Privacy Policy
Effective from January 21, 2026
I. Basic Provisions
- The data controller pursuant to Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter "GDPR") is Vít Nehasil, with registered office at Vejvanovského 1619/14, Prague 4 14900, Czech Republic, Company ID: 06329403 (hereinafter "controller").
- Contact details of the controller: address Vejvanovského 1619/14, Prague 4 14900, Czech Republic, email info@storysong.cz.
- Personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
II. Sources and Categories of Processed Personal Data
- The controller processes personal data that you have provided or personal data that the controller has obtained based on the fulfillment of your order.
- The controller processes your identification and contact data (name, surname, email, phone, address), billing data and data necessary for the performance of the contract.
- The controller also processes data provided for the creation of musical compositions (stories, names of persons, preferences, occasion information, etc.). This data is necessary for the provision of the service.
III. Legal Basis and Purpose of Processing Personal Data
- The legal basis for processing personal data is: performance of a contract between you and the controller pursuant to Article 6(1)(b) GDPR; legitimate interest of the controller in providing direct marketing (especially for sending commercial communications and newsletters) pursuant to Article 6(1)(f) GDPR; your consent to processing for direct marketing purposes pursuant to Article 6(1)(a) GDPR in conjunction with Section 7(2) of Act No. 480/2004 Coll., on certain information society services, where no order for goods or services has been placed.
- The purpose of processing personal data is: processing your order and exercising rights and obligations arising from the contractual relationship between you and the controller; when ordering, personal data necessary for successful order processing are required (name, address, contact, data for song creation), provision of personal data is a necessary requirement for concluding and performing the contract, without providing personal data it is not possible to conclude the contract or perform it by the controller; sending commercial communications and other marketing activities.
- The controller performs automated processing of data using artificial intelligence (AI) technologies for the purpose of generating musical compositions. This processing is necessary for the provision of the service and does not constitute automated decision-making with legal effects within the meaning of Article 22 GDPR, as the result is always reviewed by a human before delivery to the customer.
IV. Data Retention Period
- The controller retains personal data for the period necessary for the exercise of rights and obligations arising from the contractual relationship between you and the controller and for the assertion of claims from these contractual relationships (for 10 years from the termination of the contractual relationship with regard to statutory archiving obligations).
- Personal data processed on the basis of consent for marketing purposes are retained until consent is withdrawn, but no longer than 5 years.
- Data provided for the creation of musical compositions (stories, names, preferences) are retained as part of the order for the period specified in the previous points.
- After the expiry of the retention period, the controller will delete the personal data.
V. Recipients of Personal Data (Subcontractors of the Controller)
- Recipients of personal data are persons: involved in the delivery of goods/services/payment processing based on the contract (delivery services, PayU payment gateway); providing website platform operation services and technical infrastructure; providing marketing services.
- Only data necessary for the creation of the composition (story, names of persons for song lyrics, genre preferences, etc.) is transferred to providers of AI tools used in the creation of musical compositions. Contact and billing data (email, phone, address) is not transferred to these providers.
- The controller intends to transfer some personal data to a third country (outside the EU). Recipients of data in third countries are providers of AI services based in the USA, to whom only data for composition creation is transferred as per the previous point. The transfer takes place on the basis of standard contractual clauses approved by the European Commission.
VI. Your Rights
- Under the conditions set out in the GDPR, you have: the right of access to your personal data pursuant to Article 15 GDPR; the right to rectification of personal data pursuant to Article 16 GDPR, or restriction of processing pursuant to Article 18 GDPR; the right to erasure of personal data pursuant to Article 17 GDPR; the right to object to processing pursuant to Article 21 GDPR; the right to data portability pursuant to Article 20 GDPR; the right to withdraw consent to processing in writing or electronically to the address or email of the controller.
- You also have the right to lodge a complaint with the Office for Personal Data Protection (www.uoou.cz, Pplk. Sochora 27, 170 00 Prague 7, Czech Republic) if you believe that your right to personal data protection has been violated.
VII. Personal Data Security Conditions
- The controller declares that it has taken all appropriate technical and organizational measures to secure personal data.
- The controller has taken technical measures to secure data storage and storage of personal data in paper form.
- The controller declares that only persons authorized by it have access to personal data.
VIII. Cookies
- The website uses cookies to ensure functionality and improve user experience.
- Necessary cookies: ensure basic website functions (login, cart, language preferences) and cannot be disabled.
- Analytical cookies: help us understand how visitors use the website. All data is anonymized.
- You can restrict the use of optional cookies in your browser settings or via the cookie bar on the website.
IX. Final Provisions
- By submitting an order from the online order form, you confirm that you are familiar with the personal data protection conditions and that you accept them in full.
- The controller is entitled to change these conditions. The new version of the personal data protection conditions will be published on its website.
- These conditions take effect on January 21, 2026.
For any questions regarding personal data protection, contact us at info@storysong.cz