Privacy and cookies – Terasy Sedlec
Effective from: 17 September 2026
Informative translation. In case of any discrepancy, the Czech version prevails.
This document explains how personal data are processed in connection with the operation of Terasy Sedlec accommodation and the website https://www.terasysedlec.cz/.
1. Data controller
Responsibility for the processing of personal data in connection with Terasy Sedlec is borne by:
- Ing. Emil Buřič, Company ID (IČO): 69803218, registered address: Sadová 563, 270 61 Lány, Czech Republic,
- Michaela Buřičová, Company ID (IČO): 71306587, registered address: Sadová 563, 270 61 Lány, Czech Republic,
hereinafter referred to as the “Controller”.
Reservations: rezervace@terasysedlec.cz
Privacy contact: gdpr@terasysedlec.cz
Telephone: +420 602 338 432
The Controller has not appointed a data protection officer unless such an obligation arises under applicable law.
2. Legal framework
Personal data are processed in particular under:
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR),
- Czech Act No. 110/2019 Coll., on the Processing of Personal Data,
- Czech Act No. 89/2012 Coll., the Civil Code,
- Czech Act No. 634/1992 Coll., on Consumer Protection,
- Czech Act No. 326/1999 Coll., on the Residence of Foreign Nationals in the Czech Republic,
- Czech Act No. 565/1990 Coll., on Local Fees,
- applicable accounting and tax regulations,
- Czech Act No. 127/2005 Coll., on Electronic Communications, as regards the storage of non-technical cookies and similar technologies.
The former reference to Czech Act No. 101/2000 Coll., on Personal Data Protection, is no longer current for the general regulation of personal-data processing; Czech Act No. 110/2019 Coll. is the Czech adaptation legislation for the GDPR.
3. Personal data we may process
Depending on the specific situation, the following data in particular may be processed:
- identification data: first name, surname, date of birth,
- contact data: e-mail address, telephone number, address,
- booking and stay data: dates, number of guests, selected unit or service, price, cancellation and related communication,
- billing and payment data,
- data required by law for guest records, the local accommodation fee or reporting the stay of foreign nationals,
- identity-document data only to the extent that recording or verification is required by law,
- data that you voluntarily provide in a message, e-mail or contact form,
- technical data about use of the website, such as IP address, device type, browser, logs and data obtained through cookies or similar technologies,
- data necessary for handling complaints, damage, security incidents or legal claims.
The Controller will not request more data than is reasonably necessary for the relevant purpose.
4. Purposes and legal bases for processing
4.1 Enquiries, bookings and performance of the contract
Purpose: handling an enquiry, creating and administering a booking, communication before, during and after the stay, and providing accommodation and related services.
Legal basis: Article 6(1)(b) GDPR – processing is necessary in order to take steps at the request of the data subject prior to entering into a contract and for performance of the contract.
Consent is not required for this processing. Withdrawal of marketing consent therefore does not affect data that must continue to be processed because of a contract or a legal obligation.
4.2 Compliance with the accommodation provider’s legal obligations
Purpose: compliance with record-keeping, tax, accounting, local-fee and reporting obligations.
Legal basis: Article 6(1)(c) GDPR – compliance with a legal obligation.
This may include in particular:
- records for the local accommodation fee,
- recording and reporting the stay of foreign nationals,
- keeping accounting and tax documents,
- providing data to authorised public authorities where required by law.
4.3 Protection of rights and handling damage or disputes
Purpose: recording and enforcing receivables, defending legal claims, handling complaints, insurance events, damage or security incidents.
Legal basis: Article 6(1)(f) GDPR – the Controller’s legitimate interest in protecting its rights, property and legal claims.
You have the right to object to processing based on a legitimate interest; the Controller will assess the objection in accordance with Article 21 GDPR.
4.4 Website security and operation
Purpose: technical operation of the website, prevention of abuse, error detection, cybersecurity and necessary operational analytics.
Legal basis: depending on the particular operation, especially Article 6(1)(f) GDPR – legitimate interest in the secure and functional operation of the website.
Technical cookies that are strictly necessary for the website to function may be used without prior consent, but they must be described in the information provided to users.
4.5 Analytics, marketing and other non-technical cookies
Purpose: measuring traffic, evaluating use of the website, personalisation, marketing or loading optional third-party services.
Legal basis: the relevant non-technical cookies and similar technologies are activated only after the user has given prior consent, unless the law provides otherwise. Any subsequent processing of personal data must also have a legal basis under the GDPR.
Consent must be freely given, specific, informed and as easy to withdraw as it was to give.
4.6 Commercial communications
If you wish to receive a newsletter or other commercial communications, processing will take place only where there is an appropriate legal basis under the GDPR and Czech Act No. 480/2004 Coll. Where sending is based on consent, you may withdraw that consent at any time. Every commercial communication must include a simple way to unsubscribe.
5. Is providing the data mandatory?
Data necessary for entering into and performing the contract are a contractual requirement. Without them, it may not be possible to create a booking or provide the service.
Data required by law are a statutory requirement. If they are not provided, the Accommodation Provider may be required to refuse accommodation where it would otherwise be unable to fulfil a legal obligation.
Data for marketing or other optional purposes are provided voluntarily, and not providing them does not affect your ability to book accommodation.
6. Retention periods
We retain personal data only for as long as necessary for the relevant purpose and in accordance with statutory retention periods.
