Data we collect
When you create an account, we process your name, email address, optional telephone number, securely hashed password, and the date and version of your privacy acknowledgement. For a course request, we process the selected course, request status, experience and message you submit, payment or deposit status and necessary change history. Please do not put sensitive health information into free-text fields unless specifically requested for safety and supported by an appropriate legal basis.
Technical and app data
Our systems may process essential session identifiers, IP address, browser or device information, security logs and error information needed to deliver and protect the service. The private administrator application may register a Firebase Cloud Messaging device token so Martin can receive course-request notifications. We do not currently use third-party behavioural advertising or advertising profiles.
Purposes and legal bases
We use data to create and secure accounts, process course requests and reservations, communicate with you, restore passwords, deliver requested services, keep legally required records, prevent abuse and recover the service. The legal bases are steps before entering into and performance of a contract, compliance with legal obligations, and legitimate interests in secure administration, communication and service continuity. Where consent is legally required, it can be withdrawn without affecting earlier lawful processing.
Privacy acknowledgement
Registration requires confirmation that you have read this Policy, and we store its date and version. This acknowledgement is not consent to marketing. We do not send advertising merely because you created an account or requested a course.
Service providers and recipients
Martin and authorised technical administrators can access data where necessary. We also use providers for web and database hosting, email and SMTP delivery, encrypted backup storage or delivery and, for administrator notifications, Google Firebase Cloud Messaging. They process data only for the service they provide and under applicable contractual and security safeguards. We do not sell personal data.
International transfers
Some technology providers may process data outside the European Economic Area. Where this occurs, we rely on an applicable adequacy decision, standard contractual clauses or another lawful transfer mechanism and require appropriate protection for the data.
Retention and backups
Account and course-request data is kept while your account is active and afterwards only as necessary for contracts, disputes, accounting, taxation, safety or other legal duties. Sessions and password-reset links expire. Encrypted backups are kept separately for disaster recovery and may retain deleted information until the relevant backup is securely overwritten or deleted under the controller's backup-retention process; they are not used for ordinary business purposes. If a backup is restored, applicable deletion requests must be re-applied.
Your choices and account deletion
You can sign in and delete your account through Account Deletion, or request deletion from the registered email address. Deletion removes the active account, sessions and course requests unless particular records must be retained by law. You may also ask for access, correction, restriction, portability where applicable, or object to processing based on legitimate interests.
Cookies and local storage
We use only essential session cookies and storage necessary for login, security, selected visual preferences and service operation. We do not currently use third-party advertising cookies. If optional analytics or marketing technologies are introduced, this Policy and the consent mechanism must be updated before they are used.
Children
The account service is not directed to children who cannot lawfully provide their own data or enter the relevant agreement. A minor should use course services only with the involvement and permission of a parent or legal guardian as required by law and the specific activity.
Security and automated decisions
We use access controls, password hashing, secure sessions, encrypted backups and other proportionate safeguards. No online system can be guaranteed completely secure. We do not use solely automated decision-making with legal or similarly significant effects; Martin personally confirms or rejects course requests.
Contact, complaints and updates
Send privacy requests to PimpYourLife@outlook.com. You may complain to the Czech Office for Personal Data Protection at uoou.gov.cz or another competent supervisory authority. Material changes will be published here with a new effective date; where required, we will provide an additional notice.