Privacy policy

IN EFFECT FROM 2026-09-07

This is a translation provided for your convenience. The binding version of this document is the Czech version; in the event of a conflict, that version prevails.

WHO PROCESSES YOUR DATA (THE CONTROLLER)

The budevolno.cz service is operated, and personal data is controlled, by budevolno.cz s.r.o., Company ID No. 29810701, VAT No. CZ29810701, data box ID 2c3biv4, registered in the Commercial Register under file No. C 104704 kept by the Regional Court in Ostrava. For matters of personal data protection, contact us at podpora@budevolno.cz.

The full identification of the Operator, including its registered address, is in the Terms of use at budevolno.cz/podminky.

budevolno.cz is a booking service: for businesses (hairdressers, massage studios, restaurants and others) it takes online bookings and manages the calendar; for customers it helps to find a free slot and book it. This policy describes what data we process about you, why, who we pass it to and what rights you have.

We are the CONTROLLER for data you give us directly — when you create an account with us or book through budevolno.cz. For data a BUSINESS puts into the app (for example when it brings its own customer file over from an earlier system, or writes you in at the counter), that business is the controller and we are its processor: we handle such data only on its instructions and only as far as running the bookings requires.

WHAT DATA WE PROCESS

In connection with a booking and with the use of the service we process:

  • Identification and contact data: the name and phone number you give when booking; an email address if you create an account or if you optionally fill it in on the booking form; the name from your Google account if you sign in with Google. The email address on the booking form is voluntary: without it the booking works exactly the same, we just cannot write to you about it.
  • Booking data: the business, the service, the slot, and where relevant the number of people, a preferred table or the name of the guest if you are booking for somebody else.
  • Optional data you set yourself: favourite businesses, ratings of a visit, the interface language, and a profile photo if you upload one to your account. Only you see the photo, in your account; it is not shown to businesses. You can delete it at any time in your Account. We keep your chosen language with your account so that it applies on other devices too; if you make no choice, the one stored in your browser decides.
  • Location data: if you permit it in your browser, we determine the location of your device so that we can order businesses by distance and offer you the ones near you. The coordinates obtained stay on your device: they are not transferred to our servers and we do not store them. You can withdraw the permission at any time in your browser settings, which stops the location being determined immediately. Without the permission you choose your default area by hand, by tapping on the map.
  • Technical data: IP address, browser type and data from the cookies necessary to run the service (see Cookies and storage).
  • Data about a business's staff: if a business introduces its people on its profile, we process the name (and possibly the surname or a nickname), the job role, a short introduction and a photograph. The business enters and publishes this data itself, as the controller; we only store and display it. Publication is voluntary and the business can switch it off at any time, at which point the photograph is deleted from our storage too. A staff member's name is also shown when a particular person is chosen on the booking form, if the business turns that option on for a service. We do not publish staff contact details. The manager of a business may store an internal email address for a staff member, which serves a single purpose: sending that person their own work schedule. The address is entered by the business as the controller, is not displayed anywhere on the profile, and is not passed to anyone other than the provider that sends emails on our behalf. The business can delete it at any time.

WHY WE PROCESS THE DATA AND ON WHAT BASIS

Every processing operation has its purpose and its legal basis under the GDPR:

  • Mediating and confirming a booking with the business you choose: performance of a contract, or steps taken prior to entering into a contract (Article 6(1)(b) GDPR).
  • Text messages to the number you give (booking confirmation, a reminder the day before, a message when the business cancels a slot, a message when a slot is moved, and an offer of a slot that has become free): performance of a contract and our legitimate interest in a reliable service (Article 6(1)(f)). We always send the booking confirmation and the message about a cancelled slot, because without them you could arrive at a closed door; the business can switch the other messages off in its settings.
  • Verifying the phone number before a booking: before we create the booking, we send a text message with a one-time code to the number given, and you copy it into the form. Without this it would be possible to book on somebody else's or a non-existent number: the confirmation would then reach a different person and the business would wait for a guest who knows nothing about the booking. Legal basis: steps taken prior to entering into a contract (Article 6(1)(b) GDPR) and our legitimate interest in protecting the service from misuse (point (f)).
  • Emails to the address you give (booking confirmation, a message when a slot is cancelled or moved, and a reminder the day before): performance of a contract and our legitimate interest in a reliable service (Article 6(1)(f)). We always send the confirmation and messages about changes to your booking for as long as we hold your address, because without them you would not know about your slot. You can unsubscribe from the reminder the day before at any time, using the link in the message itself.
  • A reminder that it is time to book again: for businesses you add to your favourites, we watch the rhythm of your own visits and send you a notice by email, and possibly by text message, at the estimated time. We decide solely from your bookings with that business: we use no other data for it and pass it to nobody. Legal basis: our legitimate interest in a useful service (Article 6(1)(f)). You can switch it off at any time in your Account under notification settings (Time to book again), or by removing the business from your favourites.
  • The quality and security of the service (protection against misuse and spam): legitimate interest (Article 6(1)(f)).
  • Optional features you activate (an account, favourites, watching for an earlier slot): performance of a contract, or your consent.
  • Compliance with legal obligations, for example accounting and tax ones: Article 6(1)(c).

