Privacy Policy
Purposes of Personal Data Processing
We process personal data primarily for the following purposes:
-
entering into and performing contracts and providing related services;
-
communicating with customers, business partners, and other relevant persons;
-
improving and developing our products and services;
-
sending marketing communications where your consent is required;
-
recording and managing marketing consents, objections, and communication preferences;
-
maintaining customer, business, and contractual records;
-
establishing, exercising, and defending legal claims;
-
managing user accounts and online services;
-
ensuring the security of information systems and protecting them against misuse.
We process personal data primarily for the following purposes:
-
entering into and performing contracts and providing related services;
-
communicating with customers, business partners, and other relevant persons;
-
improving and developing our products and services;
-
sending marketing communications where your consent is required;
-
recording and managing marketing consents, objections, and communication preferences;
-
maintaining customer, business, and contractual records;
-
establishing, exercising, and defending legal claims;
-
managing user accounts and online services;
-
ensuring the security of information systems and protecting them against misuse.
Who Is the Data Controller?
Your personal data is processed by COMPI-S s.r.o., with its registered office at Ondříčkova 609/27, Žižkov, 130 00 Prague 3, Company ID No.: 274 12 725 (hereinafter referred to as the “Controller”).
The Controller processes your personal data in accordance with the GDPR and other applicable legislation. The Controller will provide you with information on the methods and purposes of personal data processing. You may also exercise with the Controller all rights granted to you under the GDPR in connection with the processing of your personal data.
The Controller processes personal data in connection with its business activities, particularly for the preparation and implementation of property development projects in the Czech Republic, the provision of related products and services, and the management, operation, or rental of real estate.
Personal data may also be processed in connection with other products and services provided by the Controller, including products and services in the leisure sector.
We process personal data primarily for the following purposes:
-
entering into and performing contracts and providing related services;
-
communicating with customers, business partners, and other relevant persons;
-
improving and developing our products and services;
-
sending marketing communications where your consent is required;
-
recording and managing marketing consents, objections, and communication preferences;
-
maintaining customer, business, and contractual records;
-
establishing, exercising, and defending legal claims;
-
managing user accounts and online services;
-
ensuring the security of information systems and protecting them against misuse.
What Personal Data We Process
-
Identification data: title, first name, surname, personal identification number, date of birth, Company ID number, Tax ID number, gender, and identity document details
-
Contact details: permanent address, correspondence address, registered office, place of business, telephone number, and email address
-
Other data: bank account details and photographs
We process personal data primarily for the following purposes:
-
entering into and performing contracts and providing related services;
-
communicating with customers, business partners, and other relevant persons;
-
improving and developing our products and services;
-
sending marketing communications where your consent is required;
-
recording and managing marketing consents, objections, and communication preferences;
-
maintaining customer, business, and contractual records;
-
establishing, exercising, and defending legal claims;
-
managing user accounts and online services;
-
ensuring the security of information systems and protecting them against misuse.
You may exercise your rights in connection with the processing of personal data with the Controller, COMPI-S s.r.o., in any of the following ways:
-
by email at ab@compis.com;
-
in writing at Ondříčkova 609/27, Žižkov, 130 00 Prague 3, Czech Republic.
We will process your request without undue delay and, in any event, within the time limits prescribed by applicable legislation. Where we have reasonable doubts concerning your identity, we may ask you to provide additional information necessary to verify it.
You also have the right to lodge a complaint with the competent supervisory authority, particularly if you believe that your personal data is being processed in breach of applicable legislation.
The competent supervisory authority in the Czech Republic is:
Office for Personal Data Protection
Pplk. Sochora 27
170 00 Prague 7
Czech Republic
www.uoou.gov.cz
How to Exercise Your Rights
In connection with the processing of your personal data and subject to the conditions laid down by applicable legislation, you have in particular the right to:
-
obtain confirmation as to whether we process your personal data and request access to such data;
-
request the correction of inaccurate personal data or the completion of incomplete personal data;
-
request the erasure of your personal data;
-
request the restriction of its processing;
-
receive your personal data in a structured, commonly used, and machine-readable format and, where applicable, request its transfer to another controller;
-
object to processing based on our legitimate interests, including processing for direct marketing purposes;
-
withdraw your consent at any time, without affecting the lawfulness of processing carried out before its withdrawal;
-
lodge a complaint with the Office for Personal Data Protection or another competent supervisory authority.
These rights do not apply automatically in every case. Their applicability depends in particular on the purpose of the processing, the legal basis relied upon, and other conditions laid down by applicable legislation.
Rights of Data Subjects
a. Performance of a Contract and Compliance with Legal Obligations
We process personal data where necessary to enter into or perform a contract to which you are a party, or to take steps at your request prior to entering into a contract. We also process personal data to comply with obligations imposed on us by law, particularly in the areas of accounting and taxation.
b. Legitimate Interests of the Controller
On the basis of our legitimate interests, we process personal data in particular for the following purposes:
-
conducting routine operational and customer communications;
-
protecting property, persons, and security;
-
maintaining and managing customer records in our CRM system;
-
preparing internal statistics, analyses, and reports;
-
establishing, exercising, or defending legal claims;
-
informing existing customers about our own similar products or services where permitted by applicable legislation.
