GDPR

Privacy

rejstr.cz makes company information from public open data easier to find. We keep public personal-data output deliberately narrow: no Czech birth numbers and no profiles of individuals. This page explains who controls the processing, why data is used and how to exercise your rights.

Version: 23 July 2026. The Czech version of this page is authoritative.

Controller

The controller is DORNIS s.r.o., Czech company ID 24061174, registered office V zářezu 902/4, Jinonice, 158 00 Prague 5, registered with the Municipal Court in Prague under file C 437945.

DORNIS s.r.o. operates the service and controls this processing. Product or group attribution to FIRMIN in the footer does not change the identity of the controller.

Privacy contact: gdpr@rejstr.cz.

Purposes and legal bases

We operate a public company registry that lets users search business entities and view data originating in public sources.

The principal legal basis is the legitimate interests of the controller and users in making information already public in government registers accessible, searchable and verifiable (Article 6(1)(f) GDPR).

We process GDPR requests to comply with legal obligations and document their handling. User accounts, the API and optional company-name tools are separate processing activities with their own purposes and legal bases.

Data we process

  • Company data such as company ID, name, registered office, legal form, business activities, court file and other registered particulars.
  • Public-register information about people connected with a company: name, role and period in office.
  • We process dates of birth internally but publish no more than the year. We neither process nor display Czech birth numbers.
  • We do not publicly display the home addresses of individuals.
  • For a GDPR request: contact details, request type, company ID or description of the person, and the request text.
  • For accounts and API access: mainly email address, account state, token hashes, API-key hashes and operational usage records.
  • For anonymous API and MCP access: a short-lived HMAC fingerprint of the client IP for rate limiting. Queries submitted to our tools may be retained for a limited time for history, security, analytics and service improvement.
  • For the AI name generator: selected settings, the assembled prompt and response, generated names, model and token/cost metrics, similarity results, first detail opening, first shortlist action, shared snapshots where requested, and HMAC fingerprints of the session and network. The generator accepts no free-text prompt and stores no raw IP in this record.

Sources

Data comes from public registers and Czech government open data, particularly ARES/VREO, ARES REST, the public register with links to justice.cz, the Czech Statistical Office business register, and other official sources identified for a particular item.

We receive data directly from you only when you submit a GDPR request or use an account, API or optional tool.

Recipients and international transfers

We do not sell personal data. Visitors see public data within company profiles. Only approved hosting, infrastructure, email, backup or support providers may access data where necessary under contracts and our processor register.

When the AI generator is enabled, we send a fixed, system-assembled prompt and the response through OpenAI's standard API. We do not send an email address, raw IP, legal form or user-entered free text. Processing may take place outside the EU/EEA under contractual safeguards including standard contractual clauses. OpenAI does not use API data to train models by default; safety abuse-monitoring data may be retained for up to 30 days.

Retention

Public views are refreshed as source data becomes available. A decision to suppress data following a request is kept permanently or until its stated expiry so that it survives later source refreshes.

Account data is kept while the account exists and for a necessary operational period. Verification tokens are short-lived and stored only as hashes. Operational query records from tools, API and MCP are retained for no more than 365 days. Other logs and backups are kept only as needed for security, recovery and audit.

Anonymous rate-limit buckets have only the short retention of their applicable window. Public API company profiles exclude individuals, birth dates, home addresses and internal matching keys.

Detailed AI-generator records currently have no automatic expiry because they support quality, cost control and future improvement. Rate-limit events are kept for 48 hours and operational alert records for 90 days. We periodically reassess whether continued retention remains necessary.

Your rights

You may request access, rectification, erasure or restriction, object to processing and, where applicable, request data portability. We respond without undue delay and no later than 30 days after receipt unless the GDPR permits an extension.

You may lodge a complaint with the Czech Office for Personal Data Protection: uoou.gov.cz, posta@uoou.gov.cz, data box qkbaa2n.

Objection, erasure or restriction of publication

Send an objection or a request for erasure or restriction to gdpr@rejstr.cz or use the form below. We will also assess a request received through another reasonable channel.

We assess the specific data, public source, person's company role, public interest and whether a less intrusive measure is available. We will notify you of the outcome within 30 days or ask for information needed to verify or locate the record.

AI name generator

The AI generator can be used anonymously. Users select only predefined industries and styles, so they do not submit a custom prompt or other free text. We append the legal form locally and do not send it to OpenAI.

The legal basis is our legitimate interest in providing, securing and improving this optional tool. We limit abuse with pseudonymous HMAC session/network fingerprints, central quotas and short retention of rate-limit events. Detailed records are accessible only in the protected internal area.

Cookies and measurement

The website uses only necessary technical storage to operate and remember your choice. If GTM/GA4 measurement is enabled, Google Tag Manager uses Google Consent Mode v2 and defaults ad_storage, ad_user_data, ad_personalization and analytics_storage to denied.

Google Analytics 4 starts only after you choose Allow all in the cookie banner. We then enable analytics_storage only; advertising storage, personalised advertising and advertising user-data sharing remain disabled. Choosing Necessary only leaves analytics storage disabled.

Your choice is stored in the browser under rejstr-cookie-consent-v1. You can change it at any time with the Cookies button in the footer or by clearing site data.