Updated: August 2026.
This page brings together everything that happens to your data on this site: which forms collect what, which external services see something, how long it is all kept and how to opt out. It is written in plain language — it is meant to be read by people, not by lawyers.
This policy applies to kompas.guide/cz — the Czech section of KOMPAS (in Russian, Ukrainian and English). The old domain kompas-czechia.com now redirects here. The Slovak section kompas.guide/sk has its own separate policy: it has a different set of services, different sections and its own supervisory authority.
1. Who is responsible for your data
The data controller (in Czech správce) is the one who decides why and how data is processed. Here this is a sole trader registered in Czechia:
- Name: Skoblei Vladyslav (OSVČ)
- IČO: 23409797
- DIČ: 0009231497
- Address: Uralská 689/7, 160 00 Praha 6 – Bubeneč, Česká republika
- E-mail: [email protected]
- Languages for enquiries: Russian, Ukrainian, Czech, Slovak, English
The e-mail address looks “Slovak” because we have one mailbox for both sites — write to it from Czechia as well; the same editorial team replies, a real person and not an autoresponder. The full imprint and the contact points for public authorities are on the Contacts page.
No Data Protection Officer (DPO / pověřenec) has been appointed. Data processing is not our core activity, we do not carry out large-scale systematic monitoring of people and we do not process special categories of data on a large scale — that is, the grounds under Article 37 GDPR for a mandatory appointment do not apply. For any questions about data, write to the address above.
2. What we collect — in brief
Data reaches us in three ways:
- You send it yourself — you fill in a form, leave a comment, register an account, write us an e-mail.
- It arises technically — every visit to any website leaves an IP address, a browser type and the time of the request. Some of this is needed for security, some is used only with your consent, for statistics.
- We take it from public sources — this applies only to the specialists directory, and there is a separate section 4 about it.
We do not send e-mail newsletters, do not sell data, do not show Google AdSense advertising and do not ask for payment details — there are no payments on the site.
3. Why we process data — situation by situation
You are simply reading the site
- Data: IP address, device and browser type, the page you came from, the time of the request, country by IP.
- Why: to deliver the page, to cope with the load, to fend off attacks and bots, to work out what happened if something broke.
- Legal basis: our legitimate interest (Art. 6(1)(f) GDPR). Put into words: keeping the site available and protected from abuse. Without basic server logs this is impossible.
- Retention: technical error logs — 90 days. Network logs of the attack protection — on Cloudflare's side, according to their periods.
Cookies and your choice
On your first visit you see a banner with three categories: necessary (always active), analytics and marketing. Both toggles are off by default — until you switch them on yourself, not a single third-party script is loaded.
- Data: your choice is stored in your browser's memory (key
kompas_cookie_consent) plus a technical cookie marker. Separately, on the server we record the fact of the choice: the date and time, which categories, the banner version, the browser string. The IP address is not stored in the process. - Why: so as not to ask you every time — and to be able to prove that consent really was given (Art. 7(1) GDPR places this burden on us, not on you).
- Legal basis: for the record of the choice itself — the legitimate interest of demonstrating compliance with the law; for whatever is switched on by your choice — your consent (Art. 6(1)(a)).
- Retention: the choice is valid for 365 days if you allowed something, and 180 days if you refused everything — after that the banner will ask again. The server-side consent log is kept while the consent is valid and for 3 more years after it is withdrawn or expires — as evidence of consent.
- To change or withdraw: the “Change cookie choice” button in the footer of every page and on the Cookies page. Withdrawal takes effect for the future and does not make unlawful what happened before it.
Traffic analytics — only with your consent
- Service: Google Analytics 4.
- Data: pages viewed, time spent on them, device type, approximate city by IP, identifiers in cookies (
_ga,_ga_*). - Why: to understand which materials people read and which they do not, and what does not work on the site.
- Legal basis: consent to the “analytics” category (Art. 6(1)(a)). Without consent the script is not loaded at all.
- Retention: in Google Analytics — 14 months; the
_gacookie — up to 2 years or until you delete it in your browser.
Marketing pixels are currently not connected on the Czech site. The “marketing” category exists in the banner, but there is nothing for it to switch on yet: there are no advertising trackers here. If any appear, we will update this policy before launching them and will ask for consent separately.
