Privacy Policy
This is a courtesy translation. The Czech version is legally binding; see ciad.cz/zasady-ochrany-dat.
1. Data controller
The data controller is Český Institut pro AI a Data z.ú. (CIAD), a registered institute with its seat at Příčná 1892/4, Nové Město, 110 00 Prague 1, Czech Republic, Company ID (IČO) 297 52 736, registered under file no. U 1452 with the Municipal Court in Prague. Contact email: office@ciad.cz.
CIAD is not required to appoint a Data Protection Officer (DPO) under Art. 37 GDPR · it is not a public authority, does not process special categories of personal data on a large scale, and does not systematically monitor individuals.
This policy describes what personal data we process, for what purpose, and what rights you have.
2. What data we process
- Email address · when subscribing to the weekly newsletter.
- Contact correspondence · data provided in an email, press inquiry, training request or security report.
- Access logs · IP address, access time, URL, browser. Kept for a maximum of 30 days in server operational records.
The newsletter signup form includes a hidden field to detect automated bots (a "honeypot"). The field is invisible to human users and normally stays empty · if a bot fills it in, the request is rejected; the field itself is not stored or further processed by CIAD.
3. Purpose and legal basis of processing
Newsletter delivery: We process your email address solely to deliver the weekly CIAD newsletter. The legal basis is your consent (Art. 6(1)(a) GDPR). Newsletter signup is also governed by Czech Act No. 480/2004 Coll. on certain information society services (§ 7(2)) · the newsletter, as a commercial communication, is sent only on the basis of explicit prior consent confirmed by clicking a confirmation link (double opt-in). You may withdraw consent at any time by unsubscribing (link in every email) or by writing to office@ciad.cz. Providing an email address is voluntary and not a statutory or contractual obligation; without it, the newsletter cannot be delivered.
Contact correspondence: Personal data provided in an email, press inquiry or training request are processed to handle your request. The legal basis is the controller's legitimate interest (Art. 6(1)(f) GDPR). Data is retained for as long as necessary to handle the request, generally no more than 3 years from the last contact.
Operational logs: Retained on the basis of the controller's legitimate interest in ensuring the security and functionality of the web service (Art. 6(1)(f) GDPR). The interest in security and operational stability outweighs the impact on visitors, since logs are kept for a maximum of 30 days and are not shared with third parties.
4. Retention period
We retain your email address for as long as you remain subscribed to the newsletter. After unsubscribing, data is deleted within 30 days.
Contact correspondence is generally retained for no more than 3 years from the last contact, or as long as necessary to resolve the matter.
Server operational logs are deleted after 30 days.
5. Recipients of personal data
Newsletter signups and delivery are processed by a self-hosted Listmonk instance (newsletter.ciad.cz) operated on a CIAD server in Germany (EEA). Signup uses double opt-in; the platform records the timestamp of consent and IP address in line with Art. 7(1) GDPR (demonstrability of consent). Listmonk's operational logs are retained on the same terms as other server logs · max. 30 days. Unsubscribing is available via a link in every email.
We use Google Tag Manager, provided by Google Ireland Limited, to manage optional analytics and marketing tags. It is not loaded by default. It loads only after you consent to analytics or marketing. Before it can load, Google Consent Mode is set to denied for analytics storage, ad storage, ad user data and ad personalisation.
Analytics consent allows site-use measurement through tags that are actually configured in Google Tag Manager and through CIAD's own aggregate measurement on campaign pages. First-party measurement sends only the event type, canonical campaign path, campaign identifier and consent version. It sends no contact-form fields, free text, complete URL, online identifier or device data. The IP address is used only transiently to limit abuse and is not stored with an analytics event. Daily aggregate counts are retained for no more than 400 days; operational logs follow the 30-day period described above. Marketing consent allows campaign attribution, marketing tags and Meta Pixel, provided by Meta Platforms Ireland Limited. Meta Pixel is loaded and receives a page-view event only after marketing consent. Once an inquiry is actually accepted, the website may emit a lead event according to your choices: to analytics only after analytics consent and to Meta only after marketing consent. A random opaque identifier is used to recognise the same event in the browser and any configured server endpoint; it does not contain form content. Depending on the active tag, Google or Meta may receive the visited URL, referrer, IP address, device and browser signals, online identifiers, campaign parameters and events such as a page view or accepted inquiry. We do not put contact-form fields or free text into browser analytics or marketing events. The website does not use analytics or marketing cookies until you consent. See the Google Privacy Policy, Meta Privacy Policy and Meta Privacy Centre. Provider retention depends on the service configuration and provider policy; CIAD retains its own attribution record for no more than 90 days.
