← Back to home page

Privacy Policy

Last updated: 1 July 2026

1. Data Controller

The controller of personal data for the NaLekci.cz platform is:

Amicora s.r.o., ID No.: 30034337, with its registered office at Koželužská 3034/1, Jižní Předměstí, 301 00 Plzeň, registered in the Commercial Register under file No. C 49035 vedená u Krajského soudu v Plzni (the "Operator").

Email: info@amicora.cz

In relation to the data the Operator processes when issuing documents on a Partner's behalf and account (Article 6 of the Terms of Use for Partners), the Operator acts as a processor of the buyer's personal data under the Partner's instructions as controller. In relation to its own archive of issued documents, to the purposes described in Article 3, and to the performance of its own legal obligations (e.g. DAC7 reporting), the Operator acts as controller.

2. What personal data we process

2.1. Partner data (instructors and organizations)

  • Identification data: first name, last name, company name, company ID (IČO)
  • Contact data: email, phone, address, website
  • Login credentials: email, password (encrypted)
  • Billing data: bank details, billing address
  • Data for the DAC7 reporting obligation under Act No. 164/2013 Coll.: for natural persons the date of birth (and, where the person has no TIN, the place of birth), primary address, tax identification number (TIN) and the state of its issue, VAT ID, company ID (IČO), state of tax residence, for legal persons details of a permanent establishment in the EU, financial account identifier (where available to the Operator), and the total consideration for reportable activities, the number of such activities and related fees and commissions per calendar quarter

2.2. User data (lesson participants)

  • First name and last name
  • Contact data: email, phone
  • Reservation data: selected lesson/event, date, reservation status, notes
  • Business buyer identification, if purchasing as a company: company ID (IČO), VAT number, company name and address — collected only when the customer selects "Buying as a business" at checkout; these details appear on the issued document

2.3. Technical data

  • IP address
  • Browser and device type
  • Cookies and similar technologies (see the Cookie Policy for details)
  • Technical application error records (diagnostics)

2.4. Instagram integration data

If an instructor connects their Instagram account, we store the Instagram account name and an encrypted access token, used solely to publish lesson posts on the instructor's behalf at their request. Disconnecting Instagram in Account settings immediately and permanently deletes this token from our systems.

3. Purposes and legal bases of processing

We process personal data for the following purposes, in each case on the stated legal basis:

  • Service provision — managing reservations, communicating with guests, operating the application: performance of a contract (Art. 6(1)(b) GDPR)
  • Invoicing and customer support: performance of a contract (Art. 6(1)(b) GDPR); for the statutory particulars of issued documents, compliance with a legal obligation (Art. 6(1)(c) GDPR)
  • Improving services, security, fraud prevention and application error diagnostics: the Operator's legitimate interest in a functional and secure platform (Art. 6(1)(f) GDPR)
  • Accounting and tax obligations: compliance with a legal obligation (Art. 6(1)(c) GDPR)
  • DAC7 reporting obligation — collecting, verifying and reporting Partner data to the tax authority under Act No. 164/2013 Coll.: compliance with a legal obligation (Art. 6(1)(c) GDPR); providing the data is a statutory requirement and, where it is not provided, the Operator is obliged to proceed under Section 14zzc of that Act (closure of the Partner's account)
  • Instructor requests — where you tell us through the form on our home page which sport, city or specific coach you would like to see on the platform, we process the e-mail address you provide in order to reply to you once such an instructor joins, and we use the sport and city in aggregate form to decide which instructors to approach: consent (Art. 6(1)(a) GDPR)
  • Marketing — sending commercial communications: consent (Art. 6(1)(a) GDPR)

No automated individual decision-making or profiling producing legal or similarly significant effects within the meaning of Art. 22 GDPR takes place.

4. Data retention periods

We retain personal data for the following periods:

  • Partner data: for the duration of the contractual relationship + 10 years (statutory archiving)
  • DAC7 due diligence and data collection documentation: 10 years from the end of the reportable period to which it relates (Act No. 164/2013 Coll.)
  • Reservation data: 3 years from the date of reservation
  • Marketing data: until consent is withdrawn
  • Instructor requests (Article 3): 24 months from submission, or until consent is withdrawn, whichever comes first
  • Technical data: 1 year

Accounting and tax documents that have been issued, including the customer identification details stated on them (name, e-mail, and where applicable ID number, VAT number and registered office), are retained for the period laid down by law and for the period necessary for the establishment, exercise or defence of legal claims. For tax documents this is 10 years from the end of the tax period in which the supply took place (Section 35 of the VAT Act). Other documents are retained as part of our own accounting records evidencing the intermediation commission (Section 31 of the Accounting Act) and for the period for assessing tax (Section 148 of the Tax Code), and further in case of a dispute, complaint or chargeback. A request for erasure of personal data does not extend to issued documents — Article 17(3)(b) GDPR (compliance with a legal obligation) and Article 17(3)(e) GDPR (establishment, exercise or defence of legal claims).

5. Recipients of personal data

Personal data may be disclosed to the following recipients:

  • Hosting and database service providers
  • Email service providers
  • The provider of our application error monitoring tool (Sentry)
  • Accounting and tax advisors
  • Public authorities (where required by law)
  • Financial Administration of the Czech Republic (to the extent of the DAC7 reporting obligation); the tax administrator further exchanges the data automatically with the tax administrations of other EU Member States according to the Partner's state of tax residence
  • Payment service providers — only from the day online payments are made available in the application

We currently use no third-party analytics or marketing tools; if we introduce any, this policy will be updated in advance.

6. Transfers to third countries

Some of our suppliers (for example the provider of the error monitoring tool) may process data outside the European Economic Area. In such cases we ensure appropriate data protection safeguards in accordance with the GDPR, in particular standard contractual clauses or an adequacy decision.

7. Your rights

In connection with the processing of personal data, you have the following rights:

  • Right of access: to obtain information about the processing of your data
  • Right to rectification: to request correction of inaccurate data
  • Right to erasure: to request deletion of data (the "right to be forgotten")
  • Right to restriction of processing: to request that processing be restricted
  • Right to data portability: to receive your data in a structured format
  • Right to object: to processing based on legitimate interest
  • Right to withdraw consent: to withdraw consent at any time
  • Right to lodge a complaint: with the Office for Personal Data Protection (www.uoou.gov.cz)

For processing carried out in compliance with a legal obligation (in particular DAC7, accounting and tax obligations), the right to erasure cannot be exercised for as long as the obligation lasts and the right to object does not apply to it; your other rights remain unaffected.

8. Data security

We implement appropriate technical and organizational measures to protect personal data, including:

  • Encryption of data in transit (HTTPS/TLS)
  • Password encryption
  • Regular data backups
  • Restricted access to data
  • Regular security audits

9. Changes to this policy

We may update this policy from time to time. We will notify you of any significant changes by email or through the application.

10. Contact

To exercise your rights or with any questions regarding personal data protection, please contact us:

  • Legal name: Amicora s.r.o.
  • ID No.: 30034337
  • Registered office: Koželužská 3034/1, Jižní Předměstí, 301 00 Plzeň
  • Commercial Register: C 49035 vedená u Krajského soudu v Plzni
  • Email: info@amicora.cz

← Back to the version list

© 2026 NaLekci.cz. All rights reserved.