LEGAL
Privacy Policy
How we handle personal data collected through this website, in line with Regulation (EU) 2016/679 (GDPR).
1. Who is responsible for your data
The controller of personal data collected through salamoncapital.com is:
COMPANY LEGAL NAME
Company registration number (IČO): IČO
Registered seat: STREET, POSTCODE CITY, Czech Republic
Registered in the Commercial Register kept by COURT, FILE NUMBER
E-mail: hq@salamoncapital.com
We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Any question about this policy or about your data goes to the e-mail address above and is answered by a person, not a queue.
2. What we collect
Data you give us
If you use the contact form, we receive the details you type into it: your name, company (optional), e-mail address and the content of your message. If you write to us by e-mail instead, we receive whatever the message contains.
Data collected automatically with a form submission
To be able to distinguish genuine enquiries from automated abuse, each submission is delivered to us together with the IP address it was sent from, the country derived from it, the browser identification (user agent) and the time of submission.
Server logs
The website is hosted on Cloudflare Pages. Like any web server, the infrastructure records technical data about requests — IP address, time, requested address, browser identification — for the purpose of operating and securing the service. We do not build user profiles from these records.
What we do not collect
This website sets no cookies of its own, contains no analytics, no advertising pixels and no social media trackers. Fonts, images and scripts are all served from our own domain, so simply browsing this site sends no data to any third party. Cloudflare may set strictly necessary cookies for security and abuse prevention as part of delivering the site; these carry no marketing function.
3. Why we process it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Answering your enquiry and preparing an offer or an audit you asked for | Article 6(1)(b) GDPR — steps taken at your request prior to entering into a contract |
| Ordinary business correspondence where no contract is in prospect | Article 6(1)(f) GDPR — our legitimate interest in responding to people who contact us |
| Spam filtering, abuse prevention and security of the website | Article 6(1)(f) GDPR — our legitimate interest in keeping the service operable and free of abuse |
| Meeting statutory obligations, e.g. in accounting or tax matters, where a contract follows | Article 6(1)(c) GDPR — compliance with a legal obligation |
Providing your data is voluntary. Without a name and an e-mail address we cannot reply to you, which is the only consequence of not providing them.
4. Who else sees the data
We do not sell personal data and we do not share it for anyone else's marketing. Data is accessible to our own staff on a need-to-know basis, and to the service providers we use to run the website and our mail, each acting as a processor under a data processing agreement:
| Provider | Role |
|---|---|
| Cloudflare, Inc. | Website hosting, CDN, DNS and security protection |
| Resend | Delivery of contact form submissions to our mailbox |
| MAILBOX PROVIDER | Hosting of our e-mail accounts |
We may also disclose data where we are legally obliged to — for instance to public authorities acting within their powers.
Transfers outside the EEA
Cloudflare and Resend are established in the United States and data may be processed there or in other countries where they operate. Such transfers take place under the safeguards provided for in Chapter V GDPR — standard contractual clauses adopted by the European Commission, or the EU–US Data Privacy Framework where the provider is certified. A copy of the relevant safeguards is available on request at the address in section 1.
5. How long we keep it
- Enquiries that do not lead to cooperation: kept for 24 MONTHS from the last communication, so that we can pick up the thread if you come back to us, and then deleted.
- Enquiries that lead to a contract: kept for the duration of the cooperation and afterwards for the period required by law, in particular accounting and tax legislation, and by limitation periods for potential claims.
- Technical metadata attached to a submission: deleted together with the enquiry it belongs to.
- Server logs: retained by our hosting provider for its own standard period and then deleted automatically.
6. Automated decision-making
We do not carry out automated decision-making or profiling within the meaning of Article 22 GDPR. The automated spam checks on the contact form assess the submission, never the person, and a rejected submission has no effect on you other than that the message is not delivered — you can always reach us by e-mail instead.
7. Your rights
Under the GDPR you have the right:
- of access to your personal data and to a copy of it (Article 15);
- to rectification of inaccurate or incomplete data (Article 16);
- to erasure, where the conditions are met (Article 17);
- to restriction of processing (Article 18);
- to data portability for data processed on the basis of a contract or consent (Article 20);
- to object at any time to processing based on legitimate interest (Article 21) — if you object, we will stop unless we can demonstrate compelling legitimate grounds that override your interests;
- to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
To exercise any of these, write to hq@salamoncapital.com. We respond within one month; if a request is complex we may extend that by up to two further months and will tell you if we do. We may need to verify your identity before acting on a request.
Complaints
If you believe we are handling your data unlawfully, you can lodge a complaint with the Czech supervisory authority:
Úřad pro ochranu osobních údajů
Pplk. Sochora 27, 170 00 Praha 7, Czech Republic
www.uoou.gov.cz
We would appreciate the chance to sort it out with you first.
8. Security
The site is served exclusively over HTTPS. Form submissions travel encrypted, and access to the mailbox that receives them is restricted to the people who need it. No system is absolutely secure, but we take the measures appropriate to the risk, as Article 32 GDPR requires.
9. Changes to this policy
If we change how the site handles data — for example by adding analytics or a booking tool — we update this page and change the date at the top. Material changes affecting people whose data we already hold will be communicated directly.