Journeys by Deni

Privacy Policy

Language

Effective from: 16 August 2026

Last updated: 16 August 2026

Protecting your privacy and personal data is one of my priorities. I consider your personal data confidential and maintain confidentiality regarding such data. I place strong emphasis on the security of personal data processing, the appropriate selection of contractual partners who have access to personal data, and strict compliance with all applicable rules by which I am bound.

I hereby inform you that I, Denisa Bayerová, Company ID No. 116 66 561, with my place of business at Ve Vilkách 86, 149 00 Újezd u Průhonic, Czech Republic, process your personal data in accordance with:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“GDPR”); and
  • Act No. 110/2019 Coll., on the Processing of Personal Data,

as described below.

01

Who is the controller of your personal data?

The controller is the person who, alone or jointly with others, determines the purposes and means of processing your personal data.

The controller of your personal data is Denisa Bayerová, Company ID No. 116 66 561, with my place of business at Ve Vilkách 86, 149 00 Újezd u Průhonic, Czech Republic, e-mail: connect@journeysbydeni.com (the “Controller”).

02

What is your legal relationship with the Controller?

A. You have entered into a contract with the Controller or ordered services from the Controller

Legal basis: performance of the contract or taking steps at your request prior to entering into a contract.

Purpose:

  • performance of the contractual relationship between you and the Controller;
  • issuing tax documents;
  • future exercise of rights arising from the contractual relationship;
  • compliance with archiving obligations;
  • compliance with obligations arising under Act No. 563/1991 Coll., on Accounting.

Retention period:

i) for the duration of the contractual relationship;

ii) to the extent strictly necessary after its termination, for the duration of the limitation period of any claim on my part and/or on the part of the data subject and for the statutory archiving period, and subsequently for an additional period of one year in case any claim has been brought before a court at the end of the limitation period without me having been informed of it.

Providing personal data is a contractual requirement. The data subject is required to provide the personal data.

B. You contacted the Controller through the contact form on the website

Legal basis: performance of a contractual obligation where the data subject is a customer; in other cases – legitimate interest.

Purpose: communication in response to an enquiry or request.

Retention period:

i) for the duration of the contractual relationship;

ii) to the extent strictly necessary after its termination, for the duration of the limitation period of any claim on my part and/or on the part of the data subject and for the statutory archiving period, and subsequently for an additional period of one year in case any claim has been brought before a court at the end of the limitation period without me having been informed of it.

Providing personal data is necessary for the protection of the Controller's legitimate interests. The data subject is required to provide the personal data.

C. The Controller has sent you an offer of services

Legal basis: legitimate interest of the Controller – marketing.

Purpose: sending commercial communications.

Retention period:

i) for a period of one year, or until withdrawal of consent by the data subject;

ii) to the extent strictly necessary after its termination, for the duration of the limitation period of any claim on my part and/or on the part of the data subject and for the statutory archiving period, and subsequently for an additional period of one year in case any claim has been brought before a court at the end of the limitation period without me having been informed of it.

Providing personal data is necessary for the protection of the Controller's legitimate interests. The data subject is required to provide the personal data.

D. The Controller has checked your identity document

Legal basis: consent of the data subject.

Purpose: verification of the correctness of the customer's identity documents.

Retention period: for the duration of the inspection of the identity document.

I process your personal data both manually and by automated means in information systems. I protect your personal data against unauthorised or accidental access, transmission, alteration or loss, as well as against any other possible misuse.

I may process your personal data manually or by automated means; however, I do not carry out any individual automated decision-making or profiling.

03

What are the sources of your personal data?

The personal data processed by the Controller has been provided by you.

04

Who may receive your personal data?

Personal data may be disclosed to third parties (recipients) to the extent strictly necessary and solely for the purposes described above.

Such recipients may include contractual partners who provide personal data processing services for me or have access to personal data, specifically IT service providers, accounting and auditing firms, legal service providers, or other entities where disclosure of your personal data is required by applicable law.

05

Right to object

Pursuant to Article 21(1) of the GDPR, you have the right, on grounds relating to your particular situation, to object to the processing of your personal data where such processing is based on a legitimate interest or is carried out in the public interest or in the exercise of official authority vested in the Controller.

Following an objection, the Controller will no longer process the personal data unless the Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.

06

What rights do you have regarding the processing of your personal data?

With regard to your personal data, you have the following rights:

Right of access – you may request access to the personal data I process about you. I will also provide you with a copy of the personal data being processed.

Right to rectification – you may request correction of inaccurate or incomplete personal data that I process about you.

Right to erasure – you may request that I erase your personal data where one of the situations specified by the GDPR applies, including where the personal data is no longer necessary for the purposes for which it was collected or otherwise processed, where you withdraw your consent and there is no other legal basis for the processing, where you object under the conditions set out in the GDPR, where the personal data has been unlawfully processed, or where erasure is required by applicable law.

Right to restriction of processing – you may request that I restrict the processing of your personal data where the conditions set out in the GDPR are met, for example where you contest the accuracy of the personal data, where the processing is unlawful, where I no longer need the personal data for the purposes of processing but you require it for the establishment, exercise or defence of legal claims, or where you have objected to the processing pursuant to Article 21(1) of the GDPR.

Right to data portability – in cases provided for by the GDPR, you have the right to receive personal data concerning you which you have provided to the Controller in a structured, commonly used and machine-readable format, provided that exercising this right does not adversely affect the rights and freedoms of others.

Right to withdraw consent – where the processing of your personal data is based on consent, you have the right to withdraw your consent to the processing of your personal data for the purpose for which you provided it at any time.

Right to object – you may at any time object to the processing of your personal data by the Controller for direct marketing purposes where such processing is based on the legitimate interest of the Controller.

Right to lodge a complaint – you have the right to lodge a complaint with the supervisory authority, which is the Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, www.uoou.cz.

07

How can you exercise your rights?

To exercise your rights, you may contact me by e-mail at:

connect@journeysbydeni.com

By providing this information, the data subject is informed of their rights and their protection under Articles 13–22 of the GDPR.