Privacy policy
Effective date: to be completed (e.g. 9 February 2026)
Version: 1.0
1) Who is the Data Controller and How to Contact Us
The data controller is CATERING Landa & Dvořák s.r.o., Company ID: 05535875, registered office: Mimoňská 475, 47001 Česká Lípa, Data box ID: xgg5ufg. Contact e-mail: adela@cateringld.cz, phone: +420 737 922 030.
2) What Personal Data We Process
We process personal data that you provide to us or that arises during communication and use of the website, typically:
a) Inquiries and communication
– identification and contact details (first and last name, e-mail, phone number)
– details about the inquiry/event (date, location, number of guests, type of event, preferred scope of services)
– message content and any attachments
– related technical data necessary for delivery and processing (e.g. communication history)
b) Orders and contract performance
– data necessary for concluding and performing the contract, delivering services, invoicing and accounting
– possibly details of contact persons at the event location
c) Allergy and dietary restriction data (may constitute sensitive data)
If you inform us about allergies, intolerances, or other dietary restrictions, this may constitute a special category of personal data (health data). We process such data only to the extent necessary for the safe preparation and provision of catering services and on the basis of your explicit consent (see section 3).
d) Website visit data and cookies
– information about website usage measured by analytics (e.g. pages viewed, traffic source, approximate location, device/browser), via cookies and similar technologies (see section 9)
3) Why We Process Data and the Legal Basis
We process personal data only if we have a legal basis under the GDPR, typically:
a) Handling inquiries and pre-contractual negotiations
Purpose: responding to inquiries, preparing offers, follow-up communication.
Legal basis: performance of a contract and pre-contractual measures (Art. 6(1)(b) GDPR).
b) Conclusion and performance of a contract, delivery of catering
Purpose: provision and delivery of services, logistics, communication regarding event execution.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
c) Accounting, taxes, and legal obligations
Purpose: issuing invoices, accounting, compliance with legal obligations.
Legal basis: legal obligation (Art. 6(1)(c) GDPR).
d) Protection of rights and legitimate interests
Purpose: defense of legal claims, dispute resolution, internal records, website security.
Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
e) Marketing (if used)
Purpose: sending news and offers, possibly remarketing (if enabled).
Legal basis: typically consent for e-mail marketing (Art. 6(1)(a) GDPR) or legitimate interest under the “similar goods/services” regime under local law, always with an easy unsubscribe option; marketing/remarketing cookies require consent (see section 9).
f) Allergies and dietary restrictions (special category of data)
Purpose: preparation of appropriate and safe refreshments.
Legal basis: explicit consent to the processing of special category personal data (Art. 9(2)(a) GDPR). You may withdraw your consent at any time; withdrawal does not affect the lawfulness of processing prior to withdrawal.
4) Sources of Personal Data
We obtain data directly from you (via web forms, e-mail, phone, or in person). Website usage data is obtained via cookies and similar technologies during your visit (if you consent, see section 9).
5) Who Has Access to the Data and Data Sharing
Personal data is accessible only to persons who need it to handle inquiries and provide services (e.g. administration, event staff, accounting).
We also use processors (suppliers) who provide certain services:
– Tally: operation of web forms and storage of responses.
– Google Analytics (provider: Google LLC): website traffic and usage measurement.
– hosting and website management provider: to be completed according to reality (name, Company ID, registered office).
– possibly an accountant/tax advisor and other suppliers necessary for service delivery (always to the extent necessary).
We do not sell or rent personal data.
6) Transfers Outside the EU/EEA
Some suppliers may transfer data outside the EU/EEA (especially services within the Google group). For such transfers, we use appropriate safeguards, typically Standard Contractual Clauses (SCCs) and possibly additional mechanisms.
According to their information, Tally is EU-based and states that data is stored in Europe.
7) Data Retention Period
We retain data only for as long as necessary:
– inquiries without subsequent cooperation: typically 6–12 months from the last communication (for follow-up and documentation)
– contractual relationships and related communication: for the duration of cooperation and thereafter for the limitation period (typically several years)
– accounting and tax documents: according to statutory periods (typically 10 years)
– analytics data: according to the settings in Google Analytics (retention period is configurable)
8) Your Rights
In connection with the processing of personal data, you have the following rights:
– right of access to personal data
– right to rectification of inaccurate data
– right to erasure (if no legal grounds for further retention exist)
– right to restriction of processing
– right to data portability (for processing based on consent or contract)
– right to object (especially to processing based on legitimate interest)
– right to withdraw consent at any time (for processing based on consent)
– right to lodge a complaint with a supervisory authority: Office for Personal Data Protection
To exercise your rights: contact us at adela@cateringld.cz.
9) Cookies and Website Analytics
We use cookies and similar technologies on our website.
a) What cookies are
Cookies are small text files stored on your device by the website. They help ensure website functionality, security, and (if you consent) measurement and improvement of the website.
b) Types of cookies we use
– necessary (technical) cookies: required for website operation; consent is typically not required
– analytical cookies: we use Google Analytics to measure website traffic and user behavior; these cookies are activated only based on your consent
c) Cookies used by Google Analytics
Depending on configuration, cookies such as _ga and _ga_[identifier] may be stored. The exact list may vary depending on settings and implementation.
d) How to give or withdraw consent to analytical cookies
Analytical cookies are activated only after consent via the cookie banner. You may withdraw or modify your consent at any time in the website’s cookie settings (add a footer link: “Cookie Settings”).
e) Managing cookies in your browser
You can also delete or block cookies in your browser settings. In such a case, the website may not function optimally.
10) Personal Data Security
We implement appropriate technical and organizational measures to prevent unauthorized access, alteration, loss, or misuse of personal data. Access to data is restricted to authorized persons and we use secure communication channels.
11) Changes to This Policy
We may update this policy from time to time. The current version is always available on our website.