Privacy Policy and Cookies
Introductory Provisions
1.1. This Privacy Policy and Cookie Policy ("Policy") governs, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data ("GDPR"), Act No. 110/2019 Coll., on Personal Data Processing, as amended, and Act No. 127/2005 Coll., on Electronic Communications, as amended (the "Electronic Communications Act"), the principles of personal data processing and the use of cookies in connection with the operation of the website www.luxuryesthetic.cz (the "Website"), operated by LUXURY ESTHETIC CLINIC s.r.o., ID No.: 235 24 863 (the "Controller").

1.2. This Policy applies to every natural person who visits the Website, fills out a form on it, contacts the Controller via the provided contact details, or otherwise uses the Website (the "Visitor").

1.3. The processing of personal data of clients of the aesthetic clinic operated by the Controller (the "Clinic") in connection with the personal provision of services at the Clinic's premises (including health data, health questionnaires, and photographic or visual documentation) is governed by the document "Consent to Personal Data Processing and Information on Personal Data Processing", which the treated person signs upon their first visit to the Clinic and which is available at the Clinic's premises, together with the relevant informed consents.

1.4. This Policy exclusively governs the processing of personal data in connection with visiting and using the Website. By using the Website, the Visitor confirms that they have read and understood this Policy. Consent to the use of non-essential cookies is granted separately by the Visitor following the procedure set out in Article 9 of this Policy.
Personal Data Controller
2.1. The Personal Data Controller is LUXURY ESTHETIC CLINIC s.r.o., ID No.: 235 24 863, VAT ID No.: CZ23524863, with its registered office at Revoluční 1082/8, Nové Město, 110 00 Prague 1, registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, Insert 428647, operating an aesthetic clinic at Pernerova 136/45, Karlín, 186 00 Prague 8.

2.2. Contact details of the Controller for the purpose of exercising rights under this Policy or any questions regarding personal data processing: email [luxuryesthetic.clinic@gmail.com], phone [+420 774 131 107].

2.3. Given the scope and nature of personal data processing via the Website, the Controller is not obliged to appoint a Data Protection Officer (DPO) and has not appointed one.
Scope and Purposes of Personal Data Processing
3.1. In connection with the operation of the Website, the Controller processes personal data about the Visitor to the following extent and for the following purposes: a) contact/inquiry form on the Website – name, email, phone number, and message content; the purpose is answering inquiries and communicating with the Visitor; b) ordering (reservation) of a service through the Altegio reservation system, to which the Website links via the "BOOK AN APPOINTMENT" button – name, phone number, email, and other data required by the reservation system; in relation to the data entered by the Visitor for the purpose of booking a service with the Controller, the Controller acts as the personal data controller and the operator of the reservation system acts as its processor under Article 28 of the GDPR; processing performed by the operator of the reservation system for its own purposes (in particular the operation and development of the system and management of the Visitor's user account) is governed by its own privacy policy, which the Visitor reads during reservation; c) newsletter and marketing communications, if ordered by the Visitor or if consent to sending them is granted – email, and possibly name; d) communication via social networks and applications to which the Website links (Instagram, Facebook, WhatsApp) – processing of messages and data entered on these platforms is governed by the privacy policy of the respective provider (Meta Platforms Ireland Limited); e) technical and operational data on the use of the Website through cookies and similar technologies (see Article 9 of this Policy).

3.2. The Controller does not process special categories of personal data, in particular health data, through the Website. The Visitor shall therefore refrain from stating details about their health condition in the contact or inquiry form; health data are processed exclusively in connection with the personal provision of services at the Clinic's premises following the procedure under Article 1.3 of this Policy.

3.3. The provision of personal data through the Website is voluntary. However, without providing the data marked as mandatory in the form, the Controller cannot process and respond to the Visitor's inquiry or send the newsletter.

