Effective date: 14 September 2026. Version 1.1.
Data controller for this policy
- Name
- Josef Pechar
- IČO
- 24005169
- DIČ
- CZ0101190518
- Registered address
- Kubelíkova 697/13, 13000 Praha 3
- Contact
- [email protected]
- Public register
- ARES (public register)
Guests who complete a form via /l/… see a separate notice naming the accommodation provider as controller. Hosts must configure a legal entity with contact e-mail so that notice is complete.
1. Scope and who should read this
This Privacy Policy ("Policy") describes how Josef Pechar, identification number (IČO) 24005169 (the "Operator"), processes personal data in connection with the UbyHost web application and related websites (the "Service"). It applies to: (a) accommodation providers and their staff who hold a Host account ("Host Users"); (b) visitors to public pages such as /login, /legal, /terms, and /privacy; and (c) technical processing of Guest Data on behalf of Hosts as described below. It does not govern the relationship between a Host and their Guests as controller and data subject — that is covered by the guest-facing privacy notice at each property link (/l/{token}/privacy) and by the Host's own policies.
2. Controller identity and contact
For Host account data, authentication, billing contact details (if any), support correspondence, and operational logs relating to the Service, the Operator is the data controller within the meaning of Regulation (EU) 2016/679 ("GDPR") and Act No. 110/2019 Coll., on personal data processing. Identity and address are published on /legal. The primary e-mail contact for privacy requests relating to the Operator's processing is
[email protected]; you may also use the postal address on /legal. The Operator does not provide a guaranteed support hotline unless published there.
3. Roles: Operator, Host, and Guest
Hosts (or the legal entities they configure per property) are typically the data controllers for personal data about Guests (names, travel documents, stays, signatures, and related records). The Operator provides hosted software and processes Guest Data only on the Host's documented instructions to deliver the Service — typically as a data processor under GDPR Article 28. The Operator is not a joint controller with the Host unless expressly agreed in writing. The Operator is controller for its own business data (accounts, security, hosting). Guest Data processing terms are in the Data Processing Agreement at /dpa. Nothing in this Policy transfers statutory duties of accommodation providers or controllers to the Operator.
4. Categories of Host User data
We may process: account identifiers (username, internal user id); authentication data (password hashes, session tokens, optional "remember me" duration, time-based one-time password (TOTP) secrets stored encrypted, and one-way hashes of recovery codes); profile and workspace settings; legal entity names, addresses, and contact e-mails you enter for guest notices; property and stay metadata; UbyPort or calendar integration credentials (stored encrypted at rest); audit and activity logs you generate in-app; communications you send to us; and billing or plan information if fees apply. We do not require Host Users to provide special categories of data about themselves unless you voluntarily include such information in free-text fields.
5. Guest Data processed on your instructions
When Hosts use the Service, we process Guest Data they or their Guests submit: identity and travel document details, dates of stay, nationality, addresses, signatures, optional passport photos or PDFs uploaded for verification, house book entries, and data formatted for transmission toward UbyPort or related police reporting channels when enabled. Purposes, legal bases, and retention for Guests are determined by the Host as controller and explained in the guest privacy notice. The Operator implements technical and organisational measures appropriate to the risk but does not decide why Guest Data is collected from a GDPR perspective.
6. Purposes and legal bases (Operator as controller)
We process Host User data to: provide and secure the Service (contract / legitimate interest, GDPR Art. 6(1)(b) and (f)); comply with legal obligations (Art. 6(1)(c)); prevent abuse, fraud, and security incidents (legitimate interest); maintain records required for accounting or tax if applicable (legal obligation); and improve reliability using aggregated or pseudonymised diagnostics where possible (legitimate interest). Where we rely on legitimate interest, we balance our needs against your rights. Where consent is required by law, we will request it separately. Czech national rules in Act 110/2019 Coll. apply alongside GDPR.
7. Cookies and similar technologies
The Service uses strictly necessary cookies and similar storage: signed session cookies for Host login (and optional extended duration if "remember me" is selected); language preference cookies; and, on guest links, cookies that remember PIN verification or language for a limited period. On production login and, after repeated failed guest PIN attempts, guest PIN pages, we may use Cloudflare Turnstile to distinguish legitimate use from automated abuse. Turnstile may set or read technical identifiers and process connection data (such as IP address) under Cloudflare's terms and privacy notice; it is not used for advertising. We do not use third-party analytics or advertising cookies in the application as shipped. You can control cookies through browser settings; disabling session cookies will prevent login.
8. Server logs and security monitoring
Our infrastructure automatically logs technical data: IP addresses, timestamps, request paths, user agents, error traces, and security events (e.g. failed logins, rate limits). We use these logs to operate, debug, and protect the Service, typically for a limited rolling period unless longer retention is needed to investigate incidents or comply with law. Logs may contain personal data in incidental form (e.g. IP address).
