# Personal Data Protection

## I. Privacy Policy

**1.1** By entering personal data, the user confirms that they are familiar with the personal data protection terms, consent to their wording and accept them in full.

This Privacy Policy is issued by Clientology Institute s.r.o., with its registered office at Nad Helmrovkou 276/8, Lysolaje, 165 00 Praha 6, Company ID No.: 033 35 526 (the “Provider”).

The Provider can be contacted by email at: info@clientology.cz.

**1.2** The Provider is the controller of users' personal data within the meaning of Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (the “GDPR”). The Provider undertakes to process personal data in accordance with applicable law, in particular the GDPR.

**1.3** Personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to that natural person's physical, physiological, genetic, mental, economic, cultural or social identity.

**1.4** When a service is ordered, personal data necessary to successfully process the order and provide the service are processed.

Depending on the specific type of service (as indicated in each case by the account creation questionnaire or another service order), this includes, in particular, identification and contact data such as first name, surname, email address and telephone number, and, where applicable, professional data such as job position, field of activity and country of operation, or other information provided by the user in the questionnaire.

For the purposes of this Article, a service means any service available through the Provider's web interface accessible through the clientology.cz domain, including, but not limited to, Clientology Scan and other online applications or any other services provided by the Provider on these websites.

The purposes of processing personal data are:

- processing the user's order and providing the ordered service;

- exercising rights and performing obligations arising from the contractual relationship between the Provider and the User;

- processing a completed form on our website; and

- sending commercial communications and carrying out other marketing activities.

The legal bases for processing personal data are performance of a contract under Article 6(1)(b) of the GDPR, compliance with a legal obligation of the controller under Article 6(1)(c) of the GDPR, the Provider's legitimate interest under Article 6(1)(f) of the GDPR and, where required by law, the data subject's consent under Article 6(1)(a) of the GDPR. The Provider's legitimate interest includes, in particular, processing personal data for direct marketing purposes, unless the law requires the data subject's prior consent for the specific marketing activities.

**1.5** To perform the licence agreement, the Provider uses subcontractors, in particular a mailing service provider (personal data are stored in third countries) and a web hosting provider. The subcontractors have been vetted with regard to secure processing of personal data. The Provider and the web hosting subcontractor have concluded a personal data processing agreement under which the subcontractor is responsible for properly securing the physical, hardware and software perimeter and therefore bears direct liability towards the user for any personal data leak or breach.

**1.6** The Provider stores the user's personal data for the period necessary to exercise rights and perform obligations arising from the contractual relationship between the Provider and the user and to assert claims arising from such contractual relationships (for 15 years from termination of the contractual relationship). After this period expires, the data will be deleted.

**1.7** The user has the right to request access to their personal data from the Provider under Article 15 of the GDPR, rectification of personal data under Article 16 of the GDPR or, where applicable, restriction of processing under Article 18 of the GDPR. The user has the right to erasure of personal data under Article 17(1)(a) and (c) to (f) of the GDPR. The user also has the right to object to processing under Article 21 of the GDPR and the right to data portability under Article 20 of the GDPR.

**1.8** The user has the right to lodge a complaint with the Office for Personal Data Protection if they believe that their right to personal data protection has been violated.

**1.9** The user is not obliged to provide personal data. However, providing personal data is a necessary requirement for the conclusion and performance of the contract, and without such data the contract cannot be concluded or performed by the Provider.

**1.10** The Provider does not carry out automated individual decision-making within the meaning of Article 22 of the GDPR.

**1.11** A person interested in using the Provider's services may, by completing the contact form, consent to the use of their personal data for the electronic sending of commercial communications, advertising materials, direct sales, market surveys and direct product offers by the Provider and third parties, no more frequently than once a week, and at the same time declares that they do not consider the sending of information under this paragraph 1.11 to constitute unsolicited advertising within the meaning of Act No. 40/1995 Coll., as amended.

The user may withdraw consent under this paragraph at any time in writing at info@clientology.cz.

**1.12** The Provider uses cookies on its website to improve service quality, personalise offers, collect anonymous data and perform analytics.

**1.13** When a user uses AI features, personal data contained in the prompt, relevant workspace content, generated response and related technical data may be processed to the extent necessary to handle the request. For these features, the Provider uses OpenAI models through Microsoft Azure OpenAI operated by a company within the Microsoft group. Processing of personal data for which the Provider is the controller is carried out to provide the ordered service on the basis of Article 6(1)(b) of the GDPR and, to the extent necessary for security and abuse prevention, on the basis of legitimate interests under Article 6(1)(f) of the GDPR. Processing through Microsoft Azure OpenAI may include retention of data and security monitoring depending on the features used, configuration and applicable service terms; this does not guarantee a specific technical region, processing exclusively within the European Union or the absence of data storage. The Provider supplies information on recipients, processing and retention of personal data to the extent and at the time required by applicable law. Any transfer outside the European Economic Area takes place only where the conditions of Chapter V of the GDPR are met, in particular on the basis of an adequacy decision or appropriate safeguards. Personal data processed by the Provider on behalf of the customer within the customer's content are subject to the relevant personal data processing arrangements, in particular Annex No. 1 to the GTC, and the instructions of the customer as controller.

**1.14** If a customer activates the MCP interface and grants access permissions to an external client, workspace data may be made available to that client on the basis of the customer's authorised instructions and within the scope of the permissions granted. The external client may subsequently store, process or transfer these data to its providers, including AI service providers, and potentially outside the European Economic Area. The customer is responsible for the lawfulness of such disclosure and the selection of the external service; that service's subsequent handling of data is governed by its terms and its actual role under applicable law. Revocation of access does not by itself remove data already disclosed to the external service. Detailed terms for the MCP interface, including preservation of the Provider's liability for its own obligations, are set out in Article 25 of the GTC.
