[{"data":1,"prerenderedAt":56},["ShallowReactive",2],{"legal:privacy-policy:en":3},{"title":4,"lastUpdated":5,"intro":6,"sections":7,"closingParagraphs":11,"sidebar":51},"Privacy Policy","21 August 2026","E-STEPS s.r.o.",[8,12,15,18,21,24,27,30,33,36,39,42,45,48],{"heading":9,"body":10,"list":11},"1. Data Controller","The controller of personal data processed under this Privacy Policy is:\r\n\r\nE-STEPS s.r.o.\r\n\r\nCompany ID No.: 28206711\r\n\r\nDate of incorporation: 11 January 2008\r\n\r\nRegistered office: Dlouhá 715\u002F38, Staré Město, 110 00 Praha 1, Czech Republic\r\n\r\nRegistered in the Commercial Register maintained by the Municipal Court in Prague, \r\n\r\nSection C, Insert 132717 (file No. C 132717\u002FMSPH).\r\n\r\nContact: info@estepsglobal.com · Tel.: +420 735 633 649\r\n","",{"heading":13,"body":14,"list":11},"2. Personal Data Processed","Depending on the nature of the Client's request or relationship, the Company may process:\r\n\r\nidentification and contact details;\r\n\r\ninformation supplied through enquiry forms;\r\n\r\ninformation contained in documents supplied by the Client;\r\n\r\ncontractual and transaction information;\r\n\r\ninformation required for compliance purposes;\r\n\r\ntechnical information necessary for Website security and operation.\r\n\r\nThe Company shall process only data reasonably necessary for the relevant purpose.\r\n\r\nSuch data may be provided directly by the Client (for example, via the Website enquiry form, a lead form on social media, or by email, telephone or messaging apps) or collected automatically when the Client visits the Website (for example, IP address, browser type and cookie identifiers), as further described in the Company's Cookie Policy.\r\n",{"heading":16,"body":17,"list":11},"3. Purposes of Processing","Personal data may be processed for:\r\n\r\n(a) responding to enquiries;\r\n\r\n(b) providing requested Services;\r\n\r\n(c) entering into and performing contracts;\r\n\r\n(d) company-formation intermediation;\r\n\r\n(e) communicating with Clients;\r\n\r\n(f) accounting and tax compliance;\r\n\r\n(g) fraud prevention and information security;\r\n\r\n(h) compliance with applicable legal obligations; and\r\n\r\n(i) other purposes permitted by applicable law.\r\n",{"heading":19,"body":20,"list":11},"4. Legal Bases","(a) Article 6(1)(b) GDPR — performance of a contract or steps taken at the Client's request before entering into a contract;\r\n\r\n(b) Article 6(1)(c) GDPR — compliance with a legal obligation;\r\n\r\n(c) Article 6(1)(f) GDPR — legitimate interests; or\r\n\r\n(d) Article 6(1)(a) GDPR — consent.\r\n\r\nThe applicable legal basis shall be determined according to the actual processing activity.\r\n",{"heading":22,"body":23,"list":11},"5. Company-Formation Intermediation","5.1 Where a Client requests company-formation intermediation or assistance with opening a bank or payment account, the Company may transfer information necessary for the requested service to the relevant Licensed Provider (which may include a bank or payment institution).\r\n\r\n5.2 The information transferred shall be limited to what is reasonably necessary for the requested service.\r\n\r\n5.3 The relevant Licensed Provider acts in accordance with its own legal, professional and data-protection obligations.\r\n\r\n5.4 Where the processing is necessary to take steps at the Client's request before entering into or performing a contract, Article 6(1)(b) GDPR may apply.\r\nWhere processing is required by law, Article 6(1)(c) GDPR may apply.\r\n",{"heading":25,"body":26,"list":11},"6. Data Recipients","Personal data may be disclosed to:\r\n\r\nLicensed Providers, including banks or payment institutions where the Client requests account-opening intermediation;\r\n\r\nsubcontractors, including CRM and communication\u002Fmailing service providers;\r\nIT and hosting providers;\r\n\r\nadvertising and analytics platforms (such as Meta Platforms Ireland Ltd. or Google Ireland Ltd.), where the Client has given the required consent;\r\n\r\nprofessional advisers;\r\n\r\npublic authorities where legally required; and\r\nother recipients where disclosure is permitted by law.\r\n\r\nThe Company has concluded a data processing agreement with each processor in accordance with Article 28 GDPR.\r\n",{"heading":28,"body":29,"list":11},"7. International Data Transfers","7.1 Where personal data is transferred outside the European Economic Area, the Company shall use an applicable GDPR transfer mechanism.\r\n\r\n7.2 Depending on the circumstances, this may include:\r\nan adequacy decision under Article 45 GDPR;\r\nStandard Contractual Clauses under Article 46 GDPR; or\r\nanother lawful transfer mechanism.