PRIVACY POLICY

(receptysnadno.com)

1. Who is the controller of personal data

1.1. The controller of personal data is:

AVATOMIS s.r.o.
registered office: B. Martinů 1885/2, 741 01 Nový Jičín
Company ID: 09765492
VAT ID: CZ09765492
a company registered in the Commercial Register, file no. C 84235, held at the Regional Court in Ostrava
email: info@avatomis.com
(hereinafter referred to as “Administrator“ or “we“).

1.2. These principles apply to the processing of personal data of users who:

  • visit the website receptysnadno.com and its subdomains (e.g. new.receptysnadno.com) (hereinafter referred to as “Website“),

  • use a user account,

  • use a subscription “No Ads”,

  • or use the Website’s community and other features,

  • communicate with us (by e-mail, forms, social networks, etc.).

1.3. When processing personal data, we proceed in particular in accordance with:

  • Regulation (EU) 2016/679 (GDPR),

  • Act No. 110/2019 Coll., on the processing of personal data,

  • Act No. 480/2004 Coll., on certain information society services,

  • and other legal regulations of the Czech Republic and the EU.


2. What personal data we process

The scope of data varies depending on how you use the Website.

2.1. Browsing the Website only (without registration)

During a normal visit to the Website we may process in particular:

  • IP address and the approximate location derived from it,

  • technical information about the device and browser (device type, OS, browser type and version, resolution),

  • access data (date and time, pages visited, movement on the Website, clicks, source of access – e.g. search engine, social network),

  • cookies and other online identifiers.

This data is mostly processed in pseudonymized form and we do not try to link it to a specific identity unless there is a reason to do so.

2.2. Registration and user account

When creating an account and using it we process in particular:

  • email address,

  • display name / nickname,

  • password in securely hashed form (passwords never are stored in plaintext),

  • date and time of registration and last login,

  • account settings, favorite recipes, internal identifiers,

  • any additional data you voluntarily provide (e.g. profile picture, notes, etc.).

2.3. “No Ads” subscription (Stripe)

When ordering and managing a subscription we process, to the necessary extent:

  • user identification (user account, user ID),

  • email, name / display name,

  • information on whether your subscription is active (subscription status, start and end date, subscription ID in Stripe, and optionally customer ID in Stripe),

  • payment history in the sense of: which period is paid, amount paid, currency, payment date, payment method.

Payment card numbers, CVC codes or other sensitive payment data are not stored on our server. These details are processed only by Stripe as the payment gateway provider. The Stripe service is governed by its own terms and privacy policies.

2.4. Communication, contact forms, emails

If you contact us (e.g., by email, a form on the Website, or via social media), we process:

  • name / nickname,

  • email address, and optionally phone number,

  • message content and any attachments,

  • information about the date and time of the communication.

2.5. Comments, ratings, community features

If the Website allows:

  • comments on recipes,

  • ratings, sharing your own recipes, uploading photos,

we process:

  • displayed name / nickname,

  • the content of the comment or other post (including photos),

  • date and time of posting,

  • IP address or other technical data (e.g., for spam protection).

2.6. Newsletter and commercial communications

If you subscribe to the newsletter or give us consent to send commercial communications, we process:

  • email address,

  • information on whether and when you gave consent,

  • data on email delivery and opening (statistics).

The newsletter may contain:

  • news from the Website,

  • a selection of recipes,

  • information about new features,

  • offers of related services or products.

You can unsubscribe from the mailing list at any time by clicking the unsubscribe link in any email or by contacting us.

2.7. Cookies and analytics

We use cookies and similar technologies on the Website. These may include, in particular:

  • necessary (technical) cookies – for logging in, saving preferences, security,

  • analytical / statistical cookies – e.g. Google Analytics 4, traffic measurement, monitoring website performance,

  • marketing cookies – e.g. for Google Ads / AdSense, affiliate systems, retargeting, social networks.

You can find more detailed information in a separate document Cookie Policy.


