GDPR

GDPR Policy

These principles describe how BlazeHost processes personal data in connection with service delivery, billing, security and legal compliance.

1. DATA CONTROLLER

Controller: Jiří Viták, Company ID: 21766177, Ametystová 702/46, Prague 16 – Radotín, Czech Republic.

Email for privacy-related questions: [email protected].

2. PURPOSES AND LEGAL BASIS OF PROCESSING

Personal data is processed for the performance of the service contract under Article 6(1)(b) GDPR, for accounting and tax obligations under Article 6(1)(c) GDPR, and for system security and abuse prevention under the legitimate interest basis in Article 6(1)(f) GDPR.

Processed data may include first name, last name, email address, IP address, login history and GoPay transaction records.

3. RETENTION PERIOD

Data needed for contract performance is retained for the duration of the contractual relationship plus 2 years.

Accounting records are retained for 10 years under Act No. 563/1991 Coll.

Logs and security records are retained for 12 months.

4. RECIPIENTS AND PROCESSORS

Data may only be disclosed to contracted processors, especially the GoPay payment gateway, server housing providers, and external accounting or IT suppliers.

The Provider has processor agreements in place with all processors in line with Article 28 GDPR.

5. TRANSFERS TO THIRD COUNTRIES

Personal data is not transferred outside the EU.

If such a transfer ever becomes necessary, it will be handled in line with Article 45 et seq. GDPR, for example by relying on an adequacy decision.

6. DATA SUBJECT RIGHTS

The customer has the right to request access to personal data, rectification or erasure, restriction of processing, objection to processing and data portability.

A complaint may be filed with the Czech Data Protection Authority at uoou.cz.

7. SECURITY

The Provider uses encrypted data transfers and regular backups.

8. FINAL PROVISIONS

These principles become effective on October 9, 2025 and are available at https://billing.blazehost.cz/terms/privacy.