Privacy policy
Personal data processing under Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 on personal data processing.
1. Data controller
The data controller within the meaning of Art. 4(7) of the GDPR is me personally:
Martin Ševr
Self-employed sole trader
Registered seat: Pod Kesnerkou 2404/46, 150 00 Praha 5 — Smíchov, Czechia
Reg. no.: 87639114
Field of business: Goldsmithing and jewellery
Email: zlatnikmartin@email.cz
Phone: +420 774 598 181
I haven't appointed a Data Protection Officer — Czech law doesn't require it in my case. For all data-protection matters, contact me directly.
2. What data I process and why
2.1 Contact form, email, phone and WhatsApp
If you contact me about a custom piece, a question or a consultation, I process:
- First and last name
- Email address
- Phone number (if you provide one)
- The content of your message and any attached reference photos
Purpose: answering your enquiry, preparing a quote, arranging a consultation, coordinating the making of a piece.
Legal basis: pre-contractual negotiations (Art. 6(1)(b) GDPR), or legitimate interest in communicating with you (Art. 6(1)(f) GDPR).
Retention: for the duration of our communication and a maximum of 3 years from the last contact. If a commission is concluded, data is retained for the period required by accounting and tax law (10 years).
2.2 Accounting and tax data
If you order a piece from me, I issue an invoice. For that I process:
- Name, surname, address
- For businesses, the Reg. no. and VAT no.
- Bank details (if paying by transfer)
Purpose: performance of the contract and compliance with statutory obligations (issuing invoices, archiving records).
Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR — Czech Act No. 563/1991 on Accounting, Act No. 235/2004 on VAT).
Retention: 10 years from the end of the tax period under accounting and tax law.
2.3 Website analytics — Google Analytics 4
If you grant consent in the cookie banner, I use Google Analytics 4 to statistically measure traffic on this website. It helps me understand which pages interest people and improve the site.
Google Analytics processes:
- Anonymised IP address (last octet truncated)
- Device type, browser, operating system
- Country / city based on IP
- Pages visited, time on site, traffic source
- Anonymous session identifier (cookies
_ga,_ga_*)
Purpose: statistical analysis and improving the website's content.
Legal basis: your consent (Art. 6(1)(a) GDPR), granted by clicking "Agree" in the cookie banner. You can withdraw consent at any time — see section 5.
Retention: 14 months in Google Analytics, then automatically deleted.
Processor: Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) and its parent company Google LLC (USA).
Transfer outside the EU: Google may process data in the USA. The transfer is covered by EU Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.
3. Cookies
Cookies are small text files that the website stores in your browser. I use only two types:
3.1 Necessary cookies (technical)
No consent required — used for basic site function and to store your cookie decision (cookie-consent in localStorage). Without them, the site would ask you again on every visit.
3.2 Analytics cookies (Google Analytics)
Only with consent. Set only after you click "Agree" in the cookie banner. If you don't consent, no analytics cookies are set (Consent Mode v2 blocks their activation).
I don't use advertising cookies, retargeting, or any other marketing tracking.
4. Recipients of your data
I do not share your personal data with third parties for their own purposes. I do, however, use the following processors who help me operate:
- Hostinger International Ltd (Cyprus) — web and email hosting
- Google Ireland Limited / Google LLC — only if you consent to analytics cookies
- Accountant — for bookkeeping
I may share data with public authorities (tax office, courts, police) if required by law.
5. Your rights
As a data subject, you have the following rights under the GDPR:
- Right of access (Art. 15) — you can request information about what data I process and a copy of it.
- Right to rectification (Art. 16) — you have the right to correct inaccurate or complete incomplete data.
- Right to erasure / "to be forgotten" (Art. 17) — you can request that your data be deleted if it isn't needed and I have no legal basis to keep it.
- Right to restriction (Art. 18) — you can ask that I only store your data without further processing.
- Right to data portability (Art. 20) — you have the right to obtain your data in a structured, machine-readable format.
- Right to object (Art. 21) — to processing based on legitimate interest.
- Right to withdraw consent (Art. 7(3)) — you can withdraw consent to analytics cookies at any time by deleting the
cookie-consententry in your browser or toggling the cookie banner. Withdrawal does not affect processing that took place before withdrawal. - Right to lodge a complaint with a supervisory authority — Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Praha 7.
To exercise any of these rights, contact me at zlatnikmartin@email.cz. I'll reply within 30 days at the latest.
6. Data security
I protect your data with appropriate technical and organisational measures — encrypted connections (HTTPS), secure email storage, access limited to me. WhatsApp communication is end-to-end encrypted.
7. Automated decision-making
I do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
8. Children
The website and my services do not deliberately process data of persons under 16. If I find that I've accidentally obtained a child's data without parental consent, I will delete it immediately.
9. Changes to this policy
I may update this policy. The current version is always available on this page. I will notify you of material changes by email if we are in active contact.
Effective: 13 May 2026