Privacy Policy
This Privacy Policy takes effect on 19 July 2026. The Controller may update it from time to time, particularly in response to changes in applicable legislation, personal data processing practices, or the services provided. The current version is always available on the website of COMPI-S s.r.o.
Further information about personal data protection and the rights and obligations arising from the General Data Protection Regulation (GDPR) is available on the websites of the European Commission and the Czech Office for Personal Data Protection.
Prague, 19 July 2026
Final Provisions
In connection with the processing of your personal data and subject to the conditions laid down by applicable legislation, you have in particular the right to:
-
obtain confirmation as to whether we process your personal data and request access to such data;
-
request the correction of inaccurate personal data or the completion of incomplete personal data;
-
request the erasure of your personal data;
-
request the restriction of its processing;
-
receive your personal data in a structured, commonly used, and machine-readable format and, where applicable, request its transfer to another controller;
-
object to processing based on our legitimate interests, including processing for direct marketing purposes;
-
withdraw your consent at any time, without affecting the lawfulness of processing carried out before its withdrawal;
-
lodge a complaint with the Office for Personal Data Protection or another competent supervisory authority.
These rights do not apply automatically in every case. Their applicability depends in particular on the purpose of the processing, the legal basis relied upon, and other conditions laid down by applicable legislation.
Rights of Data Subjects
To protect your personal data, we implement appropriate technical and organisational measures that reflect the nature of the processing and the associated risks. These measures are designed in particular to prevent unauthorised access, loss, misuse, alteration, disclosure, or destruction of personal data.
These measures include in particular:
-
restricting access to personal data to authorised persons only;
-
implementing technical safeguards for information systems and communication tools;
-
providing regular training to employees and other authorised persons;
-
continuously reviewing and updating the security measures in place.
How We Protect Personal Data
We process personal data primarily for the following purposes:
-
entering into and performing contracts and providing related services;
-
communicating with customers, business partners, and other relevant persons;
-
improving and developing our products and services;
-
sending marketing communications where your consent is required;
-
recording and managing marketing consents, objections, and communication preferences;
-
maintaining customer, business, and contractual records;
-
establishing, exercising, and defending legal claims;
-
managing user accounts and online services;
-
ensuring the security of information systems and protecting them against misuse.
Purposes of Personal Data Processing
Through marketing communications, we may provide you with relevant information about our projects, products, services, and news, including information about current projects of COMPI-S s.r.o.
We may send you marketing communications:
-
on the basis of your voluntary consent; or
-
where permitted by law, on the basis of our legitimate interests, particularly if you are an existing customer and we are informing you about our own similar products or services.
Providing consent to receive marketing communications is voluntary and is not a condition for entering into a contract or using our services. You may withdraw your consent at any time. Following its withdrawal, we will stop contacting you to the extent that the marketing communications were based on that consent.
You may object at any time to the processing of your personal data for direct marketing purposes or opt out of receiving further marketing communications, for example by using the unsubscribe link included in each marketing message. Once you do so, we will no longer use your personal data for that form of marketing communication.
We manage your marketing preferences consistently and always:
-
respect your choices;
-
use only the communication channels you have selected;
-
communicate only to the extent permitted by your consent or applicable legislation.
Marketing communications are always kept separate from communications that are:
-
contractual;
-
service-related or operational;
-
required by law.
Therefore, withdrawing your marketing consent, objecting to direct marketing, or opting out of marketing communications will not affect communications necessary for the performance of a contract, the provision of services, or compliance with our legal obligations.
Marketing Communications and Centralised Marketing Consent
The Company retains personal data only for as long as necessary to fulfil the purpose for which it is processed and in accordance with applicable legislation. The retention period depends primarily on:
-
the periods prescribed by law or other generally binding legislation;
-
the period specified in the consent provided, but no longer than until such consent is withdrawn, unless another legal basis exists for continued processing;
-
the duration of the contractual relationship and, as a rule, a further ten years after its termination, particularly for compliance with legal obligations and the establishment, exercise, or defence of legal claims, unless applicable legislation specifies a different retention period.
Once the applicable retention period has expired, personal data will be securely deleted or anonymised unless its continued retention is required by law.
Personal Data Retention Period
What Personal Data We Process
-
Identification data: title, first name, surname, personal identification number, date of birth, Company ID number, Tax ID number, gender,
and identity document details -
Contact details: permanent address, correspondence address, registered office,
place of business, telephone number, and email address -
Other data: bank account details and photographs
Your personal data is processed by COMPI-S s.r.o., with its registered office at Ondříčkova 609/27, Žižkov, 130 00 Prague 3, Company ID No.: 274 12 725 (hereinafter referred to as the “Controller”).
