HouseID legal centre · C
PRIVACY NOTICE
What personal data HouseID uses, why, for how long and how you may exercise your rights.
HouseID is controller for processing described here unless expressly acting as the Client's processor. Contact: info@houseid.cz. HouseID does not currently identify a data protection officer; if appointment becomes mandatory, contact details will be added before the relevant processing begins.
We obtain data directly from you, your employer or organisation, authorised invitations, meetings and forms, public registers and websites, commercial agents, system and security logs, and authorised integration partners. For public sources we record source and date where appropriate.
Categories include identity and contact data, work role and permissions, company and billing data, communications and meeting notes, sales case, project and implementation status, support, training and certification, device/IP/browser, authentication and audit events, consent preferences and data contained in documents. Special-category data are not requested and must not be uploaded without prior written approval and an appropriate legal basis.
Purposes and bases: enquiries and calculations—pre-contract steps and legitimate interests; B2B contracting and delivery—contract and legitimate interests for contact persons; billing and accounts—legal obligation; security, abuse prevention, audit and claims—legitimate interests and legal obligation; account operation, support and training—contract/legitimate interests; non-essential cookies—consent; marketing—consent or the statutory existing-customer regime with simple opt-out; AI assistance—service delivery and legitimate interests with human oversight.
Public website enquiries are deleted no later than 12 months after the last relevant interaction unless a contract begins or law requires a longer record. Contract and accounting records follow statutory periods. Client content processed on the Client’s behalf follows the Order, DPA and documented Client instructions. Security and audit records have a documented, purpose-limited operational period. A legal hold suspends deletion only as necessary.
Recipients may include authorised HouseID personnel, cloud, email, identity, security, support and analytics suppliers, professional advisers and Client-ordered integrations including BEIT. Access is role- and need-based. Current subprocessors appear in Part H; a missing exact legal entity blocks that supplier's production processing.
HouseID prefers EU storage for Client documents and primary databases where technically configured. Global networking, support, security telemetry or a supplier may involve access or transfer outside the EEA. Transfers require an adequacy decision, the EU-US Data Privacy Framework for an eligible recipient, standard contractual clauses and risk-based supplementary safeguards. An 'EU storage' label alone does not prove every flow remains in the EU.
You may request access, correction, erasure, restriction, portability where applicable, object to legitimate-interest processing and always to direct marketing, withdraw consent without retrospective effect, and complain to the Czech Data Protection Authority, Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz. Send requests to info@houseid.cz; identity and authority are proportionately verified.
HouseID does not use solely automated decisions producing legal or similarly significant effects on a person without a specific legal basis, transparent information and required safeguards. Readiness, potential, training and sales-process scores are support indicators and must not be the sole basis for employment or contracting decisions.
HouseID applies risk-appropriate technical and organisational measures, but no system can be declared absolutely secure. A confirmed personal-data breach is documented, contained and notified to authorities and persons where GDPR requires. For data processed for a Client, HouseID informs the Client without undue delay under the DPA.
Services are not directed to children and HouseID does not knowingly collect their data as portal users. The Client must not upload child or vulnerable-person data without prior written agreement. If found without legal basis, access is restricted and secure deletion or remediation is arranged.
This notice may be updated for processing or legal changes. The page always states the effective date and retains prior versions. A material purpose, recipient or legal-basis change is notified to active users before effectiveness; where new consent is required, processing does not begin before consent.