CompuNet s.r.o. protects the personal data of website visitors in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and other applicable data protection laws of the Czech Republic.
Below, we explain what personal data we process in connection with your activity on this website, https://compunet.cz/, why we process it, how long we retain it, and what your legal rights are.
1. Data Controller
The controller of your personal data is:
Company Name: CompuNet s.r.o.
Registered Office: Zubatého 295/5, Smíchov, 150 00 Prague, Czech Republic
Company ID No. (IČO): 27608514
VAT ID No. (DIČ): CZ27608514
Registered with: Municipal Court in Prague, Section C, File No. 118594
GDPR Contact E‑mail: info@compunet.cz
Phone: +420 257 211 846
1.1 Data Protection Officer
The Company has not appointed a Data Protection Officer (DPO).
For any matters relating to the protection of personal data, you may contact us directly at info@compunet.cz.
1.2 Statement Regarding Our Role as a Data Processor (Logs, Monitoring, and IT Support)
As part of providing our core services (IT/OT support, network administration, log analysis, SIEM, incident response, and SLA support), we may process technical and operational data such as logs, user account identifiers, IP addresses, system records, and security event data contained within our customers’ infrastructure.
In such cases, CompuNet s.r.o. acts as a Data Processor of personal data. The scope, purpose, and conditions of such processing are always strictly governed by a separate Data Processing Agreement (DPA) concluded with the respective customer.
2. Scope, Purposes, Legal Bases, and Data Retention Periods
Data submitted through the contact form is primarily used to deliver your message to our corporate e‑mail address.
If our website or its security mechanisms temporarily store technical records, this is done solely to the extent necessary to ensure the stable operation, security, and protection of the website.
As part of your activity on the website, we process personal data primarily in connection with the following activities:
| Your Activity on the Website | Scope of Processed Data | Purpose and Legal Basis | Nature of Provision and Consequences | Data Retention Period |
| Website visit, technical operation, and security | IP address, date and time of access, requested URL, status code, browser and device information, operating system, referrer, technical and security logs, essential technical cookies. | Ensuring the operation, stability, and security of the website, prevention of misuse, detection of incidents, and resolution of technical issues. The legal basis is the Controller’s legitimate interest pursuant to Article 6(1)(f) GDPR; essential technical storage does not require consent under cookie regulations. | Data is processed automatically when using the website. Without basic technical processing, the website cannot be operated securely and properly. | Standard server logs are generally retained for no longer than 30 days. Security logs are generally retained for no longer than 6 months; longer only when required for investigating a security incident, misuse, or legal claim. |
| Submission of a non-binding enquiry, contact form, or e‑mail message | First name, last name, e‑mail address, telephone number, company name, message content, information provided in the enquiry, and subsequent business communication; in the case of forms, also basic technical data relating to the submission. | Responding to enquiries, processing requests, preparing quotations, arranging meetings, and related business communication. The legal basis is taking steps at your request prior to entering into a contract pursuant to Article 6(1)(b) GDPR and the Controller’s legitimate interest pursuant to Article 6(1)(f) GDPR in maintaining records and protecting legal claims. | Voluntary. However, without contact details, we are unable to respond to your enquiry or prepare an offer. | General enquiries that do not result in a contract are generally retained for 12 months from the last communication. Relevant business communication may be retained for the period necessary to protect legal claims, generally 3 years from the last relevant communication; where a contractual relationship is established, the retention periods specified below apply. |
| Response to a job advertisement / vacancy (Careers section) | First name, last name, e‑mail address, telephone number, CV/resumé, cover letter, information about education and professional experience, communication with the applicant, interview notes, and any other information voluntarily provided during the recruitment process. | Inclusion in a recruitment process for a specific position, communication with applicants, assessment of suitability, and potential preparation of an employment contract. The legal basis is taking steps at your request prior to entering into a contract pursuant to Article 6(1)(b) GDPR; following the completion of the recruitment process, the legal basis may be the Controller’s legitimate interest pursuant to Article 6(1)(f) GDPR in protecting legal claims. | Voluntary. However, without the provision of basic information, we cannot include you in the recruitment process. | For the duration of the specific recruitment process and generally for no longer than 6 months after its completion for the purpose of defending legal claims. If you are hired, relevant data will subsequently be processed as part of personnel records in accordance with the employer’s internal policies. |
3. Recipients and Sharing of Personal Data
Your personal data is accessible only to individuals who require it for the purposes described above. We do not transfer or sell your personal data to third parties for their own marketing purposes.