The Controller processes your personal data in accordance with the GDPR and other applicable legislation. The Controller will provide you with information on the methods and purposes of personal data processing. You may also exercise with the Controller all rights granted to you under the GDPR in connection with the processing of your personal data.
The Controller processes personal data in connection with its business activities, particularly for the preparation and implementation of property development projects in the Czech Republic, the provision of related products and services, and the management, operation, or rental of real estate.
Personal data may also be processed in connection with other products and services provided by the Controller, including products and services in the leisure sector.
Who Is the Data Controller?
You may exercise your rights in connection with the processing of personal data with the Controller, COMPI-S s.r.o., in any of the following ways:
-
by email at ab@compis.cz;
-
in writing at Ondříčkova 609/27, Žižkov, 130 00 Prague 3, Czech Republic.
We will process your request without undue delay and, in any event, within the time limits prescribed by applicable legislation. Where we have reasonable doubts concerning your identity, we may ask you to provide additional information necessary to verify it.
You also have the right to lodge a complaint with the competent supervisory authority, particularly if you believe that your personal data is being processed in breach of applicable legislation.
The competent supervisory authority in the Czech Republic is:
Office for Personal Data Protection
Pplk. Sochora 27
170 00 Prague 7
Czech Republic
www.uoou.gov.cz
How to Exercise Your Rights
a. Performance of a Contract and Compliance with Legal Obligations
We process personal data where necessary to enter into or perform a contract to which you are a party, or to take steps at your request prior to entering into a contract. We also process personal data to comply with obligations imposed on us by law, particularly in the areas of accounting and taxation.
b. Legitimate Interests of the Controller
On the basis of our legitimate interests, we process personal data in particular for the following purposes:
-
conducting routine operational and customer communications;
-
protecting property, persons, and security;
-
maintaining and managing customer records in our CRM system;
-
preparing internal statistics, analyses, and reports;
-
establishing, exercising, or defending legal claims;
-
informing existing customers about our own similar products or services where permitted by applicable legislation.
When carrying out such processing, we always assess whether our legitimate interests are overridden by your interests or fundamental rights and freedoms.
c. Consent of the Data Subject
Where the processing of personal data cannot be based on another legal basis, we process the data on the basis of your consent. This applies in particular to sending marketing communications where consent is required by law and to other specific purposes of which we will inform you before obtaining your consent.
Providing consent is voluntary, and you may withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
Legal Bases for Processing Personal Data
Purposes of Personal Data Processing
We process personal data primarily for the following purposes:
-
entering into and performing contracts and providing related services;
-
communicating with customers, business partners, and other relevant persons;
-
improving and developing our products and services;
-
sending marketing communications where your consent is required;
-
recording and managing marketing consents, objections, and communication preferences;
-
maintaining customer, business, and contractual records;
-
establishing, exercising, and defending legal claims;
-
managing user accounts and online services;
-
ensuring the security of information systems and protecting them against misuse.
We process personal data primarily for the following purposes:
-
entering into and performing contracts and providing related services;
-
communicating with customers, business partners, and other relevant persons;
-
improving and developing our products and services;
-
sending marketing communications where your consent is required;
-
recording and managing marketing consents, objections, and communication preferences;
-
maintaining customer, business, and contractual records;
-
establishing, exercising, and defending legal claims;
-
managing user accounts and online services;
-
ensuring the security of information systems and protecting them against misuse.
Who Is the Data Controller?
Your personal data is processed by COMPI-S s.r.o., with its registered office at Ondříčkova 609/27, Žižkov, 130 00 Prague 3, Company ID No.: 274 12 725 (hereinafter referred to as the “Controller”).
The Controller processes your personal data in accordance with the GDPR and other applicable legislation. The Controller will provide you with information on the methods and purposes of personal data processing. You may also exercise with the Controller all rights granted to you under the GDPR in connection with the processing of your personal data.
The Controller processes personal data in connection with its business activities, particularly for the preparation and implementation of property development projects in the Czech Republic, the provision of related products and services, and the management, operation, or rental of real estate.
Personal data may also be processed in connection with other products and services provided by the Controller, including products and services in the leisure sector.
We process personal data primarily for the following purposes:
-
entering into and performing contracts and providing related services;
-
communicating with customers, business partners, and other relevant persons;
-
improving and developing our products and services;
-
sending marketing communications where your consent is required;
-
recording and managing marketing consents, objections, and communication preferences;
-
maintaining customer, business, and contractual records;
-
establishing, exercising, and defending legal claims;
-
managing user accounts and online services;
-
ensuring the security of information systems and protecting them against misuse.
