Effective date: 13 December 2024. This is an English translation of the Czech privacy information.
1. Controller
The controller is Moje srdce s.r.o., Company ID 10688099, Oblouková 848/25, 101 00 Prague 10, Czech Republic. Contact: podpora@mojesrdce.cz.
2. Sources of personal data
We process information you provide when using the Application and, where justified, information from public registers. If you knowingly connect a third-party service, we may receive data through that service. We do not collect data from connected third parties without your knowledge.
3. Data we process
Depending on how you use the service, this may include name, address, email, telephone number, sex, age, health information, questions submitted to the online advisory service, location, MAC address, browser IP address, operating system and information about use of the Application.
4. Purposes and legal bases
Performance of a contract
We process necessary identification and contact data to register you, operate the Application and provide requested features under Article 6(1)(b) GDPR. Data is normally retained for the contractual relationship and, where necessary for legal claims, no longer than the applicable limitation period of ten years.
Legitimate interests
We may process contact and usage information to maintain and improve the Application, provide support, protect legal interests and display relevant offers. This processing is based on legitimate interests, subject to your rights and freedoms, and will not continue for more than three years for these purposes.
Consent
Where you give consent, we may process data for personalised health recommendations, contact with a consulting doctor and newsletters. Consent may be withdrawn at any time. Data based solely on consent is processed until withdrawal and no longer than the stated one- or three-year period. Special-category health data receives additional safeguards.
5. Recipients and transfers
Authorised staff and carefully selected processors may access data where necessary. These may include technical hosting providers, electronic-communications providers, analytics providers, payment processors and debt-recovery providers. We do not intend to transfer personal data outside the EU; if such a transfer becomes necessary, it will use legally required safeguards and affected users will be informed.
6. Your rights
You may request information and access, explanation, correction, erasure, restriction, portability, or object to processing. You may also complain to the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7. Requests can be sent using the contact details above.
7. Security
Processing is performed by authorised and confidentiality-bound personnel, electronically or on paper, using appropriate safeguards. Data transfers are encrypted and security processes monitor potential breaches. If safeguards are compromised, we act promptly to minimise the effect and comply with notification duties.
8. Changes
We may update this policy to reflect legal and regulatory developments. We recommend reviewing it periodically. Questions or withdrawal of consent can be addressed to the controller or through the Application’s contact form.
