I. Personal Data Protection

1.1 By entering personal data, the user confirms that they are familiar with the terms of personal data protection, that they agree with their wording and that they accept them in their entirety.

1.2 The Provider is the controller of users’ personal data pursuant to Art. 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter: “GDPR”). The Provider undertakes to process personal data in accordance with the law, in particular the GDPR.

1.3 Personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

1.4 When placing an order, the personal data necessary for the successful processing of the order (name and address, contact details) are required. The purpose of processing personal data is to process the user’s order and to exercise the rights and obligations arising from the contractual relationship between the Provider and the User. The purpose of processing personal data is also sending commercial communications and carrying out other marketing activities. The legal basis for processing personal data is the performance of a contract pursuant to Art. 6(1)(b) GDPR, compliance with a legal obligation of the controller pursuant to Art. 6(1)(c) GDPR and the legitimate interest of the Provider pursuant to Art. 6(1)(f) GDPR. The legitimate interest of the Provider is the processing of personal data for direct marketing purposes.

1.5 To perform the licence agreement, the Provider uses the services of subcontractors, in particular a mailing service provider (personal data are stored in third countries) and a web hosting provider. The subcontractors have been vetted with regard to the secure processing of personal data. The Provider and the web hosting subcontractor have concluded a data processing agreement under which the subcontractor is responsible for properly securing the physical, hardware and software perimeter and therefore bears direct liability towards the user for any leak or breach of personal data.

1.6 The Provider stores the user’s personal data for the period necessary to exercise the rights and obligations arising from the contractual relationship between the Provider and the user and to assert claims arising from these contractual relationships (for 15 years from the termination of the contractual relationship). After this period, the data will be erased.

1.7 The user has the right to request from the Provider access to their personal data pursuant to Art. 15 GDPR, rectification of personal data pursuant to Art. 16 GDPR, or restriction of processing pursuant to Art. 18 GDPR. The user has the right to erasure of personal data pursuant to Art. 17(1)(a) and (c) to (f) GDPR. The user also has the right to object to processing pursuant to Art. 21 GDPR and the right to data portability pursuant to Art. 20 GDPR.

1.8 The user has the right to lodge a complaint with the Office for Personal Data Protection if they believe that their right to the protection of personal data has been violated.

1.9 The user is not obliged to provide personal data. However, the provision of personal data is a necessary requirement for the conclusion and performance of the contract, and without providing personal data it is not possible to conclude the contract or for the Provider to perform it.

1.10 The Provider does not carry out automated individual decision-making within the meaning of Art. 22 GDPR.

1.11 By completing the contact form, a person interested in using the Provider’s services:

agrees to the use of their personal data for the purposes of electronically sending commercial communications, advertising materials, direct sales, market research and direct product offers by the Provider and third parties, but not more often than once a week, and at the same time
declares that they do not consider the sending of information pursuant to point 1.11.1 to be unsolicited advertising within the meaning of Act No. 40/1995 Coll., as amended, since the user expressly consents to the sending of information pursuant to point 1.11.1 in conjunction with Section 7 of Act No. 480/2004 Coll.
The user may withdraw the consent under this paragraph in writing at any time at pavel@ptk-service.cz

1.12 In order to improve the quality of its services, personalise its offer, collect anonymous data and for analytical purposes, the Provider uses so-called cookies on its website. By using the website, the User agrees to the use of this technology.

II. Rights and Obligations Between the Controller and the Processor (Data Processing Agreement)

2.1 With regard to the personal data of users’ clients, the Provider is a processor pursuant to Art. 28 GDPR. The User is the controller of these data.

2.2 These terms govern the mutual rights and obligations in the processing of personal data to which the Provider has gained access in the course of performing the licence agreement concluded by accepting the general terms and conditions at ptk-service.cz (hereinafter the “licence agreement”) concluded with the User as of the date the user account was created.

2.3 The Provider undertakes to process personal data for the User to the extent and for the purpose set out in Art. 2.4 – 2.7 of these terms. The means of processing will be automated. As part of the processing, the Provider will collect personal data, store them on data carriers, keep, block and dispose of them. The Provider is not entitled to process personal data in breach of or beyond the scope set out in these terms.

