GDPR
GDPR Policy
These principles describe how BlazeHost processes personal data in connection with service delivery, billing, security and legal compliance.
1. DATA CONTROLLER
Controller: Jiří Viták, Company ID: 21766177, Ametystová 702/46, Prague 16 – Radotín, Czech Republic.
Email for privacy-related questions: [email protected].
2. PURPOSES AND LEGAL BASIS OF PROCESSING
Personal data is processed for the performance of the service contract under Article 6(1)(b) GDPR, for accounting and tax obligations under Article 6(1)(c) GDPR, and for system security and abuse prevention under the legitimate interest basis in Article 6(1)(f) GDPR.
Processed data may include first name, last name, email address, IP address, login history and GoPay transaction records.
3. RETENTION PERIOD
Data needed for contract performance is retained for the duration of the contractual relationship plus 2 years.
Accounting records are retained for 10 years under Act No. 563/1991 Coll.
Logs and security records are retained for 12 months.
4. RECIPIENTS AND PROCESSORS
Data may only be disclosed to contracted processors, especially the GoPay payment gateway, server housing providers, and external accounting or IT suppliers.
The Provider has processor agreements in place with all processors in line with Article 28 GDPR.
5. TRANSFERS TO THIRD COUNTRIES
Personal data is not transferred outside the EU.
If such a transfer ever becomes necessary, it will be handled in line with Article 45 et seq. GDPR, for example by relying on an adequacy decision.
6. DATA SUBJECT RIGHTS
The customer has the right to request access to personal data, rectification or erasure, restriction of processing, objection to processing and data portability.
A complaint may be filed with the Czech Data Protection Authority at uoou.cz.
7. SECURITY
The Provider uses encrypted data transfers and regular backups.
8. FINAL PROVISIONS
These principles become effective on October 9, 2025 and are available at https://billing.blazehost.cz/terms/privacy.