Privacy Policy
CURRENT VERSION
Document version: 0.5
Effective date: 29 August 2026
1. Who processes your personal data
The data controller is:
Kathelyn Nasayao Marquez-Chovanec
Company ID No.: 19875762
registered office: Matoušova 1286/5, Smíchov, 150 00 Prague 5, Czech Republic
Essence Thai Spa Massage premises: Preslova 1286/13, Prague 5 – Smíchov, Czech Republic
email: info@essencethaispamassage.cz
telephone: +420 774 481 411
hereinafter the “Controller” or “Essence Thai Spa Massage”.
You may also use info@essencethaispamassage.cz for requests and questions concerning personal data protection.
2. Scope of this Policy
This Policy explains how we process personal data relating to website visitors, prospective and existing customers, gift-voucher purchasers and people who communicate with us. It is an information document; general consent to it is not required to visit the website.
3. Personal data we may process
Depending on how you use our services, we may process in particular:
- identification data, especially your name;
- contact details, especially your email address and telephone number;
- booking data, especially the selected service, date, time, duration, price, booking status and related communications;
- for hotel bookings, the hotel name or address and room number;
- payment and voucher data, such as payment status, amount, currency, transaction identifier or voucher code; we do not directly process full payment-card details;
- information contained in an enquiry, complaint or other communication;
- technical and operational data, such as IP address, device and browser type, website-use information, cookie identifiers and records of consent or refusal;
- traffic-source and conversion data, including transaction ID, booking value and currency, where the visitor permits the relevant analytics or marketing technologies.
We do not systematically record or retain customers’ health data. If a customer orally tells a therapist before a massage about information needed for safe service delivery, such as pregnancy, an allergy or a contraindication, we do not normally record it in the booking system, customer profile, email or other records.
We do not request health data through the website or booking system, and customers should not enter it in contact fields or messages. If a customer sends us health information in writing on their own initiative, we restrict access and delete it without undue delay once its nature is identified, unless short-term retention is necessary to comply with a legal obligation or to establish, exercise or defend a legal claim.
4. Bookings and the in-house booking system
To create and manage a booking, we process mainly the customer’s name, email address, telephone number, selected service, appointment and price. A hotel booking may also require the hotel name or address and room number.
The purposes are to create and automatically confirm the booking, email appointment confirmation, provide the service, permit rescheduling, process changes or cancellation and handle related requests. The legal basis is taking steps before entering into a contract and performing the contract. Where necessary, we may also retain data to comply with legal obligations and protect legal claims.
Bookings are processed by Essence Thai Spa Massage’s in-house booking system hosted on FORPSI infrastructure. A successfully completed booking does not require manual approval: it is confirmed automatically and an automatic confirmation email is sent. Using a secure link, the customer may once change the date, time and contact details or cancel the booking; the massage type and duration cannot be changed this way. Changes or cancellations may also be requested by telephone, email or WhatsApp at +420 774 481 411.
We normally retain booking data for 3 years after the service, cancellation or missed appointment date. We then erase or anonymise it unless longer retention is required by law, an ongoing dispute or the protection of a specific legal claim.
5. Payments and Stripe
A customer may pay online when booking or later at the salon. Online payments are technically processed by Stripe. Stripe receives the information required to process the payment and prevent fraud; full payment-card details are not routinely made available to the salon.
The purposes are to receive and record payments, issue refunds, deal with complaints, keep accounts and protect legal claims. The legal bases are performance of a contract, compliance with legal obligations and, where necessary, the legitimate interest in protecting rights.
Accounting documents and related records are normally retained for 5 years from the end of the relevant accounting period. Tax documents subject to a longer statutory period, in particular applicable VAT documents, are retained for 10 years. A different mandatory period applicable to a particular document takes precedence.
6. Email, telephone, WhatsApp and SMS communications
We process contact details and communication content to confirm and remind customers of bookings, handle changes and cancellations, answer enquiries and complaints and deal with other operational matters. Depending on the situation, the legal basis is pre-contractual steps, contract performance, legal obligation or the legitimate interest in handling communications and protecting rights.
SMS sending is not currently active. If introduced later, it will be used only for booking-related communications, particularly confirmations, reminders and operational information, and not for marketing.
Email services, transactional booking emails and hosting for the new website are provided through FORPSI services.
