Privacy Policy
How we handle your data. Briefly, clearly, GDPR-compliant.
1. Who processes your data
ICT-GROUP s.r.o., Company ID 61676802, VAT ID CZ61676802, registered office Dandova 2593/6, 193 00 Prague 9, Czech Republic, recorded in the Commercial Register at the Prague Municipal Court. We are the controller of personal data we process about you.
GDPR enquiries: [email protected]
2. What data we process and why
- Contact data (name, email, phone, company) — to respond to your enquiry, deliver a quote, invoicing, and managing the customer relationship.
- Operational data (logs, IP address, email) — to secure the service and issue the audit report.
- Marketing data (email after consent) — to send you commercial communications about our services.
- Security scanner data (the domain you submit, DNS / SPF / SSL / HIBP scan results) — solely to issue the audit report; not forwarded anywhere else.
3. Legal basis
- Contract performance — for existing clients (managed IT, invoicing).
- Legitimate interest — for responding to enquiries and business communication.
- Consent — for newsletter, marketing and non-essential cookies (revocable any time).
- Legal obligation — for tax, accounting and archiving legislation.
4. Retention period
- Contractual client data: for the duration of the contract + 10 years of statutory periods (tax, accounting).
- Enquiries that didn't result in a contract: 1 year.
- Marketing data: until consent is withdrawn, max. 3 years.
- Audit data: 90 days (only email + scan results, no credentials, passwords or sensitive client data).
5. Sharing with processors
We share data only with necessary processors with whom we have a Data Processing Agreement in place:
- Microsoft 365 (email, calendar, Bookings) — Microsoft Ireland Operations Ltd., EU
- Cloudflare (CDN, web security, Workers) — Cloudflare Inc., USA, SCCs
- Resend (transactional emails / audit reports) — Resend Inc., USA, SCCs
We don't sell data. We don't transfer outside the EU without Standard Contractual Clauses. We don't process for purposes you haven't consented to.
6. Your rights
Under GDPR you have the right to:
- access your data and obtain a copy,
- rectify inaccurate data,
- erase ("right to be forgotten"),
- restrict processing,
- portability of your data,
- object to processing (especially marketing),
- withdraw consent at any time,
- file a complaint with the Czech Data Protection Authority.
7. How to exercise your rights
Email [email protected] or write to:
ICT-GROUP s.r.o.
Dandova 2593/6, 193 00 Prague 9, Czech Republic
We respond within 30 days of receiving the request. Requests are free of charge. For identity verification we may ask for additional details.
8. Cookies
This website uses cookies. A detailed list, purposes and retention periods are on the Cookies page. You can change consent for non-essential cookies any time via the "Manage consent" button in the bottom-left corner of the website.
9. Policy updates
We update this policy occasionally; the current version is always published here. Last revision: 8 May 2026.
