Legal
Privacy Policy
How we handle personal data on this website and in our work — what we collect, why we are allowed to, how long we keep it, and what you can ask us to do about it.
Last updated: 6 October 2026 · Version: 1.1
1. Who we are
The controller of your personal data is:
Telion Technologies s.r.o.
Pobřežní 370/4, 186 00 Praha 8 – Karlín, Czech Republic
Company ID (IČO): 11686715 · VAT ID (DIČ): CZ11686715
Registered in the Commercial Register kept by the Municipal Court in Prague, file no. C 352892
Email: info@telion.cz
We have not appointed a Data Protection Officer, because we are not required to under Article 37 of the GDPR. Questions about personal data go to the address above.
2. What this policy covers
This policy explains how we handle personal data when you visit telion.cz, write to us, call us, apply for a job with us, or work with us as a client, supplier or partner. It applies to processing governed by Regulation (EU) 2016/679 (the GDPR) and by Czech Act No. 110/2019 Coll., on Personal Data Processing.
Systems we build and operate for our clients are a separate matter: there, the client is the controller and we act as a processor under a data processing agreement. This policy does not describe that processing.
3. What we process, why, and on what basis
| Who / what | Data | Purpose | Legal basis | Kept for |
|---|---|---|---|---|
| Website visitors | IP address, browser and device data, pages visited, time of request (server logs) | Running and securing the site, diagnosing faults, preventing abuse | Legitimate interest — Art. 6(1)(f) | 90 days |
| Contact form and email | Name, company, email, phone, the content of your message | Answering your enquiry and the correspondence that follows | Legitimate interest — Art. 6(1)(f); steps prior to a contract — Art. 6(1)(b) | 2 years from the last exchange |
| Clients, suppliers and partners | Contact and identification data of contact persons, contract and delivery records | Performing the contract, support, invoicing | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) | Contract term, then the statutory periods below |
| Accounting and tax records | Invoices and related documents | Statutory bookkeeping and tax duties | Legal obligation — Art. 6(1)(c); Act No. 563/1991 Coll., Act No. 235/2004 Coll. | 5–10 years, as the law requires |
| Job applicants | CV, cover letter, contact data, interview notes | Assessing your application | Steps prior to a contract — Art. 6(1)(b); consent for a longer hold — Art. 6(1)(a) | End of the process, or 1 year with your consent |
| Analytics, advertising and other optional cookies | Usage data as described in section 4 | Understanding how the site is used and improving it | Consent — Art. 6(1)(a) | See section 4 |
Giving us your data is voluntary. Without the data marked as required in a form, however, we may not be able to answer you or enter into a contract with you.
5. Who else sees your data
We do not sell personal data and we do not share it for anyone else’s marketing. We run the website and our systems on our own infrastructure. We use a small number of service providers who process data for us as processors — on our instructions, under a contract that meets Article 28 of the GDPR:
- email and office tools — Google Workspace (Google Ireland Limited);
- website analytics — Google Analytics 4 (Google Ireland Limited).
Some recipients receive data as separate controllers, responsible for their own processing:
- advertising and campaign measurement — Google Ads (Google Ireland Limited), if you consent to advertising cookies;
- accounting, legal and tax advisers, under their own professional duties.
We also disclose data where the law requires it — for example to tax authorities, courts or law-enforcement bodies acting within their powers.
6. Transfers outside the EEA
We keep data inside the European Economic Area wherever we can. Our hosting runs on our own infrastructure. Google Ireland Limited acts as our processor for Google Workspace and Google Analytics, and as a separate controller for Google Ads. Where Google transfers data to Google LLC in the United States, that transfer relies on the European Commission’s adequacy decision under Article 45 of the GDPR for the EU–US Data Privacy Framework, in which Google LLC participates. Should that decision cease to apply, Standard Contractual Clauses under Article 46 of the GDPR are in place with Google. A copy of the safeguards is available on request.
7. How long we keep it
The periods are in the table in section 3. When a period ends, we delete the data or anonymise it irreversibly. Where a statutory period applies — accounting, tax, archiving — we keep the record for as long as that law demands, even if you ask for erasure.
8. Your rights
Under Articles 15 to 22 of the GDPR you have the right to:
- access — be told whether we process your data and get a copy of it;
- rectification — have inaccurate or incomplete data corrected;
- erasure — have data deleted where we no longer have a reason to hold it;
- restriction — have processing paused while a dispute is resolved;
- portability — receive data you gave us in a machine-readable format, where the processing is based on consent or on a contract;
- object — object to processing based on our legitimate interest;
- withdraw consent — at any time, without affecting what was lawful before you withdrew it.
Write to info@telion.cz and we will answer within one month. If a request is complex we may extend that by two further months and will tell you why. We may ask you to confirm your identity before we act, so that we do not hand your data to someone else.
9. Complaints
If you think we handle your data unlawfully, please tell us first — it is usually the fastest way to fix it. You can also lodge a complaint with the Czech supervisory authority:
Úřad pro ochranu osobních údajů (Office for Personal Data Protection)
Pplk. Sochora 27, 170 00 Praha 7, Czech Republic
uoou.gov.cz
10. Automated decision-making
We do not make decisions about you by automated means alone, and we do not profile you in a way that would have legal effects for you.
11. How we protect data
We apply the technical and organisational measures required by Article 32 of the GDPR: encryption in transit, access limited to the people who need it, separate environments for development and production, logging, backups, and confidentiality obligations for everyone on the team. No system is perfect, but we treat a data breach as an incident to be reported and contained, and we notify the supervisory authority and affected people where the GDPR requires it.
12. Children
This website is aimed at businesses. We do not knowingly collect data about children under 16. If you believe a child has sent us personal data, write to us and we will delete it.
13. Changes to this policy
We update this policy when our processing changes or the law does. The current version is always on this page, with the date of the last change at the top. Material changes will be announced on the website and, where we hold your contact details for that purpose, by email.
14. Contact
Questions about this policy or about your data: info@telion.cz, or write to the address in section 1.