Privacy Policy
Protecting your personal data matters to us — not only because the law requires it, but because iit's what our business is built on. We help clients collect, process, and protect data properly — and we apply the same principles to the data we collect from you.
This document describes what personal data we process, what we use it for, how long we retain it, and what rights you have.
Who controls your data?
The data controller within the meaning of the GDPR (EU Regulation 2016/679) is:
Signals s.r.o., Hlučkova 813/14, 199 00, Prague 18
Company ID (IČO): 08971251
VAT ID (DIČ): CZ08971251
Email: info@signals.cz
Website: signals.cz
The company is registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, Insert 328404.
We have not appointed a Data Protection Officer (DPO), as the GDPR does not require us to. If you have any questions about your personal data, you can contact us at any time at the email address above.
What data we process and why
We only process what we actually need for a specific purpose. For each category of data below, we explain what it is, why we process it, on what legal basis, and for how long.
1. When you contact us via the contact form or email
What data: name, email, your message, and optionally your phone number and company name.
Purpose: to reply to you and, where relevant, agree next steps.
Legal basis: steps prior to entering into a contract, and legitimate interest in communicating with a potential client (Art. 6(1)(b) and (f) GDPR).
Retention period: for the duration of the communication, and thereafter for a maximum of 3 years in case you contact us again.
2. When you order a service or product from us
What data: billing details, contacts details of your employees, the access credentials we need to deliver the service, records of our work together.
Purpose: performance of the contract, invoicing, and related obligations (accounting, taxes, archiving).
Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and compliance with a legal obligation (Art. 6(1)(c) GDPR).
Retention period: for the duration of the contract and thereafter 10 years pursuant to the Czech Accounting Act and the Czech VAT Act.
3. When you visit our website
What data: technical data about your browser and device, pages visited, approximate location, referral source.
Purpose: basic website operation and security (necessary cookies), measuring and improving the website, evaluating marketing campaigns (with your consent).
Legal basis: legitimate interest in website security (Art. 6(1)(f) GDPR) for necessary cookies; consent (Art. 6(1)(a) GDPR) for analytics and marketing cookies.
Retention period: a maximum of 14 months. Specific retention periods for individual cookies are listed on our Cookies page.
4. When you subscribe to our newsletter
What data: email address, optionally name, data on which emails you opened and which links you clicked.
Purpose: sending commercial communications (news, articles, invitations).
Legal basis: consent (Art. 6(1)(a) GDPR), or legitimate interest for existing clients (Art. 6(1)(f) GDPR and Section 7(3) of Act No. 480/2004 Coll.).
Retention period: until you unsubscribe — every email has an unsubscribe link.
5. When you using our online booking tool
What data: name, email, meeting time, optionally other details entered in the form.
Purpose: scheduling the meeting and keeping a record of it.
Legal basis: taking steps prior to entering into a contract (Art. 6(1)(b) GDPR).
Retention period: for as long as necessary to hold the meeting and any follow-up communication, for a maximum of 3 years.
Who we share your data with
We share your data only where necessary, and always under a data processing agreement or equivalent contractual safeguard. Our main processors are:
- Website hosting providers — Webflow, Cloudflare
- Google Ireland Ltd. / Google LLC — Google Workspace (email, storage), Google Analytics, Google Tag Manager, Google Cloud Platform (BigQuery)
- Accounting and tax advisor — BKP FINANCE s.r.o.
- CRM and marketing tools — ClickUp
- Cookie management tool (CMP) — Consent Studio
- Invoicing platform — Fakturoid
We do not sell your data or share it with third parties for their own marketing purposes.
Transfer of data outside the EU
Some of our suppliers (particularly Google) may also process data in countries outside the European Economic Area. In such cases, the transfer takes place on the basis of:
- standard contractual clauses approved by the European Commission, or
- the Data Privacy Framework (DPF), to which Google adheres as a certified organization.
Your rights
You have the following rights in relation to your personal data:
- Right of access — to know what data we process about you and to obtain a copy of it.
- Right to rectification — to correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — where there is no legal basis for the processing.
- Right to restriction of processing — for example, while we verify the accuracy of the data.
- Right to data portability — to receive your data in a machine-readable format.
- Right to object to processing based on legitimate interest, particularly for marketing purposes.
- Right to withdraw consent at any time, where we process data based on consent. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
- Right to lodge a complaint with the supervisory authority — in the Czech Republic, this is the Office for Personal Data Protection (Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz).
To exercise your rights, contact us at info@signals.cz. We'll respond within 30 days. In exceptional cases — an unusually large or complex request, for example — we may extend this by a further two months. We'll always let you know if that happens.
Profiling and automated decision-making
We do not carry out automated decision-making or profiling that has legal effects on you.
Data security
We take data security seriously. We use encrypted connections (HTTPS), keep production and test data in separate environments, grant system access on a least-privilege basis, and review regularly who has access to what. For client data we also apply data governance principles — we document where data lives, who owns it, and how it's handled.
Changes to this document
We may update this document from time to time — iif we add a new tool, switch provider, or the law changes. You can always find the current version on this page. We will inform you in advance of any significant changes (e.g. a new purpose of processing), typically by email or a notice on the website.
Last updated: May 20, 2026