3. Source of personal data

3.1. We obtain personal data primarily:

  • directly from you (registration, order, communication, comments),

  • from your use of the Website (server logs, cookies, analytics),

  • from our contractual partners (e.g. Stripe – information about payment or subscription status).

3.2. Personal data we never buy from third parties in the sense of “email databases” and similar services.


4. Purposes and legal bases of processing

4.1. Operation of the Website and provision of services (registration, account, subscription)

  • Purpose: operation and security of the Website, enabling registration and login, maintaining the user account, providing the paid “No ads” subscription.

  • Legal basis:

    • performance of a contract (Art. 6(1)(b) GDPR – user account, subscription),

    • the Controller’s legitimate interest (Art. 6(1)(f) – logging, security, protection against abuse).

4.2. Invoicing, accounting and tax obligations

  • Purpose: recording payments, issuing tax documents, maintaining accounting.

  • Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR – accounting and tax regulations).

4.3. Communication with users and handling requests

  • Purpose: responses to inquiries, troubleshooting, complaints, user support.

  • Legal basis:

    • performance of the contract (regarding account/subscription inquiries),

    • legitimate interest of the Controller (routine communication, service improvements).

4.4. Marketing, newsletter and commercial communications

  • Purpose: sending news, recipes, information about services and offers, remarketing.

  • Legal basis:

    • consent (Art. 6(1)(a) GDPR), if you sign up for the newsletter,

    • legitimate interest (Art. 6(1)(f) GDPR) in the case where we offer you as our customer — a subscription user — similar services and you have not explicitly refused them.

You can unsubscribe from marketing at any time.

4.5. Traffic analysis and Website improvement

  • Purpose: traffic measurement, analysis of Website usage, content, UX and performance improvement.

  • Legal basis: the Controller’s legitimate interest (if we use cookies only in aggregated form) or consent (if the Website asks you for it in the cookie banner).

4.6. Protection of rights, legitimate interests and dispute resolution

  • Purpose: protection of the Website and our rights, prevention of abuse, handling potential disputes, enforcement of claims.

  • Legal basis: the Controller’s legitimate interest (Art. 6(1)(f) GDPR).


5. How long we retain data

Retention periods vary depending on the purpose:

  • account data – for the duration of the account and for no more than 3 years after its termination (for potential disputes),

  • subscription, payment and billing data – at least for the period required by accounting and tax regulations (typically 5–10 years from the end of the tax period),

  • communications (emails, chat, forms) – usually 3 years from request resolution, unless longer retention is required (e.g. to defend against claims),

  • newsletter data – for the duration of the consent or until unsubscribed,

  • analytical cookie data – depending on the specific tool and settings (typically 14 months for GA4; exact duration is described in the cookie policy),

  • security event logs – typically 6–24 months.

After the retention period expires data:

  • either we securely delete it,

  • or we anonymize it so that it no longer constitutes personal data.


6. Who we share personal data with

We may disclose personal data only to the following categories of recipients to the extent necessary:

  • hosting and server infrastructure providers,

  • providers of traffic measurement and analytics tools (e.g. Google Analytics),

  • providers of marketing and advertising tools (e.g. Google Ads, AdSense, affiliate systems),

  • payment gateway Stripe – for processing payments and managing subscriptions,

  • providers of email and newsletter services,

  • external accountant or tax advisor,

  • lawyers, legal advisors, public authorities – if necessary to protect our rights or based on a legal obligation.

With each processor we have concluded a data processing agreement under Article 28 GDPR, where required by law.


7. Transfer of data outside the EU / EEA

Some of our partners (e.g. Google, Stripe, cloud service providers) may also process data outside the EU / EEA (in particular in the USA).

In such cases the transfer is based on:

  • European Commission decision on adequate protection,

  • standard contractual clauses,

  • or other appropriate safeguards under the GDPR.

You can find specific information in the privacy policy of the respective provider (Google, Stripe, etc.).


8. Security of personal data

8.1. We protect personal data using appropriate technical and organizational measures that take into account:

  • the nature of the data processed,

  • the risks to users’ rights and freedoms,

  • the state of the art.