2.4 The Provider undertakes to process personal data for the user to the following extent:

ordinary personal data,
special categories of data pursuant to Art. 9 GDPR which the User has obtained in connection with its own business activities.

2.5 The Provider undertakes to process personal data for the user for the purpose of processing enquiries and requests from clients obtained via the contact form.

2.6 Personal data may only be processed at the workplaces of the Provider or its subcontractors pursuant to Art. 2.8 of these terms, within the territory of the European Union.

2.7 The Provider undertakes to process the personal data of the User’s clients for the User, all for the period necessary to exercise the rights and obligations arising from the contractual relationship between the Provider and the User and to assert claims arising from these contractual relationships (for 15 years from the termination of the contractual relationship).

2.8 The User grants permission to engage a subcontractor as a further processor pursuant to Art. 28(2) GDPR, namely the application hosting provider. The User further grants the Provider general authorisation to engage another processor of personal data in the processing; however, the Provider must inform the user in writing of any intended changes concerning the addition or replacement of other processors and give the user the opportunity to object to such changes. The Provider must impose on its subcontractors acting as processors of personal data the same data protection obligations as set out in these terms.

2.9 The Provider undertakes that the processing of personal data will be secured in particular as follows:

Personal data are processed in accordance with the law and on the basis of the User’s instructions, i.e. for the performance of all activities necessary for the provision of the web platform.
The Provider undertakes to ensure, by technical and organisational means, the protection of the processed personal data so that there can be no unauthorised or accidental access to the data, their alteration, destruction or loss, unauthorised transfers, other unauthorised processing or other misuse, and so that all obligations of the processor of personal data arising from the law are continuously ensured in terms of personnel and organisation for the entire duration of the processing.
The technical and organisational measures adopted correspond to the level of risk. Through them, the Provider ensures the ongoing confidentiality, integrity, availability and resilience of processing systems and services, and restores the availability of and access to personal data in a timely manner in the event of a physical or technical incident.
The Provider hereby declares that the protection of personal data is subject to the Provider’s internal security regulations.
Only authorised persons of the Provider and of the subcontractors pursuant to Art. 2.8 of these terms will have access to personal data; the Provider will set the conditions and scope of data processing for them, and each such person will access personal data under their own unique identifier.
Authorised persons of the Provider who process personal data under these terms are obliged to maintain confidentiality about the personal data and about security measures whose disclosure would jeopardise their security. The Provider will ensure that they are demonstrably bound by this obligation. The Provider will ensure that this obligation continues for both the Provider and the authorised persons even after the termination of their employment or other relationship with the Provider.
The Provider will assist the user through appropriate technical and organisational measures, insofar as possible, in fulfilling the user’s obligation to respond to requests for the exercise of data subject rights laid down in the GDPR, as well as in ensuring compliance with the obligations pursuant to Art. 32 to 36 GDPR, taking into account the nature of the processing and the information available to the Provider.
After the end of the provision of services related to the processing pursuant to Art. 2.7 of these terms, the Provider is obliged to erase all personal data or return them to the User, unless it is obliged to retain the personal data under a special law.
The Provider will provide the User with all information necessary to demonstrate that the obligations under this agreement and the GDPR have been fulfilled, and will allow audits, including inspections, carried out by the User or another auditor mandated by the user.
2.10 The User undertakes to report without delay all facts known to it that could adversely affect the proper and timely fulfilment of the obligations arising from these terms and to provide the Provider with the cooperation necessary for the fulfilment of these terms.

III. Final Provisions

3.1 These terms expire upon the lapse of the periods specified in Art. 1.6 and Art. 2.7 of these terms.

3.2 The User agrees to these terms by ticking the consent box in the online form. By ticking the consent box, the user declares that they have read these terms, that they agree with them and that they accept them in their entirety.

3.3 The Provider is entitled to amend these terms. The Provider is obliged to publish the new version of the terms on its website without undue delay, or to send the new version to the User’s e-mail address.

3.4 The Provider’s contact details for matters relating to these terms: +420 736 759 252, pavel@ptk-service.cz

3.5 Relationships not expressly governed by these terms are governed by the GDPR and the legal order of the Czech Republic, in particular Act No. 89/2012 Coll., the Civil Code, as amended.

These terms come into effect on 06/01/2026