Privacy policy

(basic GDPR notice for website contacts & newsletter)   Last updated: June 1, 2026

1. Controller and Contact Details

1.1. The controller of your personal data is SUNFIBRE s.r.o., ID No.: 027 77 738, with its registered seat at Pekařova 408, Daliměřice, 511 01 Turnov, Czech Republic.

1.2. If you have any questions regarding this Privacy Policy or the processing of your personal data, you can contact us at email: .

2. Categories of Personal Data We Process

2.1. When you use our website and contact form, we may process the following categories of personal data:

  • Identification data: full name.
  • Professional data: company, industry.
  • Contact data: email address, phone number (if provided)
  • Message content: any information you include in the free text field of the contact form.
  • Technical data: IP address and other technical identifiers (logs) necessary for the operation and security of the website; cookies are described in our Cookies Policy or a separate cookies notice.

2.2. We do not intentionally process special categories of personal data (such as health data, biometric data, data revealing political opinions or religious beliefs). Please do not include such information in your communication with us.

2.3. We do not provide user accounts on our website. When you contact us via the contact form, your data is stored in our CRM system as a contact record.

4. Recipients and Processors

4.1. We may share your personal data with our carefully selected service providers (processors) who process personal data on our behalf and according to our instructions. These include in particular:

  • hosting and cloud service providers (for the operation of our website and CRM),
  • newsletter and emailing service providers,
  • CRM system providers (for managing contacts and communication),
  • web analytics providers (for anonymised statistics, e.g. Google Analytics, and possibly other similar tools in the future).

4.2. We only use processors that provide sufficient guarantees regarding the security and confidentiality of personal data and with whom we have concluded data processing agreements in accordance with Article 28 GDPR.

4.3. Where required by law or for the protection of our rights, we may also disclose personal data to public authorities, courts or external advisors (such as lawyers), but only to the extent necessary and on a lawful basis.

5. International Transfers of Personal Data

5.1. Some of our service providers may be located outside the European Economic Area (EEA) or may transfer personal data to countries outside the EEA, in particular to the United States (for example, certain analytics or emailing tools, or CDN services such as content delivery networks).

5.2. In such cases, we ensure that appropriate safeguards are in place as required by the GDPR, for example:

  • an adequacy decision of the European Commission for the relevant country, or
  • standard contractual clauses (SCC) approved by the European Commission, combined with additional technical and organisational measures where necessary.

5.3. You may obtain more detailed information about specific transfers and safeguards by contacting us at .

6. Retention Periods

6.1. We retain personal data only for as long as necessary for the purposes described in this Privacy Policy and in accordance with applicable legal requirements.

6.2. In particular:

  • Contact form and business enquiries:
    We generally retain your data for the duration of our communication and potential negotiations, and thereafter for a period necessary to protect our rights and handle any claims. For general enquiries, this is usually up to 3 years from the last relevant contact, unless a longer period is required by law or justified by the nature of the communication.
  • Newsletter subscribers:
    We process your data for the duration of your subscription, i.e. until you withdraw your consent or unsubscribe, and for a short period thereafter (typically up to 3 years) to keep evidence of your consent and its withdrawal, where required to demonstrate compliance.
  • Technical data and logs:
    Technical logs necessary for the operation and security of the website are usually kept for a short period, typically from several days to a few months, depending on the type of log and security needs. Certain records may be retained for a longer period if necessary for the investigation of security incidents or for the protection of our rights.

6.3. When the relevant retention period expires, we will either securely delete or anonymise the personal data, unless we are required by law to retain it for a longer period (for example, for accounting or tax purposes in relation to contractual relationships).

7. Your Rights as a Data Subject

7.1. Under the GDPR, you have the following rights in relation to the processing of your personal data:

  • Right of access:
    You have the right to obtain confirmation as to whether we process your personal data and, if so, to receive a copy of such data and further information about the processing.
  • Right to rectification:
    You have the right to request that we correct inaccurate or incomplete personal data concerning you.
  • Right to erasure:
    In certain cases, you have the right to request that we delete your personal data, for example where the data are no longer necessary for the purposes for which they were collected or where you have withdrawn your consent and there is no other legal basis for processing.
  • Right to restriction of processing:
    In certain situations, you have the right to request that we restrict the processing of your data (for example, while we verify the accuracy of the data or your objections).
  • Right to data portability:
    In respect of data processed on the basis of your consent or a contract and by automated means, you may request that we provide you with such data in a structured, commonly used and machinereadable format, or that we transmit them to another controller where technically feasible.
  • Right to object:
    If we process your personal data on the basis of our legitimate interests, you have the right to object to such processing on grounds relating to your particular situation. We will then assess your objection and stop the processing unless we demonstrate compelling legitimate grounds which override your interests or where the data are needed for the establishment, exercise or defence of legal claims.

7.2. Where we process your personal data for direct marketing purposes (including newsletter), you have the right to object at any time and free of charge, and we will then stop processing your data for such purposes.

7.3. Where processing is based on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

7.4. To exercise any of your rights, please contact us at . We may ask you for additional information to verify your identity to protect your data against unauthorised access.

7.5. You also have the right to lodge a complaint with a supervisory authority. In the Czech Republic, the supervisory authority is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů).

8. Security of Personal Data

8.1. We take appropriate technical and organisational measures to ensure a level of security appropriate to the risks associated with the processing of personal data. These measures include, in particular:

  • secure hosting and encryption of communications where appropriate,
  • access control and rolebased access to systems,
  • logging and monitoring of selected operations and security events,
  • internal policies and training regarding the handling of personal data.

8.2. Although we apply reasonable security measures, no method of transmission or storage is completely secure. We therefore cannot guarantee absolute security of your data, but we continuously work on improving our safeguards.

9. Cookies and Similar Technologies

9.1. Our website uses cookies and similar technologies to ensure its basic functionality, to measure traffic and to improve the user experience. Some cookies are strictly necessary; others (such as analytics or marketing cookies) may require your consent.

9.2. Detailed information on the types of cookies we use, their purposes and storage periods, as well as your options to manage cookies, can be found in our Cookies Policy or in a separate cookies notice on our website.

10. Changes to this Privacy Policy

10.1. We may update this Privacy Policy from time to time, for example if our processing activities or applicable legal requirements change.

10.2. The updated version will always be published on our website and will indicate the date of its last update. We recommend that you review this Privacy Policy periodically.