Processing of personal data
Information for Data Subjects – pursuant to Article 13 GDPR
The company Eurovalley s.r.o., with its registered office at Příkop 838/6, Zábrdovice, 602 00 Brno, Company ID: 29368324, registered in the Commercial Register maintained by the Regional Court in Brno, Section C, File 75913, acting as the controller of personal data (hereinafter the “Controller”), hereby, in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter the “GDPR”), informs the natural persons whose personal data it processes — in particular clients who are natural persons, natural persons representing clients who are legal entities, their employees and contact persons, and other persons involved in negotiations (hereinafter individually the “Data Subject”) — that:
Scope and source of personal data
• The Controller processes personal data to the extent necessary for the brokerage and administration of insurance or other financial products, in particular identification and contact details, data on insured risks, concluded contracts and insurance claims, other personal data according to the specific product, and the content of communications and records of meetings as per the “Records of Meetings” section below.
• The Controller obtains personal data from the Data Subject, from the client on whose behalf the Data Subject acts or whose data the client has provided to the Controller, from insurance companies and other financial institutions in a contractual relationship with the Controller, and from public registers and records.
Purposes of processing and legal basis
• Personal data is processed for the purpose of brokering insurance or other financial products and their subsequent administration, including the handling of claims arising from the brokered contract. The legal basis is the performance of a contract with the Data Subject or taking steps prior to entering into a contract, as well as compliance with the Controller’s legal obligations, particularly under Act No. 170/2018 Coll., on Insurance and Reinsurance Distribution, Act No. 253/2008 Coll., on Selected Measures against Legitimisation of Proceeds of Crime and Financing of Terrorism, consumer protection legislation, and regulations governing accounting, tax administration, and document archiving.
• For persons acting on behalf of a client that is a legal entity or a self-employed natural person — in particular members of the statutory body, employees, and contact persons — the legal basis is the performance of the contract concluded with the client and the Controller’s legitimate interest in ensuring proper communication and the fulfillment of said contract. The Controller generally obtains this data from the client, not from the Data Subject.
• The legal basis for processing special categories of personal data (health data) is the explicit consent of the Data Subject; the same applies to the processing of personal data for marketing purposes.
Meeting records
• The Controller creates and maintains records of meetings held with the Data Subject, including meetings conducted by telephone and via online communication tools, and processes them in its CRM system, including through automated tools, such as artificial intelligence tools.
• The purpose of this processing is to prepare and document meeting records in accordance with Section 79 of Act No. 170/2018 Coll., to verify the scope of information and recommendations provided, to fulfill obligations under Act No. 253/2008 Coll., to protect the legitimate interests of the Controller and the client in dispute resolution, and for internal quality control and the professional development of the Controller's employees and tied agents.
• The legal basis is the fulfillment of the Controller's legal obligations where the creation and retention of a record is required by law, and in other cases, the Controller's legitimate interest pursuant to Article 6(1)(f) of the GDPR.
• The Data Subject is entitled to object to processing based on legitimate interest pursuant to Article 21 of the GDPR. If an objection is raised against the processing of records for the purposes of internal quality control and the professional development of employees and tied agents, the Controller will no longer process the meeting records with that Data Subject for the stated purpose.
Legitimate interests of the Controller
• Where processing is based on the Controller's legitimate interests, it is for the purpose of documenting services, information, and recommendations provided, demonstrating compliance with the Controller's obligations toward supervisory authorities, internal quality control and professional development of employees and tied agents, protecting the Controller's rights in legal disputes, administrative and similar proceedings, debt collection, and securing the Controller's information systems.
Necessity of providing data
• The reason for providing personal data to the Controller is to identify the contracting parties and meeting participants, which is necessary for the brokerage of insurance or other financial products, including their subsequent administration and the assertion of claims arising from the brokered contract; without providing this data, the aforementioned would not be possible.
Retention period
• Personal data is processed for the duration of the brokered contract and its administration by the Controller, and subsequently for the duration of the limitation periods for asserting claims arising from this contract, but for no longer than 10 years from its termination or the end of administration.
• The Controller retains meeting records and related documentation for the period stipulated by Act No. 170/2018 Coll., documents and data obtained during client identification and verification for the period stipulated by Act No. 253/2008 Coll., and accounting and tax documents for the period stipulated by relevant regulations.
• Personal data processed on the basis of consent is processed for the duration of the validity of the consent, unless it has been withdrawn earlier.
• The Controller processes personal data exclusively for defined purposes and in accordance with an existing legal title for processing.
Recipients of personal data
• For the purposes of brokerage and administration, personal data may be provided to entities operating insurance or reinsurance activities, banking services, building savings, and supplementary pension savings in the Czech Republic, as well as other financial institutions in a contractual relationship with the Controller, the Controller's tied agents, authorized employees of the Controller, and persons providing IT services to the Controller, including the operation of the CRM system and tools for processing meeting records, as well as legal, accounting, and consulting services.
• Personal data may also be provided in accordance with the law to law enforcement authorities, courts, the Czech National Bank, tax administrators and financial authorities, bailiffs, insolvency administrators, the Czech Insurers' Bureau, the Office for Personal Data Protection, and other public authorities.
Location, processing, and transfer to third countries
• The Controller's CRM system is operated within the territory of the Czech Republic. The Controller selects processors, primarily providers of IT services and tools for processing meeting records, to ensure that processing takes place exclusively within the European Union or the European Economic Area.
• The Controller does not intend to transfer the Data Subject's personal data to a third country or an international organization, nor to any recipients other than those mentioned above. Should such a transfer occur in the future, it will only take place in compliance with the conditions set out in Chapter V of the Regulation, and the Controller will update this information in advance.
Automated decision-making
• The processing of the Data Subject's personal data does not involve automated decision-making or profiling that would have legal effects on the Data Subject. The use of automated tools as described in the "Meeting Records" section is intended for processing the content of meetings, not for making decisions about the Data Subject.
Rights of the Data Subject
• The Data Subject has the right to request access to their personal data from the Controller, to have it corrected or erased, to request a restriction of processing, to object to processing, and to exercise the right to data portability to another controller.
• The Data Subject has the right to withdraw their consent to the processing of their personal data or their explicit consent to the processing of special categories of personal data at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
• The Data Subject has the right to lodge a complaint with the Office for Personal Data Protection, located at Pplk. Sochora 27, 170 00 Prague 7, phone +420 234 665 111, e-mail posta@uoou.cz, if they believe that the Controller is processing personal data in violation of the Regulation.
Contact details
• Contact details for the Controller regarding the exercise of rights and inquiries about personal data processing: Luděk Peter, tel. +420 733 621 069, e-mail: gdpr@eurovalley.cz.
• The Controller has not appointed a Data Protection Officer or a representative for the fulfillment of obligations under the Regulation.
In Brno, on August 31, 2026
Personal Data Processing Consent Withdrawal Form
Travel insurance
Personal insurance
Pojištění majetku a odpovědnosti občanů
Pojištění majetku a odpovědnosti občanů
Pojištění majetku a odpovědnosti občanů
Pojištění majetku a odpovědnosti občanů
Pojištění majetku a odpovědnosti občanů
Business insurance
Vehicle insurance
Agricultural insurance
Life insurance
Pojištění majetku a odpovědnosti občanů
Pojištění majetku a odpovědnosti občanů
Pojištění majetku a odpovědnosti občanů
Pojištění majetku a odpovědnosti občanů
Pojištění majetku a odpovědnosti občanů
Pojištění majetku a odpovědnosti občanů
Let's talk about protecting your global business.
We don't know all the challenges you're currently facing. But we do know how