• Microsoft CSP
    Microsoft CSP

    With Microsoft CSP, we transform businesses to help them achieve their business and technology goals.

  • Managed Microsoft 365
    Managed Microsoft 365

    We'll take care of security, productivity, and optimization. You focus on your business; we'll focus on IT.

  • Learn more

    Learn more about Microsoft Solution Partner products

  • Copilot M365
    Copilot M365

    Copilot for Microsoft 365 offers advanced AI features integrated into business tools.

  • Copilot Personal Trainer
    Copilot Personal Trainer

    No theories—just practical advice and tips that will save you time and energy in your day-to-day work.

  • Learn more

    Learn more about Artificial Intelligence products

    • KPCS addresses technological challenges efficiently and on time. In doing so, we support the growth of your business.

      • Learn more

        Learn more about Microsoft Solution Partner products

      • Microsoft CSP
        Microsoft CSP

        With Microsoft CSP, we transform businesses to help them achieve their business and technology goals.

      • Managed Microsoft 365
        Managed Microsoft 365

        We'll take care of security, productivity, and optimization. You focus on your business; we'll focus on IT.

    • Assess your AI potential and find the best solution. AI will be your trusted partner.

      • Learn more

        Learn more about Artificial Intelligence products

      • Copilot M365
        Copilot M365

        Copilot for Microsoft 365 offers advanced AI features integrated into business tools.

      • Copilot Personal Trainer
        Copilot Personal Trainer

        No theories—just practical advice and tips that will save you time and energy in your day-to-day work.

    • Azure is a flexible and scalable platform that provides modern products, services, and operations.

    • Cybersecurity is crucial. With our services, your data and systems are protected.

  • References
  • About Us
  • Contact

Privacy Policy

This Policy has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR), and based on the requirements of Act No. 110/2019 Coll. the Act on the Processing of Personal Data, and Act No. 480/2004 Coll., the Act on Certain Information Society Services and on Amendments to Certain Acts (the Act on Certain Information Society Services). The purpose of this Policy is to provide everyone with basic information regarding the processing of personal data, its protection, and the methods of processing.

Definitions of terms used in this public privacy notice:

  • “personal data” – any information that could identify you now or at any time in the future;
  • “processing” – any operation performed on your personal data, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or any other form of disclosure, alignment or combination, restriction, erasure, or destruction;
  • “consent” – any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of his or her personal data;
  • “controller” —a natural or legal person, public authority, agency, or other entity that, alone or jointly with others, determines the purposes and means of the processing of personal data;
  • “processor” — a natural or legal person, public authority, agency, or other entity that processes personal data on our behalf;
  • “recipient” —a natural or legal person, public authority, agency, or other entity to whom personal data is disclosed, whether or not that entity is a third party.

With this document, we would like to inform you about how we handle your personal data and assure you that your personal data is our most valuable asset, which we constantly protect. Our employees handle your personal data in accordance with the applicable laws of the Czech Republic and the European Union. Our IT systems and processes are regularly reviewed through the company’s internal security procedures to ensure that we always handle your personal data in the best and most secure manner possible. We recognize that the personal data you have entrusted to us so that we can provide our service to you does not belong to us, and we value your trust. Should we wish to use your personal data for purposes other than those listed here, we will notify you in an appropriate manner before commencing such processing. We will never do so without your knowledge, even if we have an adequate “legal basis” to do so.

Who are we, and who has access to your personal information?

We would like to be fully transparent with you regarding the processing of your personal data, and therefore we will always inform you who may access and process your personal data and contact you for the purposes listed below. The controller of your personal data for the Czech Republic is KPCS CZ s.r.o., Pikrtova 1737/1a, 140 00 Prague 4, Czech Republic.

We use third-party processors primarily for the storage, backup, and transfer of your personal data; you can find a list of these processors (partners) below, or you have the right to request a complete list of processors. These processors are bound by contractual obligations, including a confidentiality agreement and, if required by our relationship with them, data processing agreements in which they declare that they have implemented appropriate security measures.

