in accordance with Act No. 110/2019 Coll., on the Processing of Personal Data, and Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR)
Effective from 11 July 2026
1. DATA CONTROLLER
This Privacy Policy applies to websites and services available primarily through:
The Data Controller is:
- Alcedo Praha z.s.
- Krymská 238/18, Vršovice
- 101 00 Prague 10
- Czech Republic
- ID No.: 22770895
(hereinafter referred to as the “Controller”).
Depending on the specific sport or activity, individual sport organizers listed in the General Terms and Conditions of Prague Rainbow Spring may also act as independent controllers of personal data.
Contact e-mail: info@alcedopraha.cz
2. GENERAL PRINCIPLES OF PERSONAL DATA PROCESSING
The Controller processes personal data only to the extent necessary for:
- organizing sports events,
- fulfilling contractual obligations,
- communicating with customers and participants,
- complying with legal obligations,
- protecting the legitimate interests of the Controller,
- marketing and promotional activities permitted by law,
- membership administration,
- administration of grant and subsidy programs.
The Controller processes personal data lawfully, fairly, and transparently in accordance with applicable legislation.
3. LEGAL BASIS FOR PROCESSING
Personal data are processed primarily on the following legal grounds:
a) Performance of a Contract
Processing is necessary for:
- participant registration,
- event organization,
- order administration,
- user account management,
- communication related to participation in events.
b) Compliance with Legal Obligations
Including:
- accounting and tax records,
- mandatory record keeping,
- compliance with applicable legal requirements.
c) Legitimate Interests
Including:
- protection of the Controller’s rights and property,
- complaint handling,
- fraud prevention,
- IT and information security,
- documentation and promotion of events.
d) Consent
Where required by law, particularly for certain marketing communications.
4. CATEGORIES OF PERSONAL DATA PROCESSED
The Controller may process the following categories of personal data:
- first name and surname,
- date or year of birth,
- residential address,
- correspondence address,
- e-mail address,
- telephone number,
- event registration details,
- purchased products and services,
- invoicing and payment data,
- membership records,
- communication with customers and participants.
For minors, identification and contact details of their legal guardians may also be processed.
5. PURPOSES OF PROCESSING
Personal data may be processed for:
- organizing and conducting sports events,
- managing registrations and orders,
- customer service,
- invoicing and accounting,
- communication with participants,
- membership administration,
- grant and subsidy administration,
- statistical and analytical purposes,
- improving products and services,
- protecting the Controller’s rights,
- marketing and information purposes.
6. PHOTOGRAPHS AND AUDIOVISUAL RECORDINGS
Photographs, video recordings or other audiovisual materials may be created during events organized by the Controller.
Such materials may be used for:
- event documentation,
- archival purposes,
- presentation and promotion of the Controller’s activities,
- publication on websites,
- publication on social media,
- promotional and annual reports.
The Controller always takes reasonable steps to protect participants‘ privacy when processing such materials.
7. COOKIES AND RELATED TECHNOLOGIES
The website uses cookies and similar technologies for:
- ensuring proper website functionality,
- website security,
- traffic analysis,
- improving the user experience.
Further details regarding cookies are available in the separate Cookie Policy published on the Controller’s website.
Users may manage cookie preferences through their web browser settings or the website cookie banner.
8. SHARING OF PERSONAL DATA
Personal data may be shared with:
- individual sport organizers,
- IT service providers,
- hosting providers,
- accounting and tax advisers,
- payment service providers,
- e-mail service providers,
- marketing service providers,
- public authorities when required by law.
All processors are selected with due regard to data security and privacy protection.
9. GRANTS AND SUBSIDY PROGRAMMES
For the purposes of applying for grants and subsidies, the Controller may maintain records of association members.
Where required by grant providers, the following information may be provided:
- first name,
- surname,
- year of birth.
Such processing is carried out on the basis of legal obligations or the legitimate interests of the Controller.
10. PERSONS UNDER 18 YEARS OF AGE
Personal data of persons under 18 years of age is processed only to the extent necessary for participation in relevant events.
Where required by law or by the nature of the service, a legal guardian acts on behalf of the minor participant.
11. INTERNATIONAL TRANSFERS OF PERSONAL DATA
Certain service providers used by the Controller may be located or store data outside the Czech Republic.
Where personal data is transferred outside the European Union or the European Economic Area, such transfers are carried out only using mechanisms that ensure an adequate level of protection in accordance with the GDPR.
12. DATA RETENTION PERIOD
Personal data is retained only for as long as necessary to fulfill the purpose of processing.
Typically:
- event-related data are retained for the period necessary for event administration and handling of potential claims,
- accounting and tax records are retained for the period required by law,
- marketing data are retained until consent is withdrawn or an objection is raised,
- membership records are retained for the duration of membership and subsequently for the period necessary to protect the Controller’s rights.
The maximum retention period is generally 10 years unless a longer retention period is required by law.
13. DATA SUBJECT RIGHTS
Under the GDPR, individuals have the right to:
- access their personal data,
- rectify inaccurate data,
- supplement incomplete data,
- request erasure of personal data,
- restrict processing,
- data portability,
- object to processing,
- withdraw consent,
- not be subject to automated decision-making where provided by law.
Requests may be submitted to: info@alcedopraha.cz
14. RIGHT TO LODGE A COMPLAINT
If you believe your personal data is being processed in breach of applicable legal requirements, you have the right to lodge a complaint with:
- Office for Personal Data Protection
- Pplk. Sochora 27
- 170 00 Prague 7
- Czech Republic
- https://www.uoou.cz
However, we would appreciate the opportunity to address your concerns directly before you contact the supervisory authority.
15. SECURITY OF PERSONAL DATA
The Controller has implemented appropriate technical and organizational measures to protect personal data against:
- unauthorized access,
- loss,
- damage,
- destruction,
- misuse.
However, no method of electronic transmission or storage can guarantee absolute security.
16. CONFIDENTIALITY
Persons who process personal data on behalf of the Controller in the course of employment or under contractual relationships are bound by confidentiality obligations.
Such obligations continue even after termination of their relationship with the Controller.
17. CHANGES TO THIS PRIVACY POLICY
The Controller reserves the right to update this Privacy Policy as necessary.
The current version will always be available at: https://www.praguerainbow.eu
18. CONTACT DETAILS
- Alcedo Praha z.s.
- Krymská 238/18
- 101 00 Prague 10
- Czech Republic
- E-mail: info@alcedopraha.cz
This Privacy Policy is effective as of 11 July 2026.
