Skip to main content

Privacy and security

Privacy policy

Last updated
August 31, 2026

This policy explains how we handle personal data when operating nextdev.cz, responding to enquiries, scheduling online meetings, assessing responses to career opportunities and working with clients. It is intended to show clearly what information we need, why we use it, how long we keep it and how you can remain in control.

Who is responsible for processing

The self-employed individual identified below is the controller of your personal data. Processing is carried out in accordance with Regulation (EU) 2016/679 (GDPR), Czech Act No. 110/2019 Coll. on Personal Data Processing and other applicable laws.

Controller
David Šinkman
Company ID
08737401
Registered office
Jablonec nad Jizerou 809, 512 43 Jablonec nad Jizerou, Czechia

For a privacy question or a request concerning your data, contact david@nextdev.cz.

When we encounter your data

What we process depends on how you use the website. Providing data is voluntary, but without fields marked as required we cannot complete a booking, respond to an enquiry or assess your interest in professional cooperation. The situations below follow the way your interaction with NEXTDEV occurs in practice.

When you send a project enquiry

Submitting the form creates an enquiry record that helps us understand your request, get back to you and begin a specific conversation about the project.

Information involved
Full name, email address, optional telephone number and company or brand, selected project type, message content and technical form metadata, in particular language, page URL and title, referring page, UTM parameters, screen and viewport dimensions, display, first-interaction and submission times, and browser identification.
Why we need it
Handling the enquiry, communicating about a potential project, preparing an offer, protecting the form against abuse and keeping a record of communications.
What we rely on
Steps taken at your request prior to entering into a contract under Article 6(1)(b) GDPR; for technical metadata and communication records, also the Controller’s legitimate interest in website security, evaluating the source of an enquiry and protecting legal claims under Article 6(1)(f) GDPR.
When we delete it
If no contractual relationship is established, no longer than 12 months from the last communication. If cooperation begins, relevant data is retained as part of the client relationship.

When you book an online meeting

Bookings are created through Cal.com. We use the details to confirm and manage the time, prepare for the conversation and display its current status on the website.

Information involved
Full name, email address, optional current website address, project information provided in the booking note, selected date and time, time zone, language and booking identifier.
Why we need it
Selecting a time, creating and managing the booking, sending confirmations and reminders, holding the video call and displaying the current meeting status on the website.
What we rely on
Steps taken at your request prior to entering into a contract under Article 6(1)(b) GDPR and the Controller’s legitimate interest in properly organising meetings under Article 6(1)(f) GDPR.
When we delete it
If no contractual relationship is established, no longer than 12 months from the last communication. If cooperation begins, relevant data is retained as part of the client relationship.

When you contact us directly

The same principles apply when you choose email, telephone or another communication channel instead of a website form.

Information involved
Contact details and the content of communications you provide when contacting us by email, telephone or another communication service of your choice.
Why we need it
Responding to your question, discussing potential cooperation and conducting follow-up communication.
What we rely on
Steps taken at your request prior to entering into a contract under Article 6(1)(b) GDPR or the Controller’s legitimate interest in handling ordinary communication and protecting legal claims under Article 6(1)(f) GDPR.
When we delete it
If no contractual relationship is established, no longer than 12 months from the last communication.

When we start working together

Once a client relationship begins, we need a broader set of information to manage the project, contracts, payments and our statutory obligations.

Information involved
Identification, contact, contractual, project, invoicing and payment details of clients and other information necessary to provide the agreed services.
Why we need it
Entering into and performing a contract, project management, invoicing, accounting, complying with tax obligations and establishing, exercising or defending legal claims.
What we rely on
Performance of a contract under Article 6(1)(b) GDPR, compliance with legal obligations under Article 6(1)(c) GDPR and the Controller’s legitimate interest in protecting legal claims under Article 6(1)(f) GDPR.
When we delete it
For the duration of the contractual relationship and subsequently for the periods required by accounting, tax and other laws and for the relevant limitation periods.

When you apply for work or cooperation

A response submitted through the careers form is stored in NEXTBOARD and used only to assess possible professional cooperation and for related communication.

Information involved
Full name, email address, an optional link to a portfolio or personal project, the text entered in the “A few words about you” field and technical form metadata: language, page URL and title, referring page, UTM parameters, screen and viewport dimensions, display, first-interaction and submission times, and browser identification. We also use the IP address, email and a content fingerprint to protect the form; only their time-limited HMAC identifiers are written to the protection store.
Why we need it
Assessing your interest, experience and suitability for possible professional cooperation, managing the selection process and conducting follow-up communication. Technical metadata is used to deliver the response securely, protect the form against abuse and identify the general source of the visit.
What we rely on
The response and follow-up communication are processed at your request prior to potentially entering into a contract under Article 6(1)(b) GDPR. Form security, submission records and identifying the general source of the visit are based on our legitimate interest under Article 6(1)(f) GDPR.
When we delete it
We retain the response while assessing possible cooperation and for no longer than 6 months after the last related communication. HMAC identifiers used for submission limits expire within 24 hours and the duplicate-content fingerprint expires after 10 minutes.

