Privacy policy
I. Basic provisions
The personal data controller referred to in Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data ("GDPR") is ScrooserPrague s.r.o., with its registered office at náměstí 14. října 1307/2, Smíchov, 150 00 Prague 5, Company ID 05523711, registered in the Commercial Register maintained by the Municipal Court in Prague, File No. C 265110 (the "Controller").
Contact details of the Controller: Saská 289/6, 118 00 Prague 1; email info@scroosertour.com; phone +420 773 677 208.
Personal data means any information about an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, an online identifier, or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity.
The Controller has not appointed a Data Protection Officer.
II. Sources and categories of processed personal data
The Controller processes the personal data you have provided, or personal data obtained on the basis of your booking. The Controller processes your identification and contact details and the data necessary for the performance of the contract.
III. Legal basis and purpose of processing
The legal basis for processing is:
- performance of the contract between you and the Controller under Article 6(1)(b) GDPR,
- the legitimate interest of the Controller in providing direct marketing under Article 6(1)(f) GDPR,
- your consent to processing for the purposes of direct marketing and of analytics and marketing cookies under Article 6(1)(a) GDPR in conjunction with Section 7(2) of Act No. 480/2004 Coll.
The purpose of processing is:
- handling your booking and exercising the rights and obligations arising from the contractual relationship. Providing personal data is a necessary requirement for concluding and performing the contract; without it the contract cannot be concluded or performed,
- sending commercial messages and carrying out other marketing activities.
No automated decision-making within the meaning of Article 22 GDPR takes place.
IV. Retention period
The Controller retains personal data:
- for the period necessary to exercise the rights and obligations arising from the contractual relationship and to assert claims under it, for 15 years from the end of the contractual relationship,
- until consent to processing for marketing purposes is withdrawn, for a maximum of 1 year, where data is processed on the basis of consent.
At the end of the retention period the Controller will erase the personal data.
V. Recipients of personal data (processors)
The recipients of personal data are parties:
- involved in delivering the service and processing payments, in particular the FareHarbor booking and payment platform,
- providing the operation of the website and its hosting,
- providing analytics and marketing services, in particular Google (Google Analytics, Google Tag Manager) and Meta Platforms, and only where you have given consent to analytics and marketing cookies,
- third-party booking platforms through which you made your reservation, such as Tripadvisor, Viator or Airbnb.
Some of these providers process data outside the European Union. Such transfers take place on the basis of the European Commission’s standard contractual clauses or an adequacy decision.
VI. Your rights
Under the GDPR you have:
- the right of access to your personal data under Article 15 GDPR,
- the right to rectification under Article 16 GDPR, or to restriction of processing under Article 18 GDPR,
- the right to erasure under Article 17 GDPR,
- the right to object to processing under Article 21 GDPR,
- the right to data portability under Article 20 GDPR,
- the right to withdraw consent, in writing or electronically, at the address or email of the Controller given above.
You also have the right to lodge a complaint with the Office for Personal Data Protection if you believe your right to the protection of personal data has been infringed.
VII. Security of personal data
The Controller declares that it has taken all appropriate technical and organisational measures to secure personal data, and that personal data may be accessed only by authorised persons.
VIII. Final provisions
By submitting a booking you confirm that you are familiar with this privacy policy and accept it in full. The Controller is entitled to amend this policy; a new version will be published on the website.