Privacy Policy
Privacy Policy
This English version is provided for the convenience of international
visitors. In the event of discrepancies or differing interpretations,
the German version shall prevail unless mandatory law requires
otherwise.
1. Controller
The controller responsible for processing personal data in connection
with this website is:
Bau Concept Group s.r.o.
Volutová 2520/10
Stodůlky
158 00 Praha 5
Czech Republic
IČO: 23050764
DIČ: CZ23050764
Registered in the Commercial Register maintained by the Municipal
Court in Prague
Section C, File No. 420510
Represented by:
Dipl.-Ing. Peter Salajka
Managing Director – jednatel
Email: ps@bauconcept.group
Website: www.bauconcept.group
No data protection officer has been appointed because, on the basis
of the current circumstances, there is no statutory obligation to
appoint one.
2. Applicable data protection
law
We process personal data in particular on the basis of:
- Regulation (EU) 2016/679 – the General Data Protection Regulation
(GDPR); - Czech Act No. 110/2019 Coll., on Personal Data Processing;
- any other statutory provisions applicable in the individual
case.
Personal data means any information relating to an identified or
identifiable natural person.
We process personal data only where a specified purpose and a lawful
basis exist.
3. Technical baseline of the
website
This website is designed to minimise data processing.
In its intended and reviewed technical baseline, the website does not
use, in particular:
- analytics or audience-measurement services;
- marketing or advertising trackers;
- profiling services;
- externally loaded fonts;
- external maps;
- automatically loaded external videos;
- social-media plugins;
- external newsletter services;
- external appointment-booking services;
- external CAPTCHA services;
- other non-essential third-party content.
Fonts, images, icons, scripts and other resources required to display
the website are generally delivered locally through the website itself
or the hosting infrastructure used for it.
If this technical baseline changes in the future, the relevant
processing and its lawful basis will be reviewed before implementation.
This Privacy Policy and, where necessary, the consent-management
mechanism will be amended accordingly.
4. Hosting and technical
delivery
This website is hosted by:
TOKEN EDV Dienstleistung GmbH
Tullnerbachstraße 99
3011 Purkersdorf
Austria
When the website is accessed, technically necessary data are
processed between your device and the hosting infrastructure.
These data may include in particular:
- the IP address of the accessing device;
- date and time of access;
- the requested page or file;
- the volume of data transferred;
- HTTP status code;
- the previously visited page or referrer URL;
- browser type and version;
- operating system;
- hostname of the accessing device;
- technical error, security and connection information.
Processing is necessary to:
- deliver the website technically;
- maintain system stability and functionality;
- identify and remedy technical errors;
- identify abusive or unlawful access;
- prevent attacks and security incidents;
- safeguard the availability and security of the website.
The lawful basis is Article 6(1)(f) GDPR.
Our legitimate interest is the secure, stable, functional and
abuse-free operation of our website.
TOKEN EDV Dienstleistung GmbH generally processes the relevant data
as a processor within the meaning of Article 28 GDPR when providing the
technical services.
The servers used are located within the European Union.
5. Server log files
Technical access data generated when the website is accessed may be
stored in server log files.
Storage serves in particular:
- technical error analysis;
- system security;
- detection of unauthorised access attempts;
- prevention of attacks;
- investigation of specific security incidents;
- evidence of proper technical operation.
Log data are retained only for as long as necessary for these
purposes. The specific technical retention period depends on the
configuration and the agreed operational and security requirements of
the hosting provider.
Longer retention may occur where there are specific indications of a
security incident, unlawful access or another relevant event. In that
case, the affected data may be retained until the matter has been
conclusively clarified and, where necessary, for the establishment,
exercise or defence of legal claims.
Server log data are not combined with analytics, advertising or
marketing profiles.
6. Cookies and comparable
technologies
In its intended technical baseline, this website uses only cookies or
comparable storage technologies that are necessary for secure and
technically proper operation or for a function expressly requested by
the user.
Technically necessary cookies may be used in particular to:
- provide basic website functions;
- secure the technical operation of forms;
- implement security mechanisms;
- prevent abusive form submissions;
- enable administrator or user logins;
- manage technically necessary session settings.
