Privacy policy
(basic GDPR notice for website contacts & newsletter) Last updated: June 1, 2026
1. Controller and Contact Details
1.1. The controller of your personal data is SUNFIBRE s.r.o., ID No.: 027 77 738, with its registered seat at Pekařova 408, Daliměřice, 511 01 Turnov, Czech Republic.
1.2. If you have any questions regarding this Privacy Policy or the processing of your personal data, you can contact us at e‑mail: .
2. Categories of Personal Data We Process
2.1. When you use our website and contact form, we may process the following categories of personal data:
- Identification data: full name.
- Professional data: company, industry.
- Contact data: e‑mail address, phone number (if provided)
- Message content: any information you include in the free text field of the contact form.
- Technical data: IP address and other technical identifiers (logs) necessary for the operation and security of the website; cookies are described in our Cookies Policy or a separate cookies notice.
2.2. We do not intentionally process special categories of personal data (such as health data, biometric data, data revealing political opinions or religious beliefs). Please do not include such information in your communication with us.
2.3. We do not provide user accounts on our website. When you contact us via the contact form, your data is stored in our CRM system as a contact record.
3. Purposes and Legal Bases of Processing
3.1. Contact Form and Business Enquiries
3.1.1. If you contact us via the contact form, e‑mail or other contact channels, we process your personal data for the following purposes:
- handling and answering your enquiry;
- taking steps prior to entering into a contract at your request (for example, discussing cooperation or a demo);
- keeping a basic record of our communication and enquiries.
3.1.2. The legal bases are:
- performance of a contract or taking steps prior to entering into a contract (Article 6(1)(b) GDPR), where your enquiry relates to a potential or existing contractual relationship with us;
- our legitimate interest (Article 6(1)(f) GDPR) in communicating with interested parties, promoting our services and keeping records of communication, where your enquiry is of a more general nature.
3.2. Newsletter and Commercial Communications
3.2.1. If you subscribe to our newsletter via the website, we process your personal data (in particular your e‑mail address and basic identification data) for the purpose of:
- sending you newsletters and commercial communications about our products, technologies and services;
- keeping evidence of your subscription and managing your preferences.
3.2.2. The legal basis is your consent (Article 6(1)(a) GDPR). You give your consent by subscribing to the newsletter (for example, by ticking a checkbox and confirming your subscription).
3.2.3. You can withdraw your consent at any time, in particular by using the unsubscribe link included in each newsletter or by contacting us at . Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
3.3. Website Operation, Security and Analytics
3.3.1. We process technical and log data in order to:
- ensure the basic operation and security of the website;
- detect and prevent misuse or attacks;
- generate anonymised statistics on the use of the website (for example using tools such as Google Analytics).
3.3.2. The legal basis is our legitimate interest (Article 6(1)(f) GDPR) in ensuring the proper functioning, security and improvement of our website and services.
3.3.3. For analytics we currently use anonymised or aggregated data. If in the future we start using personalised analytics or marketing cookies, we will ask for your consent where required by applicable law and provide you with detailed information in our Cookies Policy or in a cookies banner.
4. Recipients and Processors
4.1. We may share your personal data with our carefully selected service providers (processors) who process personal data on our behalf and according to our instructions. These include in particular:
- hosting and cloud service providers (for the operation of our website and CRM),
- newsletter and e‑mailing service providers,
- CRM system providers (for managing contacts and communication),
- web analytics providers (for anonymised statistics, e.g. Google Analytics, and possibly other similar tools in the future).
4.2. We only use processors that provide sufficient guarantees regarding the security and confidentiality of personal data and with whom we have concluded data processing agreements in accordance with Article 28 GDPR.
4.3. Where required by law or for the protection of our rights, we may also disclose personal data to public authorities, courts or external advisors (such as lawyers), but only to the extent necessary and on a lawful basis.
5. International Transfers of Personal Data
5.1. Some of our service providers may be located outside the European Economic Area (EEA) or may transfer personal data to countries outside the EEA, in particular to the United States (for example, certain analytics or e‑mailing tools, or CDN services such as content delivery networks).