Ordinary customer communications are normally retained for 1 year after the last communication. Where a communication forms part of a contract, complaint, cancellation or dispute, the relevant part may be retained for 3 years or for the duration of the specific proceedings. WhatsApp and email messages are reviewed regularly, and unnecessary personal data are deleted under the same rule.
7. Web hosting and FORPSI
Website and booking-system hosting, server infrastructure, business email and related technical services are provided under the FORPSI brand by INTERNET CZ, a.s., Company ID No. 26043319, Ktiš 2, 384 03 Ktiš, Czech Republic. To the extent that it stores or technically accesses personal data on our instructions, it acts as a processor. It may also act as an independent controller for its own contract administration, service security and legal obligations.
FORPSI is part of the Aruba group and may use group companies and contracted suppliers to the extent described in its current contractual documents and privacy policy. We control the application data on the virtual server, its deletion and the backups we create; FORPSI manages its own technical operational data under its terms.
8. Google Analytics 4 and Google Ads
Where the visitor gives the relevant consent, we use:
- Google Analytics 4, Measurement ID G-9CDK7XJLF1, to measure website traffic and use;
- Google Ads conversion tracking, ID AW-10782951242, to measure advertising effectiveness and completed bookings.
Conversion measurement may process technical identifiers, traffic-source, device and interaction information, and booking data limited to transaction ID, value and currency. Names, email addresses, telephone numbers and health data must not be sent to analytics or advertising systems.
The purposes are traffic measurement, advertising evaluation and marketing optimisation. Consent is the legal basis for storing or reading optional cookies and the related processing. We use Google Consent Mode v2 with analytics and advertising signals denied by default. The external Google tag is loaded only after the corresponding analytics or marketing consent is granted. Without consent, the relevant service is not started and no measurement request for that service is sent to Google.
GA4 records website use and the server-confirmed completion of a booking or paid voucher order. Google Ads records a server-confirmed completed booking. Data sent are limited to a pseudonymous transaction identifier, value, currency and necessary technical information. We do not use enhanced conversions and do not send Google a name, email address, telephone number, voucher code or booking token in this measurement. GA4 is configured to retain event data for 2 months and user data for 14 months.
RECOMMENDED FOR LEGAL REVIEW: allocation of roles between the Controller and Google and the legal mechanism and safeguards for any transfers outside the EU/EEA.
9. Cookies and consent management
The website may use technologies that are necessary for security and basic website and booking functions; preference technologies if introduced; analytics technologies, especially Google Analytics; and marketing technologies, especially Google Ads.
Analytics and marketing technologies start only after consent. Essence’s first-party cookie interface allows visitors to accept or reject optional categories and later change the choice just as easily through “Cookie settings” in the footer. Withdrawal does not affect the lawfulness of earlier processing.
The choice is stored in the visitor’s browser under essence_cookie_consent in localStorage for 180 days. A new choice is then requested. Essential local and session storage is also used to complete, restore and protect a booking or payment securely; it is not used for advertising profiling.
After analytics consent, GA4 may use in particular _ga and _ga_<ID> cookies, normally for up to 2 years. After marketing consent, Google Ads may use in particular _gcl_au, _gcl_aw or similar identifiers, normally for no more than 90 days. The precise name, availability and lifetime may vary with the browser, service configuration and Google’s current rules.
10. Web fonts
The web fonts used by the website are hosted locally on the same infrastructure as the website. Loading them therefore does not cause the visitor’s browser to connect to Google Fonts or another external font provider.
11. Gift vouchers, packages and Loyalty
When a voucher, package or Loyalty product is purchased or redeemed, we process the data required for ordering, payment, issuing and verifying the booking or voucher code and providing the service. The legal bases are pre-contractual steps and contract performance; legal obligation for accounting documents; and legitimate interest for protecting claims.
A gift voucher is issued for a specific service and may be delivered electronically or issued physically in the salon. It is redeemed using a voucher code. Loyalty is a prepaid package for a specified number of massages and uses a unique booking/Loyalty code emailed to the customer for successive bookings and redemption. These codes confer entitlement and should be protected against unauthorised use.
If a customer reports a code as lost, stolen or potentially misused, we may process the data needed to locate the purchase, verify entitlement and, where appropriate, block or replace the code.
