GDPR – Personal Data Protection
The protection of your personal data is important to us. On this page we clearly explain which personal data we process, why, and for how long. All in accordance with EU Regulation 2016/679 (GDPR) and Czech Act No. 110/2019 Coll.
In brief
- We only collect your data to the extent we need for handling your booking and fulfilling our legal obligations.
- We don’t sell your data and we don’t transfer it abroad (other than to approved processors).
- You have the right to access, rectify, erase or restrict the processing of your data.
1. Who is the controller of your personal data
Sjungle s.r.o.
Company ID: 61060976
Establishment: Chalupa Mlynářka, Černý Důl 100, 543 44 Černý Důl
E-mail: chalupamlynarka@gmail.com
Phone: (+420) 776 247 358
The Controller has not appointed a data protection officer (DPO), as the legal grounds for doing so have not been met.
2. What data we process
When providing accommodation services we process the following categories of data:
- Identification data: name, surname, date of birth, citizenship, ID document number (required by the Foreign Residence Act and the local accommodation fee).
- Contact data: e-mail, phone, permanent address.
- Payment data: bank account number or details needed to make payments (payments go through the Pays.cz gateway; we don’t store card details).
- Booking data: stay dates, number of guests, notes about the stay, communication with us.
3. Why we process the data (purpose and legal basis)
- Performance of a contract — handling the booking, providing accommodation, communicating with you.
- Compliance with legal obligations — keeping the guest register (Act No. 565/1990 Coll. on local fees), reporting foreign-guest stays to the Czech Police via Ubyport (Act No. 326/1999 Coll.), accounting and tax obligations.
- Legitimate interest — protection of our rights and property, handling complaints, defence against potential legal claims.
- Consent — sending the newsletter and marketing messages (if you sign up; you can withdraw consent at any time).
4. How long we keep the data
- Booking and accommodation data: for the duration of the contractual relationship and then 6 years (for accounting and tax regulations).
- Guest register: 6 years from the last entry (statutory obligation).
- Foreign-guest register: 6 years from the last entry (Foreign Residence Act).
- E-mail communication: usually 3 years.
- Data processed on the basis of consent (newsletter): until consent is withdrawn.
After the stated periods we securely delete or anonymise the data.
5. Who we share the data with (recipients and processors)
We share your data, only to the necessary extent, with the following entities:
- State authorities — Czech Foreign Police (Ubyport system), Town of Černý Důl (records for the local accommodation fee), tax authority.
- Pays.cz payment gateway — online payment processing.
- Booking portals (Booking.com B.V., Airbnb Ireland UC and others) — if you booked through their platform; in such cases they are also independent controllers of your data and follow their own policies.
- Trevlix booking system — booking records and foreign-guest reporting.
- Web hosting provider — Český hosting (THINline interactive s.r.o.).
- E-mail and cloud provider — Google LLC (Google Workspace / Gmail).
- Accountant and tax adviser — under a personal-data processing agreement.
We have contracts with all processors that bind them to the same level of data protection that we provide.
6. Transfer of data abroad
Some of our processors (notably Google and the booking portals) may process data on servers outside the EU. In such cases the transfer is secured by Standard Contractual Clauses approved by the European Commission and other appropriate safeguards under Art. 46 GDPR.
7. Cookies and analytics tools
Our website uses cookies — small text files stored in your browser. We use:
- Essential cookies — for the proper functioning of the website and the booking form. These cannot be rejected; without them the website does not work.
- Analytics cookies — Google Analytics 4 (Google Ireland Limited) — so we can see how visitors use the website and improve it. The data is anonymised.
- Advertising cookies — Google Ads / AdSense (Google Ireland Limited) — to measure the effectiveness of our promotion and to show relevant ads.
You can manage cookies at any time in your browser settings, or reject them via the cookie bar. Rejecting analytics and advertising cookies will not affect the functionality of the website.
8. Data sources
We mainly process data you provide to us yourself (when booking, during online check-in or in e-mail communication). If you book through Booking.com, Airbnb, etc., we receive the data from those portals.
9. Your rights
In relation to your personal data you have the following rights:
- Right of access — you can ask us what data we process about you and request a copy.
- Right to rectification — if the data is inaccurate or incomplete.
- Right to erasure (“right to be forgotten”) — under the conditions set by the GDPR.
- Right to restriction of processing — in justified cases.
- Right to data portability — to receive your data in a structured, machine-readable format.
- Right to object to processing based on legitimate interest.
- Right to withdraw consent — at any time, without any penalty (mainly relating to the newsletter).
- Right to lodge a complaint with the Czech Data Protection Authority, if you believe we process your data in breach of the regulations.
You can exercise your rights by emailing chalupamlynarka@gmail.com or in writing to the operator’s address. We’ll respond within 30 days at the latest.
10. Obligation to provide data
Providing personal data is voluntary. However, without it we cannot provide you with accommodation — in particular we cannot fulfil the legal obligation to keep a guest register and report foreign guests to the Czech Police.
11. Data security
We protect personal data in accordance with current standards:
- Secure encrypted connection (HTTPS) across the entire website.
- Legal and up-to-date operating system and software on all devices.
- Antivirus software and firewall.
- Strong passwords; where justified, biometric verification and two-factor authentication.
- Cloud backups and e-mail with verified providers (Google, Český hosting).
- Persons who come into contact with the data are bound by confidentiality.
12. Effective date and changes
These privacy rules take effect on 1 January 2026. The current version is always available on this page. We will inform you of any substantial changes.
Have a question about how we process your personal data?
Write to us at chalupamlynarka@gmail.com or call us on (+420) 776 247 358 — we’re happy to explain everything.
These privacy rules are valid from 1 January 2026 until further notice.
