Privacy Policy

and sending of marketing communications

Effective from: 1 October 2026

The Czech version of this document is legally binding. The English and Slovak versions are informative translations only.

The protection of personal data of natural persons (data subjects) is governed by Act No. 110/2019 Coll., on the processing of personal data, as amended, and by Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation, hereinafter “GDPR”).

Processing of personal data

The controller of personal data, which is BitWorx s.r.o., Company ID (IČO): 23591897, registered office at Hrabyňská 45/6, Svinov, 721 00 Ostrava, Czech Republic (hereinafter also the “Controller”), informs the data subject (the Client) that, for the purpose of fulfilling the Purchase Agreement and any other contractual arrangements and obligations arising from tax regulations and other regulations, and further on the basis of the Controller’s legitimate interest, it will process the Client’s personal data only for the necessary period, in particular: name and surname, date of birth, residential address, e‑mail address, telephone number, and personal data provided by the Client for the performance of the Agreement, including special categories of personal data (hereinafter collectively the “personal data”). The current list of retention periods is available on request and at https://cestahorami.cz.

Rights of the data subject

The Controller informs the Client that the Client may ask the Controller to correct and supplement personal data, to restrict the processing of personal data, and to erase personal data. The Client also has the right to object to the processing, as well as the right to data portability. If the Client has consented to the processing of personal data on the basis of voluntary consent for the purpose of sending marketing communications, the Client has the right to withdraw this consent at any time, without prejudice to the lawfulness of the processing of the given personal data based on the consent granted before its withdrawal.

The Client is entitled to ask how and when their personal data has been handled and on what legal basis.

Processors

The Controller may entrust a third party, as a processor, with the processing of the Client’s personal data. The Controller informs that it discloses personal data without the Client’s consent, in particular to contractual partners and to state authorities, on the basis of a statutory obligation or a decision of a state authority.

Supervisory authority

The Controller informs the Client that the supervisory authority with respect to the handling of personal data is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), www.uoou.cz. If the Client believes that their rights have been infringed in connection with a breach of the legal regulations governing the handling of personal data, they may lodge a complaint with the supervisory authority.

Controller contact details

The controller of personal data is BitWorx s.r.o., Company ID (IČO): 23591897, registered office at Hrabyňská 45/6, Svinov, 721 00 Ostrava, Czech Republic.

  • contact details – correspondence address: BitWorx s.r.o., Company ID (IČO): 23591897, registered office at Hrabyňská 45/6, Svinov, 721 00 Ostrava, Czech Republic
  • e‑mail address: cestahorami@bitworx.cz

Strava route import

If the Client uses the Strava import when creating a relief (the Connect with Strava button or pasting a link to an activity), they are redirected to Strava’s own sign‑in and consent screen at strava.com, where they explicitly authorize the Controller to read their activities. The Controller uses this authorization only to show the Client a list of their recent activities (name, date, type, distance, elevation gain and a route preview) and to download the location and elevation (GPS track) of the activity the Client selects. The activity list is shown only to the Client and is not stored by the Controller.

The access token issued by Strava is kept only in the Client’s browser, encrypted in the technical cookie ch_strava, for as long as Strava keeps it valid and at most 6 hours. The Client can delete it at any time with the Disconnect link. The token is not stored on the Controller’s servers. Once it expires or is deleted, the Controller has no way to access the Strava account again without the Client authorizing it anew.

The route obtained this way is then processed the same way as a GPX file the Client uploads manually – it is used to manufacture the ordered relief and is retained only for as long as necessary for that purpose.

  • Access can be revoked at any time by disconnecting the app in the Client’s Strava account settings (strava.com/settings/apps) – this authorization is managed exclusively by Strava.
  • A deletion request for data related to the imported route can be sent to the contact e‑mail address above; the Controller will carry out the deletion and confirm its completion to the Client by e‑mail.

Advertising measurement (Google Ads)

If the Client allows marketing cookies in the cookie banner, after an order is completed and paid the Controller passes data to Google Ireland Limited that lets Google recognise whether the order followed a view of or click on the Controller's advertisement (so-called enhanced conversions). This serves solely to measure the performance of the Controller's advertising campaigns.

The data passed on are the email address, phone number, first name and surname, which the Controller converts into a hash with the SHA‑256 function on its server before sending. Google therefore does not receive the data in readable form and only compares the hashes with hashes of its own users' data. For orders delivered to an address, the postal code and country are also passed on. The data are passed on only once, together with the order information.

The legal basis is the Client's consent under Article 6(1)(a) of Regulation (EU) 2016/679, given by allowing marketing cookies. Consent can be withdrawn at any time with the Cookie settings link in the site footer; withdrawal does not affect processing carried out before it. Without consent, these data are not passed on to Google.

Google processes the data as a processor under the Google Ads data processing terms and may also process them in the United States under the EU‑US Data Privacy Framework.

Personal data retention periods

Overview of personal data retention periods:

TypeRetention period
Contractual relationships – client5 years for possible tax-authority audits of accounting under § 31 of Act No. 563/1991 Coll., 3 years due to the limitation period for possible claims under § 629(1) of Act No. 89/2012 Coll., for the duration of the insurance contract – the term of the contractual relationship. This period is in particular 3 and 4 years.
Contractual relationships – supplier5 years for possible tax-authority audits of accounting under § 31 of Act No. 563/1991 Coll., 3 years due to the limitation period for possible claims under § 629(1) of Act No. 89/2012 Coll.
Contractual relationships – employee45 years due to pension-insurance obligations under § 35a of Act No. 582/1991 Coll., 10 years due to health-insurance contributions under § 22c of Act No. 589/1992 Coll., 5 years for possible tax-authority audits of accounting under § 31 of Act No. 563/1991 Coll., 3 years due to the limitation period for possible claims under § 629(1) of Act No. 89/2012 Coll.
Audiovisual recordingsLegitimate interest – 14 days