Skip to main content
kompas

Privacy Policy

Updated: August 2026.

This page brings together everything that happens to your data on this site: which forms collect what, which external services see something, how long it is all kept and how to opt out. It is written in plain language — it is meant to be read by people, not by lawyers.

This policy applies to kompas.guide/cz — the Czech section of KOMPAS (in Russian, Ukrainian and English). The old domain kompas-czechia.com now redirects here. The Slovak section kompas.guide/sk has its own separate policy: it has a different set of services, different sections and its own supervisory authority.

1. Who is responsible for your data

The data controller (in Czech správce) is the one who decides why and how data is processed. Here this is a sole trader registered in Czechia:

The e-mail address looks “Slovak” because we have one mailbox for both sites — write to it from Czechia as well; the same editorial team replies, a real person and not an autoresponder. The full imprint and the contact points for public authorities are on the Contacts page.

No Data Protection Officer (DPO / pověřenec) has been appointed. Data processing is not our core activity, we do not carry out large-scale systematic monitoring of people and we do not process special categories of data on a large scale — that is, the grounds under Article 37 GDPR for a mandatory appointment do not apply. For any questions about data, write to the address above.

2. What we collect — in brief

Data reaches us in three ways:

We do not send e-mail newsletters, do not sell data, do not show Google AdSense advertising and do not ask for payment details — there are no payments on the site.

3. Why we process data — situation by situation

You are simply reading the site

Cookies and your choice

On your first visit you see a banner with three categories: necessary (always active), analytics and marketing. Both toggles are off by default — until you switch them on yourself, not a single third-party script is loaded.

Traffic analytics — only with your consent

Marketing pixels are currently not connected on the Czech site. The “marketing” category exists in the banner, but there is nothing for it to switch on yet: there are no advertising trackers here. If any appear, we will update this policy before launching them and will ask for consent separately.

View counters

Behavioural statistics of sections — only with your consent

Personal account

Enquiries and requests through forms

Comments under articles

Reports about content and complaints about materials

The translator on the site

The “Translator” page works through the external service MyMemory (Translated srl, Italy). The text you paste into the field leaves our server — we neither store nor log it, but we do pass it to a third party for translation, and what that party does with it next depends on its own terms.

Your letters and enquiries

When you write to our mailbox or contact us about your rights, we process what is in the letter: the address, the name, the content. The legal basis is the legitimate interest of answering the enquiry, and for requests about rights — a legal obligation (Art. 6(1)(c)). We keep the correspondence for as long as is needed to reply and to confirm that a reply was given.

Sections that do not exist on the Czech site yet

Housing listings, the job board, the university directory and the directories of schools and agencies currently work only in the Slovak section. These pages do not exist on the Czech site — which means the forms attached to them do not exist either: enquiries under listings (they go directly to the author of the listing), complaints about vacancies and reviews of schools and agencies. None of this is collected here. When a section appears, we will describe it in this policy before the launch, not after.

4. The specialists directory: data we did not receive from you

Some of the cards in the specialists directory are compiled from public sources — public Telegram channels and chats, open pages on Facebook and Instagram, industry directories and the specialists' own websites. That is, we received this data not from the person it concerns. Article 14 GDPR requires us to explain this separately — we are doing so here.

Your rights here are broader than usual. If you have found yourself in the directory:

The section has not been publicly launched yet, but the data in it is already being processed — which is exactly why this part of the policy is written now and not “when we launch”.

5. Who we pass data to

We do not sell data and do not pass it to “marketing partners”. The list below is everyone who technically sees something, and for what exactly.

WhoWhat they see and whyWhere
Cloudflare, Inc.All site traffic goes through their network: IP address, request data. Protection from attacks, bot filtering, faster loading.Global network; requests from Europe are usually served by European nodes
Our own serverThis is where the site and the database physically live (Supabase, deployed by ourselves and not a cloud service).Netherlands, EU
Google Ireland Ltd. / Google LLCGoogle Analytics 4 — only with consent to analytics. Sign-in via Google — only if you used it. Google Maps — maps on the pages that have them.EU / USA
TelegramNotifications to the editorial team about new enquiries and complaints.Outside the EEA
Translated srl (MyMemory)The text you entered into the translator on the site.Italy, EU (with possible involvement of subcontractors)
OpenAI, OpenRouter, DeepL SEAutomatic translation of site content into three languages — including the descriptions in profiles and cards that you publish.EU / USA
ElevenLabsAudio for glossary terms. Receives no personal data.USA
ApifyTechnical collection of publicly available pages for the directories.Czechia, EU
Public authoritiesOnly where the law requires it and on a lawful basis.CZ / SK / EU

6. Does data leave the EU

The site and the database are located in the European Union. But some of the services in the list above are American or global, so certain data may be processed outside the European Economic Area.