Where technically necessary cookies involve processing personal data,
processing is based on Article 6(1)(f) GDPR.
Our legitimate interest is the secure, error-free and user-friendly
provision of the website.
No non-essential analytics, marketing, advertising or profiling
cookies are used.
Accordingly, in the technical baseline described here, consent to
analytics or marketing cookies is not required. If the use of cookies or
comparable technologies changes, we will assess before activation
whether prior consent is required.
7. Contact by email
If you contact us by email, we process the data you provide in order
to handle and respond to your message.
These data may include in particular:
- first and last name;
- company;
- professional role;
- email address;
- telephone number;
- subject and content of the message;
- documents and attachments submitted;
- date and time of the communication;
- technical sending and receiving information;
- other information voluntarily provided.
Where your contact concerns steps prior to entering into a contract
or performance of a contract, processing is based on Article 6(1)(b)
GDPR.
For other business enquiries, processing is based on Article 6(1)(f)
GDPR.
Our legitimate interests include:
- handling business communications;
- responding to enquiries;
- establishing and maintaining business relationships;
- documenting business-relevant matters;
- preparing possible quotations and projects.
Where we are legally required to retain certain communications,
processing is additionally based on Article 6(1)(c) GDPR.
8. Email infrastructure
Our business email communications are handled through the mail
servers of:
TOKEN EDV Dienstleistung GmbH
Tullnerbachstraße 99
3011 Purkersdorf
Austria
The following data may be processed in particular:
- sender and recipient addresses;
- names and other contact details;
- subject lines;
- message content;
- attachments;
- sending and receiving times;
- IP addresses;
- technical delivery information;
- spam, malware and security information;
- technical log data.
Processing is carried out to transmit, receive, secure and process
business communications and to prevent spam, malware and abusive
messages.
TOKEN EDV Dienstleistung GmbH generally processes the relevant data
as a processor within the meaning of Article 28 GDPR when providing the
technical services.
The mail servers used are located within the European Union.
9. Contact form
If you use a contact form provided on this website, we process the
information you enter in order to handle and respond to your
enquiry.
Depending on the form, the data may include in particular:
- first and last name;
- company;
- professional role;
- business email address;
- telephone number, where provided;
- subject or service interest;
- content of the message;
- date and time of submission;
- technically necessary delivery and security information;
- other information voluntarily submitted.
Mandatory fields are identified as such. Without the information
marked as required, we may be unable to assign or process the
enquiry.
Where the enquiry concerns steps prior to entering into a contract or
performance of a contract, processing is based on Article 6(1)(b)
GDPR.
For general business enquiries, processing is based on Article
6(1)(f) GDPR.
Our legitimate interests include:
- handling incoming business enquiries;
- communicating with prospective clients and business partners;
- assessing possible projects;
- preparing quotations;
- documenting business matters.
Form data are not used for general advertising or newsletter purposes
unless there is a separate lawful basis or valid consent.
10. System
assessment and project enquiry form
Where this website provides a form for a system assessment, project
preparation or technical requirements analysis, we process the
information entered to assess the requested project, prepare a
discussion and, where applicable, prepare an individual quotation.
The data may include in particular:
- name of the contact person;
- business contact details;
- company and company size;
- professional role;
- industry;
- intended number of users;
- details of the existing IT, server or network infrastructure;
- details of existing systems;
- requirements relating to data protection, information security and
availability; - requested services;
- project scope;
- project timeframe;
- free-text information;
- documents submitted voluntarily.
Processing is based on Article 6(1)(b) GDPR to the extent necessary
for steps taken prior to entering into a contract.
Where the processing concerns a general business assessment or
communication, it may be based on Article 6(1)(f) GDPR.
Our legitimate interest is the structured assessment of business
project enquiries and the preparation of an appropriate scope of
services and quotation.
Please do not submit through the form:
- passwords;
- private keys;
- administrator credentials;
- complete access credentials;
- recovery codes;
- health data;
- data relating to criminal convictions or offences;
- other particularly sensitive information,
unless such transmission has been expressly agreed with us in advance
and a suitable secure transmission channel has been arranged.
11. Technical prevention
of spam and abuse
Local and technically necessary security measures may be used to
protect forms and the website.
