Personal data and cookies

Information about the processing of personal data when operating the website, the contact form and donations.

Effective from:23 April 2026· Version:1.0

1. Who is the data controller

The data controller isPower of Kindness z. s., with its registered office atOpavská 390, 793 68 Dvorce, Czech Republic, registration No.24923869, registered in the associations registry kept by theRegional Court in Ostravaunder file referenceL 22684.

Contact for personal data protection matters:gdpr@powerofkindness.cz

A data protection officer has not been appointed.

2. What data we process

We process only data that is needed for operating the website, communicating with visitors and fulfilling our legal obligations.

  • identification and contact data that you provide to us yourself,
  • the content of a message sent through the contact form or by e-mail,
  • technical data about the website visit, the form submission and the security of communication,
  • data necessary for donation, accounting, contractual and related administration.

3. Website visit and technical logs

When you visit the website we may process technical and operational data, in particular:

  • IP address,
  • date and time of access,
  • the page or request visited,
  • the server response status,
  • technical data about the browser and the device,
  • referer and language preferences of the browser, if they are part of the request.

We use this data for:

  • ensuring the operation of the website,
  • website security and protection against misuse,
  • error diagnostics,
  • operational and aggregate visit statistics.

The legal basis for this processing is our legitimate interest in the secure and reliable operation of the website.

4. Contact form

If you send us a message through the contact form, we process the data needed to deliver and handle the message and also technical metadata related to the security of communication.

Messages from the contact form are delivered to the mailboxcontactform@powerofkindness.cz.

  • first name,
  • last name,
  • e-mail address,
  • message content,
  • date and time of submission,
  • technical metadata related to delivery, communication security and protection against form misuse (e.g. via Cloudflare Turnstile).

We use the data for:

  • receiving and handling your message,
  • follow-up communication,
  • protection against form misuse,
  • recording of communication to the necessary extent.

The legal basis is our legitimate interest in handling the communication and securing the website, or taking steps at your request before concluding a contract, if your message concerns specific cooperation or other legal matters.

Providing the data is voluntary. However, without your contact details we may not be able to reply to your message.

5. Donations, contracts and related administration

If you provide us with a donation, request a donation receipt, or enter into a contractual or similar relationship with us, we may process the data necessary for receiving, recording and administering such a relationship.

  • identification and contact data,
  • donation or payment data,
  • data stated in contracts and related communication,
  • data needed for accounting, tax records and the fulfilment of legal obligations.

We process this data for the purpose of:

  • receiving and recording the donation,
  • issuing a donation receipt,
  • maintaining accounting and fulfilling statutory obligations,
  • protecting our rights and demonstrating the association's financial management.

The legal basis is in particular fulfilment of a legal obligation, performance of a contract or pre-contractual negotiations, and our legitimate interest in the transparent operation of the association and the protection of rights.

6. Where we obtain the data

  • directly from you when using the website, the form or e-mail communication,
  • from banking, accounting and contractual documents,
  • from documents and data that you yourself provide to us,
  • where applicable, from public registers or public authorities, if necessary for the fulfilment of legal obligations or the protection of our rights.

7. To whom data may be disclosed

We disclose personal data only to the extent necessary and only where it is required for the given purpose.

  • providers of hosting and technical infrastructure,
  • providers of e-mail and office services, in particular Microsoft 365,
  • website administrators and technical suppliers,
  • the security service provider Cloudflare (Turnstile) for the protection of forms against misuse,
  • accounting, tax or legal advisers,
  • banks and any payment service providers,
  • public authorities, if so required by law or by a binding decision of a competent authority.

Where data is processed through external suppliers, this is done only to the extent necessary for the given service.

8. Transfer of data outside the EU/EEA

Personal data is normally processed and stored within the European Union or the European Economic Area.

We do not normally transfer personal data outside the EU/EEA. In some cases, however, transfer to the necessary extent may occur, in particular when using technical or security services provided by entities outside the EU/EEA. In such cases, appropriate safeguards in accordance with legal regulations are always applied.

9. How long we store the data

We store personal data only for the time necessary for the given purpose and for the period required by law or needed to protect our rights.

  • operational and security website logs:as a rule up to30 days, unless there is a reason to keep them longer for security or technical reasons,
  • messages from the contact form and related communication:as a rule up to12 monthsafter the end of the communication, if no further matter arises from it,
  • data on donations, accounting and tax documents, contracts and related documentation:for the period stipulated by law, as a rule up to10 years,
  • data needed to protect legal claims:for the duration of the relevant claim and necessarily thereafter.

After the relevant period has elapsed, we delete, anonymise or securely archive the data, if its further retention is required by law or to protect our rights.

10. Your rights

In connection with the processing of personal data, you have in particular the right to:

  • request access to your personal data,
  • request correction of inaccurate or outdated data,
  • request erasure of personal data, if there is no legal basis for further processing,
  • request restriction of processing,
  • object to processing based on legitimate interest,
  • request data portability, if the processing is based on a contract or consent and is carried out by automated means,
  • withdraw consent, if any processing is based on consent.

You can exercise your request by sending it to the controller's e-mail address listed in section 1.

You also have the right to lodge a complaint with the supervisory authority, which is the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, e-mail: posta@uoou.gov.cz, data box: qkbaa2n.

11. Cookies, session storage and similar technical means

On our website we try to minimise the storing of data on visitors' devices. We do not use advertising, marketing or profiling cookies.

If technical means are used on the website that are necessary for the proper functioning of the page, the forms, security or a basic technical session, this is done only to the extent necessary.

On some pages, session storage or a similar technical means may also be used for technical functioning or user convenience. For example, information about hiding an information bar may be temporarily stored within a single session.

For protecting forms against automated misuse we may also use the Cloudflare Turnstile tool, which serves to protect forms against misuse and is not used for advertising or marketing profiling of visitors.

12. Visit statistics

For a basic overview of website operation, performance and security we may use aggregate server statistics and tools without advertising profiling of visitors.

We use the statistics only for:

  • technical operation of the website,
  • aggregate evaluation of visits,
  • error diagnostics,
  • protection against misuse and security incidents.

If an analytical tool is configured to minimise the storing of data on visitors' devices, we do not use it for advertising profiling or for marketing purposes.

13. External links and social networks

Our website may contain links to external services and social networks, such as Facebook, Instagram or YouTube.

If you click on such a link and proceed to an external website, further processing of personal data is governed by the policies of the third party concerned.

Further information about the protection of personal data with the services used is available on the websites of their providers.

14. Security and data minimisation

We adopt appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or misuse.

Access to data is granted only to persons who actually need it to carry out their tasks.

When publishing public summaries and documentary materials, we ensure adequate protection of the persons concerned, partners and sensitive information. For security reasons, we may not publish all details about locations, persons, suppliers or the way the help is delivered.

15. Changes to this document

We may update this document on a continuous basis, in particular when the services used, legal requirements or the way personal data is processed change. The current version is always published on this page.

Main page Contact form Association info

Information about personal data processing and cookies: Personal data and cookies.