Personal data processing policies 

 Website: www.sacredprague.com
Controller: Martina Bea Mrackova
Company ID (IČO): 03695182
Registered address: Lomená 278, 252 25 Zbuzany, Czech Republic
Privacy contact: support@sacredprague.com

1. Purpose and scope
This Privacy Notice explains how Martina Bea Mrackova (the “Controller”) processes personal data of visitors to www.sacredprague.com (the “Website”), customers, prospective customers, subscribers, participants in courses or events, persons contacting support, suppliers and their contact persons, and, where relevant, job applicants.

The Controller processes personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”), applicable Czech data-protection legislation and other applicable laws. The Controller determines the purposes and means of processing unless a third party acts as an independent controller under its own notice.

The Controller can be contacted at the registered address above or by e-mail at support@sacredprague.com.

2. Basic terms
Personal data means information relating to an identified or identifiable natural person. Data subject means the person to whom the data relates. Processingincludes collection, recording, organisation, storage, alteration, retrieval, use, disclosure, restriction and deletion. Processor means a person processing data on the Controller’s documented instructions.

The Controller does not intentionally request special categories of personal data. Because the Website and services concern personal and spiritual development, a person may voluntarily disclose information that reveals health, religious or philosophical beliefs or other special-category data in a message, consultation or free-text field. Please do not provide sensitive information unless it is necessary. Where the Controller receives such data, it will process it only where a lawful GDPR exception applies, such as the data subject’s explicit consent or another applicable legal basis, and only to the extent necessary.

3. Categories of data and sources
Depending on the relationship, the Controller may process:

  1. name, surname, title and language preference;
  2. contact and delivery details, including e-mail, telephone and address;
  3. company and billing details, including Company ID and VAT details where supplied;
  4. account login and service-access information;
  5. order, booking, membership, payment-status and contract details;
  6. communications, support requests, complaints and feedback;
  7. information voluntarily supplied in a consultation, course or registration form;
  8. technical data such as IP address, browser, device, approximate location, access times and logs;
  9. cookie identifiers and Website usage, preference and analytics data where permitted;
  10. marketing preferences, consent records and unsubscribe records; and
  11. recruitment information supplied by an applicant, where recruitment is offered.

The Controller receives data directly from the data subject, from the person’s use of the Website or services, from a payment or booking provider, or from another person acting for the data subject. The Controller does not buy personal-data lists for unrelated marketing.

4. Purposes and legal bases
4.1. Website operation and security
The Controller processes technical logs, identifiers and necessary cookies to operate, secure and troubleshoot the Website, prevent abuse, maintain availability and remember essential preferences. The legal basis is the Controller’s legitimate interest in secure and functional online services and, where required, consent.

4.2. Enquiries and pre-contract communication
When a person contacts the Controller, the Controller processes the provided contact details and communication to answer the enquiry, prepare an offer, arrange a booking or take steps at the person’s request before entering into a contract. The legal basis is performance of pre-contractual measures and, where appropriate, legitimate interest in managing enquiries.

4.3. Orders, bookings, memberships and service delivery
For a purchase, booking, course, event, membership, consultation or other service, the Controller processes identification and contact details, order and contract data, access information, communications and payment status to conclude and perform the contract, deliver the service, administer an account, provide support and handle changes or cancellations. The legal basis is performance of the contract.

4.4. Payments and accounting
Payments are processed through the selected payment provider. The Controller normally receives payment status, transaction reference and billing information, not the full payment-card number. The Controller processes invoices, accounting records and related contract information to comply with tax, accounting and other legal obligations. Accounting and tax records are retained for the periods required by law, commonly up to 10 years where Czech tax law requires it.

4.5. Complaints, claims and legal compliance
The Controller may process relevant order, communication and service records to handle complaints, demonstrate compliance, establish, exercise or defend legal claims, recover unpaid amounts and comply with decisions or requests of public authorities. The legal basis is compliance with legal obligations and the Controller’s legitimate interest in protecting rights and property.

4.6. Direct marketing
With consent, the Controller may use contact details and information about interests, purchases or participation to send newsletters, invitations and offers by e-mail or other agreed electronic channels. Consent is voluntary and may be withdrawn at any time by using the unsubscribe link or contacting support@sacredprague.com. Withdrawal does not affect processing already carried out lawfully.

The Controller may also send existing customers information about similar products on the basis of legitimate interest where permitted by applicable law. Every such message will identify the sender and include a simple opt-out. The Controller will stop this processing when the recipient objects or unsubscribes.

4.7. Cookies and analytics
The Website uses strictly necessary cookies for core functions. Optional analytics, personalisation, advertising and remarketing cookies are used only where the visitor gives the required consent through the cookie interface. Consent can be changed or withdrawn through the cookie settings link or by deleting cookies in the browser, subject to the limits of the Website’s consent-management tool. The exact cookies and retention periods should be listed in the Website’s current cookie banner or cookie policy.

