1. Introduction
This Privacy Policy explains how we process personal data of visitors to kamennezdi.cz, customers purchasing products through the website and participants booking our practical stonework courses.
Personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation – GDPR), Czech Act No. 110/2019 Coll., on the Processing of Personal Data, and other applicable legislation.
2. Data Controller
The controller of personal data is:
Luděk Komoň
Registered address: Novosedly 301, 691 82 Novosedly, Czech Republic
Email: stavime@kamennezdi.cz
Website: https://kamennezdi.cz/
3. Personal Data We Process
Depending on how you use our website and services, we may process the following categories of personal data:
- first and last name,
- email address,
- telephone number,
- billing and company details where applicable,
- information contained in your order, including the selected course, course date or purchased product,
- information you provide when contacting us or discussing your own project,
- technical information relating to the use of the website, such as IP address, browser information and cookie identifiers, where applicable.
We only process personal data that is necessary for the relevant purpose or that you voluntarily provide to us.
4. Purposes of Processing
We process personal data for the following purposes:
- processing and managing orders,
- booking places on practical stonework courses,
- sending order confirmations, payment information and organisational information relating to courses,
- delivering electronic products or access to purchased content,
- communicating with customers and course participants,
- handling enquiries, complaints and customer support,
- maintaining accounting, tax and other legally required records,
- protecting our legal rights and documenting contractual relationships,
- sending newsletters and other commercial communications where permitted by law,
- operating, securing and improving the website,
- analytics and marketing where the relevant consent has been provided.
5. Legal Bases for Processing
We process personal data on one or more of the following legal bases:
- Performance of a contract under Article 6(1)(b) GDPR – for processing orders, course bookings, providing purchased products and communicating in connection with a contractual relationship.
- Compliance with a legal obligation under Article 6(1)(c) GDPR – particularly accounting, tax and other statutory obligations.
- Consent under Article 6(1)(a) GDPR – for processing that requires your prior consent, including certain newsletters, analytics or marketing technologies.
- Legitimate interests under Article 6(1)(f) GDPR – where appropriate, for protecting our legal claims, maintaining website security, preventing misuse and, where permitted by law, communicating with existing customers about our own similar products or services.
6. Commercial Communications and Newsletters
If you subscribe to our newsletter, we may use your email address to send commercial communications on the basis of your consent.
Where permitted by applicable law, we may also send information about our own similar products or services to existing customers using contact details obtained in connection with a previous purchase.
You can unsubscribe from commercial communications at any time by using the unsubscribe link included in the relevant email or by contacting us at stavime@kamennezdi.cz.
7. Cookies, Analytics and Marketing Technologies
Our website may use cookies and similar technologies necessary for the operation of the website. Where analytics, advertising or other non-essential technologies are used, they are activated only in accordance with applicable legal requirements and your cookie preferences.
More detailed information about the cookies and technologies currently used on the website, their purposes, providers and storage periods is available in our Cookie Policy and cookie settings.
8. Recipients and Processors of Personal Data
Personal data may be made available to trusted service providers where this is necessary for the operation of our business or fulfilment of our legal obligations.
These may include in particular:
- Ecomail.cz, s.r.o. – email marketing and newsletter services,
- web hosting and website administration providers,
- e-commerce and technical service providers,
- accounting and tax service providers,
- payment and banking service providers where applicable,
- IT, security and data storage providers,
- public authorities where disclosure is required by law.
Service providers acting as processors may process personal data only within the scope necessary to provide their services and in accordance with applicable data protection requirements.
9. Transfers of Personal Data Outside the European Economic Area
Some technology providers may process personal data outside the European Economic Area. Where such transfers occur, we ensure that they are carried out in accordance with Chapter V of the GDPR, for example on the basis of an adequacy decision or appropriate contractual safeguards.
10. How Long We Keep Personal Data
We retain personal data only for as long as necessary for the relevant purpose and to comply with applicable legal obligations.
- order and contractual records are retained for the period necessary to fulfil the contract and to protect or establish legal claims,
- accounting and tax documents are retained for the periods required by applicable Czech accounting and tax legislation, generally for 5 or 10 years depending on the type of document and legal requirement,
- data used for newsletters on the basis of consent is retained until consent is withdrawn or the relevant processing purpose otherwise ceases,
- customer contact details used for permitted direct marketing are retained only while the relevant legal conditions continue to apply,
- course-related communication may be retained for a reasonable period after the course where necessary for customer support, contractual records or legal claims.
When personal data is no longer required, it is deleted, anonymised or otherwise securely disposed of.
11. Is Providing Personal Data Mandatory?
Providing personal data required for an order or course booking is necessary in order to enter into and perform the relevant contract. If you do not provide the information required to process an order, we may be unable to accept or fulfil it.
Providing data for optional purposes, such as subscribing to a newsletter, is voluntary.
12. Your Rights
Subject to the conditions set out in the GDPR, you have the right to:
- obtain confirmation as to whether we process your personal data and request access to it,
- request correction of inaccurate or incomplete personal data,
- request deletion of personal data where the legal conditions for deletion are met,
- request restriction of processing,
- object to processing based on legitimate interests,
- object at any time to the processing of your personal data for direct marketing purposes,
- receive personal data in a structured, commonly used and machine-readable format where the right to data portability applies,
- withdraw your consent at any time where processing is based on consent.
Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.
You can exercise your rights by contacting us at stavime@kamennezdi.cz.
13. Automated Decision-Making
We do not use personal data for automated individual decision-making that produces legal effects or similarly significantly affects you within the meaning of Article 22 GDPR.
14. Right to Lodge a Complaint
If you believe that your personal data is being processed in breach of applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority.
In the Czech Republic, the supervisory authority is:
Office for Personal Data Protection (Úřad pro ochranu osobních údajů)
Pplk. Sochora 27
170 00 Prague 7
Czech Republic
15. Data Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. Access to personal data is limited to persons and service providers who need it for the relevant purpose.
16. Changes to This Privacy Policy
We may update this Privacy Policy when our processing activities, services or applicable legal requirements change. The current version will always be published on this page.
Last updated: 26 August 2026