Privacy Policy
Information about personal data processing on digitalfusion.cz
Last updated: 31. 8. 2026
The binding language of these policies is Czech. This English text is a courtesy translation of the same facts. If the two differ, the Czech privacy page prevails.
Controller
The controller of personal data is Thanh An Nguyen, DigitalFusion, company ID (IČO) 23628251, registered office Mlýnská 379, Hrušovany nad Jevišovkou, 671 67, registered with the Municipal Office in Znojmo, e-mail tony.nguyen@digitalfusion.cz, telephone +420 735 928 928, website digitalfusion.cz (the “Controller”). He is a natural person trading under the DigitalFusion brand, with his seat in Hrušovany nad Jevišovkou. The Controller is not a VAT payer and therefore does not quote a VAT ID. He has not appointed a data protection officer because the law does not require it. Requests from data subjects go to the e-mail or telephone above; post to the registered office is also possible. The name, seat and IČO are published on the website under section 435 of the Czech Civil Code. These policies describe processing the Controller performs as a controller: enquiries, call bookings, contracts, operation of this website and measurement, operational mail. Where the Controller operates a client’s website he may be a processor of that site’s visitor data; that is described in the terms of service and in the work contract. The public sample contract is at sample contract.
These policies are information under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 Coll. on the processing of personal data. They are not marketing copy and contain no blanks. If the firm’s identification changes (seat, e-mail, IČO), the Controller will publish a new version on this path. Until then the facts here apply, including IČO 23628251 and the seat in Hrušovany nad Jevišovkou.
What data we process and where it comes from
The Controller processes data people give him and data created by running the service. From forms and e-mail: name, e-mail, telephone, company name, IČO, address, message, chosen call slot, subject of the enquiry. From the work contract: the contracting party, signatory name, time and IP address at the moment of consent, contract reference, scope and price from the offer snapshot. From the website: IP address, browser type, path, request time, referrer, basic error diagnostics. From the mailbox and thread: message text, attachments the sender attached, delivery and bounce status. From booking: chosen slot, browser time zone, confirmation. The Controller does not process special-category data (health, biometrics, political opinions) and does not ask for them in forms.
Data come from the subject, from the person who sent an enquiry for a firm, from public registers only to check an IČO the subject stated, and from infrastructure logs without which the site and mail would not run. The Controller does not buy contact lists and does not merge social-network profiles into a score. A message from a company address is treated as a work contact unless shown otherwise. Children’s data are not collected on purpose; the forms are not for people under sixteen.
Purposes and legal bases
Purposes and bases are as follows. Answering an enquiry and preparing a contract: Article 6(1)(b) GDPR (performance of a contract and steps before it). Issuing a contract for signature, recording the signature, name, time and IP: the same letter (b), and for the IP also letter (f) (legitimate interest in proving who consented and from where). Booking a call and reminders: (b) and (f). Job records, invoicing and accounts: (c) (legal duties) together with tax and accounting rules. Defending claims and disputes: (f). Securing the site, limiting form abuse, access logs: (f) (availability and protection of systems). Measuring visits to this site in anonymised or aggregated counts that do not need a separate consent: (f); where information would be stored or read on a device beyond what is necessary, the Controller uses consent under the Czech Electronic Communications Act. Commercial messages to an existing contact within Act No. 480/2004 Coll. only where a basis sits in these policies and in the records; the Controller does not pass data to third parties for their marketing. Approaching companies from public registers (especially ARES) and from those companies’ public websites: Article 6(1)(f) GDPR (legitimate interest in offering a B2B service to entrepreneurs) together with Act No. 480/2004 Coll. Each such message is labelled as a commercial communication, identifies the Controller including IČO, and carries a working address for a direct opt-out; one reply “do not send” stops further messages. Register data are not used to profile consumers.
The Controller always balances his legitimate interest against the subject’s interests. The subject may object. Data are not used for credit scoring, for automatic refusal of an enquiry without a human, or for selling lists. A purpose is not widened in silence. A new incompatible purpose would need a new basis and a new notice on this path.
Recipients and transfers to third countries
The Controller does not pass data for third-party marketing. He passes them only to recipients who carry the service technically or by contract, and only as needed. Named:
- Cloudflare — Worker, network, document storage and related protection; place of business in the USA; processing may occur in the EU and outside it.
- AgentMail — inbound and outbound mail of the mailbox used for enquiries and contract letters.
- Google — spreadsheets as a one-way picture of operational records (cockpit), not as truth instead of the database; mail or documents only if actually used for that act.
- Telegram — operational notices to people in the Controller’s firm, not publication of an enquiry to strangers.
- Umami — measurement of visits to this site in the deployed instance.
- opencode-go — a tool used when preparing and checking texts and operational tasks; passwords and full client databases are not the ordinary input to a model.
Some named recipients are in the USA or may transfer data there. Where there is no adequacy decision, the Controller relies on the European Commission’s standard contractual clauses (SCC) and, where the recipient is certified, on the EU-US Data Privacy Framework (DPF). A subject may ask by e-mail for the substance of those safeguards. The Controller does not invent a country of transfer ad hoc and does not use a hidden intermediary outside this list without updating these policies. A public authority receives data only where the law requires it. Processors may use data only on the Controller’s instruction. A recipient does not change merely because a product was renamed; if the supplier changes, the policies change.
