_________________________________________________________________
1. BASIC PROVISIONS AND CONTROLLER CONTACT DETAILS
1.1. This Privacy Policy (hereinafter the “Policy”) explains how VANDERBERG MEDIA SE processes personal data in connection with the operation of the www.supa24.com internet portal, including its language versions.
1.2. The controller of personal data is VANDERBERG MEDIA SE, with its registered office at Porubská 552/26, Poruba, 708 00 Ostrava, Company ID No.: 17860709, registered in the Commercial Register maintained by the Regional Court in Ostrava, file No. H 1236 (hereinafter the “Operator”).
1.3. The Operator may be contacted in matters of personal data protection by e-mail at: [email protected], in writing at Porubská 552/26, Poruba, 708 00 Ostrava, or through the contact form on the Portal, if available.
1.4. This Policy follows on from the general terms and conditions of the Portal. Terms used in this Policy have the same meaning as in the general terms and conditions, unless the context requires otherwise.
1.5. Basic use of the Portal is not conditional upon consent to the processing of personal data for all purposes. The Operator uses consent only where it is an appropriate or necessary legal basis, in particular for optional marketing, analytical or marketing tools, and transfer of contact details to Financial Partners.
2. WHAT PERSONAL DATA WE PROCESS
2.1. For Visitors to the Portal, the Operator processes mainly technical data about the use of the Portal, such as IP address, device identifiers, browser data, operating system data, language version, access time, pages visited and technical actions performed.
2.2. For Registered Users, the Operator processes data provided during registration and management of the User Account, in particular first name, surname, e-mail, telephone number, login credentials, User Account identification, login history and account settings.
2.3. For Business Users and Real Estate Agencies, the Operator also processes business-related data, in particular business name or company name, Company ID No., registered office, billing details, contact persons, tariff data, order data, payment data and the scope of Services used.
2.4. In connection with Listings, the Operator processes Content inserted by the User, in particular the text of the Listing, photographs, videos, floor plans, real estate data, price, location, contact details, date of insertion, date of modification, status of the Listing and technical data related to publication of the Listing.
2.5. In connection with contact forms, the Operator processes data provided by the Visitor, in particular first name, surname, e-mail, telephone number, message text, Listing identification, time of submission of the form and information on who the enquiry was forwarded to.
2.6. In connection with paid services, the Operator processes data about the order, payment, tax documents, payment method used, and, where applicable, data provided by the payment gateway provider. The Operator does not process full payment card details if they are processed directly by the payment gateway provider.
2.7. In connection with Financial Partners, the Operator processes data that the Visitor enters in the contact form and that is to be transferred to the Financial Partner based on the Visitor's consent. This includes in particular first name, surname, e-mail, telephone number, real estate identification and the content of the message, if relevant for the transfer.
2.8. In connection with commercial communications, the Operator processes the e-mail address, and where applicable first name, surname, telephone number, information about granting or withdrawal of consent, information about refusal of further sending, and technical data about delivery of commercial communications. The Operator processes data on opening or clicking through commercial communications only to the extent permitted by legal regulations and the User's settings.
2.9. In connection with the reporting of illegal Content, complaints, claims or other communication, the Operator processes data stated in the submission, contact details of the notifier or User, the content of the communication, date of handling and measures taken.
2.10. The Operator does not request Users to provide special categories of personal data through the Portal, in particular data concerning health, political opinions, religion or biometric data. Users should not include such data in Listings, messages or other Content unless it is necessary and they have an appropriate legal basis for doing so.
3. PURPOSES AND LEGAL BASES OF PROCESSING
3.1. The Operator processes data necessary for registration, management of the User Account, publication of a Listing, forwarding of an enquiry, ordering of a paid service and provision of other Services mainly for the purpose of entering into and performing an agreement under Article 6(1)(b) GDPR.
3.2. The Operator processes data of contact persons of Business Users, Real Estate Agencies and other legal entities mainly for the purpose of communication, performance of the contractual relationship with the relevant entity and protection of the Operator's legitimate interests under Article 6(1)(f) GDPR.