We store the following items in browser local or session storage:
| Key | Value | Purpose |
|---|---|---|
ciad-consent-v2 | Necessary storage, analytics and marketing choices | Stores your privacy choice on this device for no more than 180 days; a policy-version change asks again |
ciad-attribution-v1 | First and last permitted campaign parameter or opaque click identifier | Only after marketing consent, to attribute an inquiry to a campaign; no complete URL, contact-form field, free text, email address, phone number, IP address or browser data; retained for up to 90 days |
theme | dark or light | Stored preference for dark or light display mode |
ciad-pre-skip, ciad-hero-played | Technical indication that the introductory animation has already played | Temporarily in sessionStorage, so the animation is not needlessly repeated in one session |
ciad-lead-analytics:*, ciad-lead-marketing:* | A technical flag tied to the random identifier of an already confirmed inquiry | Temporarily in sessionStorage, preventing the same analytics or marketing event from being emitted twice when the confirmation page is refreshed |
You can change your choices at any time using "Privacy settings" in the site footer. When you change a choice, we update Google Consent Mode. On withdrawal, we delete CIAD's stored attribution, attempt to remove accessible first-party analytics and marketing cookies, and reload the page without the withdrawn tools. Withdrawal does not affect processing that took place before it.
6. Your rights
You have the right to access your personal data, to have it corrected or erased, to restrict its processing, and to withdraw consent.
Data portability (Art. 20 GDPR): The right to portability applies only to processing based on your consent or a contract · in practice, this means the email address used for the newsletter. It does not apply to processing based on legitimate interest (contact correspondence, logs).
Right to object (Art. 21): You have the right to object to the processing of your personal data where processing is based on legitimate interest or is for direct marketing purposes.
Automated decision-making (Art. 22): CIAD does not carry out automated processing of personal data that produces legal effects or otherwise significantly affects you. We do not carry out profiling or other automated decision-making.
You may lodge a complaint with the supervisory authority · the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, ÚOOÚ), Pplk. Sochora 27, 170 00 Prague 7, email: posta@uoou.cz, website: uoou.cz.
To exercise your rights, contact office@ciad.cz. We respond to requests within 30 days.
7. International transfers
CIAD's own server processing and Listmonk run in the EEA. After your optional consent, Google and Meta may also process data in countries outside the EEA, particularly the United States. The providers state that they use applicable GDPR safeguards, such as an adequacy decision, the EU–US Data Privacy Framework or Standard Contractual Clauses, depending on the transfer. See Google's international data-transfer information and the Meta Privacy Policy.
8. Security and incident reporting
In the event of a personal data breach, we follow Art. 33 and 34 GDPR · we report the incident to the Czech Office for Personal Data Protection within 72 hours of becoming aware of it, where the breach is likely to result in a risk to the rights and freedoms of individuals, and in the case of high risk we inform the affected data subjects directly. Report website security vulnerabilities to office@ciad.cz.
9. AI use in content production
Part of the news and blog content on the CIAD website (published in the Aktuality / "News" section) is prepared and published by an automated editorial system using artificial intelligence tools (large language models). The system compiles a Czech-language article from publicly available sources according to fixed editorial rules: it verifies relevance and facts against multiple independent sources, removes duplicates, and checks that the content matches the sources; each article lists the sources used. CIAD bears editorial responsibility for the resulting content and reviews outputs on an ongoing basis, correcting or withdrawing articles where inaccuracies are found. You may send a correction request to office@ciad.cz. Articles produced this way are clearly labelled.
Where such content mentions specific individuals (typically public representatives of companies, or quoted experts), processing of their personal data takes place under the journalistic exemption of Art. 85 GDPR and § 17 of Czech Act No. 110/2019 Coll. It is limited to their professional role and relevant, publicly made statements, and does not include unnecessary personal data. An objection to processing or a correction request can be submitted to office@ciad.cz.
Generating a draft text using artificial intelligence does not constitute automated decision-making with legal effects on individuals within the meaning of Art. 22 GDPR, see section 6.
10. Changes to this policy
This policy may be updated from time to time. The current version is always available at ciad.cz/zasady-ochrany-dat (Czech, legally binding) and ciad.cz/en/privacy.
Last updated: