
Privacy Policy
Last Updated: October 5, 2026
This Privacy Policy describes how NejedNiko.cz (the "Site", "we", "us") collects, uses, stores, and protects your personal data in accordance with the EU General Data Protection Regulation (GDPR) (EU) 2016/679 and applicable Czech law (Act No. 110/2019 Coll.).
1. Data Controller
The data controller for this website is Nikola Nejedlý, the sole operator of NejedNiko.cz. Contact: use the official contact form.
2. What Data We Collect and Why
2.1 Analytics & Security Data
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) - to understand how the site is used, detect and block malicious automated traffic, and maintain site security.
- IP address - collected at each visit; used for geolocation (country only), bot detection, and security threat analysis. Stored as a hashed or raw value in the security cache for bot classification purposes. IP-to-user links are stored for registered users to support account security.
- User-Agent string - browser, OS, and device type, used for compatibility analysis and bot detection.
- Visited pages, timestamps, and referrers - to understand popular content and traffic sources. Detailed pageviews are deleted after 90 days; daily visitor summaries are kept indefinitely in anonymized aggregate form.
- Error and security logs - unauthorized access attempts, SQL injection probes, and scanner activity. Deleted after 90 days.
- External link clicks - anonymized record of external links clicked, to understand content engagement.
Admin users' own browsing is excluded from all analytics tracking.
2.2 Account Data
Legal basis: Contract performance (Art. 6(1)(b) GDPR) - necessary to provide registered user features.
- Username, email address, password (stored as a secure one-way hash)
- Email verification status and short-lived verification or password-reset tokens used to secure account access
- Account creation date, last login time
- Google OAuth identifier (if you use Google sign-in)
- Your external application pairing permission and the applications you explicitly pair
- Content you create: blog comments, likes, dislikes, favourites, and uploaded files
Content reactions store the item, reaction type, date, and IP address, plus your user ID when signed in. Guest reactions use the IP address to recognize repeat votes. Reaction identities are visible only to administrators; your account dashboard lists your own liked content. Removing a reaction deletes its vote record.
2.3 Messages
Legal basis: Contract performance (Art. 6(1)(b) GDPR) / Consent (Art. 6(1)(a) GDPR) for contact form messages from non-registered users.
- Message text, subject, and any file attachments you upload
- Sender and recipient identifiers, read status, timestamps
- For contact form messages: email address and optional consent to be contacted back
2.4 Cookies & Local Storage
The site uses necessary session and security cookies, short functional cookies, and localStorage for interface preferences. The GDPR legal basis is contract performance where storage provides a requested account feature and legitimate interest where it protects the service or prevents abuse. These GDPR bases do not replace any separate consent required for nonessential access to browser storage. No advertising or cross-site tracking cookies are set.
See the Cookie Policy for full details.
2.5 Download Tracking
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) - abuse prevention. IP addresses are logged per ordinary file download and deleted after 30 days. Built-in software update downloads also log the application identifier, success or failure, timestamp, IP address, release version when known, and the website username presented by licensed software. These update records are kept in the security audit log for up to 180 days so failed and successful update delivery can be investigated.
2.6 External Application Pairing
Legal basis: Consent (Art. 6(1)(a) GDPR) and contract performance (Art. 6(1)(b) GDPR) - to provide account linking and synchronization requested by you.
- External pairing is disabled by default and cannot succeed until you explicitly enable External permissions in your account settings.
- Pairing records contain your account identifier, the external client identifier, granted scopes, hashed access and refresh tokens, issue/expiry times, and last-use time.
- The external application receives only the account data and synchronized feature data covered by the approved scopes. Access tokens are shown only to the approved application and are stored by us as hashes.
- You may withdraw permission at any time. Disabling the setting immediately revokes all active external pairings and prevents token refresh or further authenticated access.
2.7 Drive Economics and Calendar
Legal basis: Contract performance (Art. 6(1)(b) GDPR) for the features you request and legitimate interest (Art. 6(1)(f) GDPR) in maintaining accurate shared records and preventing misuse. Optional payment-day emails are sent only when you enable both the account-wide drive email setting and the reminder for that drive. You can turn either setting off.
- For vehicles: owner account, photo, name, type, colour, inspection date, VIN, licence plate, fuel and maintenance entries, and optional payment account number, bank code, account holder name, and BIC/SWIFT.
- For drives: owner and driver accounts, name, description, type, route name and map coordinates, distance, invitation status, accepted passengers, ride dates and counts, payment day, and each user's reminder choice.
- The site calculates cost estimates and per-person shares from these records. The QR code is generated in your browser from the calculated amount and vehicle payment details; we do not process the bank transfer.
- Payment reminders use your verified email address, drive name, payment period, and calculated share when available. We record the drive, recipient, payment date, and delivery state to avoid duplicate reminders.
- Calendar tasks and event reminders contain the dates, descriptions, linked items, and notification preferences you choose to save.
Drive owners may provide a passenger's username when inviting them. An invitation is not membership: the invited user must accept. Owners, drivers, and accepted participants can view shared drive details, other participants' ride calendars and cost estimates, and a read-only vehicle overview with its photo, type, colour, inspection date, fuel and maintenance cost records. The participant preview does not show VIN or licence plate. Vehicle payment details become available to those users through the payment popup. Do not enter private information about another person unless you are entitled to share it.