For such transfers we rely on the European Commission's decision on the adequacy of the level of protection, and where it does not apply or has ceased to be valid — on the Commission's standard contractual clauses (SCC) together with additional technical measures. This wording is deliberately not tied to one specific framework: adequacy decisions are reviewed by the courts from time to time, and the set of safeguards you have should not change because of that.

7. How long we keep data

These periods are not declarative — an automatic cleanup of the database enforces them every day. Whatever is overdue is deleted, not “archived”.

WhatHow long
Enquiries and requests from forms24 months
Reports about content and complaints about materials12 months
Behavioural statistics events14 months
View counters (articles, news, events, glossary)14 months
Technical error logs90 days
Log of editorial actions in the admin panel24 months
Cookie consent logkept while the consent is valid and for 3 more years after it is withdrawn or expires — as evidence of consent (Art. 7(1) GDPR)
Account and profileuntil you delete it
Published comments and cardsas long as they are published or until you ask us to remove them

Database backups are kept for up to 30 days — that is, deleted data finally disappears from the copies within that period.

8. Your rights

All these rights are free of charge. We reply within 30 days; if the request is complex, we may extend the deadline by a further two months, but we must tell you about it and explain why.

To exercise any of them, write to [email protected]. We may ask for clarification if it is not clear from the letter whose data is meant — but we will not demand copies of documents “just in case”.

9. Where to complain

If you think we are handling your data incorrectly, write to us first — most questions are settled with a single e-mail. But you are not obliged to come to us first and can lodge a complaint with a supervisory authority straight away.

Article 77 GDPR lets you choose the authority of the country where you live, where you work or where the alleged infringement took place. The operator is registered in Czechia, and part of our audience lives in Slovakia — both are suitable:

10. Do you have to give us data

No. You can read the site without telling us anything about yourself at all: all forms are voluntary, registration is not needed, analytics can be declined with a single button — and the site works just the same.

But some actions are impossible without data, and this is not a punishment, it is physics: without a name and a contact we will not be able to answer an enquiry; without an e-mail there will be no account, because the address is exactly what your login is; without the text of a complaint a material cannot be checked. If you do not provide this data, we simply will not be able to provide the corresponding service — there will be no other consequences.

11. Automated decisions and profiling

We do not make automated decisions about you — the kind that would have legal effects or significantly affect you (Art. 22 GDPR). Nobody gains or loses access, status or a service because of an algorithm's decision.

Artificial intelligence on the site works with texts, not with people: it translates materials into three languages, sorts articles by topic and helps the editorial team prepare content. Before publication, materials are read and checked by a real person — the editorial team, which also bears responsibility for them. Moderation of comments, reviews and cards is likewise a human decision, not an automated one.

12. Children

The site is intended for adults. We deliberately do not collect data of people under 16 and do not offer them services. Czech law 110/2019 Sb. allows a lower age of digital consent, but we keep a single and more cautious bar of 16 years on both sites. If it turns out that a child's data has reached us without parental consent, we will delete it as soon as we find out. If you are a parent and see your child's data on the site — write to us and we will remove it without unnecessary formalities.

13. How we protect data

One-hundred-percent security does not exist on the internet, and promising it would be untrue. If a breach occurs that threatens your rights, we will notify the supervisory authority within 72 hours, and you — without undue delay, as required by Art. 33–34 GDPR.

14. Changes to this policy

The site changes, and the policy will change with it. The current version is always on this page, and the date of the update is at the top. If the changes turn out to be significant — a new service appears that sees your data, or the legal basis for processing changes — we will announce it visibly on the site, not by quietly editing the text. If a change concerns something you gave consent to, we will ask for consent again.

Questions, comments, a request about your data: [email protected]. Write in Russian, Ukrainian, Czech, Slovak or English — we will reply.