4.8. Recruitment
If the Controller advertises a role, applicant data is processed to administer recruitment, communicate with the applicant and take steps before a possible employment or contractor agreement. The legal basis is pre-contractual measures and legitimate interest in selecting candidates. Unless the applicant consents to longer retention, unsuccessful applicant data should be deleted or anonymised no later than three months after the recruitment process ends, unless a longer period is necessary for a legal claim.

5. Retention
The Controller retains personal data only for as long as necessary for the purpose for which it was collected, for the duration of the contract and applicable warranty or complaint period, for the period required by tax and accounting law, or for the period reasonably necessary to establish, exercise or defend legal claims. Specific examples are:

  1. enquiry data: normally until the enquiry is resolved and, where relevant, for the period necessary to document or defend a claim;
  2. customer and contract records: for the contract and the applicable statutory limitation, complaint and warranty periods;
  3. invoices and accounting records: for the statutory retention period, commonly up to 10 years;
  4. marketing data: until consent is withdrawn, an objection is made or the data is no longer needed, plus a limited suppression record to ensure the opt-out is respected;
  5. cookie and analytics data: for the period stated in the cookie settings or by the relevant provider; and
  6. recruitment data: as described in section 4.8.

When the retention period ends, data is deleted or anonymised unless a legal reason requires continued retention.

6. Recipients and processors
To provide the Website and services, the Controller may disclose necessary data to carefully selected processors and independent controllers, including:

  1. hosting, domain, cloud-storage, IT-support and security providers;
  2. payment gateways, banks and accounting or invoicing providers;
  3. e-mail, newsletter, customer-support, booking, video-conferencing and course-platform providers;
  4. analytics, cookie-consent and marketing-technology providers, where consent or another lawful basis exists;
  5. delivery, event, professional, legal, audit and debt-collection providers where relevant; and
  6. public authorities, courts or other recipients where disclosure is required by law.

Processors may process data only on the Controller’s documented instructions, under a data-processing agreement where required, and subject to confidentiality and security obligations. The Controller does not sell personal data.

7. Transfers outside the EEA
Some service providers may process data outside the European Economic Area. Where this occurs, the Controller uses a lawful transfer mechanism under Chapter V GDPR, such as an adequacy decision, European Commission Standard Contractual Clauses, or another legally permitted safeguard. Information about a particular transfer and applicable safeguard may be requested at support@sacredprague.com.

8. Security
The Controller uses reasonable technical and organisational measures appropriate to the risk, including access controls, authentication, confidentiality obligations, backups, service-provider due diligence and measures designed to protect against unauthorised access, loss, alteration or disclosure. No internet transmission or storage system can be guaranteed completely secure. In the event of a qualifying personal-data breach, the Controller will act in accordance with GDPR notification duties.

9. Data-subject rights
Subject to the conditions and limitations in the GDPR, a data subject may request:

- confirmation whether personal data is processed and access to it, together with the information in Article 15 GDPR;
- rectification of inaccurate or incomplete data;
- erasure where the data is no longer necessary, consent is withdrawn and no other legal basis applies, or another Article 17 condition is met;
r- estriction of processing in the cases set out in Article 18 GDPR;
- data portability for data processed by automated means on the basis of consent or contract, where the statutory conditions are met;
- objection to processing based on legitimate interest, including direct marketing; and
- withdrawal of consent at any time where processing is based on consent.
The Controller does not ordinarily make decisions producing legal or similarly significant effects based solely on automated processing, including profiling. If this changes for a particular service, the Controller will provide the information required by GDPR.

To exercise a right, e-mail support@sacredprague.com or write to Martina Bea Mrackova, Lomená 278, 252 25 Zbuzany, Czech Republic. The request should identify the data subject and describe the request. The Controller may ask for proportionate information to verify identity and will respond without undue delay and in any event within the GDPR time limit, normally one month. Requests are normally free; a reasonable fee may be charged or a request refused where legally permitted because it is manifestly unfounded or excessive.

10. Right to complain
A data subject may lodge a complaint with the competent supervisory authority. In the Czech Republic this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, www.uoou.cz. A data subject may also contact the supervisory authority in the EU Member State of their habitual residence, place of work or alleged infringement.

11. Children
The services are not knowingly directed at children below the age at which they can lawfully consent to online services under applicable law. If the Controller learns that it has collected a child’s data without a valid legal basis, it will take reasonable steps to delete it.

12. Changes to this Notice
The Controller may update this Notice to reflect changes in the Website, services, legal requirements or processing. The current version will be published on the Website with its effective date. Material changes will be communicated where required by law.

Last updated: 8 September 2026