3. Automated Decision-Making & Bot Classification
This site uses an automated security system (NNShield) that classifies IP addresses as human or automated based on request patterns. This classification may result in access being automatically blocked for IPs identified as bots or malicious scanners. This does not constitute automated decision-making with legal or significant effects on natural persons (Art. 22 GDPR) as it applies to automated software clients, not to individuals personally.
You can view public aggregate statistics at NNShield.
4. Data Sharing and Third Parties
- We do not sell personal data to any third party.
- We do not use third-party advertising networks or tracking pixels.
- We use ip-api.com and ipapi.co for IP geolocation lookups (country-level only). Your IP address is sent to these services as part of the lookup. Both services process IPs under their own privacy policies.
- We may disclose data to comply with a legal obligation (Art. 6(1)(c) GDPR), protect vital interests, or respond to verified law enforcement requests.
- Messages are shared only with their intended recipients.
- When you explicitly pair an external application such as Obeyra, account and synchronized feature data is disclosed to that application only under the access you approved. The external application's own storage and processing practices apply after it receives that data.
- Drive data is shared with the owner, driver, and accepted participants as described in Section 2.7. Payment-day emails are delivered through our configured email service.
- When you open a drive route map, your browser requests map tiles from OpenStreetMap and Leaflet assets from jsDelivr. When an editor asks for a route between two points, the selected coordinates are sent to the public OSRM routing service. These providers receive standard connection data, including your IP address.
5. International Transfers
Geolocation lookups and externally loaded services, including maps, routing, fonts, and email delivery, may involve providers outside the EEA. Their locations and transfer arrangements depend on the provider. The legal basis for using a feature does not by itself authorize an international transfer; where Chapter V GDPR applies, an adequacy decision, appropriate safeguards, or a permitted derogation is also required. Contact us for information about a particular provider or transfer.
6. Data Retention
| Data type | Retention period |
|---|---|
| Account data | Until account deletion is requested |
| User-created content (posts, likes, favourites) | Indefinitely unless removed by user or admin |
| Messages | Until deleted by the sender or recipient |
| Vehicle, drive, calendar, and payment account records | While needed for the requested feature. There is no fixed automatic purge schedule for drive records; removing a drive from the interface marks it as deleted but may not immediately remove underlying records. You can request erasure, subject to applicable legal requirements and backup cycles. |
| Drive invitation and payment reminder records | While needed to manage invitations, reminder preferences, and duplicate-send prevention. No fixed automatic purge schedule is currently configured; you can request erasure through the contact form, subject to applicable legal requirements and backup cycles. |
| Detailed analytics pageviews | 90 days (automatic deletion) |
| Security / error logs | 90 days (automatic deletion) |
| Daily visitor summaries | Indefinitely (anonymized aggregates only) |
| IP bot classification cache | Retained for security classification; an IP address may be personal data. Contact us to ask about a specific record or request erasure where applicable. |
| IP-to-user security mappings | Until account deletion |
| Download access logs | 30 days (automatic deletion) |
| Event / security audit logs | 180 days |
| External pairing authorization codes | 5 minutes; single use |
| External app pairing tokens and metadata | Until expiry, revocation, permission withdrawal, or account deletion |
7. Your Rights Under GDPR
As a data subject under GDPR, you have the following rights:
- Right of access (Art. 15) - obtain a copy of your personal data
- Right to rectification (Art. 16) - correct inaccurate data
- Right to erasure (Art. 17) - request deletion of your data ("right to be forgotten")
- Right to restriction of processing (Art. 18) - limit how your data is used
- Right to data portability (Art. 20) - receive your data in a structured, machine-readable format
- Right to object (Art. 21) - object to processing based on legitimate interests (including analytics and security profiling)
- Right to withdraw consent (Art. 7(3)) - withdraw consent at any time without affecting prior processing
- Right not to be subject to solely automated decisions (Art. 22) - see Section 3 above
To exercise any of these rights, contact us. We will respond within 30 days as required by Art. 12 GDPR. In complex cases, this may be extended by a further 60 days with notice.
If you believe your rights have been violated, you have the right to lodge a complaint with the supervisory authority:
Office for Personal Data Protection (UOOU)
Pplk. Sochora 27, 170 00 Prague 7, Czech Republic
www.uoou.cz
8. Security
We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, or misuse, including:
- Password hashing (one-way, not reversible)
- HTTPS encryption for all connections
- Automated bot and attack detection (NNShield)
- Session-based authentication with secure cookie flags
- CSRF protection on all forms
- Prepared SQL statements and input validation throughout
- PKCE-protected external app authorization, short-lived authorization codes, hashed tokens, and immediate revocation when external permission is withdrawn
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours and affected individuals without undue delay, as required by Art. 33-34 GDPR.
9. Children's Privacy
This site is not directed at children under the age of 16. We do not knowingly collect personal data from minors. If you believe a minor's data has been submitted, please contact us for immediate deletion.
10. Policy Updates
We may update this policy. The "Last Updated" date at the top reflects the most recent change. Material changes will be communicated via the site notification system where possible. Continued use of the site after changes constitutes acceptance of the updated policy.
11. Contact
Use the official contact form for any privacy-related questions or requests.
Thank you for using NejedNiko.cz!