We store, back up, and transfer your personal data with the help of our data processors. Our data processors provide us with internal systems and storage solutions that offer maximum protection. This primarily involves Microsoft on a global scale, and your data is stored exclusively in European Union countries.

In some situations, we need to involve external contractors (self-employed individuals) in the processing of your personal data; however, they are subject to the same terms and conditions as other processors.

We never proactively transfer or disclose your personal data. Your personal data remains completely secure with us. If we need to transfer your personal data to another recipient, we will inform you of this fact and will not transfer your data without your knowledge.

To avoid any doubt, please note that KPCS Consulting LLC, 209 Surrey St., 89074 Henderson, NV, USA, will not have access to your personal data.

What happens if you do not provide us with your personal information? In most cases, we will not be able to enter into a contract with you and/or provide you with the services covered by that contract. If we obtain your consent to process your personal data for certain purposes, your refusal to give such consent will not affect your ability to use our services.

Your personal information is safe with us, and that is why we want to let you know how we protect it

The personal data you entrust to us is subject to continuous physical, electronic, and procedural safeguards. We have modern control, technical, and security mechanisms in place to ensure the maximum possible protection of the data we process against unauthorized access or transfer, loss or destruction, as well as any other possible misuse. All persons who come into contact with your personal data in the course of performing their job duties or contractual obligations are bound by a legal or contractual duty of confidentiality. Our security solutions meet high standards, particularly with regard to data encryption during transmission and storage, access protection, multi-factor authentication, and comprehensive audit oversight, managed through the ATOM/ATOM ONE service, which we designed and continue to develop in-house. We focus primarily on Microsoft products and services, which is why we use all the tools available to our largest partner for the automated detection of security incidents.

To assure you that your personal information is safe with us, here are some of the tools we use to protect your data.

  • Customer LockBox, which gives us full control over access by Microsoft employees and Microsoft processors in accordance with the Microsoft Online Service Terms. Their access is permitted only with our company’s explicit approval.
  • Security and Compliance in Office 365, which allows us to monitor spam, detect ransomware, and handle your requests to exercise your rights
  • eDiscovery and Advanced eDiscovery, which allow us to quickly locate all data sources containing your personal information
  • Office 365 ATP, Azure ATP, and Windows Defender ATP, which help us prevent security incidents and automatically scan all email messages and their attachments for malicious code, such as ransomware
  • Threat Intelligence, which we use to test our users’ ability to avoid opening malware that may be hidden in emails
  • Azure Information Protection**,** which we use to encrypt selected important documents both internally and externally. We also set an expiration date for each selected document to prevent its misuse.
  • SharePoint Information Rights Management, which allows us to protect content when it is copied from our document repository
  • Azure Security Center, Audit Log, and ATOM ONE—built on the Log Analytics platform— which allow us to detect an attack before an attacker has a chance to gain access or disrupt our services

BitLocker, document versioning, regular backups, monitoring, etc. Today, they are a given for us—an integral part of every server and every workstation that processes our or your personal data.

Although the processing of your personal data is only a secondary activity for us, we would like to inform you that we carry out all processing in accordance with the law

In order to provide you with our service, we need to process your personal data, and therefore, for most of the processing we perform, we rely on the terms of the agreement between you and KPCS CZ s.r.o., even if it involves only an order for our services that you placed through our website

  • ATOM/ATOM ONE – https://kpcs.cz/a1

However, we may also collect certain data beyond the scope of our obligations, and for such data we always obtain your consent, which you may freely grant and which will not restrict your ability to use the services we offer. Legislation also imposes certain obligations on us that we must fulfill; therefore, we also process data about you as required by the laws of the Czech Republic.

ATOM / ATOM ONE Service

For what purposes and what personal data do we process about you?