3.3. The Operator processes data entered in the contact form for the purpose of forwarding the enquiry to the person who published the Listing and enabling subsequent communication between the Visitor and that person. The legal basis is mainly performance of an agreement or taking steps at the request of the Visitor and the Operator's legitimate interest in ensuring the basic function of the Portal.
3.4. The Operator processes and transfers data to Financial Partners only if the Visitor voluntarily consents to this. The legal basis is consent under Article 6(1)(a) GDPR.
3.5. The Operator processes data for sending commercial communications according to the specific situation. If the commercial communication concerns the Operator's own similar services and the Operator obtained the User's electronic contact details in connection with registration or an order for a service, the legal basis is the Operator's legitimate interest under Article 6(1)(f) GDPR and the special legal rules allowing such sending, provided that a simple opt-out option is available. In other cases, the Operator sends commercial communications only on the basis of consent under Article 6(1)(a) GDPR.
3.6. The Operator processes technical data, security logs and data about use of the Portal for the purpose of ensuring operation, security, stability, prevention of misuse and resolution of technical incidents. The legal basis is mainly the Operator's legitimate interest under Article 6(1)(f) GDPR.
3.7. The Operator processes data related to accounting, taxes, complaints, consumer rights, obligations under the DSA and obligations towards public authorities for the purpose of complying with legal obligations under Article 6(1)(c) GDPR.
3.8. The Operator processes data necessary to protect the Operator's rights, resolve disputes, assert claims, defend against claims of third parties and document the Services provided on the basis of legitimate interest under Article 6(1)(f) GDPR.
3.9. The Operator uses analytical, marketing or similar tools that are not necessary for the functioning of the Portal itself only to the extent to which the Operator has the relevant legal basis. If legal regulations require consent, these tools will be used only on the basis of the User's consent.
4. FINANCIAL PARTNERS AND MORTGAGE ENQUIRIES
4.1. The Operator may allow a Visitor to express interest in receiving a financing offer for the relevant real estate next to a Listing. This interest is voluntary and must not be technically set so that consent is pre-ticked or otherwise pre-filled.
4.2. If the Visitor expresses interest in a financing offer, the Operator may transfer the Visitor's data to the relevant Financial Partner or Financial Partners. The current Financial Partner or Financial Partners will be identified next to the relevant form, calculator or in this Policy.
4.3. The specific Financial Partner or Financial Partners to whom data may be transferred will always be identified directly next to the relevant form or calculator, including a link to their data protection documentation. The Operator will transfer data only to the Financial Partner to whom the Visitor has consented.
4.4. A Financial Partner may contact the Visitor for the purpose of processing the Visitor's enquiry and offering financial products only to the extent corresponding to the consent granted or to the legal relationship between the Visitor and the Financial Partner.
4.5. If the Visitor enters their data directly into the interface of a Financial Partner, for example into a mortgage calculator operated by a Financial Partner, the processing of such data is governed by the documentation of that Financial Partner. In such case, the Operator is not liable for processing of data that the Visitor provides directly to the Financial Partner outside the Operator's interface.
4.6. Consent to transfer contact details to a Financial Partner does not automatically mean consent to long-term sending of commercial communications by the Financial Partner. If the Financial Partner is to contact the Visitor also with further marketing offers, the Financial Partner must have its own legal basis for doing so.
5. COMMERCIAL COMMUNICATIONS AND NEWSLETTERS
5.1. The Operator may send Users operational, technical, security and contractual communications related to use of the Portal. These communications are not commercial communications and cannot be unsubscribed from if they are necessary for the provision of the Services or compliance with legal obligations.
5.2. The Operator may send Users commercial communications concerning the Operator's own similar services if the Operator obtained their e-mail address in connection with registration or an order for a service and the User has not refused such sending. In such case, the legal basis for processing personal data is the Operator's legitimate interest under Article 6(1)(f) GDPR.
5.3. In other cases, in particular where the communications do not concern the Operator's own similar services or where the User is to be contacted with third-party marketing, the Operator sends commercial communications only on the basis of the User's prior consent under Article 6(1)(a) GDPR.
5.4. Each commercial communication will include a simple option to refuse further sending. Unsubscribing is possible in particular through the unsubscribe link in the commercial communication or by sending a request to e-mail: [email protected].
