Legal

Privacy Policy

This Privacy Policy explains how Digi Wolf Agency s.r.o. collects, uses, and protects your personal data in compliance with GDPR and applicable Czech law.

Company: Digi Wolf Agency s.r.o., Prague, Czech RepublicLast updated: January 2025

Contents

1. Who We Are2. What Data We Collect3. How We Use Your Data4. Legal Basis for Processing (GDPR Art. 6)5. Data Retention6. Data Sharing7. Cookies8. Your Rights Under GDPR (Art. 15–22)9. Security10. Changes to This Policy

1. Who We Are

Digi Wolf Agency s.r.o. ("we", "our", "us") is a digital agency incorporated in the Czech Republic. Our registered office is in Prague, Czech Republic. We can be contacted at info@digiwolf.agency. We are the data controller for personal data collected through our website and services.

2. What Data We Collect

We collect the following categories of personal data: • Contact information: name, email address, phone number, company name • Project data: information you share about your business and project requirements • Communication records: emails and messages exchanged with us • Website usage data: IP address, browser type, pages visited, time on site (via analytics) • Account data: email and encrypted password if you register for our client portal We do not collect special category data (health, race, political opinions, etc.).

3. How We Use Your Data

We process your personal data for the following purposes: • To respond to enquiries and provide our services (legitimate interest / contractual necessity) • To manage client projects and communicate project updates (contractual necessity) • To send invoices and manage payments (legal obligation / contractual necessity) • To improve our website and services (legitimate interest) • To comply with legal obligations under Czech and EU law We do not sell your personal data to third parties.

4. Legal Basis for Processing (GDPR Art. 6)

Under GDPR (Regulation (EU) 2016/679), we process your data on the following legal bases: • Contractual necessity (Art. 6(1)(b)): processing required to fulfil a contract or take pre-contractual steps • Legitimate interests (Art. 6(1)(f)): where our business interest does not override your rights • Legal obligation (Art. 6(1)(c)): processing required to comply with Czech or EU law • Consent (Art. 6(1)(a)): where we ask for your explicit consent (e.g., marketing emails)

5. Data Retention

We retain your personal data for as long as necessary to provide our services and comply with legal obligations: • Contact form submissions: 3 years from last interaction • Client project data and invoices: 10 years (Czech accounting law requirement) • Account data: until account deletion request • Analytics data: 26 months (anonymised after 14 months) You may request deletion of your data at any time (see Section 8).

6. Data Sharing

We may share your data with: • Supabase (database hosting) — servers in the EU • Vercel (website hosting) — EU and US servers with Standard Contractual Clauses • Google (analytics, if enabled) — subject to GDPR adequacy decision • Professional advisors (lawyers, accountants) — under confidentiality obligations • Czech public authorities — when legally required We do not transfer your data outside the EEA without appropriate safeguards.

7. Cookies

Our website uses strictly necessary cookies (required for site function) and analytics cookies (with consent). See our Cookie Policy for full details.

8. Your Rights Under GDPR (Art. 15–22)

You have the following rights regarding your personal data: • Right of access (Art. 15): request a copy of your personal data • Right to rectification (Art. 16): correct inaccurate or incomplete data • Right to erasure (Art. 17): request deletion of your data ("right to be forgotten") • Right to restriction (Art. 18): limit how we process your data • Right to data portability (Art. 20): receive your data in a machine-readable format • Right to object (Art. 21): object to processing based on legitimate interests • Right to withdraw consent (Art. 7(3)): withdraw consent at any time To exercise any of these rights, contact us at info@digiwolf.agency. We will respond within 30 days. You also have the right to lodge a complaint with the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic.

9. Security

We implement appropriate technical and organisational measures to protect your personal data, including encrypted data transmission (HTTPS/TLS), encrypted database storage, access controls and authentication, and regular security reviews.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on our website. Continued use of our services after changes constitutes acceptance.

Questions about your data?

Contact our Data Protection contact at info@digiwolf.agency. We respond to all data requests within 30 days.

Contact Us →