9. Recipients and subprocessors
Personal data is accessed by authorised Operator personnel and contractors bound by confidentiality. We use infrastructure subprocessors to host the Service, including Amazon Web Services (AWS Lightsail or comparable hosting in the EEA for production), Render.com (cloud hosting for staging or other tiers; commonly EU Frankfurt), DNS or CDN providers such as Cloudflare (including Turnstile bot protection when enabled), Google Drive and/or Amazon S3 when the Operator configures off-site backups, and e-mail or support tools where used. Guest Data may be transmitted to the Czech Police UbyPort systems or related endpoints when a Host enables reporting — that transmission occurs on the Host's instructions as processor. We require subprocessors that process personal data on our behalf to provide appropriate safeguards (GDPR Art. 28). Material changes are reflected in this Policy.
10. International transfers
We aim to host and process data within the European Economic Area. If a subprocessor or support tool involves a transfer outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or other mechanisms permitted under GDPR Chapter V. Details can be provided on request where required by law.
11. Retention
Host account data is retained while the account is active and for a reasonable period after termination to allow export, resolve disputes, and comply with law. Guest Data retention is controlled by Host settings and legal obligations (including typical six-year house book rules); the Operator may retain encrypted database and key backups on the server and, when configured, encrypted off-site copies (for example weekly to Google Drive and monthly to Amazon S3) for disaster recovery for a limited period before purging. Security logs are kept for short rolling windows unless an incident requires longer storage. When retention ends, we delete or anonymise data unless statutory storage applies.
12. Security
We implement measures such as encryption of sensitive credentials and TOTP secrets at rest, HTTPS in transit, mandatory two-factor authentication (authenticator app) for Host accounts in production, Cloudflare Turnstile on host login and on guest PIN verification after repeated failures when configured, access controls, rate limiting on authentication endpoints, separation of environments, and regular dependency updates. No method of transmission or storage is 100% secure; Hosts must use strong passwords, protect authenticator devices and recovery codes, and configure guest links carefully. Report suspected security issues to the contact on /legal.
13. Your rights (Host Users)
Where the Operator is controller, you may have rights to access, rectification, erasure, restriction, portability, and objection under GDPR, and to withdraw consent where processing is consent-based. You may lodge a complaint with the Office for Personal Data Protection (ÚOOÚ), Pplk. Sochora 27, 170 00 Praha 7, www.uoou.cz. We respond to requests without undue delay and within statutory deadlines. We may need to verify your identity. Some rights may be limited where we must retain data by law or for defence of legal claims.
14. Guest rights
Guests should direct access, correction, deletion, and objection requests regarding their stay data to the Host (controller) named in the guest privacy notice for that property. The Operator will assist Hosts with technical measures to fulfil requests where feasible and contractually required as processor, but cannot usually decide guest requests without Host instruction.
15. Automated decision-making
The Service does not use solely automated decision-making that produces legal or similarly significant effects on Host Users or Guests within the meaning of GDPR Article 22. Validation rules (e.g. required fields, document checks) assist users but do not replace Host or authority decisions.
16. Children
The Service is intended for business use by accommodation providers. Host accounts are not offered to children. Guest data about minors may be processed when required by accommodation law on the Host's responsibility as controller.
17. Marketing
We do not sell personal data. We may send service-related messages (security, terms or policy updates, operational notices) to account contacts. We do not send third-party marketing on behalf of others through the application unless explicitly stated and lawfully opted in.
18. Personal data breaches
If we become aware of a personal data breach affecting data for which we are controller, we will notify the ÚOOÚ and affected individuals where required by GDPR Articles 33–34. Where we process Guest Data as processor, we will inform the relevant Host without undue delay so the Host can meet controller obligations.
19. Host obligations as controller
Hosts must provide lawful bases and transparent notices to Guests, respond to data subject requests, maintain records of processing where required, conduct DPIAs when appropriate, and ensure instructions to the Operator are lawful. Hosts must not upload unnecessary special-category data. Use of passport images should be limited to what law and risk assessment justify, with clear guest information.
20. Changes to this Policy
We may update this Policy for legal, technical, or business reasons. Material changes will be posted at /privacy with an updated effective date and, where practicable, communicated through the Service or account contact at least thirty (30) days before they take effect. Continued use after the effective date constitutes acknowledgement where permitted by law.
21. Relationship to Terms of Service
This Policy supplements the Terms of Service at /terms. In case of conflict regarding data protection roles, the more specific description of processing in this Policy and in the guest notice prevails for privacy matters; commercial terms remain in the Terms.
22. Contact
For privacy questions about Operator-controlled processing, contact Josef Pechar, IČO 24005169, at the address on /legal, or by e-mail at
[email protected]. For guest data, contact the Host entity shown in the relevant guest privacy notice.
Professional review
This policy is drafted for GDPR and Czech Act No. 110/2019 Coll. It is not legal advice. Hosts remain responsible for their own compliance as accommodation providers and data controllers for guest data. Have qualified counsel review if your operations are complex.
Legal notice (operator identity)
·
Terms of Service
·
Data Processing Agreement
·
Back to login