8.2. Measures include in particular:

  • encrypted connection to the Website (HTTPS),

  • encrypted transfers between our systems and some processors,

  • regular software updates (WordPress, plugins, server),

  • restricted access to administration and databases only for authorized persons,

  • data backups and monitoring,

  • secure password hashing.

8.3. If a security incident occurs that risks your rights, we follow GDPR procedures – we will take remedial measures and, if necessary, notify the supervisory authority and you.


9. Your rights under the GDPR

As a data subject you have the following rights:

9.1. Right of access

You have the right to know whether we process your data, and if so, to obtain:

  • a copy of personal data,

  • information about purposes, categories, recipients, retention period, your rights and the source of the data.

9.2. Right to rectification

If the data are inaccurate or incomplete, you have the right to request their correction or completion. You can edit some data directly in your account settings.

9.3. Right to erasure ("right to be forgotten")

You may request erasure of data if:

  • they are no longer necessary for the purposes for which they were processed,

  • you withdraw consent and there is no other legal basis,

  • you have objected and there are no overriding legitimate grounds,

  • the processing is unlawful,

  • erasure is required by law.

However, we cannot erase data that we must retain due to a legal obligation (e.g. accounting).

9.4. Right to restriction of processing

In certain cases you may request that we restrict processing (e.g. if you dispute the accuracy of the data or the processing is unlawful).

9.5. Right to data portability

If processing is based on consent or a contract and is automated, you can request the issuance of data in a structured, commonly used, machine-readable format or its transfer to another controller.

9.6. Right to object

You can object to processing based on legitimate interest (e.g., analytics, basic marketing, security). In that case we will stop processing the data unless we can demonstrate compelling legitimate grounds.

9.7. Right to withdraw consent

If we base processing on your consent (e.g., newsletter, marketing cookies), you can withdraw it at any time – withdrawal does not affect processing before it was withdrawn.

9.8. Right to lodge a complaint with the supervisory authority

If you believe we are processing data in violation of the GDPR, you have the right to lodge a complaint with the supervisory authority:

Office for Personal Data Protection
Pplk. Sochora 727/27, 170 00 Prague 7
website: www.uoou.cz


10. How to exercise your rights

You can exercise your rights:

For faster processing, please state:

  • which right you wish to exercise,

  • the ID or e-mail of your account,

  • or other information to verify identity (so we don't disclose data to an unauthorized person).

We will respond to the request without undue delay, no later than 1 month from receipt (in complex cases the period may be extended by another 2 months – about which we will inform you).


11. Cookies and similar technologies

11.1. The Website uses cookies and similar technologies to provide:

  • basic Website functionality (login, cart, language selection),

  • analytics and visitor statistics,

  • marketing and personalization (depending on your consent).

11.2. Detailed information about cookie types, their purposes, retention periods, and configuration options can be found in the document Cookie Policy, which is available from the Website footer.

11.3. You can manage most cookies in your browser settings or via the cookie management banner on the Website.


12. Processing of children's data

The Website and services, including the “No Ads” subscription, are not primarily intended for children under 16.

If we discover that we are processing a child's personal data without the consent of a legal guardian, we will take steps to limit processing and delete the data where permitted by law.


13. Changes to the privacy policy

13.1. We may update this policy from time to time, particularly if:

  • laws or regulations change,

  • services are expanded or modified,

  • we start using new tools or processors.

13.2. We will publish the revised wording on the Website and, in case of significant changes, may also notify you by email or an in-account notification.

The current version of the policy is always available at:
https://receptysnadno.com/gdpr (or the corresponding URL).


14. Controller contact details

If you have any questions about the processing of personal data, you can contact us:

AVATOMIS s.r.o.
B. Martinů 1885/2, 741 01 Nový Jičín
email: info@avatomis.com


Effective date

These Privacy Policy provisions come into effect on 1. 12. 2025.

Cook without ads ✨

Activate Recepty snadno without ads and get a clean site, faster loading and support the creation of new recipes.

59 Kč / month

or 589 Kč per year