Privacy Policy

Last updated: 2026-04-02

Effective from: 2026-04-02

We update this document from time to time. The version published on this page is the version currently in effect, unless mandatory law requires otherwise.

Czechs Online respects your privacy and processes personal data in a transparent, proportionate and lawful manner. This Privacy Policy explains what data we collect, why we process it, on what legal basis, how long we keep it, with whom we share it, and what rights you may exercise.

1. Who we are

Czechs Online is operated by KRITEK, s.r.o., registered office Čejkovy 23, 342 01 Hrádek, Czech Republic, Company ID 29108071, VAT ID CZ29108071.

For the purposes of applicable data protection law, KRITEK, s.r.o. acts as the data controller unless this policy states otherwise for a specific processing flow.

General contact: email
Privacy contact: email

2. Scope

This Privacy Policy applies to the website, related browser-based services, and any progressive web app (PWA) features made available through the website.

It applies to users worldwide. Where mandatory local law grants stronger rights, those rights prevail.

3. Categories of personal data we may process

  • account data, such as name, email address, username, password hash and date of birth
  • profile data, such as public profile details, avatar, bio, preferences and language settings
  • community content, such as posts, comments, messages sent through platform features, forum activity and uploads
  • operational content metadata, such as records relating to platform-managed AI-assisted or AI-generated forum seeding content, prompts, scheduling, and related moderation or quality-control notes
  • editorial workflow metadata, such as records relating to AI-assisted drafting, AI-assisted translations, AI-generated or AI-assisted images, internal prompts, review history, and editorial revisions made by or for Czechs Online
  • transactional data, such as plan selection, order reference, payment status, invoice metadata and anti-fraud signals
  • technical data, such as IP address, browser type, device information, operating system, session identifiers and log data
  • communication data, such as support requests, newsletter preferences and feedback
  • safety and enforcement data, such as moderation history, abuse reports, account restriction logs and investigation notes

We do not intentionally collect more data than is reasonably necessary for the relevant purpose.

4. Why we process personal data

  • to create and manage user accounts
  • to provide community, editorial and premium features
  • to operate the forum, comments, directory, newsletter and notifications
  • to seed and keep the forum active through platform-managed AI-assisted or AI-generated discussion starters, replies, or thematic prompts intended to surface potentially interesting topics
  • to support editorial production through AI-assisted drafting, editing, translation, research support, or the use of AI-generated or AI-assisted images, subject to human review, revision, and publication control by Czechs Online
  • to process subscriptions, purchases, billing-related events and account entitlements
  • to communicate with users about service, support, policy, security or account matters
  • to secure the platform, prevent fraud, investigate abuse and enforce our rules
  • to apply age-based access controls, enforce our minimum age rules, and apply age-appropriate protections where relevant
  • to maintain logs, backups, audits and operational records
  • to comply with legal, tax, accounting and regulatory obligations
  • to improve service quality, performance and reliability
  • to measure audience and usage where permitted by law and consent settings

5. Legal bases for users in the EU/EEA/UK

  • performance of a contract: when processing is necessary to provide your account, premium access, support or requested services
  • legal obligation: when we must retain or disclose data for tax, accounting, anti-fraud, consumer, law enforcement or other statutory reasons
  • legitimate interests: for service security, fraud prevention, abuse handling, platform integrity, operational diagnostics, and limited business administration, provided these interests are not overridden by your rights
  • consent: where consent is required, especially for non-essential cookies, optional marketing communications, or similar processing under applicable law

Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

6. Privacy rights for users in other jurisdictions

Depending on your location, local law grants additional rights relating to access, correction, deletion, portability, objection, opt-out, or restriction of certain processing.

7. Public content and visibility

Some information you choose to publish in community areas may be visible to other users or to the public, depending on the feature design and your settings. Please avoid posting personal data that you do not want to be public.

Even if content is later removed from public view, we may retain copies where necessary for backups, legal compliance, dispute handling, safety investigations or enforcement records.

