We process personal data only for specified purposes and to the extent necessary for the operation of the portal, support, security and fulfillment of legal obligations.
Data controller
The data controller is Whowhere.online s.r.o., company ID (IČO) 19638434, Tylova 749/38, 301 00 Plzeň, Czech Republic.
Contact the data controller
Send requests regarding personal data to info@whowhere.online.
Processed data
The categories depend on the functions used: account data, profile, requests, communication, technical data and public content.
Registration data
Email, name, user identifier, role, and protected WordPress authentication information may be processed.
Profile data
The information that the user adds to the profile or request is processed.
Data of company representatives
This may include name, work contacts, role, permissions, payment and billing information.
Public information
Published contacts, descriptions, photos and advertisements are available to visitors and search engines.
Reviews
The public review system is not yet live; this feature does not currently collect reviewer data.
Contact forms
The forms handle the category, name, email, subject and message text required for a response. Received suggestions are stored in a non-public record of the website administration, regardless of the sending of an e-mail notification. The record includes the information provided, the date, the source page, the processing status and the result of the email attempt; administrators have access.
Payments
The integrated payment gateway is not available. For payments agreed outside the portal, only necessary data and confirmations are processed.
Accounting data
Invoice and payment data may be stored for the period specified by Czech law.
IP and technical records
Server and security tools may process IP address, request time, URL, response status and technical logs for security and diagnostics.
Browser and device
User-agent, device type, language, screen and technical parameters needed for compatibility may be processed.
Analytics
The portal uses Google Analytics for traffic statistics. With your consent, the service can process technical data, visited pages, the source of the visit and analytical cookie identifiers.
E-mail communication
WordPress sends transactional messages and alerts via the wp_mail server function set up.
Support
Correspondence is kept to the extent necessary for the response, the history of the initiative and the protection of rights.
Breach notification
The type, URL, description, information of the whistleblower, its relation to the material and voluntarily provided evidence are processed. The proof is stored with the claim in the database's non-public repository and is available to administrators via secure download.
Legal basis
According to the purpose, performance of the contract, legitimate interest, legal obligation or consent will apply.
Performance of the contract
This basis is used for the account, company profile and ordered features if the processing is necessary to provide them.
Legitimate interest
After assessing the balance, it may include security, abuse prevention, moderation, support, rights protection and service improvement.
Legal obligations
Data is processed if required by accounting, tax, judicial or other legal obligations.
Consent
Consent is used only where appropriate; it can be revoked without affecting the legality of the previous processing.
Recipients
Authorized persons of the operator and suppliers necessary for hosting, e-mail, technical support and, with proper consent, also have access to Google Analytics.
Data processors
For individual activities, the operator can use suppliers of hosting, e-mail and technical support, for Google Analytics statistics. They only receive the data necessary for the respective service.
Transfers outside the EEA
When using Google Analytics or map data, the browser may establish a connection with third-party services. Portal fonts are loaded locally. When transferring data outside the EEA, statutory guarantees apply.
Retention periods
Data is not kept longer than necessary for the purpose, contract, legal obligation, security or protection of rights; times depend on the category.
Security
Access control, validation, sanitization, protection of forms against CSRF and other reasonable technical and organizational measures are used.
User rights
A person has rights under the GDPR, taking into account the conditions and exceptions for individual rights.
Access
Confirmation of processing and a copy of personal data can be requested.
Repair
Inaccurate or incomplete data can be corrected.
Deletion
Deletion can be requested if there is no lawful reason for further retention.
Restrictions
Restriction of processing can be requested in the cases stipulated by the GDPR.
Portability
For data processed automatically on the basis of consent or contract, the right to portability may apply.
Objection
Processing based on legitimate interest can be objected to for reasons related to a specific situation.
Withdrawal of consent
Consent can be withdrawn as easily as it was given, in particular through the available settings or by email.
Automated decision making
The portal does not declare decisions based solely on automated processing with legal or similarly significant effects.
Complaint to ÚOOÚ
A complaint can be filed with the Office for the Protection of Personal Data, Col. Billet 27, 170 00 Prague 7, posta@uoou.gov.cz, data box qkbaa2n.
Contacts
To exercise your rights write to info@whowhere.online; the operator can reasonably verify the identity of the applicant.
Policy changes
Updates are published with a new date and version. Substantial changes can also be announced separately.
Our search and reading statistics
With your explicit consent to statistics, WhoWhere.online stores public page views, site language, city, search terms, result counts, result selections, approximate active reading time and scroll depth in its own database. We use this information to improve search, the directory and our guides. You can change your choice in the cookie settings; withdrawing consent stops further collection.
This measurement does not create persistent cookies, localStorage entries or visitor profiles. Random identifiers stay in the memory of the open page to prevent double counting; they do not connect your visits across pages. The analytics table does not store IP addresses, account identifiers, contact form contents, full URLs with query parameters or screen recordings. Searches containing email addresses, links, phone-like numbers or long messages are excluded. Please do not enter personal data in search: automatic filtering cannot detect all such information.
Only portal administrators can access the reports. Data stays in the website database with its hosting provider, is retained for up to 90 days and is removed by daily scheduled cleanup. If the scheduler is temporarily unavailable, deletion resumes when it recovers. Our own measurement does not send search terms to Google Analytics; the existing Google Analytics service is described separately. For data requests, use the controller contact in our privacy policy.
Contact: info@whowhere.online · https://whowhere.online