Privacy Policy
Effective from 9 October 2026
This policy explains how Smart Collectors s.r.o. processes the personal data of visitors to smartcollectors.cz and of people who contact us through the website. We follow Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 Coll., on personal data processing. If this translation and the Czech version differ, the Czech version prevails.
1. Who the controller is and how to reach us
The controller of your personal data is Smart Collectors s.r.o., company ID 17286115, registered office at Václavské náměstí 2132/47, Nové Město, 110 00 Prague 1, Czech Republic, entered in the Commercial Register kept by the Municipal Court in Prague, section C, file 369407.
For any question about personal data or to exercise your rights, contact us:
- by e-mail at pohledavky@smartcollectors.cz,
- by post at the registered office above,
- by phone at +420 226 288 560 (working days 8:30–15:30 CET).
2. What this policy covers
This policy covers the smartcollectors.cz website. Processing of personal data in receivables management and collection, in the Smart Portál application and in the performance of client contracts is governed by separate notices you receive within that relationship.
3. What we process, why, and on what legal basis
Contact form
When you send the "Call me back" or "Send a message" form, we process the data you enter:
- name and phone number ("Call me back" form),
- e-mail address and message text ("Send a message" form),
- any other information you choose to include in your message.
Purpose: to answer your enquiry, call you back and discuss an offer of our services.
Legal basis:
- steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR) when you contact us as a prospective client,
- our legitimate interest in answering an enquiry you sent us (Art. 6(1)(f) GDPR) in all other cases, for example when you write on behalf of a company or as a debtor.
By ticking the box in the form you confirm that you have read this policy. It is not consent under Art. 6(1)(a) GDPR — we need the form data to handle your enquiry and cannot reply without it.
We do not send you marketing communications based on the form. Should that ever change, we will ask for your separate consent first.
Running and securing the website
Every visit involves technical data without which the site cannot be delivered and protected: IP address, browser and device type, time of the request and the page visited.
- We briefly use your IP address to protect the form from abuse (limiting the number of submissions from one address). It is held only in memory for about one minute and is never stored.
- The form may be protected by Cloudflare Turnstile, which checks that it is not being submitted by an automated program.
- Our hosting provider processes technical request logs to deliver the site and protect it from attacks.
Legal basis: our legitimate interest in running the website securely and reliably (Art. 6(1)(f) GDPR).
The website uses no analytics or advertising tools and does not itself store any cookies in your browser. Details are in our Cookie Policy.
4. How long we keep data
- Contact form data is kept while we handle your enquiry and any contract negotiation, and for no longer than 12 months after our last exchange. If we enter into a contract, further retention is governed by that contract and by law.
- IP address used to protect the form is held in memory only, for about one minute.
- Hosting request logs are kept by the provider for as long as needed to run and secure the service, under its own terms.
If we need data for longer to establish, exercise or defend legal claims, we keep it only for as long and to the extent necessary.
5. Who we share data with
We do not sell your data or pass it to third parties for their own purposes. It is handled by our staff who answer enquiries and by the following processors, bound by contracts under Art. 28 GDPR:
- Sendinblue SAS (Brevo), France — receives form submissions, delivers them to us by e-mail and keeps a record of form contacts,
- Microsoft Ireland Operations Limited, Ireland — the company mailbox that receives form submissions,
- Cloudflare, Inc., USA — website hosting, its protection and form protection through Turnstile.
We may also disclose data to public authorities where the law requires it.
Transfers outside the European Union
Cloudflare, Inc. and Microsoft's parent company are based in the USA. Transfers to the USA rely on the European Commission's adequacy decision (EU–U.S. Data Privacy Framework), to which both companies have self-certified, or on standard contractual clauses approved by the European Commission.
6. Your rights
You have the right:
- of access — to find out whether and which of your data we process and to get a copy,
- to rectification of inaccurate or incomplete data,
- to erasure — where we no longer need the data or process it unlawfully,
- to restriction of processing — for example while we verify the accuracy of data,
- to data portability for data you gave us to negotiate a contract,
- to object to processing based on our legitimate interest; we then stop processing the data unless we demonstrate compelling legitimate grounds that override your interests,
- to lodge a complaint with the supervisory authority, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz.
We reply to your request without undue delay and within one month at the latest. In complex cases we may extend this period and will tell you so. Handling a request is free of charge. To avoid disclosing data to the wrong person, we may ask you to verify your identity.
7. Automated decision-making
We do not use website data for automated decision-making or profiling.
8. Changes to this policy
We review this policy regularly and update it whenever the way the website handles personal data changes. The current version, with its effective date, is always published on this page.
