Privacy Policy
Last updated: April 21, 2026
This document describes how Jan Nováček, a sole trader operating under the laws of the Czech Republic, with its registered address at Novoveská 10, 664 12 Oslavany, Czech Republic, Company ID: 01839811, VAT ID: CZ9107224357 (hereinafter referred to as the “Controller”), processes the personal data of users of the VoiceTour.app service.
You can contact us regarding personal data protection via the email address .
This policy applies to the VoiceTour.app website and related services provided within this platform.
1. Who is the controller of personal data?
The controller of personal data is:
Jan Nováček
Company ID: 01839811
VAT ID: CZ9107224357
Address: Novoveská 1141/10, 664 12 Oslavany
The Controller has not appointed a Data Protection Officer, as this obligation does not arise under the applicable legal regulations.
2. What personal data we process
In connection with providing the service, we may process in particular the following categories of personal data:
- identification data, for example first name and surname, if provided,
- contact data, in particular email address,
- login and account data,
- technical data, for example IP address, device type, operating system, and browser type,
- service usage data, for example information about playback, visited places, saved offline items, or interactions with the interface,
- data related to communication with support,
- data obtained when logging in through third parties, if we offer such an option,
- data related to newsletter subscription, if the user subscribes to it.
We generally do not process special categories of personal data unless the user provides them voluntarily and there is an appropriate legal basis for doing so.
3. Purposes of personal data processing
We process personal data mainly for the following purposes:
- providing and operating the service,
- creating and managing a user account,
- enabling account login,
- enabling offline features and synchronization of related settings, if the service offers them,
- sending operational emails and service notifications,
- sending newsletters, if the user gives consent,
- analyzing service usage and improving the service,
- ensuring security, preventing misuse, and protecting the rights of the controller,
- fulfilling the controller’s legal obligations.
4. Legal bases for processing
We process personal data on the basis of the following legal grounds:
- performance of a contract pursuant to Article 6(1)(b) GDPR,
- compliance with legal obligations pursuant to Article 6(1)(c) GDPR,
- legitimate interest pursuant to Article 6(1)(f) GDPR,
- consent pursuant to Article 6(1)(a) GDPR, in particular for newsletters and optional cookies.
Providing some personal data is necessary for the use of the service. Without providing such data, it may not be possible to use the service or parts of it.
5. Cookies, local storage, and offline data
The website uses cookies and similar technologies, including browser local storage, session storage, cache, or service worker technologies, for the purpose of ensuring functionality, security, offline availability of selected content, remembering settings, and, where applicable, measuring traffic.
Offline features may store selected data locally on the user’s device or in the user’s browser. In most cases, the user can manage or remove this locally stored data in their browser.
If we use analytical or marketing cookies, we do so on the basis of the user’s consent where required by applicable law.
6. Newsletter and email communication
The user may voluntarily consent to receiving a newsletter containing information about the service, updates, or features.
Consent to receive the newsletter may be withdrawn at any time, in particular via the link included in each email or by contacting the controller.
Operational email communications related to the provision of the service may also be sent without consent if they are necessary for the performance of a contract or for the protection of the controller’s legitimate interests.
7. Recipients of personal data and processors
Personal data may be made available to entities that provide us with technical, analytical, communication, or operational support.
Typically, these may include in particular:
- hosting and cloud infrastructure providers,
- providers of analytical tools,
- providers of email and newsletter services,
- providers of authentication services, if we use them,
- Paddle in connection with payment processing.
We do not process payment data directly, such as payment card details. These data are processed by the payment service provider Paddle, which may act as an independent controller of personal data within the scope of the payment process.
8. Transfers of data outside the EU/EEA
Some of our suppliers or their subcontractors may process personal data outside the European Union or the European Economic Area.
In such cases, data transfers are carried out only in compliance with the requirements of the GDPR, in particular on the basis of an adequacy decision, standard contractual clauses, or other appropriate safeguards.
9. Retention period of personal data
We retain personal data only for as long as necessary to fulfil the purposes for which they are processed.
Specific retention periods may vary depending on the type of data and the purpose of processing, in particular:
- user account data for the duration of the contractual relationship and for a reasonable period after its termination,
- data necessary for compliance with legal obligations for the period required by applicable law,
- data processed on the basis of consent until the consent is withdrawn or until the period for which the consent was granted expires,
- technical and operational logs for the period reasonably necessary for security, diagnostics, and protection of the controller’s rights.
10. Security of personal data
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, or damage.
These measures may include in particular:
- secured access to systems,
- encryption of communication using HTTPS,
- restricting access to personal data only to authorized persons,
- regular updates and security measures.
Although we strive for maximum security, the risk of unauthorized access to personal data during transmission over the internet or when storing data on the user’s end device cannot be completely excluded.
11. Rights of data subjects
In accordance with the GDPR, you have in particular the following rights:
- the right of access to personal data,
- the right to rectification of inaccurate or incomplete data,
- the right to erasure, if the legal conditions are met,
- the right to restriction of processing,
- the right to data portability,
- the right to object to processing,
- the right to withdraw consent at any time, if the processing is based on consent,
- the right to lodge a complaint with a supervisory authority.
In the Czech Republic, the supervisory authority is the Office for Personal Data Protection.
12. Changes to this policy
We may update this Privacy Policy from time to time, in particular in connection with changes in legal regulations, technologies, or the way the service is provided.
The current version is always available on the VoiceTour.app website.