Privacy Policy
A clear overview of what data we process, why we need it, how long we keep it and what rights you have.
Effective from July 28, 2026
1. Data controller
The controller is AVATOMIS s.r.o., registered office B. Martinů 1885/2, 741 01 Nový Jičín, company ID 09765492, VAT ID CZ09765492, Registered with the Regional Court in Ostrava, Section C, File 84235. Contact: info@avatomis.com, +420 603 537 090.
2. What data we process
We process data you provide through forms, email, phone, orders or cooperation. This typically includes name, company, email, phone, project description, website address, billing data, communication history, project materials and technical data needed for website security.
For website security and source attribution we may process request time, user agent, referrer and campaign parameters (such as UTM or gclid), spam signals and a one-way hash of the IP address. After consent, Google Analytics processes online identifiers and usage data. For published reviews and references we process public author names, ratings, review text and project information.
3. Purposes and legal bases
- enquiries, offers, contract conclusion and performance: steps before entering into a contract and performance of a contract (Article 6(1)(b) GDPR);
- accounting and tax records: compliance with legal obligations (Article 6(1)(c));
- website and form security, source evaluation, operation and protection of legal claims: our legitimate interests (Article 6(1)(f));
- Google Analytics: your consent (Article 6(1)(a));
- public reviews and portfolio references: our legitimate interest in demonstrating experience and trustworthiness (Article 6(1)(f)).
4. Forms and required information
Required form fields are needed to identify the request and reply. Without them we cannot handle the inquiry. A honeypot and other security checks may automatically discard submissions showing spam signals; this is not profiling or a decision producing legal or similarly significant effects.
5. Cookies and analytics
Necessary storage supports forms, security and remembering the cookie choice. Google Analytics operated by Google Ireland Limited starts only after consent. Details, storage periods and a consent reset are available on the Cookies page.
6. Public reviews and references
Reviews are taken from our public Google profile. We compare the displayed author, wording and rating with the public record; we do not independently verify that the reviewer actually purchased a service. You may object to this processing at any time.
7. Recipients and international transfers
Data is disclosed only as necessary to providers of hosting, email, accounting, project management, security and analytics services, and to public authorities where required by law. Google Ireland Limited and its affiliates may process analytics data outside the EEA. Transfers are covered, where applicable, by an adequacy decision including the EU–US Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses.
8. Retention
Unsuccessful enquiries and related notification logs are automatically removed after 12 months. Contract and project data is retained for the cooperation and generally up to 3 years afterwards to protect legal claims; accounting and tax records are retained for the statutory period, generally 10 years. Security and rate-limit records are retained only as long as necessary. Cookie periods are listed on the Cookies page. Public reviews and references remain published while relevant or until a justified objection or deletion request is upheld.
9. Your rights
You may request access, correction, erasure, restriction, objection and data portability where applicable, and may withdraw consent at any time without affecting earlier processing. Send requests to info@avatomis.com; we may reasonably verify identity. You may lodge a complaint with the Czech Data Protection Authority.
10. Automated decision-making
We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects.
11. Security
We use technical and organizational measures such as secured access, permission limits, CSRF protection, anti-spam checks, security headers and reasonable security logging.
12. Updates
This policy may be updated according to changes in services, tools, legal requirements or processing methods. The current version is always available on this page.