Typically:
- enquiries not followed by a booking: for the time necessary to handle the enquiry, generally no longer than 12 months after the last communication unless there is a reason for longer retention,
- booking and contractual data: for the duration of the contractual relationship and subsequently for the period necessary to protect legal claims, generally at least for the general limitation period; if a dispute is ongoing, for the duration of that dispute,
- accounting and tax documents: for the period laid down by the applicable accounting and tax rules, typically 5 to 10 years depending on the type of document and the Controller’s status,
- records for the local accommodation fee: for the statutory record-keeping period of 6 years from the last entry in the register,
- data on accommodated foreign nationals in the house register / registration forms: in accordance with the Czech Act on the Residence of Foreign Nationals, typically 6 years,
- data processed on the basis of consent: until consent is withdrawn or until the period for which consent was given expires,
- cookies: for the period stated in the cookie settings or the list of individual cookies; consent can be changed or withdrawn at any time.
After the relevant period has expired, the data will be securely deleted or anonymised unless further retention is required by law or by an ongoing legal claim.
7. Recipients and processors
Personal data may be disclosed, to the extent necessary, in particular to:
- web-hosting, IT support and website-administration providers,
- booking-system providers and distribution channels,
- accounting, tax or legal advisers,
- banks and payment-service providers,
- e-mail or communication-service providers,
- analytics, mapping or marketing technology providers where you have permitted their use,
- insurers when handling an insurance event,
- public authorities where disclosure is required or permitted by law.
If you book through Booking.com or another external portal, that provider will generally also process some personal data under its own terms and privacy policy. We recommend reviewing those documents directly with the relevant provider.
Where a service provider acts as a processor, the Controller must have the appropriate agreement in place under Article 28 GDPR where that obligation applies.
8. Transfers to third countries
Some technology providers may also process personal data outside the European Economic Area.
Where such a transfer takes place, an appropriate legal mechanism must be in place, in particular:
- an adequacy decision of the European Commission,
- the EU–US Data Privacy Framework for certified recipients,
- the European Commission’s Standard Contractual Clauses and, where necessary, supplementary measures,
- or another mechanism permitted by Chapter V GDPR.
Specific information about the recipient and transfer mechanism will be available in the cookie settings or on request where the transfer relates to the relevant processing.
9. Automated decision-making
In the ordinary operation of Terasy Sedlec, the Controller does not carry out automated individual decision-making that would have legal or similarly significant effects on a guest, unless explicitly stated otherwise for a particular service.
10. Your rights
Subject to the conditions of the GDPR, you have in particular the right to:
- obtain confirmation as to whether your personal data are being processed and access those data,
- request correction of inaccurate data or completion of incomplete data,
- request erasure where the statutory conditions are met,
- request restriction of processing,
- receive data in a structured, commonly used and machine-readable format and, where applicable, transmit them to another controller if the conditions for data portability are met,
- object to processing based on a legitimate interest,
- withdraw consent at any time where processing is based on consent; withdrawal does not retrospectively affect the lawfulness of processing carried out before withdrawal,
- lodge a complaint with a supervisory authority.
Please note that the right to erasure is not absolute. Data cannot be erased where further retention is required by law or necessary for the establishment, exercise or defence of legal claims.
11. How to exercise your rights
Requests can be sent in particular to:
or in writing to:
Sadová 563, 270 61 Lány, Czech Republic
If there are doubts about the applicant’s identity, the Controller may request reasonable identity verification in order to prevent disclosure of data to an unauthorised person.
12. Supervisory authority
The supervisory authority is:
Office for Personal Data Protection (Úřad pro ochranu osobních údajů)
Pplk. Sochora 27
170 00 Praha 7
Czech Republic
Web: https://uoou.gov.cz/
13. Cookies and similar technologies
13.1 What are cookies?
Cookies are small data files stored on a website visitor’s device. Other technologies may perform a similar function, for example local storage or identifiers used by embedded third-party content.
13.2 Cookie categories
The website may use in particular:
- Necessary / technical cookies – required for basic operation, security and website functionality. These cookies cannot be disabled within the service where they are genuinely necessary.
- Preference cookies – store user choices.
- Analytics cookies – help measure website traffic and usage.
- Marketing cookies – used for advertising, remarketing or measuring marketing campaigns.
- Third-party cookies and technologies – may be created, for example, when a map, video, booking widget or other embedded content is loaded.
13.3 Consent
Non-technical cookies must not be activated before consent is given unless the law permits another regime.
The cookie banner must allow users to:
- accept optional cookies,
- reject optional cookies as easily as accepting them,
- configure individual categories,
- change or withdraw consent at any later time.
Merely visiting the website, continuing to browse, a pre-ticked option or inactivity do not constitute valid consent.
13.4 Google Maps and other embedded services
If the website uses Google Maps or other third-party content that stores or reads non-technical cookies before loading, or otherwise processes data for optional purposes, such content must be blocked until the relevant consent is given or replaced with a static element.
13.5 List of specific cookies
Visitors must have access to an up-to-date list of the cookies and similar technologies actually used on the website, including in particular:
- name,
- provider,
- purpose,
- category,
- validity / retention period,
- information about any transfer outside the EEA.
The most reliable approach is to generate this list directly from the consent-management platform in use so that it reflects the website’s actual configuration.
14. Security
The Controller takes appropriate technical and organisational measures to protect data against unauthorised access, loss, alteration or misuse. Access to data is limited to persons who need it to perform their duties and who are bound by appropriate confidentiality obligations or contractual rules.
15. Changes to this document
This document may be updated, in particular following changes to legislation, systems used or processing purposes. The current version will always be published on the website.
This version is effective from 17 September 2026.
