We are Monika Glendová, Business ID: 71363882, with registered office at Boleslavská 1905/7, Vinohrady, 130 00 Prague 3, operator of Elite Barbershop (hereinafter the "Controller").
Protecting your privacy is our priority. This policy explains what personal data we collect, why we do so, and what rights you have in connection with our services.
1.What personal data we process
We process data you provide when creating a reservation: first and last name, email address, phone number, and reservation history (date of visit, service type, barber).
2.Purposes and legal bases for processing
We process your data exclusively for the following purposes:
- Processing your reservation (Performance of contract): Accepting, confirming, and organizing your booking.
- Operational communication (Legitimate interest): Routine communication regarding any changes to appointments on our side.
- Direct marketing, Customer exception: As our existing customer, based on § 7 paragraph 3 of Act No. 480/2004 Coll. and our legitimate interest, we send you emails about services similar to those you have actually used (e.g., an early reminder of an upcoming appointment, news about freed-up capacity). You can unsubscribe at any time, free of charge, by clicking the link in the footer of every email.
3.Processors, data flow, and security
We do not sell your data to anyone. To deliver excellent service, we rely on vetted partners (processors) who act exclusively on our instructions and may not use the data for their own purposes. Primary processing takes place within the EU/EEA. When we use international analytics and marketing tools, data may be transferred to the USA, always on the basis of standard contractual clauses approved by the European Commission.
Data flows from our reservation system via a secure API to our automation software and then to the email delivery platform:
- Reservio: Booking system provider (Processor).
- Boostware: Marketing automation integration software (Processor).
- SmartEmailing: Secure email delivery platform (Sub-processor approved by the Controller).
Data security: All our processors follow strict technical and organizational measures. Data is transferred over an encrypted connection (HTTPS), the local database of the integration software is encrypted at rest (at-rest encryption), only authorized persons have access to the data, and all access is logged.
4.Data retention period
Data processed for marketing and customer care purposes is retained for a maximum of 3 years from your last visit to our barbershop. After that, the data is automatically and permanently deleted across all our systems and the systems of our processors. Some transactional data (e.g., on invoices) may be retained longer if expressly required by applicable accounting and tax laws.
5.Your rights under GDPR
Under applicable legislation, you have the right to:
- Access your personal data and the right to its portability in a machine-readable format.
- Correction of inaccurate data or its erasure (the so-called right to be forgotten).
- Restriction of processing.
- Where applicable, the right to withdraw consent at any time (if expressly granted to us for certain purposes).
- Object to processing based on legitimate interest (e.g., for direct marketing), in which case we will immediately cease processing your data for that purpose.
We handle your requests as the Controller, while we may use our processors listed above for the technical execution (e.g., data export or deletion). To exercise your rights, contact us at: elite.barbershop.praha@gmail.com.
If you believe we are handling your data unlawfully, you have the right to lodge a complaint with the Czech Office for Personal Data Protection (www.uoou.cz).
← Back to homepage