Privacy and personal data
This notice explains how Zserver s.r.o. processes personal data, which legal bases and retention periods apply, and how you can exercise your rights.
English version of GDPR-2026-07B, effective from 31 July 2026.
Controller: Zserver s.r.o.
Registered office: Heydukova 163, 572 01 Polička, Czech Republic
Company registration number: 26249928
VAT number: CZ26249928
Commercial register: file C 21393 maintained by the Regional Court in Hradec Králové
Email: info@zserver.cz
Telephone: +420 776 251 658
Website: www.zserver.cz
Document version: GDPR-2026-07B (English version)
Effective from: 31 July 2026
This document explains how Zserver s.r.o. processes personal data relating to customers, prospective customers, website visitors, users of customer interfaces, users of zCommerce modules and other people with whom it comes into contact while providing its services.
It also provides information about cookies and similar technologies used on the Zserver s.r.o. website and in related online interfaces.
This English text is a faithful translation of the Czech document "Informace o ochraně osobních údajů a cookies", version GDPR-2026-07B. It replaces the previous privacy notice to the extent that the notice applies to the processing concerned.
1. Introductory provisions
1.1 We process personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the "GDPR"), Czech Act No. 110/2019 Coll. on the Processing of Personal Data, Czech Act No. 480/2004 Coll. on Certain Information Society Services, Czech Act No. 127/2005 Coll. on Electronic Communications and other applicable laws.
1.2 Personal data means any information relating to an identified or identifiable natural person. It may include, for example, a name, email address, telephone number, address, the company registration number of a sole trader, an IP address, an online identifier, a customer number, a domain associated with a particular customer, a licence identifier or a technical installation identifier.
1.3 Zserver s.r.o. may act in different roles:
- as a data controller when it determines the purposes and means of processing, for example in connection with orders, invoicing, customer communication, account administration, zCommerce licences or its own marketing;
- as a data processor when it processes personal data on behalf of a customer acting as controller, for example when providing hosting, server management, backups, service work, technical support or work in a customer’s online store.
1.4 Where we act as a processor of a customer’s personal data, the processing is governed primarily by a data processing agreement or another legal instrument under Article 28 GDPR. In that situation, this document provides general information about our practices and does not replace the data processing agreement.
1.5 Zserver s.r.o. has not appointed a data protection officer unless otherwise stated on the company website or in an individual contract. Please send privacy enquiries to info@zserver.cz.
2. Personal data we process
2.1 We mainly process data you provide to us, data generated while services are provided and data obtained from public registers or technical systems.
2.2 Depending on the situation, the categories of data may include:
- identification data: first name, surname, business name, company registration number, VAT number, registered office and address;
- contact data: email address, telephone number and delivery details;
- billing and payment data: order number, invoice, payment reference, payment information and a bank account number to the extent required for a payment or refund;
- contractual data: services ordered, service parameters, domains, servers, licences, customer account and order history;
- communication data: emails, contact-form messages, support requests, ticket communication and notes about the handling of a request;
- technical data: IP address, hostname, domain, URL, server logs, access time, user agent, technical service state, session identifier and security records;
- zCommerce module data: licence key, customer identifier, domain, URL, installation ID, module name and version, platform version, PHP version, activation date, update-entitlement status, error codes and technical metadata;
- data supplied for technical support: credentials, logs, screenshots, exports, parts of configuration, temporary access and an error description where the customer supplies them;
- data relating to cookies and online visits: cookie identifiers, consent settings, analytics data and website-visit data within the scope of the selected cookie settings;
- data required to exercise or defend rights, handle complaints or claims, investigate incidents and comply with legal obligations.
2.3 When we act as controller, we do not intentionally request or systematically process special categories of personal data under Article 9 GDPR, such as health data. If you nevertheless provide such data in a message, request or attachment, we will process it only to the extent necessary to handle the request or protect legal rights.
2.4 When we act as processor, a customer’s infrastructure may contain personal data selected by that customer as controller. The customer is responsible for having an appropriate legal basis for that processing and for not providing us with more data than is necessary for the purpose concerned.
3. Purposes, legal bases and retention periods
3.1 Orders, contracts and service delivery
We process identification, contact, contractual, billing and technical data in order to enter into and perform contracts, deliver services, set up hosting, manage servers, register and administer domains, deliver digital content, provide technical support and communicate with customers.
