Privacy Policy
This is a courtesy translation. The Czech version is legally binding; see ciad.cz/zasady-ochrany-dat.
1. Data controller
The data controller is Český Institut pro AI a Data z.ú. (CIAD), a registered institute with its seat at Příčná 1892/4, Nové Město, 110 00 Prague 1, Czech Republic, Company ID (IČO) 297 52 736, registered under file no. U 1452 with the Municipal Court in Prague. Contact email: office@ciad.cz.
CIAD is not required to appoint a Data Protection Officer (DPO) under Art. 37 GDPR · it is not a public authority, does not process special categories of personal data on a large scale, and does not systematically monitor individuals.
This policy describes what personal data we process, for what purpose, and what rights you have.
2. What data we process
- Email address and optional name · when subscribing to the weekly newsletter; only the standalone newsletter page offers the name field, and it is optional.
- Contact correspondence · data provided in an email, press inquiry, training request or security report.
- Access logs · IP address, access time, URL, browser. Kept for a maximum of 30 days in server operational records.
- Answers and technical data in the indicative NIS2 and AI Act test · when you complete the test at /nis2-test/, we submit the selected answers, result band, IP address and browser identifier (User-Agent); the server adds the submission time and a technical submission identifier to the record. The test is therefore not anonymous. This step does not submit your name, email address or free text. If you separately submit the voluntary contact form below the result, your contact details are accompanied by a prefilled summary of the result band, organisation type, selected AI uses and status of internal rules.
- Availability request · when the booking calendar is displayed, the browser sends a technical request for available slots to CIAD's own server. The request contains no form fields, name, email address or phone number; as with every network request, the server nevertheless receives the IP address, User-Agent, time and requested URL.
The newsletter signup form includes a hidden field to detect automated bots (a "honeypot"). The field is invisible to human users and normally stays empty · if a bot fills it in, the request is rejected; the field itself is not stored or further processed by CIAD.
3. Purpose and legal basis of processing
Newsletter delivery: We process your email address and any optional name you provide solely to deliver and personalise the weekly CIAD newsletter. The legal basis is your consent (Art. 6(1)(a) GDPR). Newsletter signup is also governed by Czech Act No. 480/2004 Coll. on certain information society services (§ 7(2)) · the newsletter, as a commercial communication, is sent only on the basis of explicit prior consent confirmed by clicking a confirmation link (double opt-in). You may withdraw consent at any time by unsubscribing (link in every email) or by writing to office@ciad.cz. Providing an email address is voluntary and not a statutory or contractual obligation; without it, the newsletter cannot be delivered. The name is optional and you can subscribe without it.
Contact correspondence: Personal data provided in an email, press inquiry or training request are processed to handle your request. The legal basis is the controller's legitimate interest (Art. 6(1)(f) GDPR). Data is retained for as long as necessary to handle the request, generally no more than 3 years from the last contact.
Indicative test statistics: We process the answers, result band, submission time, technical submission identifier, IP address and browser identifier on the basis of the controller's legitimate interest (Art. 6(1)(f) GDPR) to assess aggregate preparedness among Czech organisations and improve the test. Because technical identifiers are stored, the data is not anonymous. Any public summary will be aggregated and will not identify individual people or organisations.
Operational logs: Retained on the basis of the controller's legitimate interest in ensuring the security and functionality of the web service (Art. 6(1)(f) GDPR). The interest in security and operational stability outweighs the impact on visitors, since logs are kept for a maximum of 30 days and are not shared with third parties.
4. Retention period
We retain your email address and any optional name you provide for as long as you remain subscribed to the newsletter. After unsubscribing, data is deleted within 30 days.
Contact correspondence is generally retained for no more than 3 years from the last contact, or as long as necessary to resolve the matter.
Server operational logs are deleted after 30 days.
5. Recipients of personal data
Newsletter signups and delivery are processed by a self-hosted Listmonk instance (newsletter.ciad.cz) operated on a CIAD server in Germany (EEA). Signup uses double opt-in; the platform records the timestamp of consent and IP address in line with Art. 7(1) GDPR (demonstrability of consent). Listmonk's operational logs are retained on the same terms as other server logs · max. 30 days. Unsubscribing is available via a link in every email.
We use Google Tag Manager, provided by Google Ireland Limited, to manage optional analytics and marketing tags. It is not loaded by default. It loads only after you consent to analytics or marketing. Before it can load, Google Consent Mode is set to denied for analytics storage, ad storage, ad user data and ad personalisation.
Analytics consent allows site-use measurement through tags that are actually configured in Google Tag Manager · currently Google Analytics 4 (measurement ID G-4W8JRQ1F44), also provided by Google Ireland Limited · and through CIAD's own aggregate measurement on campaign pages. First-party measurement sends only the event type, canonical campaign path, campaign identifier and consent version. It sends no contact-form fields, free text, complete URL, online identifier or device data. The IP address is used only transiently to limit abuse and is not stored with an analytics event. Daily aggregate counts are retained for no more than 400 days; operational logs follow the 30-day period described above. Marketing consent allows campaign attribution, marketing tags and Meta Pixel, provided by Meta Platforms Ireland Limited. Meta Pixel is loaded and receives a page-view event only after marketing consent. Marketing consent also allows the ChatGPT Ads measurement pixel provided by OpenAI Ireland Limited. The pixel is served from CIAD's own server and likewise receives a page view only after marketing consent. Automatic matching against form fields is switched off for this pixel, so it neither reads nor sends contact fields. Once an inquiry is actually accepted, the website may emit a lead event according to your choices: to analytics only after analytics consent and to Meta and OpenAI only after marketing consent. A random opaque identifier is used to recognise the same event in the browser and any configured server endpoint; it does not contain form content. Depending on the active tag, Google, Meta or OpenAI may receive the visited URL, referrer, IP address, device and browser signals, online identifiers, campaign parameters and events such as a page view or accepted inquiry. We do not put contact-form fields or free text into browser analytics or marketing events. The website does not use analytics or marketing cookies until you consent. See the Google Privacy Policy, Meta Privacy Policy, Meta Privacy Centre and the OpenAI EEA Privacy Policy. Provider retention depends on the service configuration and provider policy; CIAD retains its own attribution record for no more than 90 days.
