Start Creating

GDPR Compliance

Last Updated: January 2024

General Data Protection Regulation (GDPR)

ZelenaZona is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines how we comply with GDPR requirements and explains your rights as a data subject.

Data Controller Information

Data Controller: ZelenaZona
Address: Vinohradská 28, Prague 2, 120 00, Czech Republic
Email: [email protected]

Lawful Basis for Processing

We process your personal data based on one or more of the following lawful bases:

1. Consent (Article 6(1)(a))

When you provide explicit consent for specific processing activities, such as receiving marketing communications or using cookies on our website.

2. Contract (Article 6(1)(b))

Processing necessary to fulfill our contractual obligations when you enroll in our masterclasses or use our services.

3. Legal Obligation (Article 6(1)(c))

Processing required to comply with legal requirements, such as tax and accounting obligations.

4. Legitimate Interests (Article 6(1)(f))

Processing necessary for our legitimate business interests, such as improving our services, preventing fraud, and maintaining security.

Your GDPR Rights

Under the GDPR, you have the following rights regarding your personal data:

Right to Access (Article 15)

You have the right to request access to the personal data we hold about you and receive information about how we process it.

Right to Rectification (Article 16)

You can request correction of inaccurate or incomplete personal data.

Right to Erasure (Article 17)

Also known as the "right to be forgotten," you can request deletion of your personal data under certain circumstances.

Right to Restriction of Processing (Article 18)

You can request that we limit the processing of your personal data in specific situations.

Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used format and transmit it to another controller.

Right to Object (Article 21)

You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent (Article 7(3))

Where processing is based on consent, you have the right to withdraw that consent at any time.

Right to Lodge a Complaint (Article 77)

You have the right to file a complaint with your local supervisory authority if you believe we have violated your data protection rights.

How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us at:

Email: [email protected]
Subject Line: "GDPR Request"

Please include the following information in your request:

We will respond to your request within one month, as required by the GDPR. In complex cases, we may extend this period by two additional months and will inform you of the extension.

Data We Collect

We collect and process the following categories of personal data:

How We Protect Your Data

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:

International Data Transfers

Your personal data is primarily processed and stored within the European Economic Area (EEA). If we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses.

Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects on you.

Data Breach Notification

In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with Article 34 of the GDPR.

Updates to This Notice

We may update this GDPR compliance notice periodically. We will notify you of significant changes by posting a notice on our website or sending you an email.

Supervisory Authority

If you are located in the Czech Republic, the relevant supervisory authority is:

Office for Personal Data Protection (ÚOOÚ)
Pplk. Sochora 27
170 00 Prague 7
Czech Republic
Website: www.uoou.cz

Contact Us

For any questions about our GDPR compliance or to exercise your rights, please contact us:

Email: [email protected]
Address: Vinohradská 28, Prague 2, 120 00, Czech Republic