Retention
Retention follows the purpose. An enquiry that did not become a contract is kept for the time needed to reply and follow up, usually at most three years from the last message, unless a longer defence of a claim is needed. A booking is kept for the slot and a reasonable time after as proof the slot existed. The contract, signature, IP at signature and accounting records are kept for the period required by accounting and tax rules, at least ten years where the rule so requires, otherwise for the life of the contract and limitation periods. Operational web logs are kept shortly, usually weeks to a few months, unless a security event needs a longer trail. Visit measurement is kept longer in aggregate; in a form that identifies a person only for as long as the tool is set and the Controller finds reasonable, usually at most twenty-four months.
When the period ends the Controller deletes, anonymises, or stores the data with narrowed access if they must remain in a backup until it rotates. A backup is not a second file for everyday reading. Erasure is carried out unless a legal duty or defence of a claim stands in the way. Ending a client’s site follows the terms: the client’s data are exported and leave the operational layer once the grounds for processing end.
Rights of the data subject
The data subject has the right of access to what the Controller processes about them, to rectification of inaccurate data, to erasure where GDPR allows it, to restriction, to object to processing based on legitimate interest, to portability of data they provided that are processed automatically on the basis of a contract or consent, and to withdraw consent where consent is the basis, without affecting lawfulness until withdrawal. Requests go to tony.nguyen@digitalfusion.cz. The Controller answers without undue delay, at the latest within one month, with a possible extension of two further months for complex requests, of which the subject is informed. He may ask for identity checks proportionate to the risk so that data are not given to a stranger.
The right to erasure yields where the Controller needs the data for a legal duty or to establish, exercise or defend legal claims, especially a signed contract and accounts. An objection to legitimate interest is assessed; if the Controller’s interest does not prevail, processing for that purpose stops. A complaint to the supervisory authority does not exclude a request to the Controller, and vice versa. Acting through another person needs proof of authority. Ordinary requests are free; manifestly unfounded or excessive repeated requests may be refused or charged within GDPR.
Automated decision-making
The Controller does not take decisions that produce legal effects concerning a person, or similarly significantly affect them, solely on automated processing including profiling. A human reads the enquiry. A contract for signature is prepared by an operational process, but a human signs on the page made for that. Booking a slot is a human choice, not a trust score. Visit measurement is not used to lock a person out of the service. Tools that help write text or sort operational work do not replace the decision whether to enter a contract.
If the Controller later introduces automated decision-making in that sense, he will publish it in these policies first, state the significance and envisaged consequences, and provide human intervention, the chance to express a view and to contest the decision, as GDPR requires. Until then automation is help at work, not a judgment on a person. Anyone who believes an automated decision happened anyway should write to the Controller; the matter will be reviewed by a human.
Cookies and similar technologies
This website stores cookies and similar data on a device where that is necessary to run the page (session, security, remembering the language choice where it exists), or where the subject consents where the law requires consent. Strictly necessary cookies do not wait for a banner, because without them a form, a contract signature or a booking could not arrive safely. Measurement and preference cookies beyond necessity switch on only after consent, if the Controller uses them on that page at all. Consent may be refused and later withdrawn; withdrawal does not unwind measurement already in the aggregate, but it stops further storage that stood on consent.
Third parties named in the recipients article may use their own cookies on their own sites; these policies do not cover Cloudflare, Google, Telegram or those services’ documentation. On digitalfusion.cz and on the contract-signature pages this wording applies. The subject may delete cookies in the browser. Blocking all cookies may break form submit. The Controller does not use cookies to follow a person across the internet for other advertisers.
Security
The Controller protects data with measures that fit the risk: encryption in transit (HTTPS), access limited to people who need the job, secrets kept out of the repository, backups, infrastructure access logs, and the fact that the truth of a job lives in the database, not in a spreadsheet read back as the only source. Contract PDFs are stored as files with controlled access. The public signature page uses a one-time link that expires; after that the page behaves as unknown.
No measure is a promise that an incident will never happen. If a breach of security is a risk to rights and freedoms, the Controller follows Articles 33 and 34 GDPR: notice to the supervisory authority without undue delay and, where the rule requires it, to the subjects. Passwords and keys are not sent in the open in ordinary mail. The subject helps by not sending birth numbers and sensitive attachments the Controller did not ask for. Employees and collaborators are bound to keep confidential the data they see at work.
Supervisory authority (ÚOOÚ)
The supervisory authority for the Czech Republic is the Office for Personal Data Protection (ÚOOÚ), Pplk. Sochora 27, 170 00 Prague 7, website uoou.gov.cz. A subject may lodge a complaint with ÚOOÚ if they believe processing infringes their rights. They may also complain to the authority of the member state of their habitual residence, place of work or place of the alleged infringement. A complaint does not prevent asking the Controller first at tony.nguyen@digitalfusion.cz.
These policies are read together with the terms of service and the work contract. Where the policies describe processing and the terms describe the service, that is two views of the same firm, not a conflict. A change of the policies is published on this page. The Czech original is the binding text. A material change of purposes, recipients or transfers is e-mailed to people in an ongoing relationship where the e-mail is known and silence would be misleading. Questions about these policies, IČO 23628251 and the seat in Hrušovany nad Jevišovkou go to the Controller. The binding text is Czech.