Skip to main content
privacy

Privacy policy

How Digital Grooove s.r.o. collects, uses, stores and deletes personal data, and the rights you have over it under Regulation (EU) 2016/679 (GDPR) and Act No. 110/2019 Coll.

the short version
  • We collect personal data in one place only: the enquiry form on the contact page. Nothing else on this site collects data about you.
  • We do not sell, rent or share personal data with anyone for their own purposes, and we do not profile you or make automated decisions about you.
  • No analytics or advertising cookie is set unless you choose to allow it. Today none exists at all.
  • Enquiry data is deleted automatically 24 months after your last contact with us.
  • You can ask us to show you, correct or delete your data at any time, and you can complain to the Czech data protection authority.

1. Who is responsible for your data

The controller is Digital Grooove s.r.o., Na hrázi 176/17, Libeň, 180 00 Praha 8, Czech Republic, IČO 10707336, DIČ CZ10707336, registered in the commercial register kept by the Municipal Court in Prague, C 346965.

For any question about this policy or about your data, write to info@digitalgrooove.com or telephone +420 728 136 493.

No Data Protection Officer is appointed. Article 37 GDPR does not require one for this company's processing, which is neither large-scale monitoring nor large-scale special-category processing. Data protection enquiries go to the contact address below.

2. What we collect, why, and on what legal basis

2.1 Enquiries sent through the contact form

When you send an enquiry we collect the company or organisation you represent, your name, your business email address, your telephone number, the division your enquiry concerns, and the message you write.

Purpose: to read your enquiry, reply to it, and — if it goes further — prepare a proposal and, where agreed, perform a contract.
Lawful basis: Article 6(1)(b) GDPR, steps taken at your request before entering into a contract. Every field on the form is required, because we ask only for what is needed to answer a business enquiry properly; we do not collect optional data under this basis.

If you additionally tick the optional box offering occasional updates about our services, we process your name and email address for that purpose on the basis of Article 6(1)(a) GDPR — your consent. That box is unticked by default, refusing it does not prevent you from sending an enquiry, and you can withdraw it at any time by writing to us, without affecting the lawfulness of anything done before you withdrew it.

2.2 Security and abuse prevention

When the form is submitted, our server records the time of submission and a cryptographic fingerprint of your IP address — a one-way HMAC computed with a secret key held on the server. The raw IP address is not written to the database. The fingerprint lets us rate-limit and detect automated abuse without holding the address itself.

Lawful basis: Article 6(1)(f) GDPR, our legitimate interest in keeping this website available and free from automated abuse. We consider this proportionate because the fingerprint cannot be reversed to an address, is not used to build any profile, and is deleted with the rest of the record.

2.3 Web server logs

Our web server writes standard access logs containing the requesting IP address, the time, the requested URL, the HTTP status, the referring page and the browser’s user-agent string. These are operational records used to keep the site running and to investigate faults and attacks. They are kept for 14 days and then rotated out.

Lawful basis: Article 6(1)(f) GDPR, legitimate interest in the security and availability of the service.

2.4 Cookies and similar technologies

Strictly necessary cookies are set on the basis of Section 89(3) of Act No. 127/2005 Coll., which exempts storage that is strictly necessary for providing a service the user has requested. Any analytics or advertising storage requires your prior consent under the same provision and Article 6(1)(a) GDPR. Everything this site can set is itemised in the cookie policy, and no non-essential storage exists at present.

2.5 What we do not do

  • We do not buy contact lists or contact you because you appear on one.
  • We do not sell, rent, or licence personal data to anybody.
  • We do not carry out profiling or automated decision-making within the meaning of Article 22 GDPR.
  • We do not knowingly collect data from children; this is a business website.
  • We do not ask for and do not want special categories of data (Article 9 GDPR). Please do not include health, religious, political or similar information in an enquiry.

3. Who else sees your data

Personal data submitted through this website is stored on a virtual private server rented from a commercial hosting provider, which acts as our processor under a written agreement meeting Article 28 GDPR and may access the data only on our instructions.

We may disclose data to a public authority where a legal obligation requires it, and to a professional adviser under a duty of confidentiality where we need advice on a matter your enquiry raises. No other recipient exists. In particular, enquiry data is never passed to any advertising network, data broker or analytics provider.

3.1 Transfers outside the EEA

We do not transfer enquiry data outside the European Economic Area for our own purposes. Where our hosting provider’s support operations could involve access from outside the EEA, that access is governed by the Article 28 agreement and by the European Commission’s standard contractual clauses. If this ever changes in substance, this policy will be updated before the change takes effect.

4. How long we keep it

DataRetention
Enquiry that does not become an engagement24 months from your last contact with us, then automatic deletion
Enquiry that becomes a contractFor the term of the contract and then as long as Czech accounting and tax law requires the underlying documents to be kept
Marketing consent record (if you gave one)Until you withdraw it, and then a record of the withdrawal itself
Submission fingerprint and timestampDeleted together with the enquiry record
Web server access logs14 days
Your cookie choice180 days, or until you change or clear it

The 24-month deletion is not merely a promise in this document — it is enforced by a scheduled job in the database itself, so it happens whether or not anyone remembers to run it.

5. Your rights

Under the GDPR you have the right to:

  • Access — obtain confirmation of whether we hold data about you and receive a copy of it (Article 15).
  • Rectification — have inaccurate data corrected and incomplete data completed (Article 16).
  • Erasure — have data deleted where one of the grounds in Article 17 applies.
  • Restriction — have processing limited while a dispute about accuracy or lawfulness is resolved (Article 18).
  • Portability — receive data you provided in a structured, machine-readable format (Article 20).
  • Objection — object to processing based on legitimate interests (Article 21).
  • Withdraw consent — where processing rests on consent, withdraw it at any time (Article 7(3)).

To exercise any of these, write to info@digitalgrooove.com. We answer within one month. We may need to confirm your identity first, so that we do not disclose your data to somebody else; we will ask for no more than is necessary to do so. Exercising these rights is free of charge.

6. Complaints

If you believe we have handled your data unlawfully, please tell us first so we can put it right. You also have the right to complain directly to the supervisory authority:

Úřad pro ochranu osobních údajů
Office for Personal Data Protection (ÚOOÚ)
Pplk. Sochora 27, 170 00 Praha 7, Czech Republic
Telephone: +420 234 665 111
https://uoou.gov.cz/

7. Security

The site is served over HTTPS only. Enquiry data is stored in a database that is not reachable from the public internet, and application credentials are held outside the web root and readable only by the application account. Submissions are protected against cross-site request forgery, are rate-limited, and are checked for automated submission patterns. Access to the stored data is limited to the people who need it in order to answer enquiries.

No system is perfectly secure. If you become aware of a vulnerability in this site, please report it to info@digitalgrooove.com rather than disclosing it publicly, and we will respond.

8. Changes to this policy

If this policy changes in a way that affects how your data is used, the revised version is published here with a new review date before the change takes effect, and where the change requires consent we ask for it again rather than assuming it.

Last reviewed: 31 August 2026.