When carrying out such processing, we always assess whether our legitimate interests are overridden by your interests or fundamental rights and freedoms.
c. Consent of the Data Subject
Where the processing of personal data cannot be based on another legal basis, we process the data on the basis of your consent. This applies in particular to sending marketing communications where consent is required by law and to other specific purposes of which we will inform you before obtaining your consent.
Providing consent is voluntary, and you may withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
Legal Bases for Processing Personal Data
Through marketing communications, we may provide you with relevant information about our projects, products, services, and news, including information about current projects of COMPI-S s.r.o.
We may send you marketing communications:
-
on the basis of your voluntary consent; or
-
where permitted by law, on the basis of our legitimate interests, particularly if you are an existing customer and we are informing you about our own similar products or services.
Providing consent to receive marketing communications is voluntary and is not a condition for entering into a contract or using our services. You may withdraw your consent at any time. Following its withdrawal, we will stop contacting you to the extent that the marketing communications were based on that consent.
You may object at any time to the processing of your personal data for direct marketing purposes or opt out of receiving further marketing communications, for example by using the unsubscribe link included in each marketing message. Once you do so, we will no longer use your personal data for that form of marketing communication.
We manage your marketing preferences consistently and always:
-
respect your choices;
-
use only the communication channels you have selected;
-
communicate only to the extent permitted by your consent or applicable legislation.
Marketing communications are always kept separate from communications that are:
-
contractual;
-
service-related or operational;
-
required by law.
Therefore, withdrawing your marketing consent, objecting to direct marketing, or opting out of marketing communications will not affect communications necessary for the performance of a contract, the provision of services, or compliance with our legal obligations.
Legal Bases for Processing Personal Data
a. Performance of a Contract and Compliance with Legal Obligations
We process personal data where necessary to enter into or perform a contract to which you are a party, or to take steps at your request prior to entering into a contract. We also process personal data to comply with obligations imposed on us by law, particularly in the areas of accounting and taxation.
b. Legitimate Interests of the Controller
On the basis of our legitimate interests, we process personal data in particular for the following purposes:
-
conducting routine operational and customer communications;
-
protecting property, persons, and security;
-
maintaining and managing customer records in our CRM system;
-
preparing internal statistics, analyses, and reports;
-
establishing, exercising, or defending legal claims;
-
informing existing customers about our own similar products or services where permitted by applicable legislation.
When carrying out such processing, we always assess whether our legitimate interests are overridden by your interests or fundamental rights and freedoms.
c. Consent of the Data Subject
Where the processing of personal data cannot be based on another legal basis, we process the data on the basis of your consent. This applies in particular to sending marketing communications where consent is required by law and to other specific purposes of which we will inform you before obtaining your consent.
Providing consent is voluntary, and you may withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
Personal Data Retention Period
The Company retains personal data only for as long as necessary to fulfil the purpose for which it is processed and in accordance with applicable legislation. The retention period depends primarily on:
-
the periods prescribed by law or other generally binding legislation;
-
the period specified in the consent provided, but no longer than until such consent is withdrawn, unless another legal basis exists for continued processing;
-
the duration of the contractual relationship and, as a rule, a further ten years after its termination, particularly for compliance with legal obligations and the establishment, exercise, or defence of legal claims, unless applicable legislation specifies a different retention period.
Once the applicable retention period has expired, personal data will be securely deleted or anonymised unless its continued retention is required by law.
How We Protect Personal Data
To protect your personal data, we implement appropriate technical and organisational measures that reflect the nature of the processing and the associated risks. These measures are designed in particular to prevent unauthorised access, loss, misuse, alteration, disclosure, or destruction of personal data.
These measures include in particular:
-
restricting access to personal data to authorised persons only;
-
implementing technical safeguards for information systems and communication tools;
-
providing regular training to employees and other authorised persons;
-
continuously reviewing and updating the security measures in place.
Rights of Data Subjects
In connection with the processing of your personal data and subject to the conditions laid down by applicable legislation, you have in particular the right to:
-
obtain confirmation as to whether we process your personal data and request access to such data;
-
request the correction of inaccurate personal data or the completion of incomplete personal data;
-
request the erasure of your personal data;
-
request the restriction of its processing;
-
receive your personal data in a structured, commonly used, and machine-readable format and, where applicable, request its transfer to another controller;
-
object to processing based on our legitimate interests, including processing for direct marketing purposes;
-
withdraw your consent at any time, without affecting the lawfulness of processing carried out before its withdrawal;
-
lodge a complaint with the Office for Personal Data Protection or another competent supervisory authority.
These rights do not apply automatically in every case. Their applicability depends in particular on the purpose of the processing, the legal basis relied upon, and other conditions laid down by applicable legislation.
