Legal

Privacy Policy

How we handle personal data on this website and in our work — what we collect, why we are allowed to, how long we keep it, and what you can ask us to do about it.

Last updated: 6 October 2026 · Version: 1.1

1. Who we are

The controller of your personal data is:

Telion Technologies s.r.o.
Pobřežní 370/4, 186 00 Praha 8 – Karlín, Czech Republic
Company ID (IČO): 11686715 · VAT ID (DIČ): CZ11686715
Registered in the Commercial Register kept by the Municipal Court in Prague, file no. C 352892
Email: info@telion.cz

We have not appointed a Data Protection Officer, because we are not required to under Article 37 of the GDPR. Questions about personal data go to the address above.

2. What this policy covers

This policy explains how we handle personal data when you visit telion.cz, write to us, call us, apply for a job with us, or work with us as a client, supplier or partner. It applies to processing governed by Regulation (EU) 2016/679 (the GDPR) and by Czech Act No. 110/2019 Coll., on Personal Data Processing.

Systems we build and operate for our clients are a separate matter: there, the client is the controller and we act as a processor under a data processing agreement. This policy does not describe that processing.

3. What we process, why, and on what basis

Who / whatDataPurposeLegal basisKept for
Website visitorsIP address, browser and device data, pages visited, time of request (server logs)Running and securing the site, diagnosing faults, preventing abuseLegitimate interest — Art. 6(1)(f)90 days
Contact form and emailName, company, email, phone, the content of your messageAnswering your enquiry and the correspondence that followsLegitimate interest — Art. 6(1)(f); steps prior to a contract — Art. 6(1)(b)2 years from the last exchange
Clients, suppliers and partnersContact and identification data of contact persons, contract and delivery recordsPerforming the contract, support, invoicingContract — Art. 6(1)(b); legal obligation — Art. 6(1)(c)Contract term, then the statutory periods below
Accounting and tax recordsInvoices and related documentsStatutory bookkeeping and tax dutiesLegal obligation — Art. 6(1)(c); Act No. 563/1991 Coll., Act No. 235/2004 Coll.5–10 years, as the law requires
Job applicantsCV, cover letter, contact data, interview notesAssessing your applicationSteps prior to a contract — Art. 6(1)(b); consent for a longer hold — Art. 6(1)(a)End of the process, or 1 year with your consent
Analytics, advertising and other optional cookiesUsage data as described in section 4Understanding how the site is used and improving itConsent — Art. 6(1)(a)See section 4

Giving us your data is voluntary. Without the data marked as required in a form, however, we may not be able to answer you or enter into a contract with you.

4. Cookies and analytics

A cookie is a small file stored in your browser. We use them in three groups, and we ask for your consent before setting anything that is not strictly necessary — as required by § 89(3) of Czech Act No. 127/2005 Coll., on Electronic Communications, and by the GDPR.

Strictly necessary cookies

These cookies and similar browser storage keep the site working — for example, they remember your cookie choice and protect the contact form against abuse. We use them without consent, because the site cannot be delivered properly without them. Your cookie choice is stored in your own browser (in local storage) and stays there until you change or clear it.

Analytics cookies

These tell us which pages are read and how visitors move through the site, in aggregate. We set them only if you agree, using Google Analytics 4, provided by Google Ireland Limited, and we keep the data for 14 months. Google Analytics stores identifiers in cookies named _ga and _ga_<ID>, which last up to 2 years. The same measurement covers the other websites we own and operate — including the tikr website, once it is live — so that a visit which moves between them is counted as one visit rather than several.

Advertising cookies

We advertise our own services through Google Ads, provided by Google Ireland Limited. These cookies tell us which advertisement brought you to a landing page and whether the visit led to an enquiry, so that we can judge whether a campaign is worth running. We set them only if you agree. Google Ads stores identifiers in cookies whose names start with _gcl_ (for example _gcl_au and _gcl_aw), which last up to 90 days. For ad measurement, Google acts as a separate controller; see Google’s privacy policy for details.

