppliers (particularly Google) may also process data in countries outside the European Economic Area. In such cases, the transfer takes place on the basis of:

  • standard contractual clauses approved by the European Commission, or
  • the Data Privacy Framework (DPF), to which Google adheres as a certified organization.

Your rights

In connection with the processing of your personal data, you have the following rights:

  • Right of access — to know what data we process about you and to obtain a copy of it.
  • Right to rectification — to correct inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten") — where there is no legal basis for the processing.
  • Right to restriction of processing — for example, while we verify the accuracy of the data.
  • Right to data portability — to receive your data in a machine-readable format.
  • Right to object to processing based on legitimate interest, particularly for marketing purposes.
  • Right to withdraw consent at any time, where we process data based on consent. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
  • Right to lodge a complaint with the supervisory authority — in the Czech Republic, this is the Office for Personal Data Protection (Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz).

To exercise your rights, contact us at info@signals.cz. We will respond within 30 days at the latest. In exceptional cases (for example, a very extensive request), we reserve the right to extend this period by a further 2 months — we will always inform you of this.

Profiling and automated decision-making

We do not carry out automated decision-making or profiling that has legal effects on you.

Data security

We handle data professionally. We use secure transmissions (HTTPS), separate environments for production and testing data, access to systems controlled according to the principle of least privilege, and we regularly review who has access to which data. For client data, we further apply data governance principles — we document where the data is, who owns it, and how it is handled.

Changes to this document

We may update this document from time to time — if we add a new tool, change a supplier, or legislation changes. You can always find the current version on this page. We will inform you in advance of any significant changes (e.g. a new purpose of processing), typically by email or a notice on the website.

Last updated: May 20, 2026