How to Exercise Your Rights
You may exercise your rights in connection with the processing of personal data with the Controller, COMPI-S s.r.o., in any of the following ways:
-
by email at ab@compis.com;
-
in writing at Ondříčkova 609/27, Žižkov, 130 00 Prague 3, Czech Republic.
We will process your request without undue delay and, in any event, within the time limits prescribed by applicable legislation. Where we have reasonable doubts concerning your identity, we may ask you to provide additional information necessary to verify it.
You also have the right to lodge a complaint with the competent supervisory authority, particularly if you believe that your personal data is being processed in breach of applicable legislation.
The competent supervisory authority in the Czech Republic is:
Office for Personal Data Protection
Pplk. Sochora 27
170 00 Prague 7
Czech Republic
www.uoou.gov.cz
To protect your personal data, we implement appropriate technical and organisational measures that reflect the nature of the processing and the associated risks. These measures are designed in particular to prevent unauthorised access, loss, misuse, alteration, disclosure, or destruction of personal data.
These measures include in particular:
-
restricting access to personal data to authorised persons only;
-
implementing technical safeguards for information systems and communication tools;
-
providing regular training to employees and other authorised persons;
-
continuously reviewing and updating the security measures in place.
The Company retains personal data only for as long as necessary to fulfil the purpose for which it is processed and in accordance with applicable legislation. The retention period depends primarily on:
-
the periods prescribed by law or other generally binding legislation;
-
the period specified in the consent provided, but no longer than until such consent is withdrawn, unless another legal basis exists for continued processing;
-
the duration of the contractual relationship and, as a rule, a further ten years after its termination, particularly for compliance with legal obligations and the establishment, exercise, or defence of legal claims, unless applicable legislation specifies a different retention period.
Once the applicable retention period has expired, personal data will be securely deleted or anonymised unless its continued retention is required by law.
What Personal Data We Process
We process personal data primarily for the following purposes:
-
entering into and performing contracts and providing related services;
-
communicating with customers, business partners, and other relevant persons;
-
improving and developing our products and services;
-
sending marketing communications where your consent is required;
-
recording and managing marketing consents, objections, and communication preferences;
-
maintaining customer, business, and contractual records;
-
establishing, exercising, and defending legal claims;
-
managing user accounts and online services;
-
ensuring the security of information systems and protecting them against misuse.
Purposes of Personal Data Processing
-
Identification data: title, first name, surname, personal identification number, date of birth, Company ID number, Tax ID number, gender, and identity document details
-
Contact details: permanent address, correspondence address, registered office, place of business, telephone number, and email address
-
Other data: bank account details and photographs
Your personal data is processed by COMPI-S s.r.o., with its registered office at Ondříčkova 609/27, Žižkov, 130 00 Prague 3, Company ID No.: 274 12 725 (hereinafter referred to as the “Controller”).
The Controller processes your personal data in accordance with the GDPR and other applicable legislation. The Controller will provide you with information on the methods and purposes of personal data processing. You may also exercise with the Controller all rights granted to you under the GDPR in connection with the processing of your personal data.
The Controller processes personal data in connection with its business activities, particularly for the preparation and implementation of property development projects in the Czech Republic, the provision of related products and services, and the management, operation, or rental of real estate.
Personal data may also be processed in connection with other products and services provided by the Controller, including products and services in the leisure sector.
Marketing Communications
and Centralised Marketing Consent
Through marketing communications, we may provide you with relevant information about our projects, products, services, and news, including information about current projects of COMPI-S s.r.o.
We may send you marketing communications:
-
on the basis of your voluntary consent; or
-
where permitted by law, on the basis of our legitimate interests, particularly if you are an existing customer and we are informing you about our own similar products or services.
Providing consent to receive marketing communications is voluntary and is not a condition for entering into a contract or using our services. You may withdraw your consent at any time. Following its withdrawal, we will stop contacting you to the extent that the marketing communications were based on that consent.
You may object at any time to the processing of your personal data for direct marketing purposes or opt out of receiving further marketing communications, for example by using the unsubscribe link included in each marketing message. Once you do so, we will no longer use your personal data for that form of marketing communication.
We manage your marketing preferences consistently and always:
-
respect your choices;
-
use only the communication channels you have selected;
-
communicate only to the extent permitted by your consent or applicable legislation.
Marketing communications are always kept separate from communications that are:
-
contractual;
-
service-related or operational;
-
required by law.
Therefore, withdrawing your marketing consent, objecting to direct marketing, or opting out of marketing communications will not affect communications necessary for the performance of a contract, the provision of services, or compliance with our legal obligations.
Final Provisions
This Privacy Policy takes effect on 19 July 2026. The Controller may update it from time to time, particularly in response to changes in applicable legislation, personal data processing practices, or the services provided. The current version is always available on the website of COMPI-S s.r.o.
Further information about personal data protection and the rights and obligations arising from the General Data Protection Regulation (GDPR) is available on the websites of the European Commission and the Office for Personal Data Protection.
Prague, 19 July 2026