5.2. In such cases, we ensure that appropriate safeguards are in place as required by the GDPR, for example:
- an adequacy decision of the European Commission for the relevant country, or
- standard contractual clauses (SCC) approved by the European Commission, combined with additional technical and organisational measures where necessary.
5.3. You may obtain more detailed information about specific transfers and safeguards by contacting us at .
6. Retention Periods
6.1. We retain personal data only for as long as necessary for the purposes described in this Privacy Policy and in accordance with applicable legal requirements.
6.2. In particular:
- Contact form and business enquiries:
We generally retain your data for the duration of our communication and potential negotiations, and thereafter for a period necessary to protect our rights and handle any claims. For general enquiries, this is usually up to 3 years from the last relevant contact, unless a longer period is required by law or justified by the nature of the communication. - Newsletter subscribers:
We process your data for the duration of your subscription, i.e. until you withdraw your consent or unsubscribe, and for a short period thereafter (typically up to 3 years) to keep evidence of your consent and its withdrawal, where required to demonstrate compliance. - Technical data and logs:
Technical logs necessary for the operation and security of the website are usually kept for a short period, typically from several days to a few months, depending on the type of log and security needs. Certain records may be retained for a longer period if necessary for the investigation of security incidents or for the protection of our rights.
6.3. When the relevant retention period expires, we will either securely delete or anonymise the personal data, unless we are required by law to retain it for a longer period (for example, for accounting or tax purposes in relation to contractual relationships).
7. Your Rights as a Data Subject
7.1. Under the GDPR, you have the following rights in relation to the processing of your personal data:
- Right of access:
You have the right to obtain confirmation as to whether we process your personal data and, if so, to receive a copy of such data and further information about the processing. - Right to rectification:
You have the right to request that we correct inaccurate or incomplete personal data concerning you. - Right to erasure:
In certain cases, you have the right to request that we delete your personal data, for example where the data are no longer necessary for the purposes for which they were collected or where you have withdrawn your consent and there is no other legal basis for processing. - Right to restriction of processing:
In certain situations, you have the right to request that we restrict the processing of your data (for example, while we verify the accuracy of the data or your objections). - Right to data portability:
In respect of data processed on the basis of your consent or a contract and by automated means, you may request that we provide you with such data in a structured, commonly used and machine‑readable format, or that we transmit them to another controller where technically feasible. - Right to object:
If we process your personal data on the basis of our legitimate interests, you have the right to object to such processing on grounds relating to your particular situation. We will then assess your objection and stop the processing unless we demonstrate compelling legitimate grounds which override your interests or where the data are needed for the establishment, exercise or defence of legal claims.
7.2. Where we process your personal data for direct marketing purposes (including newsletter), you have the right to object at any time and free of charge, and we will then stop processing your data for such purposes.
7.3. Where processing is based on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
7.4. To exercise any of your rights, please contact us at . We may ask you for additional information to verify your identity to protect your data against unauthorised access.
7.5. You also have the right to lodge a complaint with a supervisory authority. In the Czech Republic, the supervisory authority is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů).
8. Security of Personal Data
8.1. We take appropriate technical and organisational measures to ensure a level of security appropriate to the risks associated with the processing of personal data. These measures include, in particular:
- secure hosting and encryption of communications where appropriate,
- access control and role‑based access to systems,
- logging and monitoring of selected operations and security events,
- internal policies and training regarding the handling of personal data.
8.2. Although we apply reasonable security measures, no method of transmission or storage is completely secure. We therefore cannot guarantee absolute security of your data, but we continuously work on improving our safeguards.
9. Cookies and Similar Technologies
9.1. Our website uses cookies and similar technologies to ensure its basic functionality, to measure traffic and to improve the user experience. Some cookies are strictly necessary; others (such as analytics or marketing cookies) may require your consent.
9.2. Detailed information on the types of cookies we use, their purposes and storage periods, as well as your options to manage cookies, can be found in our Cookies Policy or in a separate cookies notice on our website.
10. Changes to this Privacy Policy
10.1. We may update this Privacy Policy from time to time, for example if our processing activities or applicable legal requirements change.
10.2. The updated version will always be published on our website and will indicate the date of its last update. We recommend that you review this Privacy Policy periodically.