Home  /  Privacy policy

Privacy policy

GDPR · Personal data protection

Effective from 10 July 2026 · Updated 29 September 2026 · Version 1.2

Discretion is the foundation of our work, and we apply the same approach to your personal data. This policy explains what data we process, why, how long we keep it and what rights you have under Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).

1. Data controller

Bodyguard Group s.r.o.®
Ringhofferova 115/1, 155 21 Prague 5 – Zličín, Czech Republic
Company ID (IČO): 07608853 · VAT ID: CZ07608853
registered with the Municipal Court in Prague, Section C, File 303957

Contact for data protection matters: info@ibodyguard.cz, tel. +420 776 610 111.

2. What data we process

The only data we collect directly from you is the following (technical data processed automatically is described below):

  • via our enquiry form or the vehicle reservation form: first name and surname, email address, telephone number, client type, preferred contact method, requested service, location, timeframe, number of protected persons, response priority and a description of your requirements; for a vehicle reservation also the chosen vehicle, type of journey, pick-up point, destination, date and time and number of passengers;
  • when you communicate with us directly (by telephone, email, WhatsApp or Signal, or in person).

This website does not use analytics or marketing cookies. We use the browser's technical storage only for your chosen language (localStorage), the state of the introductory animation within the current session (sessionStorage) and a brief storage-availability check in the digital test. These records contain no personal data.

The website also measures anonymous visitor statistics (page views and scroll depth, scrolling, clicks, anonymous attention and mouse-movement zones, form interactions and video playback) without cookies, without storing IP addresses and without any visitor identifiers. The data cannot be linked to a specific individual and is used solely to improve the website.

The statistics also include information about the network a visit came from: the country, the connection type and the name of the network operator. We determine this from the IP address in the server's memory using a local database: only the result is stored; the IP address itself is not written anywhere and does not leave the server. This information relates to a network, not to a person. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR); you can raise an objection by writing to info@ibodyguard.cz. Database source: DB-IP (CC BY 4.0).

To protect the website's submission forms and access to its protected administration area from misuse, the server keeps, for no more than 24 hours, a separate pseudonymous security fingerprint derived from the IP address using a non-public server key (HMAC). The security log contains only the time, the outcome of the event and a fingerprint kept separately for each form or access point and for each day. The raw IP address is not stored, and the fingerprint is not linked to analytics.

3. Digital test, newsletter and callback requests

Digital test (Digital Exposure Test): most of the analysis runs locally in your browser. To assess the network type, the server processes the IP address briefly but does not store it, and no visitor identifier is stored either. The test result stays with you.

Newsletter: if you subscribe (for example through the digital test), we store your email address and the time you subscribed on the basis of your consent (Art. 6(1)(a) GDPR) until you withdraw that consent. Content: tips on security, privacy and Bodyguard Group® services. You can unsubscribe at any time using the link in any of our emails or by writing to info@ibodyguard.cz. Messages are sent via our email service provider (a processor in the EU).

Callback request: we use your phone number solely to make the call you have requested. The result of the digital test is not sent. We keep an operational backup of the request for no more than 30 days.

Public feedback board: on the basis of your consent (Art. 6(1)(a) GDPR), we publicly display the optional name or nickname you enter, your rating, the text of your feedback, the test version and the time of submission. We publish the entry for no more than 12 months. You may withdraw your consent at any time and we will remove the entry. The HMAC security fingerprint used to prevent misuse is not published and is kept for no more than 24 hours, in line with the rule above.

4. Purpose and legal basis for processing

  • handling your enquiry and discussing the provision of our services — Art. 6(1)(b) GDPR (steps taken at your request prior to entering into a contract);
  • newsletter subscription — Art. 6(1)(a) GDPR (consent);
  • protection of our legitimate interests — Art. 6(1)(f) GDPR (establishment, exercise or defence of legal claims; anonymous website analytics);
  • compliance with legal obligations — Art. 6(1)(c) GDPR (in particular accounting and tax legislation, if a contract is concluded).

We do not use data from enquiries or callback requests for marketing. We send commercial or informational emails (the newsletter) only to people who have expressly subscribed, and consent can be withdrawn at any time.

5. Retention period

We keep enquiry data for as long as necessary to handle the enquiry, and for no longer than 3 years from our last communication. We keep the operational backup of a callback request for no more than 30 days, and form security fingerprints for no more than 24 hours. If a contract is concluded, we keep the related data for the duration of the contractual relationship and thereafter for the periods required by law.

6. Who has access to your data

Your data is handled only by a small group of vetted individuals bound by a duty of confidentiality. As processors, we use our web hosting provider (INTERNET CZ, a.s. — FORPSI, Czech Republic; data is stored in the EU) and our email service provider. We do not pass your data to any third parties for advertising or any other purposes.

7. Your rights

  • the right of access to your personal data,
  • the right to rectification of inaccurate data,
  • the right to erasure (“right to be forgotten”),
  • the right to restriction of processing,
  • the right to data portability,
  • the right to object to processing based on our legitimate interests.

You can exercise your rights by writing to info@ibodyguard.cz. You also have the right to lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz.

8. Security

All communication with this website is encrypted (HTTPS). We treat the content of enquiries with the same strict confidentiality under which we provide our services. If you wish, we will communicate with you exclusively through encrypted channels (Signal) or in person.