Ganado

PRIVACY AND DATA

A clear account of what we process.

This policy describes the actual data flow on Ganado’s public website: from an enquiry or calculator result to operational security and optional analytics.

Updated Version 2026-08-14
Contact the controller

The essentials

01

ENQUIRIES

We use the details to reply, scope the work and continue the requested relationship.

02

ANALYTICS

Optional measurement is activated only after an explicit analytics choice.

03

NO AD PROFILES

We do not sell personal data or use it to build advertising profiles.

01

Controller and scope

The controller for the personal data described in this policy is the Czech company Ganado. This policy covers the public website, contact and calculator forms, and traffic measurement on ganado.cz.

Legal name
Ganado International s.r.o.
Company ID (IČO)
19322119
Registered office
Příčná 1892/4, Nové Město, 110 00 Praha 1
Privacy contact
[email protected]

Separate applications or client services may provide additional notices where they process a different data set. In that case, the additional notice applies together with this policy.

02

Data, purposes and legal bases

The scope depends on whether you only browse the website, submit an enquiry, request a calculator result by email or become a client.

Main processing activities on Ganado’s public website
Activity Data categories Purpose and legal basis Retention
Contact enquiry Name, contact, message, selected service, business situation, documents, timing, language and attribution context. Replying, scoping and quoting: Article 6(1)(b) GDPR; for general communication and continuity records, also legitimate interests under Article 6(1)(f). Until the enquiry closes, then only while needed for continuity, legal claims or a legal duty; the data set is reviewed regularly.
Calculator result Email, language, calculator type, entered values, calculated output and submission identifier. Sending the requested result: requested pre-contract steps under Article 6(1)(b). One commercial email about 3 days later is sent only after separate consent under Article 6(1)(a); operational protection relies on Article 6(1)(f). Using the same criteria as an enquiry. A separate delivery backup is deleted automatically after 30 days; optional-consent evidence is kept with the case only while needed to demonstrate lawful communication.
Sales pipeline and client relationship Contact, service, case status, communication history, supporting records and data required to provide the service. Managing the enquiry and contract: Article 6(1)(b); accounting and tax duties under Article 6(1)(c); protecting legal rights under Article 6(1)(f). While the enquiry or contract is active, then according to a specific statutory duty or claims risk; unnecessary scope is erased or restricted.
Security and technical operation Request time and metadata, host, origin/referrer, IP address processed to limit abuse, technical logs and error records. Availability, spam prevention, rate limiting, diagnostics and service protection: legitimate interests under Article 6(1)(f). Only for a limited period matching the security or diagnostic purpose; longer only for an incident or legal claim.
Optional analytics Identifiers, visits, journey, interactions, active time, scroll, device, referrer, UTM parameters and approximate location. Measuring usability, traffic sources and content performance without ad profiling: explicit consent under Article 6(1)(a). According to identifier lifetimes and current tool settings; data is limited to the period needed for trend analysis.
03

Forms and business communication

Contact and calculator forms collect only what is needed for the specific request. Required fields are marked; without contact details and minimum context we may be unable to reply.

A validated enquiry is written to the Supabase sales pipeline, delivered through Resend and placed in a separate delivery backup with automatic deletion after 30 days. The backup protects against losing a lead during an email outage; it is not used for marketing.

We send the calculator result without marketing consent. A separate optional box, unchecked by default, permits one commercial email about 3 days later on the basis of consent under Article 6(1)(a) GDPR. Before it is sent, it can be cancelled in one step through the secure “Cancel the scheduled email” link in the result message; without opt-in no follow-up is scheduled.

Depending on the situation, a form may include

  • name, email or phone number and preferred reply channel;
  • message, service, client type, urgency, available documents and timing;
  • business context such as IČO/OSVČ status, platform work, foreign services or previous VAT/identified-person handling;
  • for a calculator, the email, inputs, calculated totals, calculator type and year;
  • for the optional follow-up, the consent choice, time, language, form source and consent-notice version;
  • the page and button leading to the form, language, referrer, UTM parameters and a technical submission identifier.

Operational request metadata

  • The server processes origin, referer, host and IP address to validate requests, prevent abuse and apply rate limits.
  • Suspicious or malicious payloads may be rejected automatically; a valid enquiry is not assessed for a legal or similarly significant decision.
04

Cookies and analytics

We separate necessary technologies from optional measurement. Refusing analytics does not restrict website content or the ability to submit an enquiry.

Necessary technologies

These maintain security, form state and your privacy choice. Cookies or web storage may be used where necessary for a function you request. Related processing relies on legitimate interests or delivery of the requested service.

Optional analytics

After an explicit analytics acceptance, we may activate the tools below. We do not use them for targeted advertising or the sale of personal data.

01

Google Analytics

Aggregated measurement of visits, traffic sources and page performance.

Retention: The _ga cookie is set for no more than 12 months without renewal on a later visit. In the current GA4 property, event data is retained for 2 months and user data for 14 months; user-data retention resets on new activity. Standard aggregated reports are unaffected by that setting.

02

Microsoft Clarity

Usability diagnostics, heatmaps and interaction data represented as sessions; not used for ad profiling.

Retention: The _clck cookie lasts no more than 12 months and _clsk 1 day. Session-playback data is normally retained for 30 days; aggregated clicks, heatmaps, and labelled or favourited recordings for 9 months.

03

Vercel Analytics and Speed Insights

Traffic, performance and web-metric measurement used to improve the site technically.

