GDPR

Privacy policy.

Last updated: 21 August 2026

This policy explains what personal data we process about you, why, on what legal basis, how long we keep it and what rights you have. We follow Regulation (EU) 2016/679 (GDPR) and Czech law.

Data controller

All Day Digital s.r.o. (operator of KR.S Creative Studio)

Company ID: 02276801 · VAT ID: CZ02276801

Pod Strání 751, 760 01 Zlín, Czech Republic

E-mail: hello@krs.studio · Phone: +420 734 159 002

No Data Protection Officer has been appointed; please use the e-mail above.

Data we collect

We only process data needed to run the studio and the members area:

  • Identification and contact data: name, e-mail, phone; for companies also name, company ID and VAT ID.
  • Booking data: chosen space, time slot, add-on services, notes.
  • Billing and payment data: amount, invoice, payment reference (we never see your card number).
  • Membership data: tier, hours used, subscription status.
  • Entry codes and door-opening records from the smart lock.
  • Community posts and any profile details you choose to fill in.
  • Conversations with the Dot assistant and technical logs (IP address, browser type).

Purposes and legal bases

  • Bookings and studio access — performance of a contract (Art. 6(1)(b) GDPR).
  • Membership and subscriptions — performance of a contract.
  • Invoicing and accounting — legal obligation (Art. 6(1)(c)).
  • Entry codes and premises security — legitimate interest in protecting property (Art. 6(1)(f)).
  • Analytics and marketing cookies — your consent only (Art. 6(1)(a)).
  • Member newsletters — consent, withdrawable at any time in one click.
  • Dot assistant — performance of a contract (preparing a booking) and legitimate interest in improving the service.

Who we share data with

We never sell your data and never share it for someone else's purposes. We work only with processors bound by a data processing agreement:

RecipientPurposeRegionTransfer outside the EU
Lovable Cloud / SupabaseWebsite hosting, booking and account database, authentication.European UnionNo
Stripe Payments Europe, Ltd.Payment processing for bookings and memberships, receipts.Ireland / USAYes
Nuki Home Solutions GmbHManagement of entry codes for the studio smart lock.Austria (EU)No
Google (Gemini via Lovable AI)Powers the Dot assistant — processes conversation text.EU / USAYes
Google Ireland Ltd. (Analytics)Traffic statistics — only with consent.Ireland / USAYes
Meta Platforms Ireland Ltd.Advertising measurement — only with consent.Ireland / USAYes

Transfers outside the EU

Some processors (Stripe, Google, Meta) may process data outside the EU. Such transfers rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision (EU–US Data Privacy Framework), supported by a transfer impact assessment.

How long we keep data

  • Account and profile: for the life of the account, deleted within 30 days after closure.
  • Bookings: 3 years (limitation period).
  • Invoices and accounting records: 10 years (Act No. 563/1991 Coll. on Accounting).
  • Entry codes and access logs: 12 months.
  • Dot assistant conversations: 90 days.
  • Marketing consent and its record: 24 months from granting or withdrawal.

Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability, the right to object to processing based on legitimate interest, and the right to withdraw consent at any time. Write to hello@krs.studio; we respond within 30 days.

If you are not satisfied, you may lodge a complaint with the Czech Data Protection Authority (ÚOOÚ), Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz.

Cookies and tracking

Analytics and marketing cookies run only with your consent. The full list is in the Cookie policy, where you can also change your choice at any time.

Automated processing and AI

The Dot assistant suggests slots and prepares bookings. It does not set prices and does not refuse customers, and every booking can also be made through the standard form. Details are in the separate AI notice.

Security

Data is transmitted over TLS and stored in an EU database with row-level access control. Staff access is limited to what is necessary, and payment details are handled exclusively by Stripe.

Changes to this policy

We may update this policy. Material changes are announced by e-mail or in the members area; the version marked by the last-updated date always applies.

This document is a template provided for informational purposes. Have qualified counsel review it before publication.