For a voucher order, we process the purchaser’s email address and telephone number, selected service and duration, price, language, delivery and payment method, order and payment status, voucher code and any message entered by the purchaser. The voucher form does not normally request the purchaser’s or recipient’s name. Operational voucher data are retained for 3 years after redemption, expiry, cancellation or refund; accounting data may be retained for longer where required by law.
12. Recipients, processors and transfers outside the EU/EEA
Depending on the service, necessary access may be given to Stripe Payments Europe, Limited and other Stripe group entities involved in payment processing and fraud prevention; INTERNET CZ, a.s. (FORPSI) and its approved suppliers; Google where the relevant consent has been given; any future email or SMS providers involved in bookings; accounting, tax or legal advisers where necessary; and public authorities where required by law.
Stripe acts as a processor or independent controller depending on the particular activity. Its European contracting entity uses the transfer mechanisms described in its current Data Processing Agreement for any international transfer, including adequacy decisions and Standard Contractual Clauses. FORPSI may involve Aruba group companies and other suppliers under its current contractual documents. Google Ireland Limited and, where applicable, other Google group companies process analytics and advertising data under the terms of the relevant service; depending on the particular activity they may act as processor or independent controller. Any transfer outside the EU/EEA is governed by the mechanisms and safeguards described in Google’s current contractual terms.
13. Retention periods
We do not retain personal data longer than necessary. We use the following baseline periods. Where law requires longer retention or a dispute is ongoing, only the necessary data are retained for the corresponding longer period:
| Category | Rule / verification status |
|---|---|
| Bookings and evidence of acceptance of Terms | 3 years after the service, cancellation or booked appointment date. |
| Vouchers, packages and Loyalty | 3 years after redemption, expiry, cancellation or refund. |
| Ordinary customer communications | 1 year after the last communication; 3 years where it forms part of a contract, cancellation or claim. |
| Accounting and payment documents | Normally 5 years from the end of the accounting period; 10 years for tax documents where the longer statutory period applies. |
| Complaints | 3 years after closure, and longer only during an ongoing dispute or where required by law. |
| Administrative audit records | 3 years after the recorded operation. |
| Security and access logs | No more than 90 days, unless a specific record is required to investigate an incident. |
| Operational email-delivery records | 1 year after sending or the last delivery attempt. |
| Rotating technical backups | No more than 30 days; data are removed through regular backup rotation. |
| Legal claims | For the applicable limitation period, normally no more than 3 years, and longer during an ongoing dispute. |
| GA4 | Event data for 2 months and user data for 14 months under the current service settings. _ga and _ga_<ID> cookies may remain for up to 2 years. |
| Google Ads | The conversion window for a completed booking is 90 days; advertising cookies/identifiers are normally used for no more than 90 days. Google may retain aggregated reporting data for longer under its rules. |
| Cookie consent | The browser choice is retained for 180 days, after which a new choice is requested. |
| Marketing consents | Until consent is withdrawn or the purpose ends; the choice can be changed at any time in Cookie settings. |
14. Your rights
Subject to the GDPR, you have in particular the right to obtain confirmation and access; correct inaccurate or complete incomplete data; request erasure or restriction; object to processing based on legitimate interests; receive portable data where the legal conditions apply; withdraw consent at any time where processing is based on consent; and lodge a complaint with the Czech Office for Personal Data Protection.
Send requests to info@essencethaispamassage.cz. We may reasonably verify your identity before responding.
Czech Office for Personal Data Protection: Pplk. Sochora 27, 170 00 Prague 7, website uoou.gov.cz.
15. Automated decision-making and profiling
We do not make decisions based solely on automated processing that produce legal or similarly significant effects for customers. Subject to analytics consent, Google Analytics creates aggregated statistics. Subject to marketing consent, Google Ads measures completed bookings and may support campaign optimisation or advertising audiences. This processing does not itself decide availability, price or whether a contract is concluded with a customer.
16. Security
We use technical and organisational measures appropriate to the nature of the processing. Access is limited to people and suppliers who need it for the stated purpose. No transmission or storage method can guarantee absolute security.
17. Changes to this Policy
We may update this Policy when services, technologies or legal requirements change. The current version will show its version number and effective date. Material changes will be communicated appropriately.
Sources used
- Regulation (EU) 2016/679 (GDPR), particularly Articles 5, 6, 9, 12–22, 28, 32 and 44–49.
- Czech Office for Personal Data Protection guidance on basic principles, data-subject rights and cookies.
- Confirmed technical and operational information supplied by the operator.