Czechs Online may also publish editorial or informational content, including blog posts, article illustrations, thumbnails, or other media, that has been created in whole or in part with AI assistance. This may include AI-assisted text drafting, editing or translation support, and in some cases AI-generated or AI-assisted images. Unless explicitly stated otherwise for a specific item, such content is used as editorial support rather than as a fully autonomous publishing process and is subject to human review, revision, selection, correction, or adaptation by Czechs Online before or during publication.

8. Payments and billing-related data

Czechs Online uses different payment flows depending on customer type and product flow.

For B2C purchases, checkout is handled through Lemon Squeezy, which acts as Merchant of Record. For B2B purchases, checkout is processed through Stripe or another designated provider under the applicable commercial flow.

We do not intentionally store full payment card details on our own systems unless explicitly stated otherwise. Payment processors may process transaction data under their own legal terms and privacy notices.

9. Cookies and similar technologies

We use cookies and similar technologies for authentication, security, preferences, performance, consent records and, where allowed, analytics and embedded content.

For detailed information, see our Cookie Policy.

10. Sharing of personal data

  • hosting and infrastructure providers
  • payment providers and billing-related partners
  • email delivery and notification providers
  • analytics or consent-management providers, where permitted
  • moderation, security, anti-spam and abuse-prevention providers
  • professional advisers, auditors or insurers where required
  • public authorities, regulators, courts or law enforcement when legally required or justified

We do not state that we sell personal data unless that classification is required by applicable law. If local law requires a specific disclosure or opt-out mechanism, we will provide it accordingly.

11. International transfers

Because the platform uses infrastructure and service providers that process data outside your country, personal data is transferred internationally.

Where EU/EEA/UK transfer rules apply, we use appropriate safeguards where required, such as contractual protections, transfer impact review, vendor due diligence and, where relevant, Standard Contractual Clauses.

12. Data retention

  • account data: for the lifetime of the account and a limited follow-up period where justified
  • support communications: as needed for support history and dispute handling
  • transactional and invoice-related records: as required by tax or accounting law
  • moderation and security records: as needed for safety, abuse prevention and legal defence
  • technical logs: for a limited period appropriate to security and operational needs
  • consent records: for as long as necessary to demonstrate compliance

Where deletion is requested, we may retain restricted records if law or legitimate defence needs require it.

13. Security

We use proportionate technical and organisational measures intended to protect personal data against unauthorised access, accidental loss, unlawful destruction, misuse or disclosure. These measures may include role-based access control, logging, encrypted transmission where available, backups, vendor controls and internal process restrictions.

No system can be guaranteed absolutely secure, but we work to reduce risk to a reasonable level.

14. Children and minors

Czechs Online does not knowingly allow users under the age of 16 to create accounts or use account-based community features. We process date-of-birth information for the purpose of applying age-based access rules, enforcing our minimum age requirement, and applying age-appropriate protections where relevant.

If we learn that a user under 16 has created an account, we may suspend the account and delete or anonymise the related personal data unless retention is required by law. A parent or legal guardian who believes that a child under 16 has created an account may contact us to request review, restriction, or deletion. Users aged 16 and 17 may be subject to additional privacy and safety protections. In practical terms, those protections may include reduced profile visibility, hidden direct-contact details, disabled map visibility by default, restricted discoverability, and limits on certain direct-contact features.

15. Profiling and automated decisions

We use limited automated checks for spam detection, fraud prevention, abuse signals, entitlement validation, and technical risk scoring. We do not state that we make legally significant decisions solely by automated means unless that is specifically implemented and disclosed.

Where required by law, users may request human review of significant automated outcomes.

16. Your rights

  • access your personal data
  • correct inaccurate data
  • delete data in certain situations
  • restrict processing in certain situations
  • object to certain processing
  • receive portability where applicable
  • withdraw consent where processing is based on consent
  • lodge a complaint with the competent supervisory authority, including the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, UOOÚ) for Czech-based operations

To exercise rights, contact email.

17. Complaints and supervisory authorities

We encourage users to contact us first so we can try to resolve concerns quickly. Where applicable law allows, you may also lodge a complaint with the competent data protection authority. For Czech-based operations, this is the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, UOOÚ): https://www.uoou.gov.cz.

18. Changes to this policy

We may update this Privacy Policy from time to time. Material updates should be reflected by changing the Last updated date and, where appropriate, by additional notice.