Privacy Policy
Discretion is a fundamental principle of legal practice. We therefore process personal data transparently, only to the extent necessary, and with full respect for professional secrecy, the rights of our clients and the rights of other persons whose data may be involved in legal matters.
Who is the controller of your personal data?
The controller of personal data is SMARTIS LEGAL s.r.o., law firm, which determines the purposes and means of processing personal data in connection with the operation of this website, communications with prospective clients and the provision of legal services.
Krakovská 1392/7
110 00 Prague 1
Czech Republic
+420 720 724 720
+420 737 942 561
Data boxes: c97hgi8, gzwhtsz
What personal data we may process
The scope of personal data depends on the nature of the contact and the legal service concerned. It may typically include:
- identification data – first name, surname, title, date of birth, identification data of entrepreneurs or persons acting on behalf of legal entities,
- contact data – e-mail address, telephone number, postal address, data box,
- data relating to the client relationship and legal matter – instructions, communications, contracts, pleadings, supporting documents, evidence and information about transactions and business relationships,
- billing and payment data – data required for invoicing legal services and maintaining accounting records,
- AML/KYC data – identity documents, information about beneficial owners, source of funds and other information that lawyers are required or permitted to collect under anti-money laundering legislation,
- data from public registers and records – for example publicly available information from the Commercial Register, Register of Beneficial Owners, Insolvency Register or Land Registry where relevant to the matter,
- special categories of personal data and data relating to criminal matters where necessary for the provision of legal services, the establishment, exercise or defence of legal claims or where processing is otherwise permitted by law.
We do not request personal data that is not needed for a specific purpose. Where a client or another person provides documents containing personal data of third parties, we process that data only to the extent required for the relevant legal matter and subject to professional secrecy.
Why we process personal data and on what legal basis
Initial contact and assessment of an enquiry
Communication with a prospective client, preliminary assessment of the matter, conflict and engagement checks and, where appropriate, preparation of a contractual relationship. Article 6(1)(b) GDPR · steps prior to entering into a contract
Provision of legal services
Representation, legal analyses, negotiations, transactional work, litigation and other court or out-of-court activities agreed with the client. Article 6(1)(b) GDPR · performance of a contract
Compliance with legal and professional obligations
Lawyers‘ professional obligations, accounting and tax compliance, AML/KYC, duties toward courts, administrative authorities and the professional bar where applicable. Article 6(1)(c) GDPR · legal obligation
Protection of rights and legal claims
Keeping records of communications, dispute prevention, protection of the rights of the firm and its clients, debt recovery, defence against claims and documentation of professional liability. Article 6(1)(f) GDPR · legitimate interests
Special categories of personal data
Where such data forms part of a legal matter, we process it only to the extent necessary, in particular for the establishment, exercise or defence of legal claims or on another lawful basis. in particular Article 9(2)(f) GDPR
Voluntary consent
We rely on consent only where no more appropriate legal basis is available. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal. Article 6(1)(a) GDPR · consent
Where we obtain personal data
We most often receive personal data directly from you – by e-mail, telephone, in person or from documents you provide. In legal practice, however, it may also be necessary to obtain information:
- from a client or the client’s representatives concerning other persons involved in a legal matter,
- from counterparties, courts, administrative authorities, the police, experts, notaries and other participants in proceedings,
- from publicly accessible registers, records, databases and other public sources,
- from contractual partners or professional advisers where necessary and lawful for the matter concerned.
Where personal data has not been obtained directly from the data subject, we provide the information required by Article 14 GDPR to the extent applicable. The law provides for certain exceptions, for example where providing the information is impossible, would involve disproportionate effort or would conflict with a duty of confidentiality imposed by law.
Who may have access to personal data
We do not disclose personal data to third parties without a legitimate reason. Access is limited to persons and entities that need it for a specific purpose and that are bound by statutory, professional or contractual confidentiality obligations.
- lawyers, cooperating legal professionals and authorised members of the SMARTIS LEGAL team,
- providers of IT, hosting, e-mail, cloud, security and archiving services,
- accountants, tax advisers, auditors or professional indemnity insurers to the necessary extent,
- courts, administrative authorities, law enforcement bodies, the Czech Bar Association and other competent authorities,
- notaries, experts, translators, foreign or specialist law firms and other professionals involved in a specific legal matter,
- counterparties and their representatives where disclosure is a necessary part of representation or legal dealings.