  • Creating your account to access the service
    • Microsoft ID, LiveID, first name, last name, phone number, email address, address, payments for services, company ID number, tax ID number
  • Managing Your Monitoring Environment
    • Usernames, computer names, IP addresses, MAC addresses, websites visited, system login times, applications used on servers and computers, logins to internal web applications
  • Providing Support and Making Changes to the Service
    • First name, last name, and contact phone number of the person making the request, as well as the contact phone numbers of other data subjects, if required by the request
  • Billing for the services and licenses we provide
    • First name, last name, address, payments for services, company ID number, tax ID number
  • Marketing and the Sending of Commercial Communications
    • Email addresses
  • Processing of Accounts Receivable Arising from Service Operations
    • First name, last name, address, payments for services, company ID number, tax ID number

Who has access to your personal data (processors or third parties)?

We also use processors or third parties, which are the companies listed below

  • Microsoft’s Global Presence
  • External Contractors (Self-Employed Individuals)

Where might your personal data be processed (data transfers)?

Under certain circumstances (particularly in the event of service outages or load balancing), your data may be transferred outside the European Economic Area (EEA); to protect your personal data, our processor, Microsoft, relies in particular on the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks to protect your personal data, which ensure the secure transfer of data between Switzerland and the U.S. and between the European Union and the U.S.

Why are we allowed to process this data (legal basis)?

Based on consent to the processing of personal data

  • Direct Marketing and the Sending of Commercial Communications

To fulfill the contract

  • Creating your account to access the service
  • Managing Your Monitoring Environment
To comply with a legal obligation
  • Billing for the services and licenses we provide
  • Processing of Accounts Receivable Arising from Service Operations

How long will we retain your personal data (retention period)?

We will not keep your personal data indefinitely, but only for as long as is strictly necessary. Depending on the plan you choose when placing your order, this may range from 31 days to 730 days; however, we will retain all information regarding your payments for the duration of the contractual relationship and for as long as required by the applicable laws of the Czech Republic.

Where did we obtain your data (source)?

  • You provided us with your personal data yourself when you ordered the service we provide. However, we may obtain personal data that is not provided directly by you but is automatically recorded in our systems when your user (employee, contractor, supplier’s employee, etc.) performs an action on a device connected to our service. However, it is not within our power to contact every individual user; therefore, it is your responsibility to inform all your users that the aforementioned processing of personal data is taking place.
  • We may also receive your personal data from our partners, who were and are required to inform you about the transfer of your personal data to us; we will always inform you if we obtain your personal data from a source other than directly from you, no later than before we begin processing it, and no later than 1 month after obtaining it.

Selection of Employees and Their Hiring

For what purposes and what personal data do we process about you?

  • Finding you on the open job market and reaching out to you with an offer of collaboration
    • First name, last name, phone number, email address, address
    • Professional experience, skills, soft skills, language and communication skills
    • Terms and Preferences for Collaboration
    • Nationality, if you are an applicant from abroad
  • Recruitment and the Selection Process
    • First name, last name, phone number, email address, address
    • Professional experience, skills, soft skills, language and communication skills
    • Terms and Preferences for Collaboration
    • Nationality, if you are an applicant from abroad
  • An assessment of you as a candidate with regard to your suitability for the position being offered
    • First Name, Last Name, Self-Assessment
  • Storing resumes for future contact
    • First name, last name, phone number, email address, address
    • Professional experience, skills, soft skills, language and communication skills
    • Terms and Preferences for Collaboration
    • Nationality, if you are an applicant from abroad

Who has access to your personal data (processors or third parties)?

  • In exceptional cases, we use third parties, which are the companies listed below
  • External contractors (self-employed individuals) bound by a data processing agreement or a confidentiality agreement
  • Government institutions and agencies that require personal information about you, especially if you are a permanent resident of a country other than the Czech Republic

Where might your personal data be processed (data transfers)?

Under certain circumstances (particularly service outages or load balancing), your data may be transferred outside the European Economic Area (EEA); to protect your personal data, our processor, Microsoft, relies primarily on the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks to protect your personal data, which ensure the secure transfer of data between Switzerland and the U.S. and between the European Union and the U.S.

Why are we allowed to process this data (legal basis)?

Based on consent to the processing of personal data
  • Storing resumes for future contact
To fulfill the contract
  • Recruitment and the Selection Process
  • Finding you on the open job market and reaching out to you with an offer of collaboration
To comply with a legal obligation
  • An assessment of you as a candidate with regard to your suitability for the position being offered

How long will we retain your personal data (retention period)?

