Privacy policy
This is an English translation provided for convenience. The legally binding version is the Czech original.
Personal data controller
- Alfa Tower a.s.
- Registered office: Mlýnská 22/4, 160 00 Praha 6
- Company ID (IČO): 24808261
- File number: B 16939, kept by the Municipal Court in Prague
- E-mail: lucie@setina.cz
(the “Controller”)
This policy explains how the Controller processes and protects the personal data of visitors to the website www.biorezonancedejvice.cz, prospective clients and clients using therapeutic activities, frequency harmonisation and related services.
I. What personal data we process
In connection with running the website, communicating with prospective clients, booking appointments and providing services, the Controller may process in particular:
- first name and surname,
- phone number,
- e-mail address,
- details needed to book an appointment,
- details relating to the order and payment for services,
- the content of mutual e-mail, phone or other communication,
- information the client voluntarily provides in connection with the service,
- technical data related to the use of the website, in particular the IP address and data obtained through cookies.
Data concerning health
In connection with therapeutic activities and frequency harmonisation, a client may also voluntarily give the Controller information about their state of health, problems, medication, implants, previous procedures or other information that may be relevant to providing the service safely and appropriately.
Under Article 9 GDPR, data concerning health is a special category of personal data, and the Controller gives it increased protection.
Where the processing of such data is based on the client's consent, it is processed only on the basis of their explicit consent and to the extent necessary for the purpose.
The services do not replace medical diagnosis, health care or treatment provided by healthcare professionals.
II. Purposes and legal bases of processing
We process personal data in particular for the following purposes:
1. Booking appointments and communicating with clients
We use personal data to handle enquiries, arrange or change appointments, communicate before a visit and organise the service.
The legal basis is mainly taking steps prior to entering into a contract or the performance of a contract.
2. Providing booked services
We process personal data to the extent necessary to provide the booked service, keep related records and communicate with the client.
The legal basis is mainly the performance of a contract.
3. Information concerning health
If, in connection with a therapeutic activity or frequency harmonisation, a client provides information about their state of health and the Controller records or otherwise processes it, the legal basis for processing may be the client's explicit consent under Article 9(2)(a) GDPR, unless another legal basis applies to the particular processing.
The client may withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
4. Accounting and tax obligations
We also process some personal data to issue and record accounting and tax documents and to meet other legal obligations.
The legal basis is compliance with the Controller's legal obligations.
5. Protection of legal claims
Where necessary, we may also retain personal data to protect our rights and to resolve any complaints, disputes or other legal claims.
The legal basis is the Controller's legitimate interest.
6. Marketing communication
If you give us your consent, we may use your e-mail address to send news, information about services, events or other commercial communications.
Where permitted by law, we may also send commercial communications to existing customers about similar services.
You can unsubscribe from commercial communications at any time via the link in the relevant message or by sending a request to lucie@setina.cz.
III. How long we keep personal data
We keep personal data only for as long as necessary for the purpose for which it was obtained.
Data relating to bookings and the provision of services is kept for the duration of the contractual relationship and then for as long as necessary to protect the Controller's legal claims.
Accounting and tax documents are kept for the period required by the relevant legislation.
Personal data processed on the basis of consent is kept until consent is withdrawn, but no longer than necessary for the stated purpose.
Data used to send commercial communications is processed until consent is withdrawn, the subscription is cancelled or an objection to such processing is raised.
When the relevant period ends, personal data is securely deleted or anonymised, unless its further retention is required by law.
IV. Recipients of personal data
To the extent necessary, personal data may be made available to third parties that provide the Controller with technical, accounting, administrative or other support services.
These may include in particular:
- web hosting providers and website administrators,
- e-mail service providers,
- booking system providers, if one is used,
- accounting and tax service providers,
- IT service providers,
- providers of analytics and marketing tools, if they are used on the website,
- public authorities, where the law requires the data to be handed over.
The Controller passes on to these parties only the data necessary for the relevant purpose and ensures appropriate security of personal data.
V. Cookies
The website www.biorezonancedejvice.cz may use cookies and similar technologies.
Technical cookies necessary for the website to work properly may be used without the user's consent to the extent permitted by law.
Analytics, marketing and other optional cookies are used only in line with the user's settings in the cookie bar, where consent is required for their use.
Users can change their cookie preferences through the cookie settings on the website.
Specific information about the cookies used and any external services is given in the cookie settings on the website.
VI. Security of personal data
The Controller takes appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, disclosure or destruction.
Particular attention is paid to protecting any data concerning clients' health.
Only persons who need personal data to perform their work or contractual duties have access to it.
VII. Transfers of personal data outside the European Union
The Controller itself does not intend to transfer personal data to third countries outside the European Union or the European Economic Area.
However, if the Controller uses external providers through whom personal data may be transferred outside the EU/EEA, such transfers take place only when the conditions set by the GDPR are met, in particular on the basis of a European Commission adequacy decision or using appropriate data protection safeguards.
VIII. Rights of data subjects
In connection with the processing of personal data, under the conditions set by the GDPR you have in particular:
- the right of access to your personal data,
- the right to rectification of inaccurate or incomplete data,
- the right to erasure of personal data,
- the right to restriction of processing,
- the right to object to processing,
- the right to data portability,
- the right to withdraw consent at any time,
- the right not to be subject to a decision based solely on automated processing, where the conditions of the GDPR are met.
You can exercise your rights by e-mail: lucie@setina.cz
If in doubt about the identity of the person making a request, the Controller may ask for reasonable verification of identity.
IX. Right to lodge a complaint
If you believe that the processing of your personal data breaches the law, you have the right to lodge a complaint with the supervisory authority:
- Office for Personal Data Protection (Úřad pro ochranu osobních údajů)
- Pplk. Sochora 27, 170 00 Praha 7
- www.uoou.gov.cz
X. Automated decision-making
The Controller does not carry out automated individual decision-making, including profiling, that would produce legal effects concerning the client or similarly significantly affect them.
XI. Final provisions
The Controller may update this Privacy Policy from time to time, in particular if the way personal data is processed, the services used or the legislation change.
The current version is always published on the website www.biorezonancedejvice.cz.
This Privacy Policy is effective from 26 August 2026.
