Skip to content

Privacy Policy

under Regulation (EU) 2016/679 (GDPR) and Act No. 110/2019 Coll.

This Policy explains what personal data we process, why, for how long, and what rights you have. It also explains when we act as controller and when only as a processor for our customers.

Version 2.0 · Last updated: 31 August 2026

1. Data controller

The controller is Vít Kilián, Company ID (IČO) 21125511, registered office at Na Vršku 230/14, 321 00 Plzeň – Litice, Czech Republic, registered in the Czech Trade Licensing Register maintained by the Plzeň City Hall. Data protection contact: gdpr@kilivi-dev.cz, phone +420 733 299 038. No Data Protection Officer has been appointed, as the conditions of Art. 37(1) GDPR are not met. Data protection matters are handled directly at the address above.

2. Two roles: when we are controller and when processor

Two distinct situations apply and it matters which one concerns you. • If you are our customer (a restaurant, salon or clinic operator), we are the controller of your data and this Policy applies. • If you are a guest who booked a slot with one of our customers, that venue is the controller of your data. We act only as a processor operating the system on its behalf. Please exercise your rights with the venue; if you contact us, we will forward your request without delay. This processing is governed by the Data Processing Agreement.

3. Data we process

Customer data: name, email, phone, venue name and address, company and VAT number, billing details, payment history, login credentials. Operational data: IP address, browser type, login and audit logs, application error reports. Guest data (in our processor role): name, email, phone, reservation date and time, party size, reservation note.

4. Special categories of data (Art. 9 GDPR)

The system is not intended for processing health data and we do not actively request it from guests. The free-text "reservation note" may be filled in by a guest with information amounting to health data, such as an allergy or dietary restriction. The field therefore carries a notice asking guests not to enter health information. Where a venue does need to process such data, it is responsible as controller for obtaining the guest's explicit consent under Art. 9(2)(a) GDPR. The Provider merely stores such data on the controller's instruction and uses it for no purpose of its own.

5. Purposes and legal bases

• Providing the Service, account and subscription management — performance of a contract, Art. 6(1)(b) GDPR. • Invoicing and accounting — legal obligation, Art. 6(1)(c) GDPR. • Security, abuse and fraud prevention, error monitoring — legitimate interest, Art. 6(1)(f) GDPR. Our interest is safe and functional operation; you may object to this processing. • Website analytics and marketing communication — consent, Art. 6(1)(a) GDPR. • Sending commercial communications about similar services to existing customers — legitimate interest under § 7(3) of Act No. 480/2004 Coll., always with an unsubscribe option in every message. • Establishing and defending legal claims — legitimate interest, Art. 6(1)(f) GDPR.

6. Retention periods

• Invoicing and accounting records — 10 years from the end of the tax period (Accounting Act, VAT Act). • Customer account data — for the duration of the subscription plus 30 days, during which data export is possible; then deleted or anonymised. • Guest reservation data — for as long as instructed by the controller, at most for the duration of its subscription plus 30 days. • Login and audit logs — 90 days. • Data processed on the basis of consent — until consent is withdrawn. • Data needed to defend legal claims — for the duration of the limitation period.

7. Recipients and processors

We do not disclose personal data to third parties for their own purposes. We use the following processors: • Stripe Payments Europe, Ltd. / Stripe, Inc. — payment gateway, invoicing (Ireland / USA, standard contractual clauses) • SmsManager.cz (Quanda International s.r.o.) — sending SMS reminders (Czech Republic) • Railway Corp. — application and database hosting (EU (eu-west region) / USA, standard contractual clauses) • Google Ireland Ltd. (reCAPTCHA) — bot protection for forms (Ireland / USA, standard contractual clauses) • Cloudinary Ltd. — image storage and delivery (EU / USA, standard contractual clauses) • Functional Software, Inc. (Sentry) — application error monitoring (USA, standard contractual clauses) Data may also be disclosed to our accountant, legal counsel or a public authority where required by law. The current list of processors is maintained in this document; customers are notified of changes at least 30 days in advance.

8. Transfers outside the EU/EEA

Some processors are established in, or run infrastructure in, the United States. Transfers are safeguarded by the European Commission's standard contractual clauses under Art. 46(2)(c) GDPR, supplemented by a transfer impact assessment. A copy of the safeguards used is available on request at gdpr@kilivi-dev.cz.

9. Security

We have implemented the following technical and organisational measures: • encryption in transit (TLS 1.2+) and encryption at rest, • least-privilege access control and multi-factor authentication for administrator accounts, • separation of customer data (multi-tenant isolation), • regular backups with restore verification, • audit logs of access and changes, • regular dependency updates and vulnerability monitoring, • contractual confidentiality obligations for everyone with access to data.

10. Automated decision-making and profiling

We do not carry out automated decision-making or profiling producing legal effects for data subjects within the meaning of Art. 22 GDPR.

11. Cookies

Details of cookies, their categories and lifetimes are set out in our separate Cookie Policy. Consent to optional cookies can be changed at any time using the "Cookie settings" button in the website footer.

12. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability, the right to object to processing based on legitimate interest, and the right to withdraw consent at any time; withdrawal does not affect the lawfulness of prior processing. Send requests to gdpr@kilivi-dev.cz. We respond without undue delay and within one month; in complex cases this may be extended by a further two months, of which you will be informed. We may ask for additional information to verify your identity. No fee is charged, except for manifestly unfounded or repetitive requests.

13. Right to lodge a complaint

If you believe our processing infringes data protection law, you may lodge a complaint with the supervisory authority: Office for Personal Data Protection (ÚOOÚ), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, www.uoou.gov.cz.

14. Changes to this Policy

We may update this Policy. Material changes are notified to customers by email at least 30 days in advance; other changes are published on this page with the effective date. Current version: 2.0.