We will not retain your personal data indefinitely, but only for as long as is strictly necessary. Your personal data will be stored in our information system for a maximum of three months after the end of the recruitment or selection process, primarily in case the candidate we selected withdraws from the contract during the probationary period or we terminate our cooperation with them. If you consent to the retention of information from your resume, we will retain this information for no longer than one year from the date of your consent or until you revoke your consent.

Where did we obtain your data (source)?

  • You provided us with your personal data yourself for the purpose of applying for a job or in response to our job offers; alternatively, we obtained this information from public sources where you voluntarily posted it, such as professional social networks (e.g., linkedin.com) or job search portals (e.g., Jobs.cz). We may also have obtained your personal data from third parties, such as recruitment agencies, headhunters, etc., to whom you have given your consent to share your personal data with us.
  • We may also obtain your personal information from your friends and acquaintances whom you have informed that you are interested in new job opportunities.

Business Activities and Their Internal Processing

For what purposes and what personal data do we process about you?

  • Management of the Contractual Relationship and Performance of the Subject Matter of the Contract for One-Time Deliveries
    • First name, last name, phone number, email address, mailing address, company ID number, tax ID number
  • Management of the contractual relationship and fulfillment of the subject matter of the contract in the provision of long-term framework support services
    • First name, last name, phone number, email address, mailing address, payments for services, company ID number, tax ID number
  • Setup and subsequent management of the access credentials you have provided
    • First and last names of the contact persons at your company
    • Login credentials, access codes, passwords, and security codes
  • Documentation of Your ICT Environment
    • First and last names of the contact persons at your company
  • Communication between us regarding the subject matter of the contract
    • First and last names of the contact persons at your company
    • All information contained, in particular, in email messages related to the subject matter of the contract
  • Billing for the services and licenses we provide
  • In particular, first name, last name, address, payments for services, company ID number, tax ID number, and other information required by law
  • Processing of Accounts Receivable Arising from Service Operations
  • In particular, first name, last name, address, payments for services, company ID number, tax ID number, and other information required by law

Who has access to your personal data (processors or third parties)?

We also use processors or third parties, which include the following companies:

  • Microsoft’s global operations, always under our continuous supervision
  • External contractors (self-employed individuals) bound by a data processing agreement or a confidentiality agreement

Where might your personal data be processed (data transfers)?

Under certain circumstances (particularly service outages or load balancing), your data may be transferred outside the European Economic Area (EEA); to protect your personal data, our processor, Microsoft, relies primarily on the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks to protect your personal data, which ensure the secure transfer of data between Switzerland and the U.S. and between the European Union and the U.S.

Why are we allowed to process this data (legal basis)?

Based on consent to the processing of personal data
  • We do not require your consent
To fulfill the contract
  • Management of the Contractual Relationship and Performance of the Subject Matter of the Contract for One-Time Deliveries
  • Management of the contractual relationship and fulfillment of the subject matter of the contract in the provision of long-term framework support services
  • Setup and subsequent management of the access credentials you have provided
  • Documentation of Your ICT Environment
  • Communication between us regarding the subject matter of the contract
To comply with a legal obligation
  • Billing for the services and licenses we provide
  • Processing of Accounts Receivable Arising from Service Operations

How long will we retain your personal data (retention period)?

We will not retain your personal data indefinitely, but only for as long as is strictly necessary. Your personal data will be stored in our information system for a maximum of three months after the termination of the contractual relationship between us and you, or for the duration of any warranties, whichever is longer. Furthermore, we will retain certain personal data in accordance with the applicable laws of the Czech Republic.

Where did we obtain your data (source)?

  • You provided us with your personal data yourself in response to our offers of cooperation or as part of the process of entering into a contractual relationship.
  • We may also receive your personal data from our partners, who were and are required to inform you about the transfer of your personal data to us; we will always inform you if we obtain your personal data from a source other than directly from you, no later than before we begin processing it, and no later than 1 month after obtaining it.