These may include in particular:
- server-side plausibility checks;
- input validation;
- local honeypot fields;
- time-based checks;
- limits on repeated submissions;
- IP-based rate limiting;
- local spam and security filters;
- logging of specific abusive access attempts.
Processing is based on Article 6(1)(f) GDPR.
Our legitimate interest is to protect the website and communications
systems against spam, automated attacks, malware, abusive use and other
security risks.
External CAPTCHA or cloud-based bot-detection services are not used
in the intended technical baseline.
12.
Storage in the email mailbox and on the local company server
Contact, project and system-assessment enquiries are stored in the
business email mailbox for processing.
Business-relevant enquiries, correspondence and documents may
additionally be stored on the local company server of Bau Concept Group
s.r.o.
This additional local storage serves in particular:
- structured internal processing;
- documentation of business matters;
- preparation and creation of quotations;
- project preparation;
- transfer to a later customer or project file;
- safeguarding business-relevant communications;
- compliance with statutory documentation and retention
obligations; - establishment, exercise or defence of legal claims.
The local company server is operated by Bau Concept Group s.r.o. or
under its responsibility. Access is limited to persons who require the
relevant data to perform their duties.
Data are not retained permanently merely because a technical copy has
been created. Consistent organisational review and deletion rules apply
to both the email mailbox and the local company server.
13. Retention periods
We retain personal data only for as long as necessary for the
relevant processing purpose or for as long as statutory retention
obligations apply.
The following criteria apply in particular:
- Clearly unwanted or abusive messages are deleted after review unless
further retention is required to prevent or document a security
incident. - General enquiries are regularly reviewed after processing has been
completed to determine whether further storage is necessary. - Enquiries that do not result in a contractual relationship are
deleted once there is no business, statutory or legal need for continued
retention. - Where a specific quotation or project enquiry remains necessary for
documenting a potential business relationship, it may be retained for an
appropriate period. - If a contractual or project relationship is established, the
necessary data are transferred to the relevant contract, customer or
project file. - Commercial, tax, accounting or other records subject to statutory
retention obligations are retained for the legally prescribed
period. - Data may be retained until a legal matter has been finally concluded
and applicable limitation periods have expired where this is necessary
for the establishment, exercise or defence of legal claims.
Once the processing purpose no longer applies and applicable
retention periods have expired, data are deleted, anonymised or, where
immediate deletion from productive systems is not technically possible,
blocked from further ordinary use.
14. Backups
Personal data may temporarily also be contained in technically
necessary backups.
Backups are used exclusively for:
- restoration following technical disruptions;
- protection against data loss;
- ensuring the availability and integrity of systems.
Backups are not used as a permanent archive. They are subject to
defined retention and overwrite cycles.
Data deleted from productive systems may remain in backups until the
relevant backup is overwritten in the ordinary cycle. Such data are
generally no longer used for regular business purposes.
If data are restored from a backup, the applicable deletion and
retention requirements are taken into account again.
15. Recipients and authorised
persons
Within Bau Concept Group s.r.o., access to personal data is limited
to persons who require the data to perform their duties.
External recipients or processors may include in particular:
- TOKEN EDV Dienstleistung GmbH as hosting and email service
provider; - technical administrators and IT service providers where access is
required for maintenance, security, backup or troubleshooting; - lawyers, tax advisers, accountants and other professional advisers
where required for a specific matter; - banks and payment service providers where required for a specific
business transaction; - courts, authorities and other public bodies where disclosure is
required by law or otherwise legally necessary; - business partners or subcontractors where their involvement is
required to handle a specific enquiry or perform a project and is
legally permissible.
Processors are contractually bound in accordance with Article 28 GDPR
and may generally process personal data only on documented
instructions.
We do not disclose personal data for third-party advertising purposes
and do not sell personal data.
16. Processing within the
European Union
The primary website, hosting and email infrastructure is operated on
servers within the European Union.
Additional internal storage on the local company server also takes
place within the European Union.
In the technical baseline described here, there is no intended
transfer of personal data collected through this website to countries
outside the European Union or European Economic Area.
If service providers, sub-processors or technical systems are used in
the future that process personal data outside the European Union or
European Economic Area, the arrangement will be reviewed for compliance
with data protection law before implementation.