Legal basis: performance of a contract or steps taken before entering into a contract; for some related activities, also our legitimate interest in keeping proper records and protecting legal rights.
Retention period: for the duration of the contractual relationship and then for as long as necessary to protect rights and legal claims, normally four years from the end of the contractual relationship, rejection of an order or the most recent related action, unless a law requires a longer period. We also retain the order summary, versions and wording of material contractual confirmations, email delivery status and the technical audit record required to evidence the order.
3.2 Invoicing, accounting and tax obligations
We process data contained in accounting and tax documents and information about payments, orders and contractual performance.
Legal basis: compliance with a legal obligation.
Retention period: for the period required by accounting and tax laws, normally five to ten years depending on the type of document and legal obligation.
3.3 Customer communication, contact forms and enquiries
We process information included in contact forms, emails, telephone calls and other communication, including the content of the message and the subsequent history of handling the matter.
Legal basis: steps taken before entering into a contract, performance of a contract or our legitimate interest in handling the request and keeping a record of communication.
Retention period: for the time required to handle the request and normally no longer than three years afterwards, unless the communication forms part of a contractual relationship, complaint, support matter or legal claim.
3.4 Customer account and service administration
We process data required to create and administer a customer account, provide access to an interface and manage orders, licences, invoices, domains, services, requests and contact persons.
Legal basis: performance of a contract and our legitimate interest in secure and orderly service administration.
Retention period: for the lifetime of the account and contractual relationship and, after it ends, for the period required to meet legal obligations and protect rights.
3.5 Web hosting, managed servers, backups and infrastructure management
When providing hosting and related services, we may process technical and operational data, particularly IP addresses, server logs, DNS data, access information, security events, service-traffic data and information required for administration, monitoring, backups and security.
Legal basis: performance of a contract, our legitimate interest in secure and stable service operation and compliance with legal obligations where they apply to the service concerned.
Retention period: operational and security logs are retained for as long as necessary for operation, security, incident response and protection of rights, usually for days or months. If a statutory obligation to retain traffic or location data under electronic-communications law applies to a particular service, we comply with that obligation.
Under standard backup arrangements, unless otherwise agreed for a particular service, BackupPC creates a daily copy of files between 23:00 and 06:00, excluding temporary cache files, and creates separate database dumps. The standard backup history is 30 days. We may also create full-server snapshots; their frequency and retention depend on the service or proposal concerned. Data deleted from an active system may therefore remain temporarily in access-restricted backups until automatically overwritten under the applicable cycle. We use backup data only for restoration, security, incident handling or compliance with a legal obligation.
Customer data are restored on the customer’s request identifying what should be restored and from which date. Availability of a particular restore point depends on the agreed service, the time of the latest successful backup and the applicable retention period.
3.6 Technical support, service work and remote access
When providing technical support, we may process data included in communication, logs, error messages, configuration, screenshots, exports, database extracts or an environment to which the customer gives us access.
Legal basis: performance of a contract, our legitimate interest in resolving the request and protecting legal rights and, where we act as the customer’s processor, the customer’s instructions under the data processing agreement.
Retention period: for the duration of the request and then normally for three to four years to evidence the course of support and protect rights, unless otherwise agreed or required. Temporary access and exports are deleted or returned without undue delay after the purpose has been fulfilled unless there is a reason to retain them longer.
3.7 zCommerce modules – licence activation and licence administration
For zCommerce modules, we may process a licence key, customer identifier, customer email address, domain, URL, installation ID, module name and version, platform version, PHP version, IP address, activation time, licence status, update-entitlement status and technical activation error codes.
Purpose: licence activation and administration, verification of the licensed scope, protection against unauthorised use, and provision of updates and support.
Legal basis: performance of a contract and our legitimate interest in protecting licences, preventing misuse and administering digital content.
Nature: activation or licence verification may be necessary for paid modules in order to provide the licence, updates and support.
Retention period: for the lifetime of the licence and then for as long as necessary to protect rights, resolve disputes and maintain accounting or contractual records.
3.8 zCommerce modules – update checks (version checks)
A version check verifies the availability of new versions, security fixes and compatibility information, as well as the status of the entitlement to updates. It may include, in particular, the module name and version, platform version, PHP version, domain or installation ID, licence status, check time and IP address.
Legal basis: performance of a contract as regards the availability of updates, and our legitimate interest in security, compatibility and licence administration.
Nature: unless stated otherwise for a particular module, automatic version checks may be enabled but should be capable of being disabled in the module administration where the technical nature of the module permits this.
