Back

Personal Data Protection Policy (GDPR Information)

Sections 3 to 8 and 10 to 13 were translated from the binding Czech version and are awaiting formal approval. In case of any discrepancy, the Czech version prevails.

Quick Summary

  • Controller: Bez předsudků z. s. (association). We operate the website; web hosting is provided by WEDOS Internet, a.s. as processor.
  • Why we process data: for website operation, registration and ticket processing, sending news (with consent), project implementation and contracts, protection of rights, and fulfillment of legal obligations.
  • Legal bases: performance of contract, legitimate interest, consent, legal obligation.
  • How long: during the event/contract + according to law (typically 5–10 years), marketing until unsubscribe, photos/videos usually up to 5 years.
  • Cookies: we currently do not use analytical or marketing cookies or embedded third-party elements; any necessary/technical cookies (e.g., session) are only used to ensure functionality. Therefore, we do not display a cookie banner. If we activate tracking or embedded content in the future, we will update the policy and website and request consent.
  • Your rights: access, correction, deletion, restriction, objection (especially to marketing), portability, withdrawal of consent, complaint to ÚOOÚ.
  • Contact: see below. We respond to requests without undue delay, at the latest within 30 days.

Bez předsudků z. s. • ID No: 193 89 086 • Headquarters: Zenklova 24/54, 180 00 Prague 8

e-mail for data protection: katerina.maleckova@bezpredsudku.cz / bezpredsudkuzs@gmail.com

Version: 2.0

Effective from: October 6, 2025

Scope: websites, online forms, newsletter, event and education registration, photos and videos from events, cooperation with partners/donors, personnel recruitment, grant projects and school activities including work with children (in connection with Child Protection Policy).

§ 1. Who We Are and How to Contact Us

Controller: Bez předsudků z. s., Zenklova 24/54, 180 00 Prague 8, ID No 193 89 086, file no. L 77758, Municipal Court in Prague.

E-mail (GDPR): katerina.maleckova@bezpredsudku.cz / bezpredsudkuzs@gmail.com

Mail: Bez předsudků z. s., Zenklova 24/54, 180 00 Prague 8.

Data Protection Officer: not appointed (not mandatory for our size). The contact person is the statutory representative.

§ 2. What Data We Process and Where We Get It

  • Identification and contact details: name, e-mail, phone, organization, billing details.
  • Event/registration data: event type, arrival/accommodation, preferred programs, special needs.
  • Transaction data: payment/variable symbol information, ticket type (payment cards are processed by payment gateway – we do not see card numbers).
  • Communication: e-mails, form responses, inquiries.
  • Visual recordings: photos and videos from events.
  • Technical data: IP address, HTTP headers, server logs, cookie identifiers (see Cookies chapter).
  • Project/grant data: project position, CV, signature samples (for partners), attendance sheets.
  • Recruitment data: CV, cover letter, references.
  • Children and legal guardians: only to the extent necessary for safety and participation (see Child Protection Policy and consents).

Sources: directly from you (forms, e-mail), from public sources (ID/organization), from partners (e.g., school), from generated logs and cookies.

3.1 Website operation and security (logs, necessary cookies)

  • Purpose: displaying the website, investigating incidents, security (firewall/antispam).
  • Legal basis: legitimate interest (IT security, website operation).
  • Recipients: web hosting WEDOS Internet, a.s. and other IT suppliers.
  • Retention: server logs max. 6 months, unless longer retention is necessary due to an incident.

3.2 Event registration / ticket sales

  • Purpose: accepting and managing registration, organizing the event, invoicing and record keeping.
  • Legal basis: performance of contract; explicit consent for special needs/diets.
  • Recipients: accounting/legal advisors, ticketing and payment gateway providers.
  • Retention: for the duration of the event and subsequently according to statutory periods (accounting/taxes – typically 5–10 years).

3.3 Newsletter and direct marketing

  • Purpose: sending news about projects and events.
  • Legal basis: consent (double opt-in) or legitimate interest for our existing service recipients; always with the option to unsubscribe.
  • Retention: until unsubscribe / withdrawal of consent; we keep the consent record for a reasonable period (usually 3 years from the last communication) to demonstrate compliance.

3.4 Photos and videos from events

  • Purpose: documenting and informing about our activities (website, social networks, annual report), project archiving.
  • Legal basis: for adults, legitimate interest (public information about the event) – we respect objections/opt-out and offer “no photography” zones; for children, consent of the legal guardian (see the template in the CPP), always revocable at any time.
  • Retention: normally up to 5 years or until withdrawal of consent (for children).
  • Note: in sensitive situations or for close-up portraits we also use consent for adults.

3.5 Grants, projects, donors and partners

  • Purpose: fulfilling grant rules and contracts (attendance sheets, outputs, audits), records of donations and donors.
  • Legal basis: performance of contract, legal obligation, legitimate interest (evidence of activity).
  • Recipients: grant agencies, auditors, accountants; we publish public outputs only to the extent necessary.
  • Retention: for the duration of the project and according to the provider’s archiving rules (typ. 5–10 years).

3.6 Inquiries and correspondence

  • Purpose: handling inquiries and requests.
  • Legal basis: legitimate interest / performance of contract.
  • Retention: usually 12 months from resolution, unless the law provides otherwise.

