LEGAL

PRIVACY

LAST UPDATED — MAY 3, 2026

1. WHO RUNS THIS SITE

This website (davidcerny.cz) is operated by David Černý as a non-commercial portfolio of his work. References below to “we”refer to the operator. For privacy-related requests, write to the address listed in Contact.

2. WHAT PERSONAL DATA WE COLLECT

  • Contact form — when you fill in the form on the Contact page, we receive your name, email address, and the message you wrote. These are the only fields the form collects.
  • Server logs — our hosting provider records standard access logs (IP address, user agent, requested URL, timestamp). These are used for security and traffic statistics, not to identify individual visitors.
  • Analytics — we use Vercel Analytics, which works without cookies. It estimates anonymous visitor counts from the IP address and user agent without storing either in a way that can be tied back to you.
  • Authentication cookies — set only when an authorised editor logs in to the admin area. Public visitors never receive these cookies. They are strictly necessary for the admin functionality and exempt from consent requirements.

We do not use Google Analytics, Facebook Pixel, or any third-party advertising or behavioural tracking.

3. WHY WE PROCESS THIS DATA

  • To reply to messages sent through the contact form.
  • To keep the site secure (rate limiting, abuse detection).
  • To understand traffic patterns at an aggregate, anonymous level.

The legal basis under GDPR is legitimate interest for logs and analytics, and consent / performance of inquiry for the contact form (you choose to send the message).

4. WHERE THE DATA IS STORED

We use the following processors. Some operate outside the EU; transfers rely on Standard Contractual Clauses as required by GDPR.
  • Vercel — hosting and analytics (servers in EU and US).
  • Neon — database storage (US, AWS us-east-1).
  • Vercel Blob — image storage (multi-region).
  • Resend — outbound email delivery for the contact form (US).

5. HOW LONG WE KEEP IT

  • Contact-form messages remain in the recipient inbox for as long as David keeps them; copies in Resend are retained for up to 90 days.
  • Server logs are retained by Vercel for up to 30 days.
  • Analytics data is aggregated and not tied to individuals; no personal retention applies.

6. YOUR RIGHTS

Under GDPR you have the right to:
  • access the data we hold about you,
  • rectify inaccurate data,
  • request deletion (“right to be forgotten”),
  • restrict or object to processing,
  • obtain a portable copy,
  • lodge a complaint with the Czech Data Protection Authority (Úřad pro ochranu osobních údajů, uoou.cz).
To exercise any of these, write to us via the Contact page.

7. COOKIES

The public site uses no tracking cookies. The only cookies set on this domain are session and CSRF cookies generated when an editor signs in to the admin area — these are strictly necessary for that functionality and not used for tracking.

8. CHANGES TO THIS POLICY

If material changes are made to this policy, the “Last updated” date above will be revised. Significant changes will be highlighted on the home page for at least 14 days.

THIS POLICY IS A FACTUAL DESCRIPTION OF CURRENT PROCESSING — IT IS NOT LEGAL ADVICE. CONSULT A LAWYER BEFORE RELYING ON IT FOR COMPLIANCE.