Information we collect
Depending on your enquiry or booking, we may process your name, company, work email and contact details; event date, group size, language, budget, objectives, venue and programme preferences; proposal, contract, invoice, and payment-status records; participant or organiser contacts; dietary, allergy, accessibility, or health-related information voluntarily provided for event arrangements; event photographs or video where individuals may be identifiable; communications, feedback, and complaints; website, device, security, and form-submission information; and marketing preferences where you choose to subscribe.
The proposal form is not a marketing-consent form. Its purpose is to answer your request and prepare a possible event proposal.
Why we use the information
We use personal data to respond to enquiries and prepare tailored recommendations and proposals; take steps requested before a contract and perform confirmed bookings; coordinate venues, suppliers, transport, catering, and event delivery; issue invoices and maintain accounting and tax records; manage safety, access requirements, complaints, and legal claims; document and, where lawfully permitted, illustrate our events and services using selected photographs or video; protect the website; and send marketing only where we have an appropriate legal basis.
Legal bases
Our principal legal bases are pre-contract steps and contract performance for proposal requests and confirmed events; legal obligation for accounting, tax, and compliance records; legitimate interests in running, securing, and improving our business, handling professional enquiries, and defending legal claims; and consent for optional marketing or sensitive information where consent is required.
If you provide dietary, allergy, health, mobility, sensory, or accessibility information, please provide only what is necessary for the event. We use it only to assess and arrange the requested accommodation, share it only with relevant staff, venues, caterers, or suppliers, and request explicit consent where legally required.
Who receives information
We may share the minimum necessary data with venues, caterers, transport providers, guides, facilitators, performers, and other event suppliers; payment, banking, and accounting providers; website hosting, email, form, security, CRM, analytics, and IT providers; professional advisers and insurers; and public authorities where required by law.
We do not sell personal data.
Invoices and secure payment links
Most bookings are paid by bank transfer against an invoice. If we issue a secure card-payment link, card information is entered directly into the payment provider's hosted system.
Prague Adventures normally receives payment confirmation, amount, and transaction reference, not the full card number or security code. The payment provider's own privacy information applies to data entered on its page.
Cookies and website technology
Necessary cookies and similar technologies support security, language, form operation, and basic site functions. Non-essential analytics or marketing technologies are used only in accordance with the choices provided by the site and applicable law.
Form security tools may process technical information to identify automated abuse or spam.
International transfers
Some service providers may process information outside the European Economic Area. Where required, we use a lawful transfer mechanism such as an adequacy decision or European Commission Standard Contractual Clauses with appropriate safeguards.
How long we keep information
Unconfirmed enquiry and proposal records are normally reviewed for deletion or minimisation after 24 months of inactivity.
Confirmed booking and supplier records are kept for the event, support, and reasonable claims period. Invoice, accounting, and tax records are kept for the statutory period, generally up to 10 years. Security logs are generally kept for a shorter operational period unless needed for an incident. Marketing records are kept until consent is withdrawn, the contact unsubscribes, or the record is no longer valid, while a minimal suppression record may be retained.
Security
We use appropriate organisational and technical measures, including access controls, secure communications, provider safeguards, limited staff access, and reasonable backup and incident-response procedures.
No internet service can guarantee absolute security. Please do not send payment-card details or unnecessary sensitive information through the proposal form.
Your rights
Subject to applicable conditions, you may request access, correction, deletion, restriction, objection, or portability of your personal data and may withdraw consent at any time where processing is based on consent.
We may request reasonable information to verify identity. We normally respond within one month, subject to any lawful extension. You may complain to the Czech Office for Personal Data Protection or another competent supervisory authority.
Automated decisions and updates
We may use lead scoring, recommendation rules, or newsletter validation rules to prioritize and route enquiries or hold signups for review, but final custom proposals, pricing, booking decisions, and marketing-list use require human review where appropriate. We do not use proposal-form information to make solely automated decisions that produce legal or similarly significant effects.
We may update this policy when our services, providers, or legal obligations change. The current version and effective date will appear on this page.