Privacy Policy
DoCK — Desk booking and membership management
This privacy policy describes how we collect, use, and protect your personal data when you use the DoCK application (coworking desk reservation and membership management). We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable national law.
1. Data controller
The data controller — the entity that decides why and how your personal data is processed — is:
spravaubytovani.cz s.r.o.
Eliášova 761/46, 160 00 Praha - Bubeneč
Email: [email protected]
For any request regarding your personal data or this policy, please contact the controller at the address or contact details published above.
2. Scope and applicability
This policy applies to the DoCK application and to personal data we process when you:
- Register as a member and use the service (magic-link login, profile, membership, desk reservations, payment requests),
- Use the application as an administrator or super administrator,
- Submit a tour request via the public form.
We assume that our service may be used by individuals in the European Union and European Economic Area, and we therefore apply the GDPR to our processing.
3. Personal data we collect and use
We process the following categories of personal data:
| Category | Data | Purpose |
|---|---|---|
| Identifiers | User ID, username, variable symbol | Account management, billing, reservations |
| Contact | Email address, phone number | Login (magic link), contact, notifications (reminders, payment/membership emails) |
| Authentication | Password hash (stored for admin accounts only; members use passwordless magic-link login), session token in cookies, magic-link tokens | Authentication and session management |
| Preferences | Preferred language (locale), default plan preference | User interface and booking defaults |
| Financial / operational | Credit balance, membership type and dates, reservation history, payment requests | Service delivery and billing |
| Technical | Session cookie (JWT), short-lived magic-link token | Session and login flow |
Data we do not store: When you submit a tour request (email and language preference), that information is sent by email to our team only. It is not stored in the application database. The recipient may retain the email according to internal procedures.
Cookies: We use strictly necessary cookies for authentication: admin_auth_token and member_auth_token (JWT in HTTP-only, secure cookies, 30-day expiry). We do not use analytics or tracking cookies.
Logging: Our application does not intentionally log personal data in production. IP addresses are not stored or logged by the application (they may be available to the hosting infrastructure; see "Recipients" below).
4. Purposes and legal basis
We process your data for the following purposes and on the following legal bases:
- Membership and desk booking (account, reservations, payments, related notifications): necessary for the performance of the contract with you (Art. 6(1)(b) GDPR).
- Administrator accounts, security (e.g. authentication, access control), and internal operations: necessary for our legitimate interests in running and securing the service (Art. 6(1)(f) GDPR), in line with your rights and freedoms.
- Optional purposes (e.g. marketing or non-essential communications): If we use your data for such purposes, we will ask for your consent and you may withdraw it at any time (Art. 6(1)(a) and Art. 7(3) GDPR). We do not currently use your data for optional marketing without consent.
5. Recipients and data processors
We use the following service providers that process personal data on our behalf (as processors), under a data processing agreement (DPA) compliant with Art. 28 GDPR:
- Resend — email delivery (magic links, reminders, payment/membership notifications, tour request forwarding).
- Hetzner — hosting and database (storage and processing of all application data).
We do not sell your personal data. We only share data with processors as needed to provide the service.
6. International transfers
If we transfer your personal data to countries outside the European Economic Area (EEA), we ensure appropriate safeguards are in place (e.g. standard contractual clauses or other mechanisms approved by the European Commission). You may request details of these safeguards by contacting the controller.
7. Retention
- Account and profile data: We retain your account and related data (including membership and payment request information) until your account is deleted.
- Reservation data: We retain your reservation history until your account is deleted (it is linked to your account).
- Magic-link tokens: We retain magic-link tokens for a maximum of 24 hours; they are then removed.
When your account is deleted, we delete or anonymise your personal data and related records (e.g. memberships, reservations, tokens, payment requests) in line with our deletion procedures.
8. Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Passwords (admin accounts) are stored only as hashes (bcrypt); we do not store or expose plain passwords.
- Authentication cookies are HTTP-only, secure in production, and set with SameSite strict.
- Access to data is role-based (member, admin, super admin); members can access only their own profile and reservations.
- Sensitive fields (e.g. password hashes) are not exposed in API responses.
Data in transit is protected by TLS as part of our hosting environment.
9. Your rights
Under the GDPR you have the right to:
- Access (Art. 15): Obtain confirmation as to whether we process your data and, where applicable, a copy of your personal data.
- Rectification (Art. 16): Have inaccurate personal data corrected (you can update your profile; admins can edit user data).
- Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten"). As a member, you can permanently delete your account and all associated data (profile, membership, reservations, payment history) at any time via "Delete my account" in the Member Dashboard (Overview → Data & privacy). Administrators can also delete user accounts. You may otherwise contact the controller to request erasure.
- Restriction (Art. 18): Request restriction of processing in certain situations.
- Data portability (Art. 20): Receive your data in a structured, machine-readable format where the processing is based on contract or consent. As a member, you can "Export my data" from the Member Dashboard (Overview → Data & privacy) to download a JSON file containing your profile, membership, reservations, and payment requests. You may otherwise contact the controller to request a copy of your data.
- Object (Art. 21): Object to processing based on legitimate interest; we will consider your objection in line with the law.
- Withdraw consent (Art. 7(3)): Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, please contact the data controller using the contact details in section 1. We will respond within one month as required by the GDPR. You also have the right to lodge a complaint with a supervisory authority in the EU/EEA (in particular in your country of residence or place of work) if you believe that the processing of your personal data infringes the GDPR.
10. Children
The DoCK service is not directed at children. We do not knowingly collect personal data from individuals under 16. If you believe we have collected data from a child, please contact the controller so we can delete it.
11. Changes to this policy
We may update this privacy policy from time to time. We will indicate the date of the last update below. Continued use of the service after changes constitutes acceptance of the updated policy where permitted by law.
Last updated: 30 March 2026.
Effective date: 30 March 2026.
12. Contact
For questions about this privacy policy or your personal data, please contact the data controller at the details given in section 1.