3.4. Based on the Visitor's personal data obtained through the Website, the Controller does not carry out automated individual decision-making or profiling with legal effects for the Visitor or with similarly significant impacts within the meaning of Article 22 of the GDPR.
Legal Basis for Processing
4.1. The Controller processes the Visitor's personal data based on the following legal grounds under Article 6 (1) of the GDPR: a) point (b) – negotiations on entering into a contract or performance of a contract (handling inquiries, mediating Service reservations); b) point (a) – consent of the Visitor (sending newsletters and marketing communications pursuant to Section 7 of Act No. 480/2004 Coll., on Certain Information Society Services, as amended, and marketing and analytical cookies); c) point (f) – legitimate interest of the Controller (ensuring functionality, security, and basic web traffic statistics of the Website, protecting the Controller's rights); d) point (c) – compliance with a legal obligation (e.g., requirements of accounting and tax regulations for issued documents).

4.2. If the legal basis for processing was the Visitor's consent, the Visitor is entitled to withdraw this consent at any time using the contact details under Article 2.2 of this Policy or in the manner specified in Article 9.4 of this Policy (for cookies). The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. Withdrawal of consent is free of charge for the Visitor and just as easy as granting it.
Recipients of Personal Data and Transfers Outside the EU/EEA
5.1. Under the conditions laid down by legal regulations, the Visitor's personal data may be made accessible to the following processors and recipients: the operator of the Altegio reservation system, the web hosting and technical management provider of the Website, providers of Google tools (Google Ireland Limited – Google Analytics/Google Tag Manager) and Meta tools (Meta Platforms Ireland Limited – Facebook Pixel, Instagram), and possibly the provider of the newsletter tool [ecomail.cz]. The Controller has concluded a personal data processing agreement pursuant to Article 28 of the GDPR with each processor.

5.2. Some of the aforementioned recipients may be established or process personal data on servers outside the European Union and the European Economic Area, particularly in the USA. In such cases, the Controller ensures that the transfer is secured based on an adequacy decision of the European Commission (EU–US Data Privacy Framework) or based on standard contractual clauses approved by the European Commission. The Visitor acknowledges that the validity of the European Commission's adequacy decision under the EU–US Data Privacy Framework was confirmed by the judgment of the General Court of the European Union of September 3, 2025, in case T-553/23 (Latombe), against which an appeal was filed before the Court of Justice of the European Union under Case No. C-703/25 P. The Controller continuously monitors the validity of this decision and, in the event of its annulment, will ensure the transfer of personal data based on standard contractual clauses or terminate the respective processing. The Controller will provide a copy of the safeguards used to the Visitor upon request.

5.3. The Controller does not transfer Visitors' personal data to other third parties for their own marketing purposes.

5.4. If the Visitor books a Clinic service, their identification and contact data are transferred from the reservation system to the outpatient information system HealthPro, operated for the Controller by MSC Advisors s.r.o., ID No.: 036 23 700, with its registered office at Kounická 1385/60, Strašnice, 100 00 Prague 10, as its processor under Article 28 of the GDPR. The Controller subsequently keeps documentation of provided services in this system; this processing is governed by the document mentioned in Article 1.3 of this Policy, not by this Policy.
Retention Period of Personal Data
6.1. Personal data processed in connection with the Website are retained by the Controller for the period necessary to fulfill the purpose of processing, but at most:

a) data from the contact/inquiry form – for the period of handling the inquiry and 12 months from the last communication with the Visitor;

b) data processed for newsletter purposes – until the consent is withdrawn by the Visitor, but for a maximum of 5 years from when it was granted; c) cookies – for the duration of their validity stated in the cookies overview under Article 9.3 of this Policy; d) proof of consent to cookies – for a period of 12 months from when it was granted.