What Personal Data We Process
-
Identification data: title, first name, surname, personal identification number, date of birth, Company ID number, Tax ID number, gender, and identity document details
-
Contact details: permanent address, correspondence address, registered office, place of business, telephone number, and email address
-
Other data: bank account details and photographs
We process personal data primarily for the following purposes:
-
entering into and performing contracts and providing related services;
-
communicating with customers, business partners, and other relevant persons;
-
improving and developing our products and services;
-
sending marketing communications where your consent is required;
-
recording and managing marketing consents, objections, and communication preferences;
-
maintaining customer, business, and contractual records;
-
establishing, exercising, and defending legal claims;
-
managing user accounts and online services;
-
ensuring the security of information systems and protecting them against misuse.
Legal Basis for the Processing of Personal Data
a. Performance of a Contract and Compliance with Legal Obligations
We process personal data where necessary for entering into and performing a contract to which you are a party, or for taking steps at your request prior to entering into a contract. We also process personal data to comply with obligations imposed on us by applicable legislation, particularly in the areas of accounting and taxation.
b. Legitimate Interests of the Controller
On the basis of legitimate interests, we process personal data primarily for the following purposes:
-
ensuring routine operational and client communication;
-
protecting property, individuals, and security;
-
maintaining and managing client records in our CRM system;
-
preparing internal statistics, analyses, and reports;
-
establishing, exercising, or defending legal claims;
-
informing existing customers about our own similar products or services, where permitted by applicable legislation.
When carrying out such processing, we always assess whether your interests or fundamental rights and freedoms override our legitimate interests.
c. Consent of the Data Subject
Where the processing of personal data cannot be based on another legal basis, we process such data on the basis of your consent. This applies primarily to sending marketing communications where consent is required by applicable legislation, as well as to other specific purposes of which you will be informed before giving your consent.
Giving consent is voluntary, and you may withdraw it at any time. The withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
We process personal data primarily for the following purposes:
-
entering into and performing contracts and providing related services;
-
communicating with customers, business partners, and other relevant persons;
-
improving and developing our products and services;
-
sending marketing communications where your consent is required;
-
recording and managing marketing consents, objections, and communication preferences;
-
maintaining customer, business, and contractual records;
-
establishing, exercising, and defending legal claims;
-
managing user accounts and online services;
-
ensuring the security of information systems and protecting them against misuse.
Personal Data Retention Period
-
The Company retains personal data only for as long as necessary to fulfil the purpose for which it is processed and in accordance with applicable legislation. The retention period depends primarily on:
-
the periods prescribed by law or other generally binding legislation;
-
the period specified in the consent given, but no longer than until its withdrawal, unless another legal basis exists for continued processing;
-
the duration of the contractual relationship and, as a rule, for a further ten years after its termination, particularly for the purpose of complying with legal obligations and establishing, exercising, or defending legal claims, unless legislation provides for a different retention period.
-
After the applicable retention period has expired, the personal data will be securely deleted or anonymised, unless its continued retention is required by law
We process personal data primarily for the following purposes:
-
entering into and performing contracts and providing related services;
-
communicating with customers, business partners, and other relevant persons;
-
improving and developing our products and services;
-
sending marketing communications where your consent is required;
-
recording and managing marketing consents, objections, and communication preferences;
-
maintaining customer, business, and contractual records;
-
establishing, exercising, and defending legal claims;
-
managing user accounts and online services;
-
ensuring the security of information systems and protecting them against misuse.
How We Protect Personal Data
-
To protect your personal data, we implement appropriate technical and organisational measures corresponding to the nature of the processing and the associated risks. These measures are intended, in particular, to prevent unauthorised access, loss, misuse, alteration, disclosure, or destruction of personal data.
-
These measures include, in particular:
-
restricting access to personal data to authorised persons only;
-
implementing technical safeguards for information systems and communication tools;
-
regularly training employees and other authorised persons;
-
continuously reviewing and updating the security measures in place
We process personal data primarily for the following purposes:
-
entering into and performing contracts and providing related services;
-
communicating with customers, business partners, and other relevant persons;
-
improving and developing our products and services;
-
sending marketing communications where your consent is required;
-
recording and managing marketing consents, objections, and communication preferences;
-
maintaining customer, business, and contractual records;
-
establishing, exercising, and defending legal claims;
-
managing user accounts and online services;
-
ensuring the security of information systems and protecting them against misuse.
Rights of Data Subjects
In connection with the processing of personal data and subject to the conditions laid down by applicable legislation, you have, in particular, the right to:
-
obtain confirmation as to whether we process your personal data and request access to such data;
-
request the correction of inaccurate personal data or the completion of incomplete personal data;
-
request the deletion of personal data;
-
request the restriction of its processing;
-
receive your personal data in a structured, commonly used, and machine-readable format and, where applicable, request its transfer to another controller;
-
object to processing based on our legitimate interests, including processing for direct marketing purposes;
-
withdraw your consent at any time, without affecting the lawfulness of processing carried out before its withdrawal;
-
lodge a complaint with the Czech Office for Personal Data Protection or another competent supervisory authority.
