1. Data Controller
This Privacy Policy describes how EcoTransfer ("we", "us", or "our"), operating in Prague, Czech Republic, collects, uses, and processes your personal data in accordance with the General Data Protection Regulation (GDPR) and local data protection laws.
2. Legal Bases and Purposes of Data Processing
We process your personal data only when there is a lawful basis to do so under Article 6 of the GDPR:
- Performance of a Contract: To process your booking, manage payment transactions, communicate updates regarding your transfer, and provide the transport services requested.
- Legal Obligation: To comply with European and Czech financial, accounting, and tax regulations (e.g., maintaining billing records).
- Legitimate Interests: To improve our website and services, ensure IT security, prevent fraudulent bookings, and conduct analytical assessments of our operations.
- Consent: Where you have explicitly agreed to receive promotional marketing materials or cookies (which can be withdrawn at any time).
3. Types of Personal Data We Collect
Depending on how you interact with our website, we may collect the following categories of data:
- Identity and Contact Data: First name, last name, phone number, and email address.
- Booking and Ride Details: Pick-up and drop-off locations, date, time, flight/train details (if provided), special requests, and route details.
- Financial and Transaction Data: Payment details (processed securely via encrypted third-party payment gateways), invoice records, and payment history.
- Technical and Analytical Data: IP address, browser type, operating system, and data collected via essential and analytical cookies.
4. Data Sharing and Recipients
To successfully execute your transfer, we may share relevant portions of your data with strictly vetted third parties:
- Subcontracted Drivers and Partners: Professional transport entities operating under contractual agreements with EcoTransfer to complete your specific ride.
- Payment Processors: Secure third-party payment gateway operators handling transaction data under strict PCI-DSS standards.
- IT and Administration Providers: Cloud hosting, server management, and automated notification services.
- Public Authorities: Legal, tax, or law enforcement bodies when strictly required by European Union or member state law.
All transfers of personal data are strictly bound to partners operating within the European Economic Area (EEA) or countries with confirmed adequate data protection levels.
5. Data Retention Periods
We store your personal data only as long as strictly necessary for the purposes it was collected for:
- Contractual Data: Retained for the duration of your service agreement and for up to 3 years following the contract's fulfillment to protect against legal claims.
- Accounting and Tax Documents: Retained for up to 10 years in compliance with Czech and EU tax laws.
- Marketing Data: Stored until you object to the processing or withdraw your explicit consent.
6. Your Rights Under GDPR
As a data subject within the European Union, you possess comprehensive rights regarding your personal data. You may request to exercise these at any time:
- Right of Access (Art. 15 GDPR): The right to obtain confirmation as to whether your data is being processed and receive a copy of it.
- Right to Rectification (Art. 16 GDPR): The right to demand correction of inaccurate or incomplete data.
- Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): The right to request deletion of your data when it is no longer needed or processing lacks a legal basis.
- Right to Restriction of Processing (Art. 18 GDPR): The right to temporarily block processing under specific legal disputes.
- Right to Data Portability (Art. 20 GDPR): The right to receive your data in a structured, machine-readable format.
- Right to Object (Art. 21 GDPR): The right to object to data processing based on legitimate interests or direct marketing.
7. Complaints to Supervisory Authorities
If you believe that our processing of your personal data infringes on your privacy rights under GDPR, you have the statutory right to lodge an official complaint with a data protection authority.
The competent authority for our operations is the Czech Office for Personal Data Protection:
Úřad pro ochranu osobních údajů (ÚOOÚ)
Pplk. Sochora 27, 170 00 Prague 7, Czech Republic
Website: www.uoou.cz
8. Changes to This Privacy Policy
We reserve the right to modify this Privacy Policy to reflect changing legal requirements or adjustments in our operational frameworks. Any modifications will be made visible on this page with an updated effective date.