Terms of Personal Data Processing – GDPR

Last updated: April 29, 2025

1. GDPR

1.1. For the purposes of these Terms of Personal Data Processing of OneFlow s.r.o. (hereinafter referred to as the “Terms”), the Provider shall mean OneFlow s.r.o., ID No.: 23121726, with its registered office at Školská 660/3, 110 00 Prague – Nové Město, registered with the Municipal Court in Prague, Section C, Insert 421776, and the Data Subject shall mean any person who visited the Provider’s website https://one-flow-jitter.webflow.io/ and who may decide to provide the Provider with their personal data and subsequently conclude a Contract with the Provider.

1.2. The Provider is the controller of the personal data provided to it under the contract or during pre‑contractual negotiations. As such, it undertakes to process all personal data provided by the Data Subject in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the “GDPR”) and Act No. 110/2019 Coll., on the Processing of Personal Data. The Provider’s contact details as controller of personal data are specified in Article 1.9 of these Terms.

1.3. The reasons for processing personal data are as follows:

  • Article 6(1)(b) GDPR – processing is necessary for the performance of a contract to which the Data Subject is party or to take steps prior to entering into a contract within the contracting process,
  • Article 6(1)(c) GDPR – compliance with a legal obligation to which the Provider as the data controller is subject.

1.4. The Provider is entitled to process personal data to the following extent:

a) Data processed for the purpose of performance under the contract: - Identification data: name and surname, - Contact data: e‑mail address, telephone number, - Access data: access data to the Meta Business Manager web application and access data to social network accounts managed by the Provider on behalf of the Data Subject, - Other data contained in the contract: other personal data relating to the performance of the Data Subject’s business or other activities.

b) Data processed for the purposes of the Provider’s accounting and tax legislation: - Billing data: e‑mail address.

c) Other personal data provided or disclosed by the Data Subject to the Provider in any form or on any medium. If the Data Subject is an entrepreneur, these data include their business ID number (IČO), tax ID number (DIČ), and information about their business activities.

1.5. Personal data are processed for the purpose of performing the contract and also for the purpose of fulfilling the Provider’s obligations under accounting and tax legislation, i.e. transferring personal data to tax authorities or other public authorities in accordance with applicable laws; including e‑mail communication, contact lists, and services provided in accordance with the GDPR, as apparent from Article 1.3 of these Terms.

1.6. Processing of personal data is necessary for the provision of proper performance under the contract, since identification and contact data are necessary for the conclusion of the contract, to identify the contracting party, and for subsequent communication and delivery between the contracting parties. Access data and other contractual data are provided at the time of or immediately after conclusion of the contract, as access by the Provider to these data is necessary for proper performance, in particular for the proper management of social networks, advertising activities, and campaign management. Other data are also necessary for payment processing and for the fulfilment of the Provider’s legal tax and accounting obligations. Without such processing, the Provider cannot provide full performance.

1.7. Provision of personal data by a Data Subject who intends to enter into a contract with the Provider may not be refused; refusal to provide personal data will result in no contract being concluded, as the Provider would be unable to meet its contractual obligations without such data.

1.8. Personal data are processed for the period necessary to ensure all rights and obligations arising from the contractual relationship and further for the period for which the Provider, as controller, is obliged to retain such data under generally binding legal regulations. Other personal data are retained for 3 years after termination of the contractual relationship between the Provider and the Data Subject.

1.9. Contact details of the controller: OneFlow s.r.o., ID No.: 23121726, Školská 660/3, 110 00 Prague – Nové Město, e‑mail: dopita@oneflow.cz.

1.10. Personal data are processed exclusively by the Provider.

1.11. Personal data are processed only within the territory of the European Union.

1.12. The Provider has not appointed a Data Protection Officer.

1.13. No automated decision‑making or profiling takes place in the context of personal data processing by the Provider.

1.14. Some of the above personal data may also be accessible to third parties for the purpose of website functionality optimization, payment methods, etc., namely: - Google Inc. and other companies providing services in the area of Google analytics and marketing, in particular Google Analytics, Google Ads, and Google Drive, - Meta Platforms Inc. and other companies providing services in the area of analytics and marketing, in particular Facebook Pixel.