Legal document Updated 25 August 2026

Privacy policy

Základní škola Unhošť, operator of UnhostCampus at unhostcampus.com, takes protection of your personal data seriously. This document describes what we collect, how we handle it and what rights you have when using our API and related services. Our practices follow GDPR and the applicable law of the Czech Republic.

Obsah dokumentu

Structure of this privacy policy

This document has six thematic parts: the controller’s role, purposes of processing, how data is transferred, retention, your rights, and how the policy is changed.

01

Data controller and scope of processing

Who is responsible for the platform and which categories of data are processed when the service is provided.

The personal-data controller is Základní škola Unhošť with its seat at nám. T. G. Masaryka 58, 273 51 Unhošť. We process data needed to run the SaaS platform: user identifiers (given name, family name, student ID), contact details of system administrators, and technical logs of API access.

That data is used only to provide the contracted service, keep the system secure and meet the school’s legal duties. Student identifiers are linked to credit accounts and ID-card records only to the extent needed to run payment records and asset management.

Identification data

Given name, family name and student ID for linking to school ERP systems.

Contact data

Email and phone of IT administrators for technical communication and alerts.

Technical logs

API access records, timestamps and session identifiers.

Transaction records

Internal-credit transaction records tied to the school’s accounting rules.

02

Purpose and legal basis

On what legal basis we process data and why we do not use it for marketing.

The main legal bases are performance of the contract with your institution and a legitimate interest in securing school infrastructure. Credit-system transaction data is processed for payment records and accounting rules. Those credits remain internal records, not a regulated payment service.

We do not use your personal data for marketing and we do not sell it to third parties for their own commercial use. Data is used only to run contracted UnhostCampus services: credit management, identity-card records and school-asset tracking through the API.

Legal bases of processing

  • Contract performance — providing API services under the agreed licence terms.
  • Legitimate interest — securing school infrastructure and preventing misuse.
  • Legal obligation — keeping accounting records and meeting archival periods.
03

Transfers and security

Where data is stored, who can access it, and when it may be handed to public authorities.

Personal data is stored in secured data centres in the European Union that meet high physical and digital security standards. Only vetted system-administration staff can access data, and only as needed for their work.

Data may be handed to public authorities only on a legal request or where needed to protect our rights under the law. Before any transfer we check the legal basis, and school leadership records every such case.

Technical safeguards include encryption in transit and at rest, regular security patches and monitoring of API access. All traffic between your ERP and UnhostCampus uses secured connections authenticated with API keys.

Encryption

Data is encrypted in transit and at rest.

EU data centres

Data is stored exclusively inside the European Union.

Controlled access

Only vetted administration staff have access.

04

Retention period

How long we keep data and what happens when the licence ends.

We keep data only as long as needed for the purpose it was collected, or for statutory archival periods. After the licence ends and obligations are settled, data in our systems is anonymised or deleted unless the law requires further retention.

We regularly review stored data and remove records the platform no longer needs. Credit-system transaction records follow Czech accounting and tax archival periods, so they may be kept longer than the active licence.

Technical logs of API access are kept only as long as needed to detect security incidents and then deleted automatically. Concrete periods are defined in operational documentation and may differ by record type.

05

Data-subject rights

What privacy rights you have and how to exercise them.

As a user you have the right to access your personal data, to rectification, erasure (the right to be forgotten) or restriction of processing. You may also object to processing based on legitimate interest, or complain to the Office for Personal Data Protection if you believe your rights were breached.

Right of access

You can request an overview of the data we process about you.

Right to rectification

Correction of inaccurate or outdated personal data.

Right to erasure

A request to delete data where the law allows it.

Restriction of processing

Temporary blocking of processing while a dispute is resolved.

Right to object

An objection to processing based on legitimate interest.

Complaint to the authority

Filing a complaint with the Office for Personal Data Protection.

Exercising your rights

You can contact us at any time to exercise your rights. We handle requests without undue delay, typically within 30 days of receipt.

support@unhostcampus.com / martin.macek.zak@zsunhost.cz
06

Changes to this policy

How and when we may update this policy, and how you will hear about changes.

We may update this privacy policy so it tracks changes in our services or in the law. We will tell users and contracting partners about material changes by email or a notice in the platform administration.

We recommend checking this page so you stay informed about how we protect privacy in the UnhostCampus ecosystem. The last-updated date is always in the header of this document.

Minor edits that do not change the scope of processing or your rights may be made without a separate notice. For large changes that affect how we handle your personal data, we will communicate clearly and with enough lead time before they take effect.

Contact information

A question about data protection?

To exercise data-subject rights or for any question about personal-data processing, use the channels below.

Data controller

Základní škola Unhošť

nam. T. G. Masaryka 58 (Office 11)

273 51 Unhošť, Středočeský kraj

Czech Republic

Opening hours

Mon–Fri: 8:00–17:00

Related documents

Continue to the other legal documents that complement this privacy policy.

UnhostCampus is a database-software provider, not a bank. The credit system is only an internal record of school-infrastructure services and is not a payment service or a financial instrument regulated by the Czech National Bank.