Marketing and Public Relations (PR) Activities

For what purposes and what personal data do we process about you?

  • Direct Marketing
    • First name, last name, phone number, email address, role/position, employer
  • Sending news related to our business activities or those of our business partners
    • First name, last name, phone number, email address, role/position, employer
  • Organizing special events (conferences, lectures, webinars, seminars, webcasts, podcasts, etc.)
    • First Name, Last Name, Phone Number, Email Address, Role/Position, Employer, Signature
  • Photography and audio and video recording at our events or those of our partners
    • First name, last name, phone number, email address, address, employer
    • Alternatively, a group documentary photograph
  • Gifts for You on Your Anniversaries
    • First Name, Last Name, Date of Birth
  • Organizing Contests
    • First Name, Last Name, Date of Birth, Phone Number, Email Address, Signature

Who has access to your personal data (processors or third parties)?

We also use processors or third parties, which are the companies listed below

  • External contractors (self-employed individuals) bound by a data processing agreement or a confidentiality agreement
  • The agencies that conduct outreach on our behalf are bound by a data processing agreement or a confidentiality agreement
  • Agencies that organize special events for us and are bound by a service agreement or a confidentiality agreement

Where might your personal data be processed (data transfers)?

Under certain circumstances (particularly service outages or load balancing), your data may be transferred outside the European Economic Area (EEA); to protect your personal data, our processor, Microsoft, relies primarily on the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks to protect your personal data, which ensure the secure transfer of data between Switzerland and the U.S. and between the European Union and the U.S.

Why are we allowed to process this data (legal basis)?

Based on consent to the processing of personal data
  • Direct Marketing
  • Sending news related to our business activities or those of our business partners
  • Organizing special events (conferences, lectures, webinars, seminars, webcasts, podcasts, etc.)
  • Gifts for You on Your Anniversaries
  • Organizing Contests
For our legitimate interests
  • Photography and audio and video recording at our events or those of our partners

How long will we retain your personal data (retention period)?

  • If you consent to the retention of information from your resume, we will retain this information for a maximum of 1 year from the date you give your consent or until you withdraw your consent.
  • If we rely on legitimate interests, your personal data will be processed only for as long as is strictly necessary. However, since these are photographs or, in some cases, audio or video recordings used exclusively for PR and marketing purposes, we cannot guarantee their permanent deletion, as these photographs may be shared online without the possibility of retroactive control, and we cannot ensure their removal from all locations where they may appear. If you do not consent to being photographed or to the creation of audio or video recordings at an event organized by us, you are required to inform the event organizer or the company’s data protection officer, whose contact information is provided below in this document, of this fact. This person will then ensure that your personal data is not processed during the event.

Where did we obtain your data (source)?

  • You provided us with your personal data yourself when entering into a contractual relationship, in response to our offers of cooperation, or when registering for our events and activities; alternatively, we obtained it from a third party to whom you had given your consent to share your personal data with us.
  • We may also receive your personal data from our partners, who were and are required to inform you about the transfer of your personal data to us; we will always inform you if we obtain your personal data from a source other than directly from you, no later than before we begin processing it, and no later than 1 month after obtaining it.

Sometimes we also act as a processor of your personal data on behalf of the controller

Although we are not required under the GDPR to inform you about the processing of personal data in our capacity as a processor (typically a service provider for a controller), we would nevertheless like to provide you with transparent information about the types of processing in which your personal data is or may be processed.

These are primarily additional services that we provide to our customers, specifically the following:

  • Providing consulting and services related to the successful implementation of the GDPR, ISO 27xxx standards, or laws such as the ZokB
  • Conducting health checks on IT systems, sometimes in connection with Article 32 of the GDPR
  • Providing VPN or AP as a Service, where we provide you with secure access to your environment as a service
  • Providing services for the full or partial outsourcing of your environment
  • Providing the implementation of any IT services specified in your request

Depending on the service provided, its scope, the manner of performance, and the complexity of the solution, we may become aware of a significant amount of personal data, particularly the personal data of your employees, partners, external collaborators, etc., and therefore it is not possible to define the exact scope at this time; however, you will always be informed of this scope before the actual project begins. For any such processing, a relevant agreement is in place between us and you, which obligates us to protect all personal data we process.

