Last updated: July 2026
This policy explains what personal data Being lifestyle s.r.o. (trading as Being Labs) processes when you visit this website or get in touch with us, why we process it, who else sees it, and what you can require us to do about it. It is written to meet Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 Coll. on the processing of personal data.
The short version: this website sets no cookies of its own, runs no advertising or profiling, and the only personal data we ask you for is what you type into the contact form.
1. Who is responsible for your data
The data controller is:
- Being lifestyle s.r.o., trading as Being Labs
- Registered office: Česká Bělá 79, 582 61 Česká Bělá, Czech Republic
- Company ID (IČO): 19067135
- Data box ID (datová schránka): ndwt9p8
- Email: [email protected]
We are not required to appoint a Data Protection Officer under Art. 37 GDPR and have not appointed one. Send any privacy question or rights request to the address above and it reaches the person who can act on it.
2. What we process, why, and for how long
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Answering an enquiry sent through the contact form | Name, email address, message, language, timestamp | Art. 6(1)(b) — steps taken at your request before entering into a contract | 24 months from the last contact |
| Ongoing email and phone correspondence | Contact details and the content of the correspondence | Art. 6(1)(b) and Art. 6(1)(f) — our legitimate interest in maintaining a business relationship | 24 months from the last contact |
| Keeping the website and server secure and available | IP address, user agent, requested URL, response status (server and firewall logs) | Art. 6(1)(f) — our legitimate interest in preventing abuse and attacks | Up to 30 days, then deleted or aggregated |
| Understanding which pages are read | Aggregated page views, referrer, country, device class — no cookies, no identifier that follows you | Art. 6(1)(f) — our legitimate interest in improving the site | Aggregated statistics only; no visitor-level record is created |
| Meeting statutory accounting and tax duties for clients | Billing details on invoices | Art. 6(1)(c) — compliance with the Czech Accounting Act and VAT Act | 10 years, as required by law |
Providing your data is voluntary. If you do not fill in the contact form we simply have no way to reply to you; nothing else on the site is affected.
3. What we do not do
- We do not sell, rent or trade personal data. Ever.
- We run no advertising, remarketing or cross-site tracking, and we set no marketing cookies.
- We do not build visitor profiles and we carry out no automated decision-making or profiling within the meaning of Art. 22 GDPR.
- We do not knowingly collect special categories of data (Art. 9) and this site is not directed at children.
4. Analytics without cookies
Our traffic statistics come from Cloudflare, which already routes every request to this site. They are computed in Cloudflare’s network from those requests: no analytics script is loaded into your browser, nothing is stored on your device, no cross-site identifier is created and your browser is not fingerprinted. We see aggregate numbers — how many people opened a page, roughly where from, on what kind of device — and never an individual visitor’s browsing history. Because no information is stored on or read from your device, no consent banner is required under Art. 5(3) of the ePrivacy Directive.
5. Who else sees your data
We share data only with the processors below, only for the purpose stated, and only under a data processing agreement under Art. 28 GDPR. We also disclose data to public authorities where a law obliges us to.
| Recipient | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Hosting of this website and our internal tooling | Germany (EU) | No transfer outside the EEA |
| Cloudflare, Inc. | DNS, CDN, WAF and traffic statistics computed from request logs — no script, no cookie | EU edge network; US parent company | EU-US Data Privacy Framework and Standard Contractual Clauses |
| n8n (self-hosted) | Moves contact-form submissions from the website into our own systems | Our own server at Hetzner, Germany (EU) | No transfer outside the EEA |
| Telegram FZ-LLC | Internal alert telling us a new enquiry has arrived | United Arab Emirates | Standard Contractual Clauses; we keep the alert content minimal |
| Google Ireland Limited | Business email (Gmail / Google Workspace) used to reply to you | Ireland (EU), with support access from the US | EU-US Data Privacy Framework and Standard Contractual Clauses |
| Notion Labs, Inc. | CRM record of enquiries, clients and projects | United States | EU-US Data Privacy Framework and Standard Contractual Clauses |
6. Transfers outside the EEA
The website itself is hosted in the European Union. Where a recipient listed above sits outside the EEA, the transfer relies on the European Commission’s Standard Contractual Clauses under Art. 46(2)(c) GDPR and, where the provider is certified, on the EU-US Data Privacy Framework adequacy decision. You may ask us for a copy of the safeguards that apply to a specific transfer.
7. Cookies
This website sets no cookies of its own and uses no browser storage to identify you. The only cookies you may encounter come from Cloudflare’s security layer and are strictly necessary. The detail is in our Cookie Policy.
8. How we keep data safe
- All traffic is served over HTTPS with a modern TLS configuration.
- Servers sit in EU data centres behind a firewall, with a WAF and rate limiting in front of the application.
- Access to enquiry data is limited to the people who need it, over authenticated accounts with multi-factor authentication.
- Secrets and API keys are held in server-side environment variables and never shipped to the browser.
No method of transmission over the internet is completely secure, so we cannot guarantee absolute security — but we do review these measures as the site changes.
9. Your rights
Under the GDPR you have the right to:
- Access (Art. 15) — get confirmation of whether we process your data and a copy of it.
- Rectification (Art. 16) — have inaccurate or incomplete data corrected.
- Erasure (Art. 17) — have your data deleted, unless we must keep it to meet a legal duty.
- Restriction (Art. 18) — have processing paused while a dispute about accuracy or legitimate interest is resolved.
- Data portability (Art. 20) — receive the data you gave us in a structured, machine-readable format.
- Object (Art. 21) — object at any time to processing based on our legitimate interest.
- Withdraw consent (Art. 7(3)) — where processing rests on consent, withdraw it at any time, without affecting what was lawful before.
To exercise any of these, email [email protected]. We reply within one month of receiving the request, as required by Art. 12(3) GDPR; if a request is unusually complex we may extend that by two further months and will tell you why. Exercising your rights is free of charge.
10. Complaints
If you believe we are handling your data unlawfully, please raise it with us first — most things are quicker to fix directly. You also have the right to lodge a complaint with the Czech supervisory authority:
- Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, Czech Republic
- www.uoou.gov.cz
If you live in another EU or EEA country, you may also complain to the supervisory authority where you live or work.
11. Changes to this policy
We update this policy whenever the site changes what it does with data. The current version is always published here with its ‘last updated’ date; material changes are highlighted at the top of the page.
12. Contact
Being lifestyle s.r.o., Česká Bělá 79, 582 61 Česká Bělá, Czech Republic — [email protected] — www.being-labs.com