Consequences of disabling: disabling version checks does not terminate the licence and does not in itself prevent normal operation of the module, but it may limit automatic information about new versions, security fixes and compatibility.
Retention period: we retain operational version-check records only for a reasonable period, normally measured in months, unless longer retention is necessary to protect rights, maintain security or resolve a problem.
3.9 zCommerce modules – optional diagnostics and telemetry
Some modules may allow optional diagnostics to be sent, such as error codes, status information, anonymised or pseudonymised technical metadata, compatibility information and other data required to analyse errors and improve the module.
Legal basis: the user’s consent or our legitimate interest to the extent that the processing constitutes necessary security or operational diagnostics.
Nature: extended diagnostics that are not necessary for licence activation, security, version checks or performance of a contract are optional. Unless stated otherwise for a particular module, extended telemetry should be disabled by default and the user may enable it in the module administration.
Consequences of disabling: disabling optional diagnostics does not prevent normal operation of the module, but it may limit our ability to analyse an error quickly or recommend a fix.
Retention period: we retain diagnostic data for as long as necessary to analyse and improve the module, normally for no longer than 12 months, unless longer retention is required to resolve an incident or protect rights.
We do not describe telemetry or technical metadata as anonymous if they can be linked to a licence, customer account, domain, installation ID, IP address or another identifier.
3.10 Security, service protection and prevention of misuse
We process operational and security data to protect services, prevent misuse, detect attacks, respond to incidents, limit harmful traffic, protect customers and maintain infrastructure stability.
Legal basis: our legitimate interest in the security and protection of services, customers and rights, or compliance with a legal obligation where applicable.
Retention period: we retain security logs and records for a period proportionate to the nature of the risk, normally measured in months. For serious incidents, we retain them for as long as necessary to resolve the incident, protect rights or comply with legal obligations.
3.11 Direct marketing and commercial communications
We may send customers commercial communications concerning our own similar services or products where they have provided their email address in connection with an order for a service or digital content and have not opted out. Every commercial communication must provide a simple means of unsubscribing.
We send commercial communications to other people only on the basis of consent or another valid legal ground.
Legal basis: legitimate interest and the specific rules for commercial communications under Czech Act No. 480/2004 Coll.; consent for marketing to people who are not customers.
Retention period: for the duration of the customer relationship and then for a reasonable period, no longer than until the person unsubscribes or objects. We may retain an opt-out record in order to demonstrate that we no longer send commercial communications.
3.12 Legal claims, complaints, disputes and inspections
We process data required to handle complaints, withdrawals, refunds, grievances, incidents, communication with public authorities, inspections and legal claims.
Legal basis: compliance with a legal obligation and our legitimate interest in protecting rights.
Retention period: for as long as necessary to resolve the matter and then normally for four years from its closure or the most recent related action. We retain data for longer where a dispute, inspection or legal claim is ongoing, or where required by law.
3.13 Notices of illegal content and the DSA
When receiving and assessing a notice of illegal content, we process the information supplied by the notifier, particularly the notifier’s name, organisation and email address, the exact location of the content concerned, the reasons for the notice and subsequent communication. For notices concerning child sexual abuse or exploitation in cases defined by law, an exception from providing a name and email address may apply.
Purpose: receipt and assessment of the notice, acknowledgement of receipt, communication with the notifier and the affected customer, adoption of an appropriate measure, documentation of the decision and compliance with applicable laws, including the Digital Services Act (DSA).
Legal basis: compliance with a legal obligation or, where applicable, our legitimate interest in the safe and lawful operation of services and protection of rights.
Retention period: for as long as necessary to resolve the case and then normally for four years from its closure or the most recent related action. We retain data for longer where a dispute, inspection or legal claim is ongoing, or where required by law.
4. Cookies and similar technologies
4.1 Cookies are small files or similar identifiers stored in a visitor’s browser or device. They may be used to operate the website, save settings, measure traffic, maintain security, personalise content or support marketing.
4.2 We use the following principal categories of cookies and similar technologies:
| Category | Purpose | Legal basis | Consent |
|---|---|---|---|
| Necessary cookies | Website operation, security, forms, customer interfaces and storage of the consent choice | legitimate interest / performance of a contract | not required |
| Preference cookies | Storage of user settings where not necessary for a requested function | consent | required |
| Analytics cookies | Measurement of website traffic and use | consent | required |
| Marketing cookies | Advertising personalisation, remarketing and campaign measurement | consent | required |
4.3 We may use necessary cookies without consent because they are required to operate the website, maintain security, transmit a communication, store the consent choice or provide a service requested by the user.
