Privacy Policy
E-STEPS s.r.o.
1. Data Controller
The controller of personal data processed under this Privacy Policy is: E-STEPS s.r.o. Company ID No.: 28206711 Date of incorporation: 11 January 2008 Registered office: Dlouhá 715/38, Staré Město, 110 00 Praha 1, Czech Republic Registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, Insert 132717 (file No. C 132717/MSPH). Contact: [email protected] · Tel.: +420 735 633 649
2. Personal Data Processed
Depending on the nature of the Client's request or relationship, the Company may process: identification and contact details; information supplied through enquiry forms; information contained in documents supplied by the Client; contractual and transaction information; information required for compliance purposes; technical information necessary for Website security and operation. The Company shall process only data reasonably necessary for the relevant purpose. Such data may be provided directly by the Client (for example, via the Website enquiry form, a lead form on social media, or by email, telephone or messaging apps) or collected automatically when the Client visits the Website (for example, IP address, browser type and cookie identifiers), as further described in the Company's Cookie Policy.
3. Purposes of Processing
Personal data may be processed for: (a) responding to enquiries; (b) providing requested Services; (c) entering into and performing contracts; (d) company-formation intermediation; (e) communicating with Clients; (f) accounting and tax compliance; (g) fraud prevention and information security; (h) compliance with applicable legal obligations; and (i) other purposes permitted by applicable law.
4. Legal Bases
(a) Article 6(1)(b) GDPR — performance of a contract or steps taken at the Client's request before entering into a contract; (b) Article 6(1)(c) GDPR — compliance with a legal obligation; (c) Article 6(1)(f) GDPR — legitimate interests; or (d) Article 6(1)(a) GDPR — consent. The applicable legal basis shall be determined according to the actual processing activity.
5. Company-Formation Intermediation
5.1 Where a Client requests company-formation intermediation or assistance with opening a bank or payment account, the Company may transfer information necessary for the requested service to the relevant Licensed Provider (which may include a bank or payment institution). 5.2 The information transferred shall be limited to what is reasonably necessary for the requested service. 5.3 The relevant Licensed Provider acts in accordance with its own legal, professional and data-protection obligations. 5.4 Where the processing is necessary to take steps at the Client's request before entering into or performing a contract, Article 6(1)(b) GDPR may apply. Where processing is required by law, Article 6(1)(c) GDPR may apply.
6. Data Recipients
Personal data may be disclosed to: Licensed Providers, including banks or payment institutions where the Client requests account-opening intermediation; subcontractors, including CRM and communication/mailing service providers; IT and hosting providers; advertising and analytics platforms (such as Meta Platforms Ireland Ltd. or Google Ireland Ltd.), where the Client has given the required consent; professional advisers; public authorities where legally required; and other recipients where disclosure is permitted by law. The Company has concluded a data processing agreement with each processor in accordance with Article 28 GDPR.
7. International Data Transfers
7.1 Where personal data is transferred outside the European Economic Area, the Company shall use an applicable GDPR transfer mechanism. 7.2 Depending on the circumstances, this may include: an adequacy decision under Article 45 GDPR; Standard Contractual Clauses under Article 46 GDPR; or another lawful transfer mechanism. 7.3 The Company shall not represent that a particular transfer mechanism is used unless that mechanism actually applies to the relevant transfer.
8. Security
8.1 The Company implements appropriate technical and organisational measures appropriate to the risks of processing. 8.2 Such measures may include access controls, confidentiality measures, backup procedures, security monitoring and other measures appropriate to the nature of the processing. 8.3 The Company shall not claim to use a specific security technology or certification unless it has actually implemented it and it remains current.
9. Data Retention
9.1 Personal data is retained only for as long as reasonably necessary for the purposes for which it was collected, unless a longer period is required by law. 9.2 Accounting and tax records shall be retained for the periods required by applicable law. 9.3 Personal data necessary to establish, exercise or defend legal claims may be retained for the applicable limitation period. 9.4 Where statutory AML retention obligations apply to a particular activity, the relevant records shall be retained for the period required by law. 9.5 By way of illustration, and without limiting Article 9.1: enquiries that do not lead to a contract are generally retained for 24 months from the date of last contact; client data under a contract is generally retained for the duration of the contract and 10 years thereafter, to the extent required by Czech accounting and tax legislation; data processed on the basis of consent is retained until consent is withdrawn; and cookie-related data is retained in accordance with the periods stated in the cookie settings, and in any event no longer than 24 months.
10. Data Subject Rights
Subject to GDPR and applicable law, data subjects may have the right to: access personal data and obtain a copy of it (Article 15 GDPR); request rectification of inaccurate or incomplete data (Article 16 GDPR); request erasure ("right to be forgotten") (Article 17 GDPR); request restriction of processing (Article 18 GDPR); object to processing based on legitimate interests, including direct marketing (Article 21 GDPR); request data portability in a structured, machine-readable format, where applicable (Article 20 GDPR); withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal (Article 7(3) GDPR); not be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning the data subject (Article 22 GDPR) — the Company does not make such decisions; and lodge a complaint with the competent supervisory authority. Requests to exercise these rights may be sent to [email protected]. The Company shall respond within one month of receipt; in certain cases this period may be extended by a further two months, and the Company shall notify the data subject accordingly.
11. Restrictions
Where processing is required by law, certain rights may be restricted to the extent permitted by GDPR and applicable Czech law. In particular, statutory retention requirements may prevent immediate erasure of certain records.
12. Supervisory Authority
The competent Czech supervisory authority is: Office for Personal Data Protection Pplk. Sochora 27 170 00 Praha 7 Czech Republic Website: uoou.gov.cz A data subject may lodge a complaint with the competent supervisory authority.
13. Data Protection Officer
Based on the Company's current assessment of its processing activities, the Company does not consider that the conditions requiring mandatory appointment of a Data Protection Officer under Article 37 GDPR are currently met. The Company shall reassess this position if the nature or scale of its processing materially changes.
14. Changes
This Privacy Policy may be updated where necessary due to changes in processing activities, applicable law, service providers or technical arrangements. The current version shall be published on the Website.
Need assistance?
Our team is here to help you with any questions about your privacy or data.
Contact us →