What is created when you use the website

When you visit the website, technical data may be processed to the extent necessary, such as your IP address, browser and device identification, requested URL, date and time of the request, and error information. This serves the secure and reliable operation of the website, abuse prevention and fault diagnosis. The legal basis is the Controller’s legitimate interest under Article 6(1)(f) GDPR. The data is retained only for as long as necessary according to security needs and the settings of the relevant infrastructure provider.

After a booking is created, the website stores an essential nextdev_meeting cookie containing a signed booking identifier. The cookie allows the website to display the scheduled meeting status, reflect rescheduling or cancellation and offer a link to join. It is set for no longer than 180 days and may be removed earlier if the booking is no longer active. The cookie is HTTP-only, secure in production and is not used for advertising or cross-site tracking.

To remember that the meeting information banner has been temporarily dismissed, only the meeting start time is stored in the browser’s session storage. This information expires with the browser session and is not sent to third parties.

We use Vercel Web Analytics to measure basic website traffic and commercially relevant actions. The service processes aggregated anonymised data such as the visited page path, referring page, visit time, approximate location, device and browser type, and the name of a recorded event. It does not use analytics cookies, and our custom events never include a name, email address, form content or booking identifier. The one-way visitor hash expires after 24 hours, and aggregated statistics are retained for no longer than 12 months. We use this information to improve the website and evaluate interest in our services on the basis of our legitimate interest under Article 6(1)(f) GDPR.

The website currently uses no analytics or advertising cookies and does not track visitors for personalised advertising.

Who helps us process data

The following categories of recipients and processors may access personal data to the extent necessary for the relevant purpose:

  • Vercel as the provider of hosting, technical infrastructure and anonymised web analytics,
  • providers of hosting, cloud, database and infrastructure services,
  • the NEXTBOARD platform and its infrastructure providers, through which submitted contact and careers forms are recorded,
  • the operator of the Cal.com booking platform and its contracted processors when you book an online meeting,
  • providers of email, communication and calendar services used by the Controller or selected by the user,
  • accounting, tax, legal and other professional advisers where their involvement is necessary,
  • public authorities and other persons where disclosure is required by law or necessary to protect the Controller’s rights.

The Controller does not sell personal data, provide it to advertising networks or use it for automated profiling.

When data crosses EEA borders

Some cloud and booking service providers may also process personal data in countries outside the European Economic Area, particularly the United States. Any such transfer takes place only where the GDPR requirements are met, in particular on the basis of a European Commission adequacy decision or Standard Contractual Clauses under Article 46 GDPR, supplemented by additional safeguards where necessary. The Controller will provide information about the safeguards used or a copy of them upon request.

How you can influence your data

Subject to the conditions set out in the GDPR, you have the right to:

  1. obtain confirmation as to whether the Controller processes your personal data and request access to it and a copy,
  2. request the correction of inaccurate or completion of incomplete personal data,
  3. request erasure of personal data where the statutory conditions are met,
  4. request restriction of processing,
  5. receive data you have provided in a structured, commonly used and machine-readable format and, where applicable, transmit it to another controller where the conditions for data portability are met,
  6. object to processing based on the Controller’s legitimate interests,
  7. withdraw your consent at any time where particular processing is based on consent; withdrawal does not affect the lawfulness of processing carried out before withdrawal.

You may exercise your rights by contacting david@nextdev.cz. The Controller will respond without undue delay, normally within one month; in complex cases this period may be extended in accordance with the GDPR.

You also have the right to lodge a complaint with the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, Czechia, email posta@uoou.gov.cz, data box ID qkbaa2n.

How we look after your data

The Controller implements appropriate technical and organisational measures corresponding to the nature and scope of the processing. Access to data is limited to authorised persons and contracted service providers, data is transmitted over secure connections, and processing is limited to information necessary for the stated purposes. However, no method of electronic transmission or storage can guarantee absolute security.

Decisions are made by people, not algorithms

The processing described in this policy does not involve automated individual decision-making or profiling that would produce legal or similarly significant effects for you.

When our processing changes

The Controller may update this policy as appropriate, particularly when the services used, the scope of processing or legal requirements change. The current version is always published on this page together with the date of the last update.