GDPR & Data Protection

Last updated: 14.04.2026

1. Data Controller

Rokofsky Events s.r.o. acts as the data controller for personal data collected through this website. Registered address: Simackova 24, Prague, CZ. Data protection contact: info@rokofsky.com

2. Scope

This policy applies to all individuals whose personal data we process, including clients, prospects, and website visitors within the European Union (EU), European Economic Area (EEA), and internationally.

3. Lawful Basis for Processing

Under the General Data Protection Regulation (EU 2016/679), we process personal data on the following legal bases:

  • Consent — When you voluntarily submit information via our contact or registration forms.
  • Contractual necessity — To deliver services you have engaged us to provide.
  • Legitimate interest — To improve our services and communicate relevant updates, where this does not override your fundamental rights.

4. Data Subject Rights

Under GDPR, you have the right to:

  • Access — Request a copy of the personal data we hold about you.
  • Rectification — Request correction of inaccurate data.
  • Erasure — Request deletion of your data (“right to be forgotten”).
  • Restriction — Request limitation of processing in certain circumstances.
  • Portability — Receive your data in a structured, machine-readable format.
  • Objection — Object to processing based on legitimate interests or direct marketing.

5. International Data Transfers

Where data is transferred outside the EU/EEA (e.g., to service providers in the United States), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.

6. Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These include encryption, access controls, and regular security assessments.

7. Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay.

8. Third-Party Processors

We use the following categories of third-party processors:

  • Website hosting and infrastructure
  • Email delivery services
  • Video conferencing platforms
  • Analytics tools

9. Supervisory Authority

If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local supervisory authority. A list of EU data protection authorities can be found at <a href="https://edpb.europa.eu" target="_blank" rel="noopener">edpb.europa.eu</a>.