Privacy
Privacy Policy
Effective from: 1 June 2026
This policy describes how we handle personal data in connection with the operation of the Eazo service - a booking widget available on the eazo.eu website and related domains. Processing takes place in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the “GDPR”) and Czech Act No. 110/2019 Coll., on the Processing of Personal Data.
1. Controller
The controller of personal data is the operator of the service:
- Radek Hřebeček
- Registered office: Jirečkova 1017/18, Praha 7 - Holešovice, 170 00, Česká republika
- Company ID (IČO): 04557824, VAT ID (DIČ): CZ9106050756
- E-mail: [email protected]
- Data box (datová schránka): iyxbwt7
The operator has not appointed a data protection officer. In all matters relating to the processing of personal data and the exercise of your rights, you can contact us at the e-mail address above.
2. Our two roles: controller and processor
For the Eazo service, we distinguish two roles depending on whose data we process and for what purpose:
We are the controller
Towards visitors to the eazo.eu website and towards our customers (businesses that create an account with us), we act as the controller. We determine the purpose and means of processing ourselves - for example when registering an account, invoicing or handling an enquiry from the contact form.
We are the processor
When an end customer fills in a booking through the widget embedded on our customer’s website, their personal data is processed for that customer. For this data, the controller is our customer (the website operator) and Eazo acts as a processor that processes the data only on the customer’s instructions and on the basis of a data processing agreement. Information about processing in this case is provided by the respective business in its own policy.
3. What data we process and why
3.1 Website visitors
| Data | Purpose | Legal basis |
|---|---|---|
| IP address, technical and log data, session identifier | Operation, security and protection of the website against misuse | Legitimate interest (Art. 6(1)(f) GDPR) |
| Data from essential cookies | Providing basic website functionality | Legitimate interest |
3.2 Contact form
| Data | Purpose | Legal basis |
|---|---|---|
| Name, e-mail, subject and content of the message | Handling your enquiry and communicating with you | Consent, or steps taken prior to entering into a contract (Art. 6(1)(a) and (b) GDPR) |
3.3 Registered customers (businesses)
| Data | Purpose | Legal basis |
|---|---|---|
| Name, e-mail, password (in encrypted form), account and service settings | Creating and managing the user account and providing the service | Performance of a contract (Art. 6(1)(b) GDPR) |
| Billing details (name/company, address, company ID, VAT ID), payment and subscription data | Issuing tax documents and keeping accounts | Compliance with a legal obligation (Art. 6(1)(c) GDPR) |
| E-mail address | Service and operational messages about the account | Legitimate interest / performance of a contract |
3.4 End customers making a booking
Data filled in the booking widget (usually name, e-mail, phone and a note to the booking) is processed by us as a processor on behalf of the respective business - see section 2. The purpose is to arrange and record the booking and to send a confirmation.
3.5 Connection with Google Calendar or Microsoft Outlook (optional feature)
If a customer voluntarily connects their Google or Microsoft account in the administration (a feature available in the Pro and Business plans), we request the following permissions through the respective provider’s sign-in:
- Google: reading, creating and editing events in Google Calendar and the e-mail address of the connected account (to display it in the administration and to verify that it is still the same account).
-
Microsoft: reading, creating and editing events in the Outlook calendar (permission
Calendars.ReadWrite) and basic profile information of the connected account (permissionUser.Read), including the persistent access needed to renew the sign-in in the background (offline_access).
We use this data solely to:
- check existing events in the calendar and prevent scheduling conflicts,
- create an event in the calendar corresponding to a confirmed booking,
- automatically generate a Google Meet or Microsoft Teams link for this event for online services.
We do not share data from the connected calendar with any other third party, we do not use it for advertising or profiling, and we do not read anything from the account beyond the scope above. We keep it only for the duration of the connection; after it is removed, we no longer work with it. The use and transfer of information received through Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements; information received through the Microsoft Graph API is processed in accordance with the Microsoft Products and Services Data Protection Addendum. The customer can remove the connection at any time with one click in the administration, or directly in their account’s permission settings - for Google at myaccount.google.com/permissions, for Microsoft at myaccount.microsoft.com.
4. Retention period
- Account data is kept for the duration of the account and then for the period necessary to settle mutual rights and obligations.
- Data from a connected Google or Microsoft calendar is kept only while the connection is active; after it is removed, it is no longer processed.
- Accounting and tax documents are kept for the period required by law (usually 10 years).
- Messages from the contact form are kept for the period necessary to handle the enquiry, at most 2 years.
- Logs and technical data are kept for a limited period necessary for operation and security (usually at most 12 months).
- Booking data processed as a processor is kept according to the instructions and period set by the respective business.
5. Recipients and processors
We do not sell personal data. To operate the service, we use vetted providers who process data for us on the basis of a data processing agreement, in particular in these categories:
- server and hosting infrastructure providers,
- e-mail (transactional) service providers,
- payment and billing service providers,
- providers of operational monitoring and support tools,
- Google (Google Ireland Limited) and Microsoft (Microsoft Ireland Operations Limited) - only for customers who voluntarily connect their Google or Microsoft calendar, see section 3.5.
We may also disclose data to public authorities where required by law.
6. Transfers to third countries
We primarily process data within the European Union / European Economic Area. Should data be transferred outside the EU/EEA in a specific case, we will ensure appropriate safeguards under the GDPR (in particular the standard contractual clauses approved by the European Commission).
7. Cookies
On the website, we use essential (technical) cookies needed for its basic functioning and security, for example to keep the session and protect forms. These cookies do not require consent. Optional cookies for analytics or marketing are used only with your consent, which you can withdraw at any time in your browser settings.
8. Your rights
In connection with the processing of personal data, you have in particular the right to:
- access your personal data and obtain a copy of it,
- rectification of inaccurate or incomplete data,
- erasure (“right to be forgotten”) under the conditions set by the GDPR,
- restriction of processing,
- data portability,
- object to processing based on legitimate interest,
- withdraw consent where processing is based on consent, without affecting the lawfulness of prior processing,
- lodge a complaint with a supervisory authority.
You can exercise your rights by e-mail at [email protected]. If you are an end customer who made a booking, please first contact the operator of the website where you filled in the booking (the controller of your data); as a processor, we will provide them with the necessary cooperation.
9. Security
We have adopted appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS), storing passwords as unreadable hashes, access control and isolating the widget from other systems. Data is stored on secure servers in the EU and regularly backed up automatically to prevent its loss or damage.
10. Supervisory authority
If you believe that the processing of your personal data has breached the law, you have the right to lodge a complaint with the supervisory authority, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, www.uoou.cz.
11. Changes to this policy
We may update this policy from time to time. The current version is always available on this page with its effective date. We will inform registered users of material changes in an appropriate way.
This policy is drawn up in Czech and English. In the event of any discrepancy, the Czech version prevails.