You have certain rights with regard to us, so please don’t hesitate to contact us at any time

If you do not consent to our processing of your data or if you would like to contact us—even if it is just to ask a question—you can reach out to us at any time. You can contact us with confidence, and after verifying your identity, you will be able to revoke the consent you have given free of charge, or you may exercise the rights granted to you under the applicable laws of the Czech Republic.

Right of Access

We will provide you with information about what we have done with your personal data during the time it has been stored by our company, including a copy of the personal data you have submitted. However, we cannot provide you with all information, particularly information that would infringe on our intellectual property rights or violate the privacy of others.

The Right to Be Forgotten

We will delete or anonymize the personal data you have provided to us or that we have obtained through our activities.

Right to Restrict Processing

If you object to our processing of your personal data, we will restrict such processing for as long as your objection remains valid. A similar situation will arise if you believe that we are processing outdated data; in that case, we will restrict processing until such personal data is up to date. Alternatively, this may happen automatically if any of the processing becomes unlawful or if there is a risk of a breach of your privacy.

The Right to Object to Processing

You have the right to object to our processing of your personal data for direct marketing purposes. Alternatively, if you believe that our processing of your personal data—which is based on a legitimate interest—infringes too much on your privacy.

The right not to be subject to automated decision-making, including profiling

We do not currently engage in any automated decision-making, including profiling, and for this reason, we are unable to accommodate your request to exercise this right.

Right to Data Portability

We are happy to provide you with a copy of the personal data you have provided, in a machine-readable format, so that you can transfer it to another company. However, we cannot provide you with all the information, particularly that which would infringe on our intellectual property rights or violate the privacy of others.

To exercise your rights, you may contact our designated representative, who is responsible for ensuring we fulfill our obligations in accordance with the applicable laws of the Czech Republic, by email at privacy@kpcs.cz or by calling our central phone number at +420 778 411 744 on business days from 9:00 a.m. to 5:00 p.m. You can also visit us at the address listed above, and we will be happy to handle everything for you while you wait at our office. We would like to inform you that exercising your rights may be subject to a fee in certain situations, provided that we have determined that you already possess the information in question, or if the number of your requests is disproportionately high given the timeframe in which you are exercising your rights.

If we obtain information from a source other than directly from you, we will inform you of this fact, and you may exercise your rights. We will provide you with this information no later than one month after we obtain it, but always before we begin processing it. We would like to assure you that no processing will begin until you have been informed.

We don’t keep your personal information forever. How long will we retain your personal information?

We will not retain your personal data indefinitely, but only for as long as is strictly necessary to provide you with our services and to improve our existing ones. In accordance with the principles of our core business activities, your personal data will be stored in our information system for as long as is strictly necessary, as specified for each service described above in this document. If the law requires us to retain information about you for a longer period, we will retain certain personal data for that longer period; however, if you exercise your rights, we will inform you of this.

We always work with up-to-date information.

We regularly update all the personal data we have on file about you. We do not process any incomplete or outdated information, as we understand that your personal data may change over time; therefore, we will periodically ask you to update the personal data we have on file. We would greatly appreciate your help in keeping our contact database up to date, and we would therefore be very grateful if you could provide us with information about any changes to your personal data.

Final Provisions

All legal relationships arising from or in connection with the processing of personal data are governed by the laws of the Czech Republic, regardless of where access to such data was made. Any disputes arising in connection with privacy protection between you and KPCS CZ, s.r.o. shall be resolved by the competent Czech courts, which will apply Czech law.

We may and will periodically update the text of this Public Notice on Personal Data Protection. We will notify you of any such changes in advance here on our website at least 10 days before the changes take effect, in the form of a news item published on our website.

This Public Notice on the Protection of Personal Data takes effect on the 31st. 8. 2018 and was last updated on the 1st. 12. 2019.

Contact