top of page

Privacy Policy

A legal disclaimer

Effective from and last updated on: 16 July 2026

1. Controller Details
Controller: Abigail Mokrá
Tax ID (IČO): 21624674
Registered Address (Sídlo):

  • Školská 660/3

  • Praha 1 – Nové Město

  • 110 00 Prague 1

  • Czech Republic


If you have any questions about this Privacy Policy or the way in which your personal data is processed, please contact us using the contact details provided on our website.

2. Personal Data We Collect
We collect personal data only where it is necessary to provide our services or where you voluntarily provide it.
Personal data we collect
We may collect the following personal data:

  • First name

  • Last name

  • Email address

  • Telephone number

  • IP address

  • Bank account details where payment is made by bank transfer and this is necessary for payment reconciliation and accounting purposes


Payment information
We do not collect, process or store your full payment card details. Appointments and payments are facilitated through Calendly, which is integrated with certified third-party payment processors, including Stripe and PayPal.

Calendly stores only:

  • the last four digits of your payment card;

  • the card type; and

  • the card expiry date,

for record-keeping purposes.

Third-party payment processors
Our payment providers, Stripe and PayPal, may collect and process:

  • credit or debit card details;

  • bank account details, where applicable;

  • your name;

  • billing address;

  • email address;

  • telephone number;

  • date of birth where required;

  • transaction details, including payment amount and date;

  • device information, including IP address, browser type and device identifiers; and

  • location data where their mobile applications are used.


These providers retain personal data in accordance with their own privacy policies and applicable financial, tax and anti-money laundering legislation, typically for between seven and ten years.

3. Purpose and Legal Basis for Processing
We process personal data only where permitted under the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (GDPR), where applicable.

Performance of a contract
We process personal data to:

  • provide the services you request;

  • respond to your enquiries;

  • arrange consultations and appointments;

  • provide educational, advisory, editing, proofreading and other requested services;

  • process payments and issue invoices; and

  • communicate with you regarding your bookings and services.


Legal obligation
We process certain personal data where we are legally required to do so, including to:

  • retain invoices and accounting records in accordance with Czech accounting and tax legislation; and

  • comply with other applicable legal or regulatory obligations.


Legitimate interests
We may process personal data where necessary for our legitimate business interests, including to:

  • maintain records of previous services and ongoing client relationships;

  • improve the quality of our services;

  • protect our business against fraud, misuse and security risks; and

  • maintain the security and performance of our website and systems.


Consent
Where required by law, we rely on your consent. This includes:

  • sending marketing emails or newsletters; and

  • using non-essential cookies or analytics technologies.


You may withdraw your consent at any time without affecting the lawfulness of any processing carried out before your consent was withdrawn.

4. Data Retention Period
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected or to comply with legal obligations. Unless a longer retention period is required by law, we retain:

  • client correspondence and service records for up to five years after completion of our services;

  • accounting records, invoices and tax documentation for ten years in accordance with Czech accounting and tax legislation;

  • bank transfer records for ten years where required by applicable financial regulations;

  • records of marketing consent until consent is withdrawn or the records are no longer required; and

  • website technical logs, including IP addresses, only for as long as necessary to maintain website security and technical administration.


Where there is no legal requirement to retain personal data, it will be securely deleted or anonymised.

5. Data Processors and Sharing
We do not sell, rent or trade your personal data. We may share personal data only where necessary with trusted third-party service providers acting on our behalf, including:

  • Calendly (appointment bookings and scheduling);

  • Stripe (online payment processing);

  • PayPal (online payment processing);

  • our website hosting provider;

  • our email service provider;

  • our cloud storage provider;

  • our accounting or bookkeeping provider; and

  • our IT support providers.


All third-party providers process personal data only:

  • in accordance with our instructions;

  • under appropriate contractual safeguards; and

  • in compliance with applicable data protection legislation.


Where personal data is transferred outside the European Economic Area or the United Kingdom, appropriate safeguards will be implemented in accordance with applicable data protection laws.

6. Your Rights
Under the GDPR, you have the following rights regarding your personal data:

  • the right to access your personal data;

  • the right to request correction of inaccurate or incomplete personal data;

  • the right to request erasure of your personal data where legally permitted;

  • the right to request restriction of processing;

  • the right to object to processing based on our legitimate interests;

  • the right to receive your personal data in a portable format where applicable;

  • the right to withdraw consent at any time where processing is based on consent; and

  • the right to lodge a complaint with the Czech supervisory authority, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů – ÚOOÚ).


If you wish to exercise any of these rights, please contact us using the contact details provided on our website.

7. Data Security
We implement appropriate technical and organisational measures to protect your personal data against:

  • unauthorised access;

  • loss;

  • misuse;

  • alteration; and

  • unauthorised disclosure.


Access to personal data is restricted to individuals who require it in order to provide our services or comply with legal obligations.

8. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect:

  • changes to our services;

  • changes in legal or regulatory requirements; or

  • changes to our data processing practices.


The most recent version of this Privacy Policy will always be published on our website together with the date on which it was last updated.

bottom of page