// Privacy Policy
Privacy Policy
How we collect, use, share and retain personal data, and the rights you have over it under the GDPR.
Published by
DERD AWESOME SOFTWARE s.r.o.
Korunní 2569/108, Vinohrady, 101 00 Praha 10, Czech Republic
Registration number (IČO) 24212628 · EU VAT CZ24212628
C 189150 held at the Municipal Court in Prague
info@derdawesomesoftware.com · +420 65578485
Last updated: 8 September 2026
1. Who is responsible for your data
DERD AWESOME SOFTWARE s.r.o., a company registered in the Czech Republic under registration number (IČO) 24212628, with registered office at Korunní 2569/108, Vinohrady, 101 00 Praha 10, Czech Republic, is the data controller for personal data collected through derdawesomesoftware.com.
No Data Protection Officer is required under Article 37 GDPR for our processing activities; privacy enquiries are handled by the company's management. You can reach us about any data protection matter at privacy@derdawesomesoftware.com or by post at the address above.
2. What personal data we collect
We collect only what we need, and only when you give it to us or when it is technically unavoidable.
a) Information you submit through a form
- Organisation name
- Contact person’s name
- Business email address
- Telephone number (optional)
- Advisory area of interest and, optionally, an annual turnover band
- The message you write to us
- The fact, date and time that you gave consent
b) Information collected automatically
- Server log data: IP address, date and time of request, the page requested, HTTP status and user agent. This is generated by the web server for security and error diagnosis.
- Your cookie choice, stored in your own browser (see the Cookie Policy).
c) What we deliberately do not collect
The Strategic Efficiency Simulator runs entirely inside your browser. The figures you enter are never transmitted to us and never stored on our servers. We do not use profiling or automated decision-making that produces legal or similarly significant effects, and we do not knowingly collect data from children — this is a business-to-business website.
3. Why we use it, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) | Retention |
|---|---|---|
| Responding to your advisory or contact enquiry | Consent, Art. 6(1)(a); and our legitimate interest in answering a business enquiry, Art. 6(1)(f) | 24 months from last contact |
| Preparing an outline scope or proposal for you | Steps taken at your request prior to entering a contract, Art. 6(1)(b) | 24 months from last contact |
| Keeping the website secure and diagnosing faults | Our legitimate interest in operating a secure service, Art. 6(1)(f) | Server logs: 30 days |
| Recording your cookie choice | Legal obligation to evidence consent, Art. 6(1)(c), with ePrivacy | 12 months |
| Complying with accounting and tax law where an engagement follows | Legal obligation, Art. 6(1)(c) | As required by Czech law, typically 10 years |
Where we rely on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew it.
5. Your rights
Under the GDPR you have the right to:
- Access — obtain confirmation of whether we process your data, and a copy of it (Art. 15).
- Rectification — have inaccurate or incomplete data corrected (Art. 16).
- Erasure — have your data deleted where one of the grounds in Art. 17 applies.
- Restriction — have processing limited in the circumstances set out in Art. 18.
- Data portability — receive the data you gave us in a structured, machine-readable format (Art. 20).
- Object — object at any time to processing based on our legitimate interests (Art. 21).
- Withdraw consent — at any time, without affecting processing already carried out (Art. 7(3)).
To exercise any of these, write to privacy@derdawesomesoftware.com. We will respond within one month, as required by Art. 12(3). We do not charge for this. We may ask you to confirm your identity where we cannot otherwise be sure the request is yours.
6. Complaints
If you believe we have handled your data unlawfully, please raise it with us first — we would rather put it right. You also have the right to lodge a complaint with the supervisory authority:
Úřad pro ochranu osobních údajů (Office for Personal Data Protection) (ÚOOÚ)
Pplk. Sochora 27, 170 00 Praha 7, Czech Republic
https://uoou.gov.cz
7. How we protect your data
The site is served exclusively over HTTPS with a valid TLS certificate. Form submissions are protected against cross-site request forgery and rate-limited against abuse. Access to the database holding enquiries is restricted to named administrators, and the database itself is not reachable from the public internet. We keep the server and its software patched.
No system is perfect. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours as required by Art. 33, and will inform you directly where Art. 34 requires it.
9. Changes to this policy
We may update this policy to reflect changes in our processing or in the law. The date at the top of this page shows when it was last revised. Where a change materially affects how we use data you have already given us, we will contact you directly.