3.7 Personnel recruitment

  • Purpose: assessing candidates, conducting the selection procedure.
  • Legal basis: legitimate interest; retention for the future only with consent.
  • Retention: unsuccessful candidates 6 months (or up to 12 months subject to consent).

3.8 Legitimate interest in the protection of rights

  • Purpose: fraud prevention, asserting/defending legal claims, records of consents and objection procedures.
  • Legal basis: legitimate interest; you may raise an objection.
  • Retention: usually 3 years after the end of the main purpose or until the end of a dispute.
  • Purpose: accounting, taxes, mandatory reports and inspections.
  • Legal basis: legal obligation.
  • Retention: according to the relevant regulations (typically 5–10 years).

§ 4. Cookies and Online Identifiers

Current status: On our public pages we do not use analytical or marketing cookies and we do not load embedded third-party content (YouTube, maps, etc.). A necessary technical cookie (e.g., session/CSRF) may appear for the functionality of forms or administration – this is not tracking.

  • Consent banner: we do not display one, because we do not use optional cookie categories.
  • Future change: if we introduce measurement, marketing or embedded content, we will display a cookie banner before loading them and allow granular choices.

Note: Some third-party plugins/iframes may add their own cookies. We will load such elements only after consent has been granted and we will update this document.

§ 5. Recipients and Processors

  • IT and web hosting: WEDOS Internet, a.s.
  • E-mail/communication/storage: Google Ireland Limited (Gmail/Workspace), Microsoft.
  • Newsletter/mailings: depending on the project.
  • Accountants, lawyers and auditors: depending on the project.
  • Payment gateway/ticketing: depending on the project.
  • Public authorities and supervisory bodies: only where required by law.
  • Social networks (Facebook/Instagram/YouTube): separate controllers; processing takes place according to their own policies.

Relationships with processors are covered by a data processing agreement (DPA). We transfer only the necessary data.

§ 6. Transfers to Third Countries Outside the EU/EEA

We process data primarily within the EU/EEA. If a transfer outside the EU/EEA occurs (e.g., providers with servers outside the EEA), we use standard contractual clauses (SCC) and/or the transfer takes place on the basis of an adequacy decision; we assess the risks and adopt supplementary measures.

§ 7. Retention Periods (Retention Table)

AreaExample of dataLegal basisRetention period
Web logs and securityIP, URL, user-agentLegitimate interestmax. 6 months (longer only in case of an incident)
Event registration/ticketsname, e-mail, paymentContract, obligationduration of the event + 5–10 years by law
Newslettere-mail, preferencesConsent / legitimate interestuntil unsubscribe; consent record 3 years
Photos and videos (adults)visual recordingLegitimate interestup to 5 years or until objection
Photos and videos (children)visual recordingGuardian’s consentup to 5 years or until withdrawal
Inquiries/correspondencee-mails, formsLegitimate interest12 months from resolution
Grants/projectsattendance sheets, contractsContract/obligationduration of the project + 5–10 years
Personnel recruitmentCV, cover letterLegitimate interest6 months (up to 12 months with consent)
Protection of rightsrecords of consents, objectionsLegitimate interestusually 3 years after the main purpose
Child Protection (incidents)per CPPObligation/legitimate interest5 years from closure (see CPP)

§ 8. Security of Processing (TOMs)

We use appropriate technical and organizational measures: encryption and access control, two-factor authentication, access logging, team training, data minimization, pseudonymization of selected outputs, regular updates. We report security breaches in accordance with the GDPR.

§ 9. Your Rights and How to Exercise Them

  • Access to your data, correction, deletion, restriction of processing.
  • Objection to processing (especially to direct marketing – which we will stop based on objection).
  • Data portability (for consent/contract and automated processing).
  • Withdrawal of consent at any time, without affecting previous processing.
  • Complaint to supervisory authority: Office for Personal Data Protection, Pplk. Sochora 727/27, 170 00 Prague 7, www.uoou.cz.

How to request: write to us at the above e-mails with the subject “GDPR – exercise of rights”. We may ask for reasonable verification of identity. We will respond without undue delay, at the latest within 30 days.

§ 10. Automated Decision-Making and Profiling

We do not carry out automated individual decision-making with legal effects, nor profiling in that sense.

We run profiles on platforms (e.g., Facebook/Instagram/YouTube). These platforms are separate controllers. They are governed by their own privacy policies. We may include links to external websites – we are not responsible for their content or data processing.

§ 12. Relationship to Other Policies

This document builds on:

  • Child Protection Policy (CPP) – child protection and the related GDPR clause,
  • Gender Equality Plan (GEP),
  • Environmental Policy and Action Plan.

Where there is a conflict, the stricter rule applies in favour of the protection of individuals and children.

§ 13. Changes to the Document

We may update these principles (e.g., when tools or legislation change). We will always state the version and the effective date. We will communicate material changes in an appropriate way (website, e-mail to subscribers).

Bez předsudků z. s. • Zenklova 24/54, 180 00 Prague 8 • ID No 193 89 086

© 2025 Bez předsudků • This page: Personal Data Protection Policy (GDPR), version 2.0, effective from October 6, 2025.

Want a clear and unbiased answer?

Write to us through the contact form and we will get back to you.