6.2. After the relevant period expires, the Controller erases or anonymizes the personal data, unless a special legal regulation (e.g., accounting or tax regulations) provides for a longer retention period.
Rights of the Data Subject
7.1. In connection with the processing of their personal data, the Visitor has the following rights in particular:
a) the right of access to personal data under Article 15 of the GDPR;
b) the right to rectification of inaccurate personal data under Article 16 of the GDPR;
c) the right to erasure of personal data under Article 17 of the GDPR;
d) the right to restriction of processing under Article 18 of the GDPR;
e) the right to data portability under Article 20 of the GDPR;
f) the right to object to processing based on the legitimate interest of the Controller under Article 21 of the GDPR;
g) the right to withdraw granted consent to processing at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
h) the right to lodge a complaint with a supervisory authority, which is the Office for Personal Data Protection, located at Pplk. Sochora 27, 170 00 Prague 7, website www.uoou.cz.

7.2. The Visitor may exercise these rights using the Controller's contact details listed in Article 2.2 of this Policy. The Controller shall process the Visitor's request without undue delay, but no later than within the time limits set by the GDPR (usually within one month of receipt).
Personal Data Security
8.1. The Controller has adopted appropriate technical and organizational measures to ensure a level of security appropriate to the nature, scope, and purposes of personal data processing and the risks associated therewith, particularly regarding data transmission security and limiting access to personal data strictly to persons who need it to perform their activities.

8.2. Persons who come into contact with the Visitors' personal data as part of their activities for the Controller are bound by confidentiality, even after their activities for the Controller have ended.
Cookies and Similar Technologies
9.1. Cookies are small text files stored on the Visitor's end device during a visit to the Website, serving primarily to ensure the functionality of the Website, customize its content, and analyze web traffic (Section 89 (3) of the Electronic Communications Act and Article 6 of the GDPR).

9.2. Cookies used on the Website are divided into the following categories: a) essential (technical) cookies – enable basic functionality and secure operation of the Website; the Website cannot function properly without these cookies; in accordance with Section 89 (3) of the Electronic Communications Act, the Visitor's consent is not required for their use; b) analytical cookies – used to determine web traffic and how the Website is used in order to improve it (e.g., Google Analytics/Google Tag Manager); c) marketing (advertising) cookies – used to display relevant advertising and measure its effectiveness on and off the Website (e.g., Facebook Pixel/Meta Pixel).

9.3. The use of analytical and marketing cookies is subject to the prior consent of the Visitor granted through the cookie banner upon their first visit to the Website. A current overview of the cookies used, their specific name, provider, purpose, and validity period are available to the Visitor in the cookie consent management tool on the Website.

9.4. Non-essential cookies are neither stored nor read by the Controller prior to the Visitor granting consent. The cookie banner allows the Visitor to refuse all non-essential cookies as easily as accepting them, with a single action on the same menu level; consent is granted by an active action of the Visitor, and pre-ticked boxes are not used. Failure to grant consent has no consequences for the Visitor, except for limiting features that depend on the respective cookies. The Controller will not repeatedly request consent earlier than after 12 months.

9.5. The Visitor can withdraw or change consent to the use of non-essential cookies at any time via the cookie management tool available on the Website, or by adjusting their internet browser settings (refusing or deleting cookies); however, this may limit the functionality of the Website.

9.6. The Website is not intended for persons under 15 years of age, and the Controller does not knowingly collect personal data of children on it without the consent of their legal representative (Section 7 of Act No. 110/2019 Coll., on Personal Data Processing).
Changes to This Policy
10.1. The Controller is entitled to unilaterally amend this Policy, particularly in connection with changes to legal regulations, the scope of personal data processing, or technologies used on the Website. The current version is always published on the Website.

10.2. This Policy comes into force and effect on August 1, 2026.
Final Provisions
11.1. Relations not regulated by this Policy are governed by the GDPR, Act No. 110/2019 Coll., on Personal Data Processing, the Electronic Communications Act, and other relevant legal regulations of the Czech Republic and the European Union.

11.2. If any provision of this Policy is or becomes invalid or ineffective, this shall not affect the remaining provisions, which shall remain valid and effective.