Back to homepage

Privacy Policy

TAK HostCheck · TakHostCheck.com · effective 1 January 2026

1. Data Controller

The data controller for user data is:

Tomáš Bartusek · Za Zahradama 69, 251 01 Herink, Czech Republic · Business ID: 23578106 · info@itakk.cz

2. Roles in Data Processing

2.1 With respect to user personal data, the Operator acts as the data controller.

2.2 With respect to guest data entered in the application, the User acts as the controller and the Operator acts as the data processor under Art. 28 GDPR.

2.3 The terms of guest data processing are governed by a separate Data Processing Agreement (DPA).

3. Data Processed

A) User data

The Operator processes in particular: name, email address, billing details, subscription information, IP address, technical logs (login times, access logs, security logs), and customer support communications.

B) Guest data (entered by the User)

This may include: name, date of birth, nationality, travel document number, home address, check-in and check-out dates.

The Operator does not store photographs of identity documents.

4. Purpose and Legal Basis

Personal data is processed for: providing the TAK HostCheck service, managing user accounts, processing payments and invoicing, fulfilling legal obligations, protecting the Operator's rights and legitimate interests, and ensuring system security.

Legal basis: performance of a contract (Art. 6(1)(b) GDPR), legal obligation (Art. 6(1)(c) GDPR), legitimate interests (Art. 6(1)(f) GDPR).

5. Automated Decision-Making

The Service does not carry out automated decision-making or profiling within the meaning of Art. 22 GDPR.

6. Retention Periods

6.1 User data is retained for the duration of the contractual relationship and subsequently as required by law.

6.2 Guest data is retained according to the User's instructions for the duration of the service.

6.3 Upon termination, data is retained for a maximum of 30 days for export purposes and then permanently deleted, unless there is a legal requirement for longer retention.

7. Recipients

The Operator may use sub-contractors, particularly providers of cloud infrastructure, database services, payment systems (e.g. Stripe), and accounting and technical services. Data is processed primarily within the EU/EEA or in compliance with GDPR.

8. Third-Country Transfers

Where data is transferred outside the EU/EEA, this is done solely in compliance with GDPR requirements, in particular on the basis of standard contractual clauses or an adequacy decision.

9. Security

The Operator has implemented appropriate technical and organisational measures, including: encrypted data transmission (HTTPS/TLS), access control, user authentication, audit logging, secure cloud environment, and regular system updates.

10. Data Subject Rights

Data subjects have the right to: access their data, rectification, erasure, restriction of processing, object to processing, data portability, and to lodge a complaint with a supervisory authority.

Requests may be sent to: info@itakk.cz

11. Supervisory Authority

Data subjects have the right to lodge a complaint with the supervisory authority:

Office for Personal Data Protection (ÚOOÚ) · Pplk. Sochora 27, 170 00 Prague 7 · www.uoou.cz

12. Changes to This Policy

The Operator may amend this policy proportionately. Users will be notified via the website or application.

Tomáš Bartusek · Za Zahradama 69, 251 01 Herink · IČ: 23578106 · info@itakk.cz