Privacy policy
Last updated: 2026-05-27
This document explains how we (ITHOPE s.r.o., hereafter “we” or “the controller”) handle the personal data you send us through the form on the website, by email, or dictate over the phone. We try to put it in plain language — if anything is unclear, write to us and we’ll be glad to explain.
1. Who we are
ITHOPE s.r.o.
Reg. No.: 28309952, VAT ID: CZ28309952
Registered office: Viniční 3587/216, 615 00 Brno-Židenice
Website: www.servispc-brno.cz
Contact: info@servispc-brno.cz, 774 777 774
We do not have a Data Protection Officer (DPO) — our activity is not subject to the duty to appoint one. All matters are handled directly by the operator (Miroslav Jaroš).
2. What data we collect
It depends on how you contact us:
- The form at /en/objednavka/ — name, phone, email (optional), type of service, description of the problem, device brand, urgency and location of the job. In addition, the server records the IP address and browser headers (User-Agent) — this serves as spam protection and for forensic purposes.
- Email or phone directly — only what you tell us yourself (name, contact, description of the fault).
- During the service itself — the model and serial number of the device, and possibly the contents of the drive if we are dealing with data recovery. We do not look at the contents of drives beyond what is necessary for diagnostics; if we need access to personal files (for example when recovering after ransomware), we always agree it with you in advance.
3. Why we need it (purpose and legal basis)
| Purpose | Legal basis | Retention period |
|---|---|---|
| Handling your order / request (calling you back, arranging a slot) | Performance of a contract or pre-contractual steps (Art. 6(1)(b) GDPR) | 3 years from the last communication |
| Issuing and archiving invoices, tax documents | Compliance with a legal obligation (Accounting Act, VAT) | 10 years |
| Claims, dispute resolution, proving the scope of the work | Legitimate interest (Art. 6(1)(f) GDPR) | 3 years from the end of the service |
| Web form log (IP, time, content) — spam protection, audit | Legitimate interest | 6 months, then deleted |
4. Who we share your data with
As a rule, no one. We process your data ourselves and do not “lend” it to any third party for marketing.
There are only a few necessary exceptions:
- Hosting provider — the server on which this website runs and where the form logs are stored. The operation is provided by ITHOPE s.r.o. on its own infrastructure (HestiaCP, Czech Republic).
- Email provider — for forwarding info@servispc-brno.cz to a working mailbox (Google LLC, USA — Gmail). Google is subject to the Standard Contractual Clauses for transfers to third countries.
- DNS provider — WEDOS Internet a.s. (Czech Republic).
- Google Maps — the contact page (/en/kontakt/) embeds a Google map. When it loads, your browser contacts Google LLC (USA) servers, which may record your IP address and User-Agent. If you do not want to load the map, use the text link “Open in Google Maps” instead — it only opens after you click it.
- Accountant — an external accounting firm for issuing and archiving invoices. Contractually bound to confidentiality.
- Public authorities — only where we are required to by law (e.g. a police request backed by a ruling).
5. Cookies and analytics
This website stores no marketing or tracking cookies. We do not use Google Analytics, Facebook Pixel or similar tools that require cookie consent.
The server keeps standard server logs (IP address, time, URL, User-Agent) — this is necessary for operation and security. The logs are rotated and deleted after 30 days.
If we deploy an analytics tool in the future, it will be Plausible Analytics (privacy-friendly, no cookies, no cross-site tracking) — no banner will be needed. We will inform you of any change by updating this document.
6. Your rights
You have the full range of rights under the GDPR. Just write to info@servispc-brno.cz or call 774 777 774 and we will handle it free of charge within 30 days:
- Right of access — we tell you what data we hold about you.
- Right to rectification — when something is wrong, we fix it.
- Right to erasure (“the right to be forgotten”) — we delete it, unless accounting law prevents us or an active claim is ongoing.
- Right to restriction of processing — you can ask us to only keep the data but not actively work with it.
- Right to data portability — we send you your data in a machine-readable format (JSON / CSV).
- Right to object — against processing based on legitimate interest.
- Right to lodge a complaint — with the Office for Personal Data Protection (uoou.cz) if you feel we have done something wrong.
7. Security
The server runs on our own VPS with an up-to-date OS, a Let’s Encrypt TLS certificate and restricted SSH access (authorised keys only). Form data goes over HTTPS; on the server it sits in a log protected by file permissions (readable only by the web server and the operator).
When servicing devices, we work in a service centre with no public access. Drives with customer data are kept in a locked space and, once the service is finished, we return them to you together with the device. If we make a backup during the service (e.g. before a reinstall), we delete it within 14 days of handing over the completed job, unless we expressly agree otherwise.
8. Children
Our services are not aimed at persons under 16, and we do not knowingly process their personal data. If we find that we have processed a minor’s data without the consent of a legal guardian, we delete it.
9. Automated decision-making and profiling
We do not use your data for automated decision-making or profiling within the meaning of Art. 22 GDPR. Every request and every service job is handled by a specific person (the operator), not an algorithm. We tell you the price after a human diagnosis, not as a figure calculated automatically by a model.
10. Changes to this document
If we revise this policy, you will always find the new version at this URL with the current date at the top. For significant changes (for example deploying new analytics), we will publish a notice on the website’s home page for 14 days.
11. Contact for GDPR questions
info@servispc-brno.cz · 774 777 774
ITHOPE s.r.o., Viniční 3587/216, 615 00 Brno-Židenice
Plain-language version (TL;DR)
- We use your data only for the reason you contacted us.
- We don’t sell it to anyone or send it to advertising databases.
- We delete it when you ask us to (unless the law makes us keep it — typically invoices for 10 years).
- The site has no tracking cookies, so no “accept cookies” banner is needed.
- We handle questions and requests within 30 days, free of charge.