LEGAL

Privacy Policy & GDPR

Last updated: July 2026

This policy explains what personal data Being lifestyle s.r.o. (trading as Being Labs) processes when you visit this website or get in touch with us, why we process it, who else sees it, and what you can require us to do about it. It is written to meet Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 Coll. on the processing of personal data.

The short version: this website sets no cookies of its own, runs no advertising or profiling, and the only personal data we ask you for is what you type into the contact form.

1. Who is responsible for your data

The data controller is:

  • Being lifestyle s.r.o., trading as Being Labs
  • Registered office: Česká Bělá 79, 582 61 Česká Bělá, Czech Republic
  • Company ID (IČO): 19067135
  • Data box ID (datová schránka): ndwt9p8
  • Email: [email protected]

We are not required to appoint a Data Protection Officer under Art. 37 GDPR and have not appointed one. Send any privacy question or rights request to the address above and it reaches the person who can act on it.

2. What we process, why, and for how long

PurposeDataLegal basisRetention
Answering an enquiry sent through the contact formName, email address, message, language, timestampArt. 6(1)(b) — steps taken at your request before entering into a contract24 months from the last contact
Ongoing email and phone correspondenceContact details and the content of the correspondenceArt. 6(1)(b) and Art. 6(1)(f) — our legitimate interest in maintaining a business relationship24 months from the last contact
Keeping the website and server secure and availableIP address, user agent, requested URL, response status (server and firewall logs)Art. 6(1)(f) — our legitimate interest in preventing abuse and attacksUp to 30 days, then deleted or aggregated
Understanding which pages are readAggregated page views, referrer, country, device class — no cookies, no identifier that follows youArt. 6(1)(f) — our legitimate interest in improving the siteAggregated statistics only; no visitor-level record is created
Meeting statutory accounting and tax duties for clientsBilling details on invoicesArt. 6(1)(c) — compliance with the Czech Accounting Act and VAT Act10 years, as required by law

Providing your data is voluntary. If you do not fill in the contact form we simply have no way to reply to you; nothing else on the site is affected.

3. What we do not do

  • We do not sell, rent or trade personal data. Ever.
  • We run no advertising, remarketing or cross-site tracking, and we set no marketing cookies.
  • We do not build visitor profiles and we carry out no automated decision-making or profiling within the meaning of Art. 22 GDPR.
  • We do not knowingly collect special categories of data (Art. 9) and this site is not directed at children.

4. Analytics without cookies

Our traffic statistics come from Cloudflare, which already routes every request to this site. They are computed in Cloudflare’s network from those requests: no analytics script is loaded into your browser, nothing is stored on your device, no cross-site identifier is created and your browser is not fingerprinted. We see aggregate numbers — how many people opened a page, roughly where from, on what kind of device — and never an individual visitor’s browsing history. Because no information is stored on or read from your device, no consent banner is required under Art. 5(3) of the ePrivacy Directive.

5. Who else sees your data

We share data only with the processors below, only for the purpose stated, and only under a data processing agreement under Art. 28 GDPR. We also disclose data to public authorities where a law obliges us to.

RecipientPurposeLocationTransfer safeguard
Hetzner Online GmbHHosting of this website and our internal toolingGermany (EU)No transfer outside the EEA
Cloudflare, Inc.DNS, CDN, WAF and traffic statistics computed from request logs — no script, no cookieEU edge network; US parent companyEU-US Data Privacy Framework and Standard Contractual Clauses
n8n (self-hosted)Moves contact-form submissions from the website into our own systemsOur own server at Hetzner, Germany (EU)No transfer outside the EEA
Telegram FZ-LLCInternal alert telling us a new enquiry has arrivedUnited Arab EmiratesStandard Contractual Clauses; we keep the alert content minimal
Google Ireland LimitedBusiness email (Gmail / Google Workspace) used to reply to youIreland (EU), with support access from the USEU-US Data Privacy Framework and Standard Contractual Clauses
Notion Labs, Inc.CRM record of enquiries, clients and projectsUnited StatesEU-US Data Privacy Framework and Standard Contractual Clauses

6. Transfers outside the EEA

The website itself is hosted in the European Union. Where a recipient listed above sits outside the EEA, the transfer relies on the European Commission’s Standard Contractual Clauses under Art. 46(2)(c) GDPR and, where the provider is certified, on the EU-US Data Privacy Framework adequacy decision. You may ask us for a copy of the safeguards that apply to a specific transfer.

7. Cookies

This website sets no cookies of its own and uses no browser storage to identify you. The only cookies you may encounter come from Cloudflare’s security layer and are strictly necessary. The detail is in our Cookie Policy.

8. How we keep data safe

  • All traffic is served over HTTPS with a modern TLS configuration.
  • Servers sit in EU data centres behind a firewall, with a WAF and rate limiting in front of the application.
  • Access to enquiry data is limited to the people who need it, over authenticated accounts with multi-factor authentication.
  • Secrets and API keys are held in server-side environment variables and never shipped to the browser.

No method of transmission over the internet is completely secure, so we cannot guarantee absolute security — but we do review these measures as the site changes.

9. Your rights

Under the GDPR you have the right to:

  • Access (Art. 15) — get confirmation of whether we process your data and a copy of it.
  • Rectification (Art. 16) — have inaccurate or incomplete data corrected.
  • Erasure (Art. 17) — have your data deleted, unless we must keep it to meet a legal duty.
  • Restriction (Art. 18) — have processing paused while a dispute about accuracy or legitimate interest is resolved.
  • Data portability (Art. 20) — receive the data you gave us in a structured, machine-readable format.
  • Object (Art. 21) — object at any time to processing based on our legitimate interest.
  • Withdraw consent (Art. 7(3)) — where processing rests on consent, withdraw it at any time, without affecting what was lawful before.

To exercise any of these, email [email protected]. We reply within one month of receiving the request, as required by Art. 12(3) GDPR; if a request is unusually complex we may extend that by two further months and will tell you why. Exercising your rights is free of charge.

10. Complaints

If you believe we are handling your data unlawfully, please raise it with us first — most things are quicker to fix directly. You also have the right to lodge a complaint with the Czech supervisory authority:

  • Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, Czech Republic
  • www.uoou.gov.cz

If you live in another EU or EEA country, you may also complain to the supervisory authority where you live or work.

11. Changes to this policy

We update this policy whenever the site changes what it does with data. The current version is always published here with its ‘last updated’ date; material changes are highlighted at the top of the page.

12. Contact

Being lifestyle s.r.o., Česká Bělá 79, 582 61 Česká Bělá, Czech Republic — [email protected] www.being-labs.com