View counters
- Data: the fact that an article, a news item, an event or a glossary term was viewed. So as not to count the same person ten times, we take an irreversible hash of the IP address, a secret key and the current date. The IP address itself is not stored anywhere, and the key changes every day — that is, yesterday's hashes cannot be matched with today's.
- Why: to show “how many times it was read” and to understand what people need on the site.
- Legal basis: the legitimate interest of having honest statistics about our own content without identifying the reader (Art. 6(1)(f)).
- Retention: 14 months.
Behavioural statistics of sections — only with your consent
- Data: events such as “opened a card”, “clicked show contact” — linked to a random device identifier that is stored in your browser's memory.
- Why: to show card owners anonymised statistics of interest.
- Legal basis: consent to analytics (Art. 6(1)(a)). Without consent the identifier is not created and the events are not recorded.
- Retention: 14 months.
Personal account
- Data: e-mail; a personal or company name; optionally — phone, messengers, links to social networks, a website, a profile photo. Sign-in — via Google or via e-mail and password. We do not see your password: it is stored as a hash.
- Why: to let you sign in, edit your own cards and materials and contact you about them.
- Legal basis: performance of the contract with you — use of the account (Art. 6(1)(b)).
- If you sign in via Google: Google tells us your address, name and profile photo. We do not receive your password and have no access to your mailbox.
- Retention: as long as the account exists. In the account there is a “Delete account” button — it works immediately: the profile is wiped, the account and all sessions are deleted. Directory cards assigned to you do not disappear in the process — they are unpublished and returned to the moderation queue without any link to you.
Enquiries and requests through forms
- Data: name, means of contact (e-mail, phone or messenger nickname), the text of the request, the page it was sent from, and the IP address.
- Why: to answer you and to pass the request on to whoever it concerns.
- Legal basis: steps taken at your request prior to entering into a contract (Art. 6(1)(b)); storing the IP address — the legitimate interest of investigating spam and abuse of the form (Art. 6(1)(f)).
- Where it goes: a notification about a new enquiry arrives in the editorial team's working chat on Telegram. Your IP address is not included in that message — it stays only in our database.
- Retention: 24 months.
Comments under articles
- Data: name or nickname, the text of the comment, optionally — e-mail (it is not shown publicly).
- Legal basis: your consent to publication (Art. 6(1)(a)).
- Retention: as long as the comment is published; we delete it at the author's request or for breaking the rules.
- When commenting, the IP address is used only as a temporary key for rate limiting and is not stored.
Reports about content and complaints about materials
- Data: your name and e-mail, a link to the material and a description of the problem.
- Why: to consider the complaint and inform you of the decision — this is required by Art. 16 of Regulation (EU) 2022/2065 (DSA).
- Legal basis: compliance with a legal obligation (Art. 6(1)(c)).
- Retention: 12 months.
The translator on the site
The “Translator” page works through the external service MyMemory (Translated srl, Italy). The text you paste into the field leaves our server — we neither store nor log it, but we do pass it to a third party for translation, and what that party does with it next depends on its own terms.
- Legal basis: provision of the service you requested (Art. 6(1)(b)).
- Retention on our side: zero — neither the source text nor the translation goes into the database.
- A warning worth taking seriously: do not paste passport details, medical certificates, rental agreements or letters from the úřad that contain other people's data into it. Documents need a sworn translation (soudní překlad), not a machine one.
Your letters and enquiries
When you write to our mailbox or contact us about your rights, we process what is in the letter: the address, the name, the content. The legal basis is the legitimate interest of answering the enquiry, and for requests about rights — a legal obligation (Art. 6(1)(c)). We keep the correspondence for as long as is needed to reply and to confirm that a reply was given.
Sections that do not exist on the Czech site yet
Housing listings, the job board, the university directory and the directories of schools and agencies currently work only in the Slovak section. These pages do not exist on the Czech site — which means the forms attached to them do not exist either: enquiries under listings (they go directly to the author of the listing), complaints about vacancies and reviews of schools and agencies. None of this is collected here. When a section appears, we will describe it in this policy before the launch, not after.
