Spa Hotel Ulrika Karlovy Vary Spa Hotel Ulrika Karlovy Vary

Information on the Processing of Personal Data by the CCTV System

 
OZON
CLEAN
30
let

Information on the Processing of Personal Data by the CCTV System

1. Introduction

This information document is issued by Hotel ULRIKA, s.r.o., with its registered office at Sadová 875/16, 360 01 Karlovy Vary (hereinafter the “Controller”), for the purpose of the maximum protection of your personal data, which is a fundamental priority for the Controller. It serves in particular to inform you about how the Controller handles your personal data and which rules it follows when processing your personal data.

2. Purpose and Legal Basis of Processing

The Controller processes personal data:

  • for the purpose of protecting property against theft, protecting property entrusted by third parties, protecting property against vandalism, preventing damage to property and protecting the health of persons;
  • for the purpose necessary for compliance with the legal obligations to which the Controller is subject;
  • for the purpose of legitimate interests.

In accordance with the GDPR, the legal basis for the processing is the legitimate interest of the Controller.

3. Basic Principles of Processing

The Controller processes personal data with an emphasis on compliance with the basic principles:

  • principle of lawfulness, fairness and transparency: the Controller processes personal data in a fair, lawful and transparent manner;
  • principle of purpose limitation: the Controller collects personal data only for a legitimate and specified purpose, and the data may not be processed in a manner incompatible with that purpose;
  • principle of data minimisation: the Controller limits personal data to what is necessary and relevant in relation to the purpose for which they are processed;
  • principle of storage limitation: the Controller stores personal data in a form that permits identification of the data subject only for as long as is necessary for the purpose for which they are processed;
  • principle of integrity and confidentiality: the Controller processes personal data in a manner that ensures their maximum protection against unauthorised processing, loss, destruction or damage.

To this end, the Controller has implemented all necessary technical and organisational measures:

  • The Controller has carried out a detailed internal analysis justifying the lawfulness and proportionality of the use and scope of the personal data it processes, including a balancing test.
  • The Controller has put in place all necessary measures so that the processing of personal data does not interfere inappropriately or disproportionately with the privacy of the natural persons concerned.
  • The Controller has appointed a limited group of persons responsible for the management of personal data. These persons are bound by confidentiality and have been instructed to handle personal data with the utmost care. They access personal data only in justified cases and only for the purpose for which the data were obtained.
  • The Controller keeps careful records of all interventions in the processing and of any transfers to third parties.

4. CCTV System

4.1 The CCTV system is a technical device that processes exclusively video recordings of the monitored area. No audio recordings are made. No systematic evaluation of data takes place during the processing of personal data.

4.2 The CCTV system is operated by the Controller on the premises of the building at Sadová 875/16, 360 01 Karlovy Vary.

4.3 The CCTV system is operated for the following purposes: protection of property against theft, protection of property entrusted by third parties, protection of property against vandalism, prevention of damage to property, and protection of the health and safety of persons.

4.4 The CCTV system may monitor all areas of the building referred to in point 4.2, with the exception of areas where the personal integrity of persons could be violated, such as toilets, showers, changing rooms and the like.

4.5 The CCTV system is operated according to the company’s operating schedule, upon motion detection, in the absence of persons, and depending on the individual cameras.

4.6 Recordings from the CCTV system may be disclosed exclusively in accordance with the specified purpose of processing and the rights guaranteed under the principles of the GDPR.

4.7 The processed CCTV recordings are secured against theft, and access to them is restricted to a carefully selected group of persons authorised by the Controller.

4.8 Individual CCTV recordings are retained only for as long as strictly necessary, and for a maximum of 4 days.

4.9 After the specified retention period has expired, the recordings are deleted automatically, unless during that period another previously unforeseen legal ground or legitimate interest of the Controller in extending the retention of the personal data arises.

5. Your Rights and How to Exercise Them

5.1 The Controller processes personal data with maximum transparency and fairness within the limits of the law. So that you, as a data subject, are fully informed and have access to your personal data, you have the rights listed below.

  • Right of access: the right to request a copy of the personal data we hold about you.
  • Right to erasure: the right to have personal data erased if they are processed unlawfully.
  • Right to restriction of processing: the right to restrict the processing of your personal data in the cases set out in Article 18 of the GDPR.
  • Right to object: you have the right to object to the processing of your personal data.
  • Right to lodge a complaint: you have the right to contact the Controller at any time with a complaint about the processing of your personal data, or to lodge a complaint with the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic.

5.2 The Controller is obliged to handle a request free of charge and without undue delay, at the latest within one month of receiving it. This period may be extended by a further two months, taking into account the complexity and number of requests.

5.3 In the cases defined by legislation, the Controller is not obliged to comply with a request or part of it, in particular where the request is manifestly unfounded, excessive or repetitive.

5.4 To ensure the security of personal data, the Controller is entitled, in case of doubts about the identity of the applicant, to ask the applicant to provide additional information to confirm their identity.

6. Information Obligation

6.1 The Controller has designated a contact person to represent it in communication with data subjects. The contact person is the director of the company, e-mail: gdpratspa-ulrika [emailtecka] cz (gdpr[at]spa-ulrika[dot]cz), telephone: +420 353 243 111.

6.2 The Controller has a legal obligation to, or may, provide personal data to the following categories of recipients or processors:

  • public authorities and other entitled entities where required by applicable law or imposed by a decision of an administrative authority or a court;
  • entities and persons where this is necessary on the grounds of the Controller’s legitimate interests;
  • entities and persons where this follows from the nature of the services and products they provide or where the data subject has so instructed;
  • an insurance company and other entities in the event of an insured event, where required by the Controller’s insurance contracts.

Document updated: 1 July 2026

Let yourself be pampered in a luxurious setting in one of the most equipped hotels in Karlovy Vary.

book onlinecontact us