Skip to content

Legal

Privacy Policy

Wording
Version 1
Effective from
Published

The Czech wording of this document is the binding one. This English translation is provided for understanding only.

1. Who processes your data

The controller of personal data is Dakl benefits, s.r.o., Company ID No. 19707118, with its registered office at Dolní náměstí 384, 250 70 Odolena Voda, registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, Insert 390447 (hereinafter referred to as “we” or the “Operator”), the operator of the DAKL Benefits platform at www.daklbenefits.cz (hereinafter referred to as the “Platform”).

In all matters concerning personal data protection, please contact us by e-mail at [email protected] or by letter sent to our registered office address. We have not appointed a data protection officer, as we are not required to do so by law.

These policies explain how, under Regulation (EU) 2016/679 (hereinafter referred to as the “GDPR”) and Act No. 110/2019 Coll., on the Processing of Personal Data, we handle the personal data of website visitors, representatives of our clients and partners, and Platform users.

2. When we are the controller and when we are the processor

The Platform serves companies (hereinafter referred to as the “Client”) which, through it, make available discounts and benefits of our partners (hereinafter referred to as the “Partner”) to their employees and contractors (hereinafter referred to as the “Employee”).

  • The Employee data entered into the Platform by the Client (name, work e-mail, personal number, group assignment) and data relating to the making available of Benefits are processed by us as the Client’s processor. In this respect, the controller is the Client (the employer); exercise your rights in relation to these data primarily with them. If you contact us, we will forward the request to the Client and assist with its handling.
  • In all other cases described below, we are an independent controller — this concerns in particular the operation and security of user accounts, prevention of misuse, statistics, payments, communication with clients and partners, marketing, and the website.

Further details for Employees can also be found in the document Information for Employees, which is displayed upon the first login to the application.

3. What data we process, why and for how long

3.1 Website visit

  • Data: IP address, browser and device type, pages visited, where you came from (including campaign parameters), language, data stored in cookies.
  • Purpose: website display, security and protection against attacks, aggregate traffic statistics; with your consent, measurement of traffic by Google Analytics and measurement and targeting of advertising by Google Ads.
  • Legal basis: legitimate interest in the operation and security of the website (Art. 6(1)(f) GDPR); for analytical and marketing cookies, consent (Art. 6(1)(a) GDPR and Section 89(3) of Act No. 127/2005 Coll.).
  • Retention period: our own statistics are stored without the IP address — instead, we retain only a one-way hash with a daily changing salt, for 24 months; afterwards, only aggregate figures remain. The retention periods for cookies are set out in the Cookie Policy.

3.2 Inquiry and contact form

  • Data: name, e-mail, telephone number, company and message content; optionally, the code of the sales representative through whose referral you came.
  • Purpose: responding to the inquiry, preparing an offer, and assigning the inquiry to a sales representative.
  • Legal basis: negotiations for the conclusion of a contract (Art. 6(1)(b) GDPR), otherwise legitimate interest in handling the inquiry.
  • Retention period: for the duration of the negotiations and thereafter for 3 years from the last contact, unless a contractual relationship is established.

3.3 Company registration and Client administrator account

  • Data: company identification data (name, Company ID No., tax ID No., registered office — we verify it in the ARES register), first name, surname, e-mail and telephone number of the administrator, password (stored only in irreversibly encrypted form), language, optionally connection with a Google or Microsoft account, two-factor authentication settings.
  • Purpose: conclusion and performance of the contract, management of the Client account, communication regarding the service.
  • Legal basis: performance of the contract with the Client (Art. 6(1)(b) GDPR); with respect to the administrator, the legitimate interest of the Client and ours that the account is managed by an authorized person (Art. 6(1)(f) GDPR).
  • Retention period: for the duration of the contract; afterwards, we anonymize the person’s data, except for data that we must retain under points 3.4 and 3.8.

3.4 Subscription, payments and invoicing

  • Data: billing details of the company, billing e-mail, selected tariff, subscription history, invoices and payments. Payment card details are entered directly into the Stripe payment gateway — we never see or store them; from Stripe we receive only information about the payment result and the payment method used.
  • Purpose: billing of the subscription, debt recovery, fulfilment of accounting and tax obligations.
  • Legal basis: performance of the contract and compliance with legal obligations (Art. 6(1)(b) and (c) GDPR).
  • Retention period: accounting and tax documents for 10 years from the end of the year in which they arose (Act No. 563/1991 Coll., on Accounting, and Act No. 235/2004 Coll., on VAT); technical records of payment events for 12 months.

3.5 Employee account and use of the application

  • Data: first name and surname, e-mail, personal number (if entered by the Client), company and groups, account status, language, password (encrypted), login via Google or Microsoft, usage records — display of Benefits, issuance and verification of Coupons, clicks through to Partners’ websites.
  • Purpose: in the role of processor, making Benefits available according to the Client’s instructions (see point 2); as an independent controller, operation and security of the account, verification of the validity of Coupons, prevention of misuse, aggregate statistics for Partners and Clients, settlement with Partners, and service improvement.
  • Legal basis: legitimate interest in the secure and functional operation of the Platform and in evaluating its usability (Art. 6(1)(f) GDPR).
  • To whom we disclose the data: the Client sees a list of its Employees and the status of their accounts, but receives only aggregate overviews of Benefit usage, not data about individuals. The Partner, when verifying a Coupon, sees your name (if entered by the Client), the name of the Client and Benefit data; otherwise, it receives only aggregate statistics.
  • Retention period: account data for the duration of membership with the Client and the term of the contract with the Client, at the latest until 90 days after its termination, when we anonymize them; detailed usage records for 24 months, then only aggregate figures without linkage to a person.