Any such transfer will take place only in compliance with Articles 44
et seq. GDPR. In that event, this Privacy Policy will be supplemented
with information on the recipient, third country and transfer
mechanism.
17. Data security
We implement appropriate technical and organisational measures to
protect personal data against risks including in particular:
- accidental or unlawful destruction;
- loss;
- unauthorised alteration;
- unauthorised disclosure;
- unauthorised access;
- abusive use;
- technical disruptions;
- malware and other security incidents.
Measures may include in particular:
- encrypted transmission of the website via HTTPS;
- access controls;
- role- and task-based permissions;
- individual user accounts;
- secure authentication procedures;
- system hardening;
- regular security updates;
- firewall and network protection measures;
- backups;
- recovery procedures;
- logging of security-relevant events;
- protection of servers and endpoints;
- organisational deletion and retention rules.
The specific measures are determined and reviewed regularly, taking
into account the state of the art, implementation costs, the nature and
scope of processing and the relevant risks.
18. Requirement to provide
personal data
Providing personal data when making a general enquiry is generally
voluntary.
Certain information may nevertheless be required so that we can:
- assign your enquiry;
- communicate with you;
- assess a requested project;
- prepare a quotation;
- take steps prior to entering into a contract;
- enter into or perform a contract.
If required information is not provided, the relevant enquiry may be
impossible to process or may be processed only to a limited extent.
There is no statutory obligation to use the contact, project or
system-assessment form. You may generally also contact us by email.
19. No automated
decision-making
No decision based solely on automated processing within the meaning
of Article 22 GDPR takes place in connection with this website.
Information submitted through contact, project or system-assessment
forms is not used for automated profiling that produces legal effects
concerning you or similarly significantly affects you.
20. Rights of data subjects
Where the statutory requirements are met, you have in particular the
following rights:
Right of access
Under Article 15 GDPR, you may request confirmation as to whether we
process personal data concerning you and, where applicable, access to
those data.
Right to rectification
Under Article 16 GDPR, you may request correction of inaccurate
personal data and completion of incomplete personal data.
Right to erasure
Under Article 17 GDPR, you may request erasure of your personal data
where no statutory or other lawful ground requires continued
processing.
Right to restriction of
processing
Under the conditions of Article 18 GDPR, you may request restriction
of processing.
Right to data portability
Where the conditions of Article 20 GDPR are met, you may request that
the relevant data be provided to you in a structured, commonly used and
machine-readable format or transmitted to another controller.
Right to object
Where we process personal data on the basis of Article 6(1)(e) or (f)
GDPR, you may object to processing under Article 21 GDPR on grounds
relating to your particular situation.
Right to withdraw consent
Where processing is based on your consent, you may withdraw that
consent at any time with effect for the future.
Withdrawal does not affect the lawfulness of processing carried out
on the basis of consent before its withdrawal.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection
supervisory authority if you consider that processing of your personal
data infringes applicable data protection law.
To exercise your rights, contact:
21.
Objection to processing based on legitimate interests
Where we process personal data on the basis of Article 6(1)(f) GDPR,
Article 21 GDPR gives you the right to object at any time, on grounds
relating to your particular situation, to such processing.
Following a justified objection, we will no longer process the
relevant personal data unless we demonstrate compelling legitimate
grounds for the processing which override your interests, rights and
freedoms.
Continued processing may also be lawful where it is necessary for the
establishment, exercise or defence of legal claims.
22. Competent
data protection supervisory authority
The supervisory authority generally competent for Bau Concept Group
s.r.o. is:
Úřad pro ochranu osobních údajů
Pplk. Sochora 27
170 00 Praha 7
Czech Republic
Under the GDPR, you may also contact a data protection supervisory
authority at your habitual residence, your place of work or the place of
the alleged infringement.
23. Amendments to this
Privacy Policy
We may amend this Privacy Policy if, in particular, any of the
following changes:
- the legal framework;
- the technical systems used;
- hosting or email service providers;
- forms or requested data fields;
- storage locations;
- processors;
- categories of recipients;
- cookies or comparable technologies;
- external content or services;
- other data-processing activities.
The version published on this website at the relevant time
applies.
Last updated: July 2026