These rights do not apply automatically in every case. Their applicability depends, in particular, on the purpose of the processing, the legal basis relied upon, and other conditions laid down by applicable legislation.
We process personal data primarily for the following purposes:
-
entering into and performing contracts and providing related services;
-
communicating with customers, business partners, and other relevant persons;
-
improving and developing our products and services;
-
sending marketing communications where your consent is required;
-
recording and managing marketing consents, objections, and communication preferences;
-
maintaining customer, business, and contractual records;
-
establishing, exercising, and defending legal claims;
-
managing user accounts and online services;
-
ensuring the security of information systems and protecting them against misuse.
How to Exercise Your Rights
You may exercise your rights in connection with the processing of personal data by contacting the Controller, COMPI-S s.r.o., in one of the following ways:
by e-mail at ab@compis.cz;
in writing at Ondříčkova 609/27, Žižkov, 130 00 Prague 3, Czech Republic.
We will process your request without undue delay and, in any event, within the time limits prescribed by applicable legislation. If we have reasonable doubts concerning your identity, we may ask you to provide additional information necessary to verify it.
You also have the right to lodge a complaint with the competent supervisory authority, particularly if you believe that your personal data is being processed in breach of applicable legislation.
The competent supervisory authority in the Czech Republic is:
Office for Personal Data Protection
Pplk. Sochora 27
170 00 Prague 7
Czech Republic
www.uoou.gov.cz
We process personal data primarily for the following purposes:
-
entering into and performing contracts and providing related services;
-
communicating with customers, business partners, and other relevant persons;
-
improving and developing our products and services;
-
sending marketing communications where your consent is required;
-
recording and managing marketing consents, objections, and communication preferences;
-
maintaining customer, business, and contractual records;
-
establishing, exercising, and defending legal claims;
-
managing user accounts and online services;
-
ensuring the security of information systems and protecting them against misuse.
Marketing Communications and Centralised Marketing Consent
Through marketing communications, we may provide you with relevant information about our projects, products, services, and news, including information about current projects of COMPI-S s.r.o.
We may send you marketing communications:
on the basis of your freely given consent; or where permitted by applicable legislation, on the basis of our legitimate interests, particularly if you are an existing customer and we inform you about our own similar products or services.
Giving consent to receive marketing communications is voluntary and is not a condition for entering into a contract or using our services.
You may withdraw your consent at any time. Following its withdrawal, we will stop contacting you to the extent that the marketing communication was based on that consent.
You may object to the processing of personal data for direct marketing purposes at any time or opt out of receiving further commercial communications, for example by using the unsubscribe link included in each commercial communication. Once you do so, we will no longer use your personal data for that form of marketing communication.
We manage your marketing preferences consistently and always:
-
respect your choices;
-
use only the communication channels you have selected;
-
act within the scope of your consent or applicable legislation.
-
Marketing communications are always kept separate from communications that are:
-
contractual;
-
service-related and operational;
-
required by applicable legislation.
Therefore, withdrawing your marketing consent, objecting to processing, or opting out of commercial communications does not affect communications necessary for the performance of a contract, the provision of services, or compliance with our legal obligations.
We process personal data primarily for the following purposes:
-
entering into and performing contracts and providing related services;
-
communicating with customers, business partners, and other relevant persons;
-
improving and developing our products and services;
-
sending marketing communications where your consent is required;
-
recording and managing marketing consents, objections, and communication preferences;
-
maintaining customer, business, and contractual records;
-
establishing, exercising, and defending legal claims;
-
managing user accounts and online services;
-
ensuring the security of information systems and protecting them against misuse.
Final Provisions
This Privacy Policy takes effect on 19 July 2026. The Controller may update it from time to time, particularly in response to changes in applicable legislation, personal data processing practices, or the services provided. The current version is always available on the website of COMPI-S s.r.o.
Further information about personal data protection and the rights and obligations arising from the General Data Protection Regulation (GDPR) is available on the websites of the European Commission and the Czech Office for Personal Data Protection.
Prague, 19 July 2026
We process personal data primarily for the following purposes:
-
entering into and performing contracts and providing related services;
-
communicating with customers, business partners, and other relevant persons;
-
improving and developing our products and services;
-
sending marketing communications where your consent is required;
-
recording and managing marketing consents, objections, and communication preferences;
-
maintaining customer, business, and contractual records;
-
establishing, exercising, and defending legal claims;
-
managing user accounts and online services;
-
ensuring the security of information systems and protecting them against misuse.