To the extent necessary, your personal data may be accessed in particular by:
- providers of web hosting, website administration, and website technical support services;
- providers of cloud, communication, and e‑mail services;
- providers of cookie consent management systems and, where applicable, analytics service providers;
- providers of internal operational, security, CRM, or ticketing systems;
- technology partners and suppliers where necessary for processing a specific enquiry, delivering a service, or providing support;
- external advisors in the fields of accounting, taxation, auditing, and legal services;
- public authorities, courts, or other entities where disclosure is required by law or necessary to protect our legal claims.
3.1 Transfers of Data Outside the EEA
We strive to process personal data primarily within the European Economic Area (EEA).
In exceptional cases, personal data may be transferred outside the EEA, particularly where this is necessary for the use of certain cloud, communication, security, or analytics services. In such cases, we only proceed where the requirements of the GDPR are met, in particular on the basis of an adequacy decision issued by the European Commission, Standard Contractual Clauses, or other appropriate safeguards.
Information regarding the specific safeguards applied will be provided upon request.
4. Cookies and Technical Storage
We use the Complianz platform to manage technical storage, cookies, and user preferences.
A complete and up-to-date list of individual cookies, their providers, purposes, retention periods, and categories is available in our separate Cookie Policy and through the cookie banner accessible from the website footer.
Depending on your preferences selected in the cookie banner, we may use the following categories of cookies:
Necessary (Technical) Cookies:
These cookies are essential for the proper, secure, and basic technical functioning of the website, including remembering your choices within the cookie banner. They do not require active consent; however, the obligation to provide information remains applicable.
Preference / Functional Cookies:
These cookies are used to remember additional user preferences where such functionality is implemented on the website. Where such storage is not strictly necessary for a service explicitly requested by the user, these cookies are used only on the basis of consent.
Statistical Cookies:
Subject to your consent, these cookies are used for internal measurement of website traffic, stability, and usability. The results are primarily used in aggregated form.
Marketing Cookies:
Under our current configuration, we do not use marketing cookies or third-party advertising tools. Should such tools be implemented in the future, they will only be used on the basis of your prior consent and following an update of the cookie banner and Cookie Policy.
You may modify or withdraw your preferences and granted consents at any time via the consent management link or button available in the website footer.
Refusing or withdrawing consent for non-essential cookies does not affect your ability to use the basic functions of the website.
5. Automated Decision-Making and Profiling
No automated decision-making within the meaning of Article 22 GDPR, nor any profiling that would produce legal or similarly significant effects concerning you, takes place in connection with the processing of personal data through this website.
6. Technical Data Security
We implement appropriate technical and organizational measures corresponding to the nature of the processing and the risks associated with the website:
- All communication between your browser and our website is encrypted using the HTTPS protocol (SSL/TLS certificate).
- Access to submitted enquiries and e‑mail communications is restricted to authorized persons only and protected by appropriate technical and organizational security measures.
7. Your Rights Under the GDPR
The GDPR grants you the following rights in relation to your personal data, which you may exercise to the extent and under the conditions set out by applicable law:
Right of Access: You have the right to obtain confirmation as to whether we process your personal data and, where that is the case, to access such data and related information.
Right to Rectification: You have the right to request the correction of inaccurate personal data or the completion of incomplete personal data.
Right to Erasure: You have the right to request the deletion of personal data where it is no longer necessary, consent has been withdrawn, a legitimate objection has been raised, or there is no other legal basis for its continued retention.
Right to Restriction of Processing: You have the right to request the restriction of processing in cases specified by the GDPR.
Right to Data Portability: Where processing is based on consent or a contract and is carried out by automated means, you may request the transfer of your personal data in a structured, commonly used, and machine-readable format.
Right to Object: You have the right to object to processing based on our legitimate interests, including objections to any related follow-up business communications.
Right to Withdraw Consent: Where processing is based on consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before such withdrawal.
Right Not to Be Subject to Automated Decision-Making: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you. We do not carry out such processing on this website.
Right to Lodge a Complaint: You have the right to lodge a complaint with the Czech Data Protection Authority (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, www.uoou.cz.
You may exercise your rights by sending an e‑mail to info@compunet.cz. We will respond to requests without undue delay and no later than one month from receipt of the request. In justified cases, this period may be extended by up to an additional two months in accordance with the GDPR, of which you will be informed.
8. Final Provisions
These Privacy Policy provisions are valid and effective as of 28 May 2026.
We reserve the right to update these provisions in the event of legislative or technical changes. The current version of the Privacy Policy is always available on our website together with the effective date.
