Data Protection & Privacy Policy
Data Controller
EMES finance s.r.o.
Registered office: Dvorecká 387/2, 147 00 Prague 4 – Podolí, Czech Republic
Company ID: 19185219
E-mail: info@emesfinance.cz | Tel.: +420 733 610 198
These principles describe how we process personal data of visitors to the website emesfinance.cz, consultation applicants and our clients, including the use of cookies, analytics and communication with authorities. We act in compliance with Regulation (EU) 2016/679 (GDPR) and related legislation.
1) What Data We Process and Where It Comes From
Identification and contact data:
First name, last name, company name, Company ID / VAT ID (if provided), e-mail address, phone number.
Data from enquiries and forms:
Message content, preferred meeting date, notes regarding accounting services (e.g. interest in a 15-minute consultation / review).
Accounting and contractual data of clients:
Billing and payment details, accounting documents, data necessary to fulfil legal obligations (especially tax and accounting regulations).
Technical data and cookies:
IP address, device/browser type, anonymised traffic statistics, cookie consent preferences.
Communication with us:
E-mail and phone communication, possibly meeting records (date and subject discussed).
Sources:
You provide us with the data (form, e-mail, phone); further data arises in the course of service provision and automatically when using the website (cookies/analytics).
2) Purposes and Legal Bases of Processing
Responding to enquiries / arranging consultations
Processing via contact form, e-mail, phone.
Legal basis: Legitimate interest (Art. 6/1/f GDPR) or pre-contractual steps (Art. 6/1/b).
Provision of accounting services and contract fulfilment
Processing includes accounting, business reporting, VAT and tax agendas, payroll processing, communication with authorities.
Legal basis: Performance of a contract (Art. 6/1/b).
Compliance with legal obligations
Processing tax and accounting documents, statutory document retention.
Legal basis: Legal obligation (Art. 6/1/c).
Service communications (e.g. appointment confirmations, service changes)
Legal basis: Legitimate interest (Art. 6/1/f).
Marketing (only with your consent, e.g. newsletter)
Legal basis: Consent (Art. 6/1/a). Consent can be withdrawn at any time.
Website improvement and traffic measurement (analytics)
Legal basis: Consent (Art. 6/1/a) for non-essential cookies; legitimate interest for strictly necessary cookies.
3) Data Recipients
We transfer only necessary data and only to verified partners:
Web hosting & e-mail: e.g. WEDOS Internet, a.s. – data stored within the EU.
Website tools: WordPress and related plugins (e.g. form plugin / Elementor).
Analytics & measurement (if enabled): Google Analytics 4 / Google Tag Manager.
Authorities & institutions: Tax Office, health insurance companies, Social Security Administration, as required by law or within accounting services.
Other processors: Only if necessary for service provision; data processing agreements are concluded in accordance with Art. 28 GDPR.
4) Transfers Outside the EU
We primarily process data within the EU. If tools with servers outside the EU are used (e.g. Google/Meta), transfers take place based on Standard Contractual Clauses (SCC) and additional safeguards. We use only widespread services compliant with GDPR requirements.
5) Data Retention Periods
Enquiries and communication: generally up to 12 months after last contact unless cooperation is established.
Contractual and accounting documentation: 5–10 years according to legal requirements.
Marketing consent: until consent is withdrawn.
Cookies and analytics: according to cookie type settings (see below).
6) Cookies and Similar Technologies
We use:
Technical / necessary cookies – ensure website operation (sessions, security, saved consent settings).
Preference and analytics cookies (e.g. GA4) – only with your consent.
Marketing tags (e.g. Meta Pixel) – only if activated and with your consent.
You may change your consent at any time via the cookie bar (“Adjust settings”). Cookies can also be blocked in browser settings; some website functions may then be limited.
Indicative cookie duration:
Necessary cookies – session / several days
Analytics – minutes to months
Marketing – days to months
7) Data Security
We use SSL/HTTPS, access controls, regular system and plugin updates, processing agreements with partners and internal data protection rules. Data is not disclosed to unauthorised persons.
In the event of a security incident, we take necessary measures and inform affected persons and the supervisory authority if required by GDPR.
8) Your Rights
You have the right to:
access your personal data,
rectification of inaccurate data,
erasure (“right to be forgotten”),
restriction of processing,
data portability,
object to processing (especially based on legitimate interest or direct marketing),
withdraw consent (where consent is the legal basis).
You may exercise your rights at info@emesfinance.cz.
You also have the right to lodge a complaint with the Czech Data Protection Authority (www.uoou.cz).
9) Third-Party Websites
Our website may contain links to third-party websites. We are not responsible for their content or personal data processing. Please follow their respective privacy policies.
10) Document Updates
These principles may be updated from time to time (e.g. due to technology or legislative changes). The current version including the effective date is always available on this page.
Effective from: 1 September 2025