4. The specialists directory: data we did not receive from you
Some of the cards in the specialists directory are compiled from public sources — public Telegram channels and chats, open pages on Facebook and Instagram, industry directories and the specialists' own websites. That is, we received this data not from the person it concerns. Article 14 GDPR requires us to explain this separately — we are doing so here.
- Categories of data: a personal or company name, profession and specialisation, city, languages of service, a public business contact (phone, messenger, a link to a profile or website), a description of services.
- Sources: the public resources listed above; some cards were created by the specialists themselves, some were sent in by readers. Technically, we collect public pages through the Apify service.
- Legal basis: legitimate interest (Art. 6(1)(f)). We name it plainly: to give people who have recently arrived a way to find a specialist who speaks their language, instead of searching blindly through chats. We weighed this against the interests of the specialists themselves and limited ourselves to business contacts, which they publish for clients anyway.
- What we deliberately do not do: we do not publish home addresses or personal phone numbers, we do not add photos of people without their permission, we do not collect data about the specialists' clients.
- Who we pass it to: no one. The cards are public on the site, but we do not sell or hand over the database.
- Retention: as long as the card is published or until you ask us to remove it.
Your rights here are broader than usual. If you have found yourself in the directory:
- every card has a “This is my card” button — through it you can claim the card, correct the data or ask for it to be removed completely;
- we do not ask for reasons. A request to remove a card is carried out within 72 hours;
- you have the right to object to the processing (Art. 21 GDPR) at any time — and when it comes to a card in the directory, we do not argue.
The section has not been publicly launched yet, but the data in it is already being processed — which is exactly why this part of the policy is written now and not “when we launch”.
5. Who we pass data to
We do not sell data and do not pass it to “marketing partners”. The list below is everyone who technically sees something, and for what exactly.
| Who | What they see and why | Where |
|---|---|---|
| Cloudflare, Inc. | All site traffic goes through their network: IP address, request data. Protection from attacks, bot filtering, faster loading. | Global network; requests from Europe are usually served by European nodes |
| Our own server | This is where the site and the database physically live (Supabase, deployed by ourselves and not a cloud service). | Netherlands, EU |
| Google Ireland Ltd. / Google LLC | Google Analytics 4 — only with consent to analytics. Sign-in via Google — only if you used it. Google Maps — maps on the pages that have them. | EU / USA |
| Telegram | Notifications to the editorial team about new enquiries and complaints. | Outside the EEA |
| Translated srl (MyMemory) | The text you entered into the translator on the site. | Italy, EU (with possible involvement of subcontractors) |
| OpenAI, OpenRouter, DeepL SE | Automatic translation of site content into three languages — including the descriptions in profiles and cards that you publish. | EU / USA |
| ElevenLabs | Audio for glossary terms. Receives no personal data. | USA |
| Apify | Technical collection of publicly available pages for the directories. | Czechia, EU |
| Public authorities | Only where the law requires it and on a lawful basis. | CZ / SK / EU |
6. Does data leave the EU
The site and the database are located in the European Union. But some of the services in the list above are American or global, so certain data may be processed outside the European Economic Area.
For such transfers we rely on the European Commission's decision on the adequacy of the level of protection, and where it does not apply or has ceased to be valid — on the Commission's standard contractual clauses (SCC) together with additional technical measures. This wording is deliberately not tied to one specific framework: adequacy decisions are reviewed by the courts from time to time, and the set of safeguards you have should not change because of that.
7. How long we keep data
These periods are not declarative — an automatic cleanup of the database enforces them every day. Whatever is overdue is deleted, not “archived”.
| What | How long |
|---|---|
| Enquiries and requests from forms | 24 months |
| Reports about content and complaints about materials | 12 months |
| Behavioural statistics events | 14 months |
| View counters (articles, news, events, glossary) | 14 months |
| Technical error logs | 90 days |
| Log of editorial actions in the admin panel | 24 months |
| Cookie consent log | kept while the consent is valid and for 3 more years after it is withdrawn or expires — as evidence of consent (Art. 7(1) GDPR) |
| Account and profile | until you delete it |
| Published comments and cards | as long as they are published or until you ask us to remove them |
Database backups are kept for up to 30 days — that is, deleted data finally disappears from the copies within that period.
8. Your rights
All these rights are free of charge. We reply within 30 days; if the request is complex, we may extend the deadline by a further two months, but we must tell you about it and explain why.