3.6 Security and activity records

  • Data: IP address and browser data at login, login and session records, records of changes made to the account (who changed what and when), records of e-mails sent and their delivery.
  • Purpose: protection of accounts and the Platform, detection and investigation of misuse, evidence of performed actions, protection of legal claims.
  • Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
  • Retention period: logins and sessions for 7 days after their expiration; records of e-mails sent for 12 months; records of changes in accounts for 10 years (in change records, we do not store the IP address, only its one-way hash).

3.7 Document consents and marketing

  • Data: which document and which version of it you confirmed, when, from which IP address and browser; granting and withdrawal of consent to marketing communications.
  • Purpose: evidence that you were familiar with the terms and that consent was granted; sending commercial communications to Client administrators.
  • Legal basis: legitimate interest in proving consent and compliance with a legal obligation (Art. 7(1) GDPR); for marketing, consent (Art. 6(1)(a) GDPR), and for existing clients also Section 7(3) of Act No. 480/2004 Coll.
  • Retention period: record of consent for the duration of the account and thereafter for 10 years; marketing until consent is withdrawn. You may withdraw consent to marketing at any time in account settings, via the link in each commercial e-mail, or by e-mail to our address.

3.8 Partners and sales representatives

  • Data: first name, e-mail and telephone number of the Partner’s contact persons, billing details, invoices; for sales representatives, identification and billing data, overview of acquired clients and commissions.
  • Purpose: conclusion and performance of the contract, publication of the Partner on the Platform, billing.
  • Legal basis: performance of the contract and legal obligations, and with respect to contact persons legitimate interest (Art. 6(1)(b), (c) and (f) GDPR).
  • Retention period: for the duration of the cooperation; accounting documents for 10 years.

3.9 Exercise of rights and protection of claims

Data necessary for the determination, exercise or defence of our legal claims may be retained for the duration of the limitation period and the duration of any dispute (Art. 6(1)(f) GDPR).

4. To whom we disclose the data

We do not sell personal data. We disclose it only to the extent necessary to the following recipients:

  • the Client — to the extent described in point 3.5;
  • Partners — when verifying a Coupon (point 3.5) and aggregate statistics;
  • sales representatives of the Operator — contact and business data of Clients and Partners that they have obtained or manage;
  • processors who ensure the operation of the Platform for us: Railway Corporation (hosting of the application and database, data center in the Netherlands), Cloudflare, Inc. (file storage in the EU, content delivery, protection of forms against bots), Plus Five Five, Inc. — Resend (sending e-mails), OpenAI (machine translation of Partner and Benefit texts — we do not transfer Employee or Client data to it), IT support providers, accounting and tax advisors and attorneys bound by confidentiality;
  • independent controllers: Stripe Payments Europe, Ltd. (payment gateway), Google Ireland Limited (Google Analytics, Google Ads and login with a Google account — only if you have consented to cookies, respectively selected login via Google), Microsoft Ireland Operations Limited (login with a Microsoft account, if you choose it);
  • public authorities, if required by law.

5. Transfers outside the European Union

Platform data are stored in data centers within the European Union. Some of our suppliers are based in the USA and may have access to the data. In such case, the transfer is based on the European Commission’s adequacy decision (EU-US Data Privacy Framework), under which the recipient is certified, or on the standard contractual clauses approved by the European Commission.

6. Cookies

We use necessary cookies at all times, and analytical and marketing cookies only with your consent. Details and the option to change your consent can be found in the document Cookie Policy.

7. Automated decision-making

We do not carry out automated decision-making or profiling that would have legal effects for you or similarly significantly affect you. With your consent, Google Ads may use data from cookies to display more relevant advertising.

8. Your rights

You have the right:

  • to access your personal data and obtain a copy thereof;
  • to rectification of inaccurate data;
  • to erasure, if the data are no longer needed, you withdraw consent or raise a justified objection;
  • to restriction of processing;
  • to data portability of the data you have provided to us and which we process on the basis of a contract or consent;
  • to object to processing based on legitimate interest — to processing for direct marketing at any time and without stating a reason;
  • to withdraw consent at any time; withdrawal does not affect the lawfulness of processing prior to withdrawal;
  • to lodge a complaint with the Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, www.uoou.gov.cz.

Please send the request to us by e-mail at [email protected]. We will handle it without undue delay, at the latest within one month; in complex cases, we may extend the period by a further two months and will let you know. Before handling, we may verify your identity. If the request concerns data that we process as the Client’s processor, we will forward it to the Client.

9. Security

Communication with the Platform is encrypted, passwords are stored only in irreversibly encrypted form, access to data is governed by roles, accounts with extended permissions are protected by two-factor authentication, data are regularly backed up, and we keep records of changes. Only persons who need the data to perform their tasks and are bound by confidentiality have access to the data.

10. Changes to the policies

We may update these policies, in particular if the Platform or legal regulations change. The current and previous wording can be found on this page; we inform users of material changes by e-mail or in the application.

Archive

Wording history

Every published wording stays available exactly as it was issued. Open the one that applied when you accepted the document.

  1. Version 1Current wording

    Effective from · Published