Retention: Vercel Web Analytics uses no cookies. Its visit hash for deduplication is discarded after 24 hours according to the provider documentation.

Cookieless visit measurement (Ganado Track)

We also measure site traffic with our own tool that stores nothing on your device — no cookies, no web storage. The visitor key is derived on the server as a salted hash; the salt rotates every day and the previous one is deleted, so visits cannot be linked across days.

  • pages visited, time spent on a page and scroll depth;
  • clicks on elements we labelled for this purpose; their text and link target are not read;
  • the referrer origin, meaning the scheme and domain only, never the page address, and UTM tags;
  • a coarse browser family, for example “Chrome / Android”.

These records are deleted automatically after 10 years. We do not sell them and do not share them with advertising networks.

You can opt out of this measurement at any time: open any page of the site with ?gnd_notrack=1 appended to the address. Your choice is remembered on our server for 90 days, so opting out stores nothing on your device either; ?gnd_notrack=0 turns measurement back on.

05

Recipients and transfers outside the EEA

Access is limited to people and suppliers who need it for the stated purpose. Depending on the service, a supplier acts as a processor or an independent controller.

Main recipient and supplier categories
Recipient Role Data and purpose Location / transfer
Supabase Database infrastructure Sales pipeline and the 30-day backup of validated enquiries. According to the selected service region and contractual configuration.
Resend Email delivery Contact, message content and metadata required for delivery and error handling. Resend retains email data for 30 days; open/click tracking is disabled for the domain. According to the provider’s documentation, email metadata, logs and API records are stored in the United States. Transfers from the EEA are covered by the provider’s DPA, EU standard contractual clauses and, where applicable, the EU–US Data Privacy Framework.
Vercel Hosting, security and optional analytics Web requests, technical logs, performance and, after consent, analytics metrics. The provider may use infrastructure outside the EEA.
Cloudflare Network infrastructure and security Network and technical data needed to transmit requests securely, protect the service and deliver an optional analytics event to our infrastructure. The global network may process data outside the EEA; the provider identifies GDPR mechanisms including the Data Privacy Framework and standard contractual clauses where applicable.
Google and Microsoft Optional analytics providers Website-usage data only after analytics acceptance. A transfer outside the EEA may occur under the provider’s configuration and mechanism.
Public authorities and professional advisers Legal duty or claims protection Only data necessary for the specific duty, dispute or security incident. According to jurisdiction and the legal basis of the specific case.

Where a provider processes data outside the European Economic Area, a Chapter V GDPR mechanism is required. Depending on the recipient, this may be an adequacy decision, including the EU–US Data Privacy Framework for a certified recipient, or Article 46 standard contractual clauses with appropriate supplementary measures.

You can request information about the mechanism used for a specific transfer and an available copy of the safeguards from the controller’s email address.

06

Retention and security

We do not retain data longer than its purpose requires. The period is determined by the enquiry or contract status, statutory archiving, potential legal claims, security needs and provider settings.

  • separate form-delivery backup: automatic deletion after 30 days;
  • enquiry and sales pipeline: until the case closes, then only while justified by continuity, a claim or a legal duty;
  • evidence of consent to one commercial follow-up: with the case while needed to demonstrate consent and defend claims; no follow-up is scheduled without consent;
  • browser cookie and analytics choice: no more than 12 months; a new policy version requires a fresh choice;
  • client accounting and tax records: for periods required by applicable law and the contractual relationship;
  • technical and security logs: a limited operational period, longer only for an incident or claim;
  • optional analytics: according to the described identifiers and current retention settings, no longer than needed for justified trend analysis.

Security and data minimisation

We use access separation, server-side validation, rate limiting, spam protection, encrypted transport and restricted service roles. The pipeline and backups are not publicly accessible.

No control removes every risk. When a purpose, supplier or data flow changes, we reassess the scope and update this policy.

07

Your rights

Subject to the GDPR conditions, your rights include:

  • access to personal data and information about its processing;
  • rectification of inaccurate or completion of incomplete data;
  • erasure where there is no longer a legal basis to retain the data;
  • restriction of processing in the circumstances set by the GDPR;
  • portability for automated processing based on consent or a contract;
  • objection to processing based on legitimate interests;
  • withdrawal of consent for future optional analytics or a commercial follow-up that has not yet been sent;
  • a complaint to the supervisory authority and judicial remedy.

If you object to processing based on legitimate interests, we will stop unless we demonstrate compelling legitimate grounds or a need to establish, exercise or defend legal claims.

Analytics consent can be withdrawn in Cookie settings. Consent to one commercial follow-up can be withdrawn before sending through the secure “Cancel the scheduled email” link in the result message; the controller also accepts requests at the contact email. Withdrawal does not affect delivery of the requested result or access to the website.

Send a request to the controller’s email address. To protect the data, we may reasonably verify identity without asking for more information than the verification requires.

We respond without undue delay, normally within one month. The GDPR may allow an extension for complex requests; we will explain the reason in time.

Supervisory authority Czech Office for Personal Data Protection (ÚOOÚ) Pplk. Sochora 27, 170 00 Prague 7, Czech Republic How to lodge a complaint with ÚOOÚ
08

Automation and official sources

We may automatically sort an enquiry by topic, source, priority or technical risk so it reaches the appropriate workflow. We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you.

Analytics is not used for advertising profiles. This policy is a transparent description of processing, not a compliance certification or individual legal advice.