- Access (Art. 15) — to find out whether we hold your data, exactly what it is and what we do with it, and to receive a copy.
- Rectification (Art. 16) — to correct a mistake or complete incomplete data.
- Erasure (Art. 17) — the “right to be forgotten”. For the account — the button in your personal account, it works immediately. For everything else — an e-mail to us.
- Restriction of processing (Art. 18) — to ask us to “put it on pause” while we look into a disputed point.
- Portability (Art. 20) — to receive the data you gave us in a machine-readable format.
- Objection (Art. 21) — to object to processing based on legitimate interest: the directory, statistics, security. You can object to direct marketing at any time and without explanation.
- Withdrawal of consent (Art. 7(3)) — at any moment and just as easily as you gave it: the “Change cookie choice” button in the site footer. Withdrawal does not make unlawful what already happened before it.
- Not to be subject to an automated decision (Art. 22) — see section 11.
To exercise any of them, write to [email protected]. We may ask for clarification if it is not clear from the letter whose data is meant — but we will not demand copies of documents “just in case”.
9. Where to complain
If you think we are handling your data incorrectly, write to us first — most questions are settled with a single e-mail. But you are not obliged to come to us first and can lodge a complaint with a supervisory authority straight away.
Article 77 GDPR lets you choose the authority of the country where you live, where you work or where the alleged infringement took place. The operator is registered in Czechia, and part of our audience lives in Slovakia — both are suitable:
- Czechia: Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7. E-mail: [email protected], website: uoou.gov.cz
- Slovakia: Úrad na ochranu osobných údajov Slovenskej republiky, Galvaniho Business Centrum II, Galvaniho 7/B, Bratislava. E-mail: [email protected], website: dataprotection.gov.sk
10. Do you have to give us data
No. You can read the site without telling us anything about yourself at all: all forms are voluntary, registration is not needed, analytics can be declined with a single button — and the site works just the same.
But some actions are impossible without data, and this is not a punishment, it is physics: without a name and a contact we will not be able to answer an enquiry; without an e-mail there will be no account, because the address is exactly what your login is; without the text of a complaint a material cannot be checked. If you do not provide this data, we simply will not be able to provide the corresponding service — there will be no other consequences.
11. Automated decisions and profiling
We do not make automated decisions about you — the kind that would have legal effects or significantly affect you (Art. 22 GDPR). Nobody gains or loses access, status or a service because of an algorithm's decision.
Artificial intelligence on the site works with texts, not with people: it translates materials into three languages, sorts articles by topic and helps the editorial team prepare content. Before publication, materials are read and checked by a real person — the editorial team, which also bears responsibility for them. Moderation of comments, reviews and cards is likewise a human decision, not an automated one.
12. Children
The site is intended for adults. We deliberately do not collect data of people under 16 and do not offer them services. Czech law 110/2019 Sb. allows a lower age of digital consent, but we keep a single and more cautious bar of 16 years on both sites. If it turns out that a child's data has reached us without parental consent, we will delete it as soon as we find out. If you are a parent and see your child's data on the site — write to us and we will remove it without unnecessary formalities.
13. How we protect data
- All connections are over HTTPS (TLS) only, without exceptions.
- The site and the database are on our own server in the EU; access to the database is limited to a small circle of people and only with secure keys.
- Personal data from forms and reviews is not accessible to the site's public key — it is read only by the server side of the admin panel.
- Passwords are stored as irreversible hashes, IP addresses in the counters — as salted hashes with a daily key rotation.
- Backups are made daily and stored separately from the main server.
- Third-party scripts are not loaded until you have given consent.
One-hundred-percent security does not exist on the internet, and promising it would be untrue. If a breach occurs that threatens your rights, we will notify the supervisory authority within 72 hours, and you — without undue delay, as required by Art. 33–34 GDPR.
14. Changes to this policy
The site changes, and the policy will change with it. The current version is always on this page, and the date of the update is at the top. If the changes turn out to be significant — a new service appears that sees your data, or the legal basis for processing changes — we will announce it visibly on the site, not by quietly editing the text. If a change concerns something you gave consent to, we will ask for consent again.
Questions, comments, a request about your data: [email protected]. Write in Russian, Ukrainian, Czech, Slovak or English — we will reply.