We do not sell personal data, we do not share it for anyone else’s marketing, and we do not track you across websites that we do not operate ourselves.

Changing your mind

You can withdraw or change your consent at any time — as easily as you gave it — through the cookie settings link in the footer of every page. Withdrawing consent does not affect processing that took place before you withdrew it. You can also block or delete cookies in your browser settings; blocking the strictly necessary ones may break parts of the site.

5. Who else sees your data

We do not sell personal data and we do not share it for anyone else’s marketing. We run the website and our systems on our own infrastructure. We use a small number of service providers who process data for us as processors — on our instructions, under a contract that meets Article 28 of the GDPR:

  • email and office tools — Google Workspace (Google Ireland Limited);
  • website analytics — Google Analytics 4 (Google Ireland Limited).

Some recipients receive data as separate controllers, responsible for their own processing:

  • advertising and campaign measurement — Google Ads (Google Ireland Limited), if you consent to advertising cookies;
  • accounting, legal and tax advisers, under their own professional duties.

We also disclose data where the law requires it — for example to tax authorities, courts or law-enforcement bodies acting within their powers.

6. Transfers outside the EEA

We keep data inside the European Economic Area wherever we can. Our hosting runs on our own infrastructure. Google Ireland Limited acts as our processor for Google Workspace and Google Analytics, and as a separate controller for Google Ads. Where Google transfers data to Google LLC in the United States, that transfer relies on the European Commission’s adequacy decision under Article 45 of the GDPR for the EU–US Data Privacy Framework, in which Google LLC participates. Should that decision cease to apply, Standard Contractual Clauses under Article 46 of the GDPR are in place with Google. A copy of the safeguards is available on request.

7. How long we keep it

The periods are in the table in section 3. When a period ends, we delete the data or anonymise it irreversibly. Where a statutory period applies — accounting, tax, archiving — we keep the record for as long as that law demands, even if you ask for erasure.

8. Your rights

Under Articles 15 to 22 of the GDPR you have the right to:

  • access — be told whether we process your data and get a copy of it;
  • rectification — have inaccurate or incomplete data corrected;
  • erasure — have data deleted where we no longer have a reason to hold it;
  • restriction — have processing paused while a dispute is resolved;
  • portability — receive data you gave us in a machine-readable format, where the processing is based on consent or on a contract;
  • object — object to processing based on our legitimate interest;
  • withdraw consent — at any time, without affecting what was lawful before you withdrew it.

Write to info@telion.cz and we will answer within one month. If a request is complex we may extend that by two further months and will tell you why. We may ask you to confirm your identity before we act, so that we do not hand your data to someone else.

9. Complaints

If you think we handle your data unlawfully, please tell us first — it is usually the fastest way to fix it. You can also lodge a complaint with the Czech supervisory authority:

Úřad pro ochranu osobních údajů (Office for Personal Data Protection)
Pplk. Sochora 27, 170 00 Praha 7, Czech Republic
uoou.gov.cz

10. Automated decision-making

We do not make decisions about you by automated means alone, and we do not profile you in a way that would have legal effects for you.

11. How we protect data

We apply the technical and organisational measures required by Article 32 of the GDPR: encryption in transit, access limited to the people who need it, separate environments for development and production, logging, backups, and confidentiality obligations for everyone on the team. No system is perfect, but we treat a data breach as an incident to be reported and contained, and we notify the supervisory authority and affected people where the GDPR requires it.

12. Children

This website is aimed at businesses. We do not knowingly collect data about children under 16. If you believe a child has sent us personal data, write to us and we will delete it.

13. Changes to this policy

We update this policy when our processing changes or the law does. The current version is always on this page, with the date of the last change at the top. Material changes will be announced on the website and, where we hold your contact details for that purpose, by email.

14. Contact

Questions about this policy or about your data: info@telion.cz, or write to the address in section 1.

Tell us what you’re working on.