This Privacy Policy explains how Educademy Prague s.r.o. collects and uses personal data when you browse our website, contact us, submit a course reservation, participate in a programme or communicate with our team.
1. Data controller
Educademy Prague s.r.o.
IČO: 10853359
Vlkova 679/39, 130 00 Prague 3 – Žižkov, Czech Republic
Email: info@educademyprague.com
Telephone: +420 296 842 262
2. Personal data we process
- Identity and contact details, including name, work email address and telephone number.
- Organisation, country, occupation and Erasmus+ project information.
- Course, session, participant number and accessibility or practical requirements you choose to provide.
- Messages, administrative notes, reservation status, payment references and related correspondence.
- Questions submitted to the Educademy virtual assistant when it cannot identify an approved answer; these are reviewed to improve the information service.
- Technical and security data such as IP address, browser information and server logs where generated by our hosting and service providers.
- Records showing when you accepted the applicable Terms of Service and acknowledged this Privacy Policy.
Please do not include sensitive personal data in free-text fields unless it is genuinely necessary for accessibility, safety or programme arrangements. Where such information is provided, we restrict its use to the stated purpose.
3. Purposes and legal bases
We do not use course reservation consent as permission for unrelated advertising. The virtual assistant offers a separate, optional choice to receive course and Erasmus+ news. We record the name, email address, preferred language, source, consent date and subscription status for this purpose. Marketing consent may be withdrawn at any time using the unsubscribe link in an email or by contacting us.
4. Recipients and service providers
Access is limited to authorised Educademy Prague staff and providers that help us operate the service. These may include Supabase for database, authentication and server functions; Resend for transactional email delivery; Turhost for domain, website or email hosting; banking and accounting providers; trainers, venues or partner organisations where necessary to deliver a confirmed activity; and public authorities where disclosure is legally required.
Providers process data under contractual and confidentiality obligations. Where processing involves a country outside the European Economic Area, we use an applicable lawful transfer mechanism and appropriate safeguards.
5. Provisional letter verification
If an organisation requests a provisional registration letter for an Erasmus+ application, we generate a document reference and QR verification link. The public verification page displays only information also printed on the letter: document status and reference, organisation, course, session, location, participant number, duration, issue date and validity date. It does not display participant or coordinator names, email addresses, telephone numbers, messages or private reservation notes. This limited verification service is operated in our legitimate interest in preventing document fraud and allowing funding bodies to confirm authenticity.
6. Retention
- Unconfirmed enquiries and provisional reservations: normally up to 24 months after the last relevant communication.
- Confirmed programme, contractual and payment records: for the period necessary to provide the service and normally up to 5 years afterwards, unless a longer accounting, tax or legal period applies.
- Invoices and records subject to statutory retention: for the period required by Czech law, which may be up to 10 years.
- Security logs: for a limited period determined by security need and provider configuration.
- Terms and privacy acknowledgement records: for as long as reasonably necessary to demonstrate the applicable agreement and compliance.
Data may be retained longer when necessary for an active legal claim, regulatory request or safeguarding matter.
7. Your rights
Subject to the GDPR and any applicable limitations, you may request access, correction, deletion, restriction, portability or objection to processing. Where processing is based on consent, you may withdraw that consent without affecting earlier lawful processing. You may also complain to the Czech supervisory authority:
Office for Personal Data Protection (Úřad pro ochranu osobních údajů)
Pplk. Sochora 27, 170 00 Prague 7, Czech Republic
uoou.gov.cz/en
To exercise a right, email info@educademyprague.com. We may need to verify your identity before responding.
8. Cookies, local storage and analytics
Essential technical storage may be used for security, authenticated administration, remembering your cookie preference and operating requested features. These functions do not require analytics consent.
With your optional consent, we use Google Analytics 4, provided by Google Ireland Limited, to understand aggregate website use, including page views, approximate location, device type, referral source and interactions such as a successful reservation submission. We configure the site not to send reservation names, email addresses, telephone numbers, messages or reference numbers to Google Analytics. Analytics does not load before you select “Accept analytics”. You may refuse it by selecting “Essential only” and may reopen Cookie settings in the footer at any time.
Analytics data is processed on the basis of your consent. Google may process information on infrastructure outside the European Economic Area using applicable transfer safeguards. Further information is available in Google’s Privacy Policy.
9. Security and automated decisions
We use proportionate organisational and technical measures, including access controls, authenticated administration and restricted database permissions. No internet service can guarantee absolute security. Course reservations are reviewed by a person; we do not make decisions producing legal or similarly significant effects solely by automated means.
10. Children
Online reservation forms are intended for adult participants, school representatives and coordinators. Organisations arranging activities involving minors should not submit a child’s personal data unless requested through an appropriate, safeguarded process.
11. Changes
We may update this Policy when our services, providers or legal obligations change. The effective date and version at the top identify the applicable text.