We store the following items in browser local or session storage:
| Key | Value | Purpose |
|---|---|---|
ciad-consent-v2 | Necessary storage, analytics and marketing choices | Stores your privacy choice on this device for no more than 180 days; a policy-version change asks again |
ciad-attribution-v1 | First and last permitted campaign parameter or opaque click identifier | Only after marketing consent, to attribute an inquiry to a campaign; no complete URL, contact-form field, free text, email address, phone number, IP address or browser data; retained for up to 90 days |
ciad-pre-seen, ciad-hero-played | Technical indication that the introductory animation has already played | Temporarily in sessionStorage, so the animation is not needlessly repeated in one session |
ciad-lead-analytics:*, ciad-lead-marketing:* | A technical flag tied to the random identifier of an already confirmed inquiry | Temporarily in sessionStorage, preventing the same analytics or marketing event from being emitted twice when the confirmation page is refreshed |
The items above are set by CIAD itself. Only after your consent may Google, Meta and OpenAI set their own cookies, in particular these:
| Cookie | Set by | Purpose and when it appears |
|---|---|---|
_ga, _ga_*, _gid, _gat_* | Google Ireland Limited | Distinguishing visitors and sessions for traffic measurement; only after analytics consent. Lifetime follows Google's service configuration, typically up to 2 years for _ga and minutes for _gat_* |
_gcl_* | Google Ireland Limited | Attributing an inquiry to an advertising campaign; only after marketing consent |
_fbp, _fbc | Meta Platforms Ireland Limited | Identifying the browser and an ad click for campaign measurement and attribution; only after marketing consent |
__obref, __oppref, __oaiq_consent | OpenAI Ireland Limited (first-party cookies written by the pixel script) | Identifying the browser, an ad click inside ChatGPT and the consent state for campaign measurement and attribution; only after marketing consent |
Until you give consent, none of these cookies is created · the tools that set them are not loaded at all. On withdrawal we attempt to remove them; cookies the browser does not expose to the site for security reasons can be cleared in your browser settings.
You can change your choices at any time using "Privacy settings" in the site footer. When you change a choice, we update Google Consent Mode. On withdrawal, we delete CIAD's stored attribution, attempt to remove accessible first-party analytics and marketing cookies, and reload the page without the withdrawn tools. Withdrawal does not affect processing that took place before it.
6. Your rights
You have the right to access your personal data, to have it corrected or erased, to restrict its processing, and to withdraw consent.
Data portability (Art. 20 GDPR): The right to portability applies only to processing based on your consent or a contract · in practice, this means the email address and any optional name used for the newsletter. It does not apply to processing based on legitimate interest (contact correspondence, logs).
Right to object (Art. 21): You have the right to object to the processing of your personal data where processing is based on legitimate interest or is for direct marketing purposes.
Automated decision-making (Art. 22): CIAD does not carry out automated processing of personal data that produces legal effects or otherwise significantly affects you. We do not carry out profiling or other automated decision-making.
You may lodge a complaint with the supervisory authority · the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, ÚOOÚ), Pplk. Sochora 27, 170 00 Prague 7, email: posta@uoou.cz, website: uoou.cz.
To exercise your rights, contact office@ciad.cz. We respond to requests within 30 days.
7. International transfers
CIAD's own server processing and Listmonk run in the EEA. After your optional consent, Google, Meta and OpenAI may also process data in countries outside the EEA, particularly the United States. The providers state that they use applicable GDPR safeguards, such as an adequacy decision, the EU-US Data Privacy Framework or Standard Contractual Clauses, depending on the transfer. See Google's international data-transfer information, the Meta Privacy Policy and the OpenAI EEA Privacy Policy.
8. Security and incident reporting
In the event of a personal data breach, we follow Art. 33 and 34 GDPR · we report the incident to the Czech Office for Personal Data Protection within 72 hours of becoming aware of it, where the breach is likely to result in a risk to the rights and freedoms of individuals, and in the case of high risk we inform the affected data subjects directly. Report website security vulnerabilities to office@ciad.cz.
9. AI use in content production
Part of the news and blog content on the CIAD website (published in the Aktuality / "News" section) is prepared and published by an automated editorial system using artificial intelligence tools (large language models). The system compiles a Czech-language article from publicly available sources according to fixed editorial rules: it verifies relevance and facts against multiple independent sources, removes duplicates, and checks that the content matches the sources; each article lists the sources used. CIAD bears editorial responsibility for the resulting content and reviews outputs on an ongoing basis, correcting or withdrawing articles where inaccuracies are found. You may send a correction request to office@ciad.cz. Articles produced this way are clearly labelled.
Where such content mentions specific individuals (typically public representatives of companies, or quoted experts), processing of their personal data takes place under the journalistic exemption of Art. 85 GDPR and § 17 of Czech Act No. 110/2019 Coll. It is limited to their professional role and relevant, publicly made statements, and does not include unnecessary personal data. An objection to processing or a correction request can be submitted to office@ciad.cz.
Generating a draft text using artificial intelligence does not constitute automated decision-making with legal effects on individuals within the meaning of Art. 22 GDPR, see section 6.
10. Changes to this policy
This policy may be updated from time to time. The current version is always available at ciad.cz/zasady-ochrany-dat (Czech, legally binding) and ciad.cz/en/privacy.
Last updated: