Personal Data Processing (GDPR)

Last update: August 2025

1 | Who is the Data Controller?

The controller of your personal data is the operator of this website – full contact details are available on the Contact page. For any questions or to exercise your rights, please write to the e‑mail address provided there.

2 | What Data We Process & Why

ScenarioDataPurpose / Legal basisRetention period
Website visit onlyIP address*, browser data, cookies1) Necessary – website operation & security (legitimate interest)2) Analytics & marketingonly with consentsee cookie table
Adding a commentName/nickname, e‑mail, comment text, IP address*Operating the comment section, spam protection (legitimate interest)3 years after publication

* The IP address is stored only for a short period for technical and security reasons.

3 | Cookies & Similar Technologies

To measure traffic, speed up the site and—if you consent—personalise advertising, we use the cookies listed below.

Cookie nameCategoryProvider / DomainExpiryDescription
_clckAnalytics.sabatka.net1 yearMicrosoft Clarity user identifier.
_clskAnalytics.sabatka.net1 dayConnects multiple Microsoft Clarity sessions.
_gaAnalytics.sabatka.net2 yearsGoogle Analytics – distinguishes users.
_ga_QN91ZSCSNSAnalytics.sabatka.net2 yearsGoogle Analytics – sessions/events.
ANONCHKMarketingc.clarity.ms10 minMicrosoft Clarity / Bing campaign measurement.
cc_cookieNecessarywww.sabatka.net6 monthsStores the user’s choice in the cookie banner.
CLIDAnalyticswww.clarity.ms1 yearClarity identifier from previous visits.
languageFunctionalwww.sabatka.net1 yearRemembers selected site language.
MRMarketing.bing.com7 daysMicrosoft remarketing token.
MUIDMarketing.clarity.ms / .bing.com1 yearUnique ID for Microsoft Ads / Clarity.
SMAnalyticsc.clarity.msSessionMaintains Microsoft Clarity session state.
SRM_BMarketing.bing.com1 yearBing – manages user ID for ads.

4 | Processors & Data Transfers

ProcessorRegistered officePurposeLegal basis
Cloudflare, Inc.UK branch Riverside Building, 6th Floor, County Hall/The, Belvedere Rd, London SE1 7PB, United KingdomCDN & site securityLegitimate interest (speed & protection)
Google Ireland Ltd.Gordon House, Barrow Street, Dublin 4, IrelandGoogle Analytics + Google AdsConsent (analytics / marketing cookies)
Microsoft CorporationOne Microsoft Way, Redmond, WA 98052, USAMicrosoft Clarity + Bing AdsConsent (analytics / marketing cookies) — SCCs
Webglobe, s.r.o.Pobřežní 620/3, 186 00 Prague 8, Czech RepublicWeb hosting & WordPress databaseLegitimate interest / data‑processing agreement

For transfers outside the EU/EEA, Standard Contractual Clauses (SCCs) or other valid mechanisms are used.

5 | Google Analytics (GA4)

Purpose: Improving the website and marketing campaigns. GA4 records key events (page views, add‑to‑cart, etc.) and integrates with Google Ads to build remarketing audiences and measure conversions.

Legal basis: Your consent to analytics or marketing processing.

Data processed:

  • traffic source (referrer, URL),
  • pages viewed & events,
  • product and order information (ID, value, contents),
  • internal user ID,
  • HTTP identifiers (anonymised IP, cookies, screen resolution, device, browser, country, language).

Retention period: 14 months.

Processor: Google Ireland Limited (Reg. No. 368047).

Terms: https://policies.google.com/technologies/ads

6 | Microsoft Clarity

The Microsoft Clarity service helps us understand user behaviour (clicking, scrolling, form usage) and adapt the website to your needs.

  • It is activated only after you have consented to analytics cookies.
  • Clarity records clicks, movement, anonymised IP, screen resolution, device, browser, country and language. Data are stored in a pseudonymised profile and cannot be used to identify individual persons.

Processor: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA
Microsoft adheres to the Privacy Shield framework and SCCs.

7 | Your Rights

You have the right to request at any time:

  1. access to personal data,
  2. rectification of inaccuracies,
  3. erasure (“right to be forgotten”),
  4. restriction of processing,
  5. data portability,
  6. objection to processing based on legitimate interest,
  7. withdrawal of consent (analytics / marketing).

8 | How to Exercise Your Rights

Send an e‑mail via the Contact page with the subject “GDPR request”. We respond within 30 days and may ask you to verify your identity.

9 | Data Security

We use technical and organisational measures (encryption, firewall, access permissions) to prevent the loss, misuse or unauthorised access to your data.

10 | Changes to This Notice

We may update these terms when legislation or our services change. The new version will always be published on this page with its effective date.