4.4 We enable analytics, marketing, preference and other non-essential cookies only after prior consent. Consent must be freely given, specific, informed and unambiguous. Refusing or withdrawing consent does not restrict access to the ordinary content of the website.
4.5 You can change or withdraw cookie consent at any time, just as easily as you gave it, through the permanently available cookie settings on the website. You may also use browser settings, although these may not replace the choice stored on the website. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
4.6 A specific list of cookies used, their providers and retention periods may be shown directly in the cookie banner or in separate cookie settings where available on the website. If our use of cookies changes, we will update the cookie-banner settings or this document.
4.7 Some browsers allow cookies to be blocked or deleted. Blocking necessary cookies may prevent the website, a form, login or customer interface from working correctly.
5. Recipients and processors of personal data
5.1 We do not disclose personal data to third parties for their own marketing purposes without an appropriate legal basis.
5.2 Where necessary, personal data may be made available to the following categories of recipients or processors:
- providers of data centres, servers, colocation, cloud, backup, network and infrastructure services;
- domain registrars, registry operators and DNS providers;
- providers of email, invoicing, accounting, banking, payment and business-management services;
- providers of customer-support, ticketing, monitoring, security, logging and analytics tools;
- external administrators, programmers, consultants, lawyers, accountants and tax advisers;
- providers of software tools, repositories, development, testing and AI tools, where used for a particular service and in accordance with applicable law;
- public authorities, courts, the police or other authorised bodies where disclosure is required by law or a lawful request.
5.3 Where we use a processor, we ensure that the processor provides appropriate safeguards for personal data and that processing is governed by a contract or another legal instrument where required by the GDPR.
5.4 For services where we act as the customer’s processor, a specific list of sub-processors may be included in the data processing agreement or customer interface, or provided on request.
5.5 In our ordinary infrastructure operations, we primarily use OVH SAS (OVHcloud) for server infrastructure and, depending on the service, TELE3 s.r.o. for data-centre and related infrastructure services. We use Gransy s.r.o. and its Subreg or Regtons services for domain registration and administration; the relevant registries and registrars may also be involved depending on the top-level domain. The precise scope depends on the service ordered and the location selected.
5.6 We use Google traffic-measurement tools, such as Google Analytics through Site Kit, only where they are expressly enabled and identified in the cookie settings. Analytics cookies and related transfers are activated only after the visitor has consented; the cookie settings identify their provider, purpose and storage period.
6. Transfers outside the EU/EEA
6.1 We seek to process personal data primarily in the Czech Republic, the European Union or the European Economic Area.
6.2 If personal data are to be transferred outside the EU/EEA in a particular case, we will transfer them only where the conditions of the GDPR are met, in particular on the basis of an adequacy decision, standard contractual clauses, a GDPR derogation or another legal mechanism.
6.3 Where we act as the customer’s processor, transfers outside the EU/EEA are also governed by the customer’s instructions and the data processing agreement.
7. Personal-data security
7.1 We take technical and organisational measures appropriate to the nature and scope of the processing, the risks and the state of the art.
7.2 These measures include, in particular:
- restricting access to authorised persons;
- using individual accounts and access permissions where appropriate;
- using strong passwords, password managers and multi-factor authentication where possible and appropriate;
- encrypting data in transit, particularly through HTTPS, SSH, VPN or comparable secure protocols;
- logging, monitoring and reviewing security events;
- making backups according to the nature of the service;
- updating systems and applying safeguards against misuse;
- minimising the data supplied for support and restricting temporary access;
- imposing confidentiality obligations on people who have access to data.
7.3 For technical support, we recommend that customers provide temporary and restricted access, use test environments and change or revoke access after the work is complete.
7.4 No technical measure can guarantee absolute security. If we identify a personal-data breach, we follow the GDPR and our internal procedures for responding to security incidents.
8. Rights of data subjects
8.1 Subject to the conditions of the GDPR, you have in particular the following rights:
- the right of access to personal data;
- the right to rectification of inaccurate data;
- the right to erasure;
- the right to restriction of processing;
- the right to data portability;
- the right to object to processing based on legitimate interests;
- the right to withdraw consent where processing is based on consent;
- the right to lodge a complaint with a supervisory authority.