WHERE WE GET THE DATA FROM

Most of the data comes straight from you — you fill it in when booking or when creating an account.

Some data may reach us from the business whose customer you are: when it moves over from an earlier booking system and brings its customer file with it, or when it writes you in by hand. In that case the business is the controller of that data — ask it about the processing and exercise your rights with it. We handle the data only on its instructions.

Bringing a customer file over does not send you any message from us. You get booking messages (confirmation, reminder) only for slots you actually have with the business.

WHO WE PASS THE DATA TO

We pass your booking data to the business you are booking with, as otherwise it could not confirm the booking. The business receives your name and phone number from us. We do NOT pass on the email address you fill in on the booking form: it serves only for us to write to you about your booking. We also use vetted providers (processors) that run the service for us technically:

  • Supabase: database, sign-in and storage (storing bookings and accounts).
  • Vercel: running and hosting the web application.
  • GoSMS: sending text messages to customers (the verification code before a booking, the booking confirmation, the reminder, a message when the business cancels or moves a slot, an offer of a slot that has become free, and the notice that it is time to book again).
  • Stripe: processing subscription payments. You enter your payment card details directly with them; we neither see nor store them.
  • Fakturoid: issuing and keeping records of tax documents for payments received.
  • Resend: sending email notifications (the booking confirmation to the business; the confirmation, a message about a cancellation or a move, and the reminder to the customer; the notice that it is time to book again; a staff member's schedule to their internal address; the newsletter).
  • Stadia Maps, OpenMapTiles and OpenStreetMap: base maps (your IP address is transmitted when a map loads). The tiles are loaded from a European region.
  • Cloudflare: protecting forms against automated misuse (where active) and a security backup copy of the database kept outside the main storage (R2 storage in the European Union).

TRANSFERS OUTSIDE THE EU

Some providers may process data on servers outside the European Union, for example in the USA. In that case the transfer is covered by appropriate safeguards under the GDPR, in particular the European Commission's standard contractual clauses. We pass data to nobody with whom we do not have a corresponding contract in place.

HOW LONG WE KEEP THE DATA

We keep booking and account data for as long as you use the service, and afterwards for as long as is necessary to protect our rights and to meet legal obligations (accounting documents, for example, for the period laid down by law).

If you delete your account, we remove or anonymise the associated personal data, except for what we are required by law to keep.

We hold a verification code, and the number we sent it to, only for as long as it is valid: ten minutes. We delete the record as soon as you enter the code, ask for a new one or request a code from elsewhere; anything left over is cleared up in the nightly run at the latest. Separately we keep a count of the codes sent to a single number, so that we can watch for misuse and for the cost of text messages; we delete those records within 45 days at the latest, and immediately when your data is erased.

To protect against data loss we make regular backup copies of the database. Data is not deleted from a backup immediately: it disappears from the live database at once, and drops out of the backups within 90 days at the latest, when the oldest backup is automatically removed. Backups serve solely to restore the service; they are not worked with in any other way.

YOUR RIGHTS

In relation to your personal data you have the right:

  • to access your data and to obtain a copy of it,
  • to have inaccurate data corrected,
  • to erasure (the right to be forgotten), unless we are obliged to keep the data,
  • to restriction of processing and to data portability,
  • to object to processing based on legitimate interest,
  • to withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.

HOW TO EXERCISE YOUR RIGHTS AND WHERE TO COMPLAIN

Send your request to podpora@budevolno.cz, or directly to the business you booked with. We will deal with it without undue delay, within one month at the latest.

If you believe we are processing your data unlawfully, you can lodge a complaint with the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz.

COOKIES AND SECURITY

Which cookies and browser storage we use, and how to manage your consent, is described on the Cookies and storage page. We use no marketing cookies.

We measure traffic with our own means, and only where you give us consent in the banner. The legal basis is your consent, which you can withdraw at any time. The only thing that comes out of it is aggregate daily and monthly counts of visits, registrations and bookings, together with where a visit came from and which of our pages it landed on. We do not store the exact time, your IP address or anything that could be used to trace an individual person, and we pass these numbers to nobody. Without consent nothing is sent: such a visit is simply not counted.

We protect data by technical and organisational measures (encrypted transmission, controlled access for authorised people only). Access to a business's data is held only by its members and, to the extent necessary, by our support desk.

CHANGES TO THIS POLICY

We may update this policy to a reasonable extent, for example when we add a new feature or provider. The current wording is always on this page; we will tell you about substantial changes.