/ Privacy
Data Privacy Policy
Last updated: September 2026
RED ARROW s.r.o. takes the protection of your personal data seriously. This privacy policy explains who we are, what personal data we collect through this website and our advisory services, why we process it, on which legal bases, with whom we share it, how long we retain it, and which rights you have under the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and Czech Act No. 110/2019 Coll. on the Processing of Personal Data.
1. Who we are
The controller of personal data processed through this website within the meaning of Article 4(7) GDPR is:
RED ARROW s.r.o.Jiráskova 109/14, Veveří
602 00 Brno
Czech Republic
IČO: 03817156, registered in the Commercial Register maintained by the Regional Court in Brno, Section C, insert 86953
Represented by: Ing. Pavel Drozdek, managing director
Email: info@redarrow.cz
Phone: +420 724 091 014
We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. The person responsible for privacy enquiries at RED ARROW s.r.o. is the managing director, reachable via the contact details above.
For all questions concerning the processing of your personal data, or to exercise the rights described in section 7, please contact us at info@redarrow.cz.
2. Terms you should know before reading this policy
- Personal data means any information relating to an identified or identifiable natural person, such as your name, email address, telephone number or IP address.
- Sensitive personal data means special categories of personal data as defined in Article 9 GDPR (e.g. health data, data revealing political opinions). We do not intentionally collect sensitive personal data through this website.
- Activities information means information collected automatically through persistent identifiers such as cookies, which may be linked to a device without directly identifying you.
- Processing means any operation performed on personal data, such as collection, storage, use, disclosure or erasure.
3. Categories of personal data we process
a) Data you provide to us
When you contact us through the contact form, by email, by phone, or in the course of an advisory engagement, we may receive personal data such as: your first and last name, your professional title, the name of your organisation, your business email address, your telephone number, your postal address, and the content of the message or documents you send us.
b) Data collected automatically when you visit the website
When you visit this website, our web server and, where applicable, third-party providers may collect the following data: the URL of the page requested, the referring URL, the date and time of the request, the HTTP response code, the volume of data transferred, the type and version of your browser and operating system, the language settings of your browser, your IP address (in truncated or full form depending on the tool), and the approximate geographical region derived from the IP address.
c) Data from cookies and similar technologies
We may use cookies and similar technologies to run essential website functions, remember your preferences, protect the contact form against automated abuse (Google reCAPTCHA), and, where you have opted in, to measure aggregated website use. See section 8 for details.
4. Purposes of processing and legal bases
We process personal data on the following legal bases under Article 6(1) GDPR:
| Purpose | Legal basis |
|---|---|
| Responding to enquiries submitted through the contact form, by email or by phone, and taking pre-contractual steps at the request of the person concerned | Art. 6(1)(b) GDPR — steps prior to entering into a contract; Art. 6(1)(f) GDPR — legitimate interest in responding to business enquiries |
| Performance of consulting services and related contractual obligations (invoicing, reporting, deliverables) | Art. 6(1)(b) GDPR — performance of a contract |
| Compliance with statutory obligations (accounting, tax, anti-money-laundering, retention of business correspondence) | Art. 6(1)(c) GDPR — legal obligation |
| Ensuring the technical operation, availability and security of the website, including protection against automated abuse via Google reCAPTCHA | Art. 6(1)(f) GDPR — legitimate interest in a functioning and secure website |
| Aggregated statistical analysis of website use to improve our content, where applicable | Art. 6(1)(a) GDPR — consent (obtained through the cookie banner, where implemented) or Art. 6(1)(f) — legitimate interest for purely first-party, anonymised analytics |
| Occasional marketing communication about our services to existing clients or persons who have contacted us | Art. 6(1)(f) GDPR — legitimate interest, with the right to object at any time |
5. Recipients and international transfers
Access to your personal data is limited to authorised personnel of RED ARROW s.r.o. and to carefully selected processors who provide services to us under written data-processing agreements pursuant to Article 28 GDPR. Such processors may include:
- Our webhosting provider Websupport, s. r. o. (Bratislava, Slovakia) — hosting of the website and email;
- Providers of the contact-form and email-delivery service used on this website;
- Google Ireland Limited — provision of the Google reCAPTCHA service used to protect the contact form against automated abuse (bots);
- Providers of accounting, tax and IT support services;
- Legal advisers, auditors and public authorities where required by law.
Where personal data is transferred to a country outside the European Economic Area (for example, in connection with Google reCAPTCHA), we ensure that the transfer is protected by appropriate safeguards under Chapter V GDPR, such as the European Commission's Standard Contractual Clauses or an adequacy decision.
6. How long we keep your data
We retain personal data only for as long as necessary for the purposes for which it was collected, or for as long as required by applicable law. The following retention periods apply as a rule:
- Contact-form and email enquiries that do not lead to a business relationship: up to 12 months from the last contact;
- Correspondence and documents relating to a consulting engagement: for the duration of the engagement plus the statutory retention periods under Czech accounting, tax and civil law (as a rule, 10 years);
- Server log files: up to 30 days, unless a security incident requires longer retention;
- Data processed on the basis of consent: until consent is withdrawn.
7. Your rights
Subject to the conditions set out in the GDPR, you have the following rights with regard to your personal data:
- Right of access (Art. 15 GDPR) — to obtain confirmation of whether we process personal data concerning you and, if so, a copy of that data;
- Right to rectification (Art. 16 GDPR) — to have inaccurate personal data corrected without undue delay;
- Right to erasure (Art. 17 GDPR) — to have your personal data deleted, where one of the grounds listed in the GDPR applies;
- Right to restriction of processing (Art. 18 GDPR);
- Right to data portability (Art. 20 GDPR) — to receive the personal data you have provided to us in a structured, commonly used and machine-readable format;
- Right to object (Art. 21 GDPR) — to object at any time to processing based on legitimate interests, including direct marketing;
- Right to withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before the withdrawal;
- Right to lodge a complaint with a supervisory authority — in the Czech Republic, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Prague 7, www.uoou.cz).
To exercise your rights, please contact us at info@redarrow.cz. We may ask you to verify your identity before processing your request.
9. Security
We apply appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include transport encryption (HTTPS/TLS), access controls, logging, regular backups and staff confidentiality obligations.
10. Children
This website is directed at professional audiences and is not intended for children under the age of 16. We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this privacy policy from time to time to reflect changes in our processing activities, applicable law or guidance from supervisory authorities. The date of the most recent update is shown at the top of this page.
12. How to contact us
If you have any questions about this privacy policy or the processing of your personal data by RED ARROW s.r.o., please contact us:
RED ARROW s.r.o.Jiraskova 109/14, 602 00 Brno, Czech Republic
Email: info@redarrow.cz
Phone: +420 724 091 014