6. COOKIES AND TECHNICAL TOOLS
6.1. The Portal may use cookies and similar technologies. Some cookies are necessary for the functioning of the Portal, login, security, remembering basic settings and provision of requested Services.
6.2. Analytical, marketing or similar cookies that are not necessary for the functioning of the Portal are used only to the extent permitted by legal regulations. If consent is required for their use, the User will be asked for consent through the cookie banner or a similar tool.
6.3. The User may manage cookie settings through the cookie banner, if available, or through the settings of their internet browser. Restricting certain cookies may affect the availability or proper functioning of selected parts of the Portal.
6.4. More detailed information about specific cookies and similar technologies may be provided directly in the cookie banner or in separate cookie settings available on the Portal.
7. WHO MAY ACCESS PERSONAL DATA
7.1. Only persons who need personal data to perform their tasks have access to it, in particular persons ensuring the operation of the Portal, customer support, technical administration, accounting, marketing, legal services and security.
7.2. Personal data may be made available to the Operator's processors and suppliers. These include in particular providers of technical operation and administration of the Portal, hosting providers, developers, IT administrators, providers of e-mail tools, payment service providers, accounting, tax, legal and marketing advisers.
7.3. The Operator's main suppliers include in particular the technical supplier Webvalley s.r.o., the provider of software and marketing support Religis s.r.o. and the accounting company Account professional a.s. The group of suppliers may change over time, but always only to the extent necessary to ensure the activities stated in this Policy and while maintaining appropriate protection of personal data.
7.4. Data from the contact form next to a Listing is forwarded to the person who published the Listing, in particular to the Registered User or Real Estate Agency. That person subsequently processes the transferred data as an independent controller and is responsible for its further use.
7.5. Data may be transferred to Financial Partners only if the Visitor expresses interest in a financing offer and grants the corresponding consent to the transfer.
7.6. Personal data may also be made available to public authorities, courts, administrative authorities, law enforcement authorities or other persons if required by legal regulations or if necessary to protect the rights of the Operator, Users or third parties.
8. TRANSFERS OF PERSONAL DATA OUTSIDE THE EUROPEAN ECONOMIC AREA
8.1. The Operator primarily uses suppliers that process personal data in the European Union or the European Economic Area.
8.2. If, in connection with any technical, analytical, marketing or other tool, personal data is transferred outside the European Economic Area, the Operator will ensure that such transfer takes place only if the conditions under the GDPR are met, in particular on the basis of an adequacy decision, standard contractual clauses or other appropriate safeguards.
9. RETENTION PERIODS FOR PERSONAL DATA
9.1. The Operator retains personal data only for the period necessary for the purpose for which it was collected or for the period required by legal regulations.
9.2. The Operator processes data in the User Account for the duration of the User Account. After its cancellation, selected data may be retained for the period necessary to protect the Operator's rights, resolve disputes, comply with legal obligations and prove the Services provided, usually for 3 years after cancellation of the account, unless legal regulations require a longer period.
9.3. After a Listing is deleted, the Listing is technically retained for 3 days for the possibility of restoration. After this period expires, the Operator removes the photographs of the Listing, unless their longer retention is necessary for the protection of rights, dispute resolution or compliance with a legal obligation.
9.4. Selected data about a Listing may be retained after the Listing is removed for operational purposes of the Portal, linking with leads, statistics, prevention of duplicates, handling complaints, protection of the Operator's rights and proof of the Services provided. If such data is no longer personal data, the Operator may continue to retain it as anonymised statistical data.
9.5. The Operator retains data from contact forms and enquiries for the period necessary to forward the enquiry, ensure the subsequent function of the Portal, handle possible complaints and protect the Operator's rights, usually for 3 years after the enquiry is sent.
9.6. The Operator retains data related to accounting, taxes, payments and tax documents for the period required by legal regulations, usually up to 10 years for tax documents.
9.7. The Operator processes data processed on the basis of consent for the duration of the consent, but no longer than the period stated next to the specific consent or arising from the purpose of processing. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
9.8. The Operator retains security and technical logs for the period necessary to ensure the security and stability of the Portal, usually for no longer than 12 months, unless longer retention is needed due to a security incident, dispute or legal obligation.