8.2 You can exercise your rights by emailing info@zserver.cz or writing to our registered office. To help us process the request, we may require reasonable identity verification, particularly where the request concerns sensitive or contractual information.
8.3 We will respond without undue delay, normally within one month at the latest. This period may be extended in justified cases in accordance with the GDPR.
8.4 Where we process data as a processor on behalf of a customer, we will forward the request to the relevant customer as controller or follow that customer’s instructions where it is clear which controller the request concerns.
8.5 The competent supervisory authority is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, website https://uoou.gov.cz.
9. Right to object
9.1 Where we process personal data on the basis of legitimate interests, you have the right to object at any time on grounds relating to your particular situation.
9.2 If you object to direct marketing, we will stop processing your personal data for that purpose.
9.3 If you object to other processing based on legitimate interests, we will assess whether we have compelling legitimate grounds to continue that override your interests, rights and freedoms, or whether the processing is necessary for the establishment, exercise or defence of legal claims.
10. Consent and withdrawal
10.1 Where processing is based on consent, providing consent is voluntary. You may withdraw consent at any time.
10.2 Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn. It also does not prevent processing that we are permitted or required to carry out on another legal basis, for example to perform a contract, maintain accounting records, handle a complaint or protect rights.
10.3 You can manage cookie consent through the cookie banner or cookie settings. You can withdraw consent to commercial communications using the unsubscribe link in the email or by writing to info@zserver.cz.
10.4 Consent to optional diagnostics or telemetry in zCommerce modules can be withdrawn in the module administration where the module provides that function, or by another method specified in its documentation.
11. Automated decision-making and profiling
11.1 We do not make decisions based solely on automated processing that produce legal effects concerning a data subject or similarly significantly affect that person within the meaning of Article 22 GDPR.
11.2 We may use automated technical tools for security, monitoring, attack detection, spam filtering, licence verification, update-availability checks or service protection. These tools support technical administration and service security.
11.3 If we introduce automated decision-making with legal or similarly significant effects in the future, we will inform the affected data subjects in advance in accordance with the GDPR.
12. Children
12.1 Our services, web hosting, managed servers, technical support and zCommerce modules are not directed at children.
12.2 We do not knowingly collect children’s personal data for marketing purposes. If we learn that such data have been supplied without an appropriate legal basis, we will take reasonable steps to delete them or restrict their processing.
13. AI and development tools
13.1 We may use software, development, analytics or AI tools for development, error analysis, drafting, programming or technical support. We enter personal data into such tools only to the extent necessary and only where we have a legal basis or the customer’s instruction.
13.2 When using these tools, we minimise data and use pseudonymisation or anonymisation where possible. We avoid unnecessarily disclosing production data, access credentials, online-store customer data or other sensitive information.
13.3 If a customer expressly prohibits the use of specified external or AI tools for its data and that prohibition forms part of the contractual arrangements, we will follow the instruction to the extent agreed in the contract or data processing agreement.
14. Changes to this document
14.1 We may update this document, particularly when laws, services, technical solutions, zCommerce modules, cookies, processors or processing purposes change.
14.2 The current version is available at www.zserver.cz. For material changes that substantially affect data-subject rights, we may also notify customers by email, in a customer account, in the module administration or by another appropriate method.
14.3 If we begin processing personal data for a new purpose that is incompatible with the original purpose, we will provide the affected people with the required information before that processing begins.
15. Summary for zCommerce modules
15.1 We distinguish three technical modes for zCommerce modules:
- licence activation and administration – normally necessary for a paid module, updates, support and licence protection;
- version checks – checks for updates, security fixes and compatibility information; they may be capable of being disabled depending on the technical capabilities of the module;
- optional diagnostics or telemetry – extended diagnostic data used to analyse errors and improve the module; these should be expressly optional unless necessary for security, licensing or performance of a contract.
15.2 Normal module operation should not depend on the licence server being permanently available where this is technically possible and unless stated otherwise for a particular module.
15.3 Disabling version checks or optional diagnostics does not in itself terminate the licence. It may, however, limit automatic information about new versions, the availability of updates or the scope of technical support.
15.4 Detailed licensing rules for zCommerce modules are set out in the separate zCommerce Module Licence Terms (EULA). Commercial aspects of purchasing modules, including the voluntary money-back guarantee, are governed by the Zserver s.r.o. General Terms and Conditions.
