Privacy Policy (GDPR)
A note on this translation
This is an informative English translation of our Czech privacy policy, provided for the convenience of readers who do not speak Czech. In the event of any discrepancy between the two versions, the Czech version prevails.
1) Controller
FortiCore s.r.o.
Registered office: U půjčovny 953/4, 110 00 Prague 1 – Nové Město, Czech Republic
Company ID (IČO): 22203605
Registered at the Municipal Court in Prague, file C 412548
Email for data protection matters: info@forticore.eu
FortiCore acts as the controller of personal data under Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 Coll., on personal data processing.
2) What this is about
This document explains what personal data we process, why, for how long, and what rights you have. We update it as our practice and the law change.
Our services are aimed primarily at business customers (B2B) in digital transformation, process automation and the deployment of artificial-intelligence tools — for example process analysis and mapping, integration of company systems, sales and marketing automation, implementation and operation of AI solutions, and training. Neither our websites nor our services are directed at children, and we do not knowingly process children's data.
3) What data we process, why, and for how long
3.1 Identification and billing data
- Examples
- first name, surname, job title, company, company/VAT ID, address
- Purpose
- concluding and performing the contract, managing the customer relationship, invoicing
- Legal basis
- performance of a contract; legal obligation (accounting and tax rules)
- Retention
- for the term of the contract + 3 years; accounting records 5–10 years as required by law
3.2 Contact details
- Examples
- email, phone
- Purpose
- business communication, project coordination, support
- Legal basis
- performance of a contract / legitimate interest (effective communication)
- Retention
- for the term of the contract + 3 years
3.3 Access, authentication and operational logs
- Examples
- IP address, user ID, timestamps, technical events
- Purpose
- securing the services, audit trail, incident response, preventing misuse
- Legal basis
- performance of a contract; legitimate interest; legal obligation (depending on the service)
- Retention
- typically 6–24 months (depending on the service configuration and contract)
3.4 Analysis and project data
- Examples
- outputs of process diagnostics and analysis, project documentation, access to and data from connected systems provided by the client to the extent necessary to deliver the service
- Purpose
- delivering the service, reporting, recommending next steps, follow-up support
- Legal basis
- performance of a contract
- Retention
- for the duration of the project + 12 months (warranty support and complaint handling); after that, erasure or handover to the client as agreed. Access to client systems is created in the client's own name and we no longer hold it after handover.
3.5 Support data
- Examples
- ticketing, records of communication
- Purpose
- resolving requests and incidents
- Legal basis
- performance of a contract / legitimate interest
- Retention
- for the duration of the case + 2 years
3.6 Recruitment
- Examples
- CV, cover letter, interview notes, references
- Purpose
- the selection process
- Legal basis
- legitimate interest; consent (for future positions)
- Retention
- for the duration of the selection process; with consent, a maximum of 1 year
3.7 Marketing (with consent)
- Examples
- email address for the newsletter, preferences
- Purpose
- sending news and invitations to webinars and events
- Legal basis
- consent
- Retention
- until consent is withdrawn / a maximum of 5 years
3.8 Web and technical data
- Examples
- IP address, cookies, device and browser identifiers
- Purpose
- site functionality, security, basic statistics
- Legal basis
- essential cookies – legitimate interest; analytics and marketing – consent
- Retention
- see the Cookies section below
Note: where a retention period is set by law (for example accounting or tax rules), we follow those periods. Otherwise we keep data only as long as the purpose requires and in line with industry standards.
4) Where the data comes from
- directly from you (or your colleagues) during enquiries, contracting and communication,
- from public registers (the Czech ARES and Commercial Register),
- in the course of providing our services (operational logs, data from connected systems within the agreed scope).
5) Who we share data with (recipients)
Access is limited to the employees and processors who genuinely need it:
- providers of IT and cloud services (hosting, email, ticketing, log management and monitoring tools),
- accountants, tax advisers and legal counsel,
- operators of the automation and AI platforms used on a project (for example Make, n8n, HubSpot, Google Workspace, AWS) — to the extent necessary to deliver the service,
- subcontractors and specialists involved in delivery (under NDAs and data processing agreements),
- public authorities, where required by law.
Transfers outside the EEA: where these occur (for example with some cloud tools), they take place under appropriate safeguards required by the GDPR, in particular standard contractual clauses. We will provide specific details on request.
6) Security
We apply technical and organisational measures appropriate to the risk — access control, encryption, segmentation, audit logs, backups and a need-to-know policy. We review and update these measures regularly.
Automated decision-making and profiling: we do not carry these out.
7) Your rights
You have the following rights, to the extent the GDPR provides them:
- access to your data and information about the processing,
- rectification of inaccurate or incomplete data,
- erasure (the "right to be forgotten"), where the statutory conditions are met,
- restriction of processing,
- data portability, where processing is based on consent or a contract and is carried out by automated means,
- objection to processing based on legitimate interest (including direct marketing),
- withdrawal of consent at any time, where consent is the legal basis.
Requests can be made at info@forticore.eu. We will verify your identity before providing any information.
Supervisory authority:
The Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, tel. +420 234 665 111, www.uoou.cz.
8) Marketing communications
If you consent to receiving news from us (newsletter, invitations, materials), you can withdraw that consent at any time:
- using the unsubscribe link in the email, or
- by emailing info@forticore.eu.
Limiting marketing does not affect messages related to the performance of a contract, such as operational and service notices.
9) Cookies
What cookies are
Cookies are small files stored in your browser. Some are essential for the site to work; others (analytics and marketing) we use only with your consent.
The cookies we use
- Technical (essential) – provide the basic functions of the site (sign-in, security, forms).
Legal basis: legitimate interest. Duration: for the session / short-term. - Analytics (for example Google Analytics 4 – the IP address is processed in truncated form, without identifying an individual) – help us improve the site and understand aggregate statistics.
Legal basis: consent. Duration: typically up to 12 months. - Marketing (for example Google Ads, Seznam Sklik, Meta Ads) – allow us to show relevant offers and measure campaign performance.
Legal basis: consent. Duration: as set by the provider, usually up to 12 months.
Cookies and storage currently in use
We do not currently deploy any analytics or marketing cookies. Before we do, we will add them to this list and only activate the tools after you have given consent.
You can change or withdraw consent at any time via the cookie bar or the "Cookie settings" link in the footer.
10) Retention periods (summary)
- contract performance: for the term of the relationship + usually 3 years (protection of legal claims),
- accounting and tax records: 5–10 years as required by law,
- logs and security records: typically 6–24 months, depending on the service,
- recruitment: for the duration of the selection process; with the candidate's consent, a maximum of 1 year,
- marketing with consent: until consent is withdrawn / a maximum of 5 years.
Once these periods expire we securely delete or anonymise the data.
11) If you don't provide data
For data necessary to conclude and perform a contract or to deliver a service, provision is mandatory; without it we cannot deliver the service. For activities that depend on consent, provision is voluntary.
12) Server logs
When you visit the site, our servers automatically record requests (IP address, date and time, URL, user agent, referrer, cookies). These logs serve security, functionality and diagnostics, and are not used to identify individual visitors directly.
13) Changes to this document
We may update this policy, for example when the law or our processes change. We will always state the new effective date and announce material changes in an appropriate way.
This version is effective from 6 September 2026 and replaces the version published on our previous website.
Contact
Please send questions and requests to info@forticore.eu.