9.9. The Operator retains data contained in reports of illegal Content, complaints, claims and related communication for the period necessary for their handling and protection of rights, usually for 3 years after handling, unless legal regulations or specific circumstances require a longer period.
10. RIGHTS OF DATA SUBJECTS
10.1. Under the conditions set out in the GDPR, the data subject has the right to request confirmation from the Operator as to whether the Operator processes their personal data and has the right of access to such data.
10.2. The data subject has the right to rectification of inaccurate personal data and completion of incomplete personal data.
10.3. The data subject has the right to erasure of personal data if any of the grounds under the GDPR apply, in particular if the data is no longer necessary for the purposes for which it was processed or if consent has been withdrawn and there is no other legal basis for processing.
10.4. The data subject has the right to restriction of processing of personal data in the cases set out in the GDPR.
10.5. The data subject has the right to data portability if the processing is based on consent or an agreement and is carried out by automated means.
10.6. The data subject has the right to object to processing based on the Operator's legitimate interest. If the objection concerns direct marketing, the Operator will no longer process personal data for that purpose.
10.7. The data subject has the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
10.8. The data subject has the right to lodge a complaint with the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, website www.uoou.cz, if the data subject believes that the processing of their personal data has breached the GDPR or other legal regulations.
11. HOW RIGHTS MAY BE EXERCISED
11.1. Rights under this Policy may be exercised by e-mail at: [email protected] or in writing to the Operator's address.
11.2. The Operator may, to the extent necessary, request verification of the applicant's identity if it has reasonable doubts about the identity of the person exercising the right.
11.3. The Operator will handle the request without undue delay, no later than within 1 month of receiving it. In complex cases or where there are a larger number of requests, this period may be extended by up to an additional 2 months, of which the Operator will inform the data subject.
12. PERSONAL DATA SECURITY
12.1. The Operator adopts appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, disclosure or destruction.
12.2. These measures include in particular restriction of access rights, security of User Accounts, password management, backups, technical security of the Portal, recording of selected actions and contractual safeguards with processors.
12.3. The User is obliged to protect their login credentials and use the Portal in a secure manner. The User is obliged to notify the Operator without undue delay of any suspected misuse of the User Account or security incident.
13. AUTOMATED DECISION-MAKING AND PROFILING
13.1. The Operator does not carry out automated individual decision-making within the meaning of Article 22 GDPR that would have legal effects for the data subject or similarly significantly affect them.
13.2. The Portal may use technical rules for ranking, filtering and highlighting Listings, in particular according to the rules stated in the general terms and conditions. These rules serve the operation of the Portal and presentation of Listings and do not constitute automated decision-making about the rights of data subjects.
14. CHANGES TO THIS POLICY
14.1. The Operator may reasonably amend or supplement this Policy, in particular due to changes in legal regulations, changes to the Portal, changes in the processing of personal data, changes in suppliers or changes in the offered Services.
14.2. The current version of the Policy will always be available on the Portal. If there is a material change, the Operator will inform users in an appropriate manner, for example by publishing a notice on the Portal, by e-mail or by notice in the User Account.
15. FINAL PROVISIONS
15.1. This Policy takes effect on 20. 7. 2026.
15.2. This Policy may be available in several language versions. For users using the Czech language version of the Portal and for processing with a primary connection to the Czech Republic or the Slovak Republic, the Czech version of the Policy shall prevail. For users outside the Czech Republic and the Slovak Republic, the English version of the Policy shall prevail, unless expressly stated otherwise for a specific language version. Translations of the Policy into other languages are for information purposes only and serve to make it easier for users to understand them. In the event of a conflict between an informative translation and the governing version of the Policy, the governing version under this clause shall prevail. This does not affect the Operator's obligation to provide information about the processing of personal data in a concise, transparent, intelligible and easily accessible form, using clear and plain language appropriate to the specific situation.
15.3. This Policy replaces the Operator's previous documents governing general consent to the processing of personal data on the Portal to the extent that they were intended to inform Users about the processing of personal data.
15.4. Separate consents granted by the User for specific purposes, in particular for commercial communications, cookies or transfer of contact details to a Financial Partner, are governed by the text of the specific consent and this Policy