Privacy Policy
English translation for your convenience. The binding version is the Czech version; in case of any discrepancy, the Czech version prevails. Version effective from 6 October 2026. We archive previous versions and send them on request. Compared with the version of 30 September 2026, point 2 c2) (contact persons of companies) has been added.
1. Controller
The controller of personal data is the operator of the Pravano platform – Pravano MG s.r.o., Company ID (IČO) 29860148, with its registered office at Lešenská 168, Kostelec, 763 14 Zlín, Czech Republic, registered in the Commercial Register kept by the Regional Court in Brno (Czech Republic), section C, file 153218. Contact for personal data matters: info@pravano.cz.
2. What data we process, why and on what legal basis
a) Quick check and enquiry. Name, e-mail, company, optionally phone (only where the form asks for it), information on your role and portfolio (type of goods, scope, country of establishment, target markets). Purpose: preparing and sending the Pravano Kompas (a free indicative overview) and follow-up communication. Legal basis: performance of a contract / steps taken prior to entering into a contract (Art. 6(1)(b) GDPR). Without this data we cannot prepare the check.
b) Booking a phone call. Name, e-mail, phone, chosen time. Purpose: holding the call, confirming and, where applicable, cancelling the appointment. Legal basis: Art. 6(1)(b) GDPR. Calls are held in Czech or Slovak.
b2) Live call with assistance. If we agree on a phone call via our “live adviser” tool, the spoken word is transcribed during the call and the transcript is sent in short segments to an AI assistant (Anthropic), which offers us verified material on what you are discussing in real time. The transcript serves only to conduct the call and summarise it, no audio is recorded, and we delete the transcript no later than 30 days after the call (the summary remains with your enquiry). Legal basis: Art. 6(1)(b) GDPR; we inform you about the transcription at the start of the call.
c) Providing the ordered service. Contact and billing details, the documents you hand over to us, communication and Outputs. Legal basis: performance of a contract (point b); for invoices, compliance with a legal obligation under accounting and tax legislation (point c).
c2) Contact persons of companies. If you act on behalf of a company (as its employee, director or other representative), the contracting party is the company, not you personally. In the cases under points a) to c) we therefore process your contact details on the basis of our legitimate interest in communicating with the company and in preparing and performing the contract with it (Art. 6(1)(f) GDPR); the purposes and retention periods are the same. Data shown on accounting and tax documents continue to be processed to comply with a legal obligation (point c, Art. 6(1)(c) GDPR). We obtained your data from you or from the company on whose behalf you act. You may object to this processing (see your rights below).
d) Legitimate interests (Art. 6(1)(f)): securing operations (technical logs, protection against spam and attacks), establishing and defending legal claims, and reasonable direct marketing to existing clients (with the option to unsubscribe at any time).
e) Consent (Art. 6(1)(a)): measurement cookies (analytics) and marketing communications to persons who are not yet our clients. Consent is voluntary and can be withdrawn at any time – withdrawal does not affect the lawfulness of earlier processing.
3. AI processing with human review
We prepare drafts of outputs (e.g. the text of the Pravano Kompas) with the help of AI tools (Anthropic). We never send you an output without review and approval by a person – it is therefore not a decision based solely on automated processing within the meaning of Art. 22 GDPR. We do not use your data to train AI models.
4. Who we share data with (processors)
We process data in the EU or with providers offering safeguards under the GDPR. We use these categories of processors:
- Cloudflare (hosting, databases, website protection, anonymous visitor statistics) – data primarily in the EU; transfers covered by the EU–US Data Privacy Framework (DPF) and standard contractual clauses (SCC).
- Resend (sending transactional e-mails) – we use the EU region (eu-west-1); DPF/SCC.
- Anthropic (AI assistance in preparing outputs and assistance during live calls, see Art. 2 b2 and Art. 3) – DPF/SCC; we pass on only the data necessary for preparing the output (answers from the check, company name, segments of the call transcript).
- Google (GA4 analytics – only if you give consent in the cookie bar; until then the measurement script is not loaded at all).
- Providers of invoicing and accounting (in particular Fakturoid) and, should one be switched on, a payment gateway provider; we provide the current list on request.
We have concluded a data processing agreement under Art. 28 GDPR with each processor. If the adequacy decision (EU–US Data Privacy Framework) is changed or repealed, transfers to third countries continue on the basis of standard contractual clauses (SCC) approved by the European Commission.
We do not pass data to other parties for their own marketing and we do not sell it.
Documents you hand over to us for the check may contain personal data of third parties – for those we are not the controller but a processor acting for you. The conditions are set out in the data processing agreement (Annex 1 to the Terms).
5. How long we keep data
- Enquiries and checks without a subsequent order: 24 months from the last communication (after that the data is anonymised automatically).
- Transcript of a live call: no later than 30 days after the call (deleted automatically).
- Contract and order documentation: for the duration of the contract and then 5 years for the defence of legal claims.
- Accounting and tax documents: 10 years under statutory obligations.
- Technical and security logs (including records of sent e-mails and aggregated visitor statistics): 12 months, then deleted automatically.
- Data processed on the basis of consent: until consent is withdrawn.
6. Cookies and measurement
Necessary: your consent choice (pravano_consent, browser storage), the admin session for our staff and technical protection of forms (Cloudflare Turnstile – protection against bots). Attribution: if you come from an advert, we keep the campaign identifier only in browser storage for the duration of the visit (it is not sent anywhere); only after your consent in the cookie bar do we store it as the first-party cookie pravano_attrib for 90 days and may pass it with your enquiry to the advertising system to evaluate the campaign. Measurement (Google Analytics 4): Google’s measurement script is loaded only after consent given in the cookie bar; until then no request is sent from our pages to Google (fonts and everything else are served from our own domain). Anonymous visitor statistics (Cloudflare Web Analytics): we count page visits without cookies and without storing anything on your device; according to Cloudflare the tool does not use browser fingerprinting or cross-site tracking and serves only aggregate statistics (legitimate interest in operating and improving the website). You can change your consent at any time via the “Cookie settings” link in the website footer (the choice is stored in browser storage, not in a cookie – deleting cookies therefore does not reset it). Rejecting is as easy as accepting. The management page of a Watch subscription (an address with a personal link) is never measured.
7. Your rights
You have the right of access to your data, rectification, erasure, restriction of processing, data portability, the right to object (in particular to direct marketing – after an objection we will stop sending you marketing) and the right to withdraw consent. You can exercise them by e-mail to info@pravano.cz; we will reply within 1 month. We carry out erasure by anonymisation across all our records; accounting documents on which you appear must be kept for 10 years by law (Art. 17(3)(b) GDPR). You also have the right to lodge a complaint with the Czech Office for Personal Data Protection (ÚOOÚ, uoou.gov.cz), which supervises us, or with the supervisory authority of the EU member state where you live or work (Art. 77 GDPR).
8. Security
We transfer data encrypted (TLS) and store it with vetted providers with access control; only an authorised person of the controller has access to operational data. The admin interface is protected by a login with a time-limited session and all actions are logged.
9. Changes to this policy
We may update this policy (e.g. when engaging a new processor); the current version is always on this page. Effective from 6 October 2026.