1. Data Controller
The data controller for personal data collected through the Prague Spa Penthouse website and booking process is:
JM2RE s.r.o.
IČO: 06034799
Revoluční 655/1, 110 00 Praha 1, Czech Republic
2. What Data We Collect
We may collect and process the following categories of personal data:
- —Identity data: first name, last name, date of birth, nationality
- —Contact data: email address, phone number
- —Booking data: check-in / check-out dates, number of guests, special requests
- —Payment data: processed securely via our booking platforms (Lodgify, Airbnb, Booking.com, VRBO). We do not store full payment card details.
- —Technical data: IP address, browser type, pages visited (via Google Analytics / Google Ads)
- —Communication data: emails and messages you send us
3. Purpose and Legal Basis
Booking fulfilment
Legal basis: Performance of a contract (Art. 6(1)(b) GDPR). We need your data to process and manage your reservation.
Legal obligations
Legal basis: Legal obligation (Art. 6(1)(c) GDPR). Czech law requires us to register foreign guests with the relevant authorities.
Marketing and analytics
Legal basis: Legitimate interest / consent (Art. 6(1)(a) and (f) GDPR). We use Google Analytics and Google Ads to understand website usage and measure advertising effectiveness.
Guest communication
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR). We may contact you before, during, or after your stay to provide information or follow-up support.
4. Data Retention
We retain your personal data only as long as necessary:
- —Booking records: 10 years (Czech accounting and tax law requirements)
- —Guest registration data: 6 years (Czech Foreigners Act requirements)
- —Marketing communications: until you withdraw consent or object
- —Website analytics: aggregated data per Google's retention policy (up to 26 months)
5. Data Sharing
We do not sell your personal data. We may share it with:
- —Booking platforms (Lodgify, Airbnb, Booking.com, VRBO) as part of the reservation process
- —Czech authorities as required by law (e.g. foreign police registration)
- —Google LLC (analytics and advertising services)
- —Accounting and legal advisors under confidentiality obligations
6. Your Rights
Under the GDPR, you have the following rights:
- —Right of access — request a copy of the data we hold about you
- —Right to rectification — ask us to correct inaccurate data
- —Right to erasure — request deletion where there is no lawful reason to retain it
- —Right to restrict processing — ask us to pause processing in certain circumstances
- —Right to data portability — receive your data in a structured, machine-readable format
- —Right to object — object to processing based on legitimate interests
- —Right to withdraw consent — at any time where processing is based on consent
To exercise any right, contact us at jm2re.praha@gmail.com.
7. Cookies & Tracking
This website uses Google Analytics and Google Ads (gtag.js) to collect anonymised data about website usage. These services may set cookies on your device. By using this website, you acknowledge this use. You can disable cookies in your browser settings at any time.