1. Who controls your personal data
The controller is Whowhere.online s.r.o., Company ID 19638434, based in Pilsen, Czech Republic, e-mail: info@whowhere.online.
The controller determines the purposes and means of processing personal data in connection with operating this website, providing digital marketing services, preparing offers, communicating with leads, and fulfilling client contracts.
2. What personal data we process
We process only data necessary for a specific purpose. This may include:
- identification and contact data such as name, e-mail, phone, company name, company ID, and billing details if a business relationship is established;
- contact form data such as selected service, message content, project information, website URL, and preferred communication language;
- diagnostic quiz data such as the main problem, project stage, indicative budget, timeline, project website, additional message, and contact data;
- business communication data such as e-mails, consultation notes, briefs, documents, and information needed to prepare an offer or deliver a project;
- technical data such as IP address, date and time of visit, browser and device information, server logs, security records, and cookie consent settings;
- analytics and marketing data if you give consent via the cookie banner.
3. Purposes and legal bases
We process personal data for the following purposes:
- responding to inquiries, preparing offers, and pre-contract communication — Article 6(1)(b) GDPR;
- performing a contract and delivering ordered services — Article 6(1)(b) GDPR;
- accounting, tax records, and legal obligations — Article 6(1)(c) GDPR;
- website security, abuse prevention, technical troubleshooting, and incident handling — Article 6(1)(f) GDPR, our legitimate interest in secure website operation;
- analytics, website improvement, and marketing evaluation — Article 6(1)(a) GDPR where non-essential cookies or similar technologies are used;
- reasonable direct communication with existing clients about related services — legitimate interest, with the possibility to object.
4. Contact forms and diagnostic quiz
If you submit a contact form, service request, or diagnostic quiz in the hero section, we use the data to evaluate your request, reply to you, prepare a recommendation, and, where relevant, propose a specific service offer.
Without mandatory data, especially name, e-mail, and message content, we cannot respond. Optional data such as phone, company, or website URL helps us understand the situation and prepare a more relevant reply.
5. Cookies, analytics, and third-party tools
We may use technically necessary cookies for correct website operation and consent management. Analytics, marketing, or other non-essential cookies are used only if you give consent.
The website may use tools such as WordPress, Polylang, Contact Form 7, Rank Math, Complianz, and Site Kit by Google. If Google measurement is enabled, analytics data may be processed by Google. See our Cookie Policy for more details.
6. Who may receive the data
Personal data may be shared only to the extent necessary for the stated purposes. Recipients may include:
- hosting and technical infrastructure providers;
- e-mail, analytics, security, and administration tool providers;
- contractors helping us with development, website management, marketing, or service delivery;
- accounting, tax, or legal advisors;
- public authorities where required by law.
We require processors to protect personal data in line with GDPR.
7. Transfers outside the EU/EEA
We prefer processing within the European Union or European Economic Area. Some global cloud, analytics, or communication services may involve transfers outside the EU/EEA.
Where such transfers occur, we rely on appropriate safeguards under GDPR, such as adequacy decisions, standard contractual clauses, or other mechanisms required by law.
8. How long we keep data
We keep data only as long as necessary:
- inquiries, contact forms, and diagnostic quiz submissions are usually kept for up to 12 months unless cooperation follows;
- contract-related data is kept during the contract and then as needed to protect legal claims;
- accounting and tax documents are kept for the period required by law, usually up to 10 years;
- technical and security logs are kept for a reasonable period needed for website protection and operation;
- cookie consents are kept according to the consent tool settings or until withdrawn.
9. Your rights
Under GDPR, you have the right of access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interest, and withdrawal of consent where processing is based on consent.
You also have the right to lodge a complaint with a supervisory authority. In the Czech Republic this is the Office for Personal Data Protection, uoou.gov.cz.
10. Data security
We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, or alteration. Access is limited to people who need the data for a specific purpose. Security measures are adjusted over time according to the nature of processing and technologies used.
11. Automated decision-making
We do not carry out automated decision-making that would have legal or similarly significant effects on you. The diagnostic quiz is used as input for human evaluation and recommendation preparation.
12. Changes to this policy
We may update this policy, especially when services, technologies, legal requirements, or processing practices change. The current version is always published on this page.