Where an external supplier acts as our processor, its activities are governed by an agreement compliant with Article 28 GDPR and the supplier may process personal data only on our documented instructions.
Transfers outside the European Economic Area
In the ordinary course of providing legal services, we seek to keep personal data processing within the European Union or European Economic Area. International matters or certain technology services may, however, require a transfer to a third country.
Such transfers are made only in accordance with the GDPR, typically on the basis of an adequacy decision of the European Commission, Standard Contractual Clauses, other appropriate safeguards under Article 46 GDPR, or one of the derogations provided for in Article 49 GDPR.
How long we retain personal data
We do not retain personal data for longer than necessary. The specific retention period depends on the purpose of processing, professional rules, statutory record-keeping duties and any need to establish, exercise or defend legal claims.
- AML/KYC documentation: where Czech Act No. 253/2008 Coll. applies to the relevant legal service, the related identification and due diligence records are generally retained for 10 years from the transaction or termination of the business relationship.
- Accounting and tax documents: for the statutory retention periods under applicable Czech accounting and tax legislation, typically between 5 and 10 years depending on the type of document.
- Enquiries that do not lead to an engagement: for as long as necessary to handle the communication, assess whether the matter can be accepted and protect any potential legal claims.
- Security and technical logs: only for as long as necessary to secure the website, diagnose faults and investigate security incidents.
Where a dispute, audit, investigation or other legal reason is ongoing, relevant data may be retained for a longer period, but no longer than is justified by that specific purpose.
Website, technical data, cookies and language preference
When you visit the website, basic technical data may be processed where necessary to deliver the website, maintain security and perform diagnostics – for example your IP address, request time, browser type or server logs.
Website language
The website may locally read the preferred language of your browser and use that information to offer or select the Czech, English or German version. A manually selected language preference may be stored in your browser’s local storage so that your choice is retained for a future visit. This technical storage is used solely for the operation of the language switcher.
Cookies and similar technologies
Technical cookies or similar technical storage that is necessary for the proper operation of the website or for a service explicitly requested by the user may be used without consent to the extent permitted by Section 89(3) of Czech Act No. 127/2005 Coll. Where the website uses analytics, marketing or other non-essential technologies, they are activated only after valid user consent has been obtained.
A more detailed list of technologies actually in use, their purposes and duration should be published in a separate Cookie Policy.
Your rights
Depending on the particular processing, the GDPR gives you the following rights. You may send your request to office@smartislegal.cz. We respond without undue delay, normally within one month. In complex cases, the period may be extended subject to the conditions laid down by the GDPR.
Your rights are not absolute
Certain rights may be limited in a specific case, in particular where continued storage or processing is necessary to comply with a legal obligation, establish, exercise or defend legal claims, protect the rights of another person or where providing certain information would conflict with a lawyer’s professional secrecy obligations.
The supervisory authority in the Czech Republic is the Office for Personal Data Protection.
Security, confidentiality and professional secrecy
We apply appropriate technical and organisational measures proportionate to the nature and risks of the processing. These include access controls, security of working devices and communications, backups, supplier management, internal rules for handling legal files and procedures for responding to security incidents.
In addition to general data protection requirements, lawyers and persons involved in the provision of legal services are subject to statutory professional secrecy. Information obtained in connection with the practice of law is therefore treated as professionally confidential unless the client lawfully releases the lawyer from confidentiality or applicable law provides otherwise.
Automated decision-making and modern technologies
We do not make decisions concerning clients that produce legal or similarly significant effects and are based solely on automated processing within the meaning of Article 22 GDPR.
Where modern technological tools are used for legal analysis, document management or administration, the lawyer remains responsible for the legal service. We assess the suitability of such tools also from the perspective of confidentiality, data protection and professional secrecy.
Legal framework, changes to this policy and contact
This Privacy Policy is based in particular on Regulation (EU) 2016/679 (GDPR), Czech Act No. 110/2019 Coll. on the Processing of Personal Data, the legislation governing the practice of law and – depending on the nature of the relevant activity – for example Czech Act No. 253/2008 Coll. (AML), Act No. 127/2005 Coll. on Electronic Communications and Act No. 480/2004 Coll. on Certain Information Society Services.
We may update this Privacy Policy where appropriate, in particular following changes in legislation, our services, technologies used or the manner in which personal data is processed. The current version will always be published on the website and will state the date of the latest update.
Would you like an explanation of how your data is processed?
Contact us at office@smartislegal.cz. You may also submit your request by post to our office or through an electronic data box.