\r\n\r\n7.3 The Company shall not represent that a particular transfer mechanism is used unless that mechanism actually applies to the relevant transfer.\r\n",{"heading":31,"body":32,"list":11},"8. Security","8.1 The Company implements appropriate technical and organisational measures appropriate to the risks of processing.\r\n\r\n8.2 Such measures may include access controls, confidentiality measures, backup procedures, security monitoring and other measures appropriate to the nature of the processing.\r\n\r\n8.3 The Company shall not claim to use a specific security technology or certification unless it has actually implemented it and it remains current.\r\n",{"heading":34,"body":35,"list":11},"9. Data Retention","9.1 Personal data is retained only for as long as reasonably necessary for the purposes for which it was collected, unless a longer period is required by law.\r\n\r\n9.2 Accounting and tax records shall be retained for the periods required by applicable law.\r\n\r\n9.3 Personal data necessary to establish, exercise or defend legal claims may be retained for the applicable limitation period.\r\n\r\n9.4 Where statutory AML retention obligations apply to a particular activity, the relevant records shall be retained for the period required by law.\r\n\r\n9.5 By way of illustration, and without limiting Article 9.1: enquiries that do not lead to a contract are generally retained for 24 months from the date of last contact; client data under a contract is generally retained for the duration of the contract and 10 years thereafter, to the extent required by Czech accounting and tax legislation; data processed on the basis of consent is retained until consent is withdrawn; and cookie-related data is retained in accordance with the periods stated in the cookie settings, and in any event no longer than 24 months.\r\n",{"heading":37,"body":38,"list":11},"10. Data Subject Rights","Subject to GDPR and applicable law, data subjects may have the right to:\r\n\r\naccess personal data and obtain a copy of it (Article 15 GDPR);\r\n\r\nrequest rectification of inaccurate or incomplete data (Article 16 GDPR);\r\n\r\nrequest erasure (\"right to be forgotten\") (Article 17 GDPR);\r\n\r\nrequest restriction of processing (Article 18 GDPR);\r\n\r\nobject to processing based on legitimate interests, including direct marketing (Article 21 GDPR);\r\n\r\nrequest data portability in a structured, machine-readable format, where applicable (Article 20 GDPR);\r\n\r\nwithdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal (Article 7(3) GDPR);\r\nnot be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning the data subject (Article 22 GDPR) — the Company does not make such decisions; and\r\nlodge a complaint with the competent supervisory authority.\r\n\r\nRequests to exercise these rights may be sent to info@estepsglobal.com. The Company shall respond within one month of receipt; in certain cases this period may be extended by a further two months, and the Company shall notify the data subject accordingly.\r\n",{"heading":40,"body":41,"list":11},"11. Restrictions","Where processing is required by law, certain rights may be restricted to the extent permitted by GDPR and applicable Czech law.\r\n\r\nIn particular, statutory retention requirements may prevent immediate erasure of certain records.",{"heading":43,"body":44,"list":11},"12. Supervisory Authority","The competent Czech supervisory authority is:\r\n\r\nOffice for Personal Data Protection\r\n\r\nPplk. Sochora 27\r\n\r\n170 00 Praha 7\r\n\r\nCzech Republic\r\n\r\nWebsite: uoou.gov.cz\r\n\r\nA data subject may lodge a complaint with the competent supervisory authority.",{"heading":46,"body":47,"list":11},"13. Data Protection Officer","Based on the Company's current assessment of its processing activities, the Company does not consider that the conditions requiring mandatory appointment of a Data Protection Officer under Article 37 GDPR are currently met.\r\n\r\nThe Company shall reassess this position if the nature or scale of its processing materially changes.\r\n",{"heading":49,"body":50,"list":11},"14. Changes","This Privacy Policy may be updated where necessary due to changes in processing activities, applicable law, service providers or technical arrangements.\r\n\r\nThe current version shall be published on the Website.",{"title":52,"description":53,"linkLabel":54,"linkHref":55},"Need assistance?","Our team is here to help you with any questions about your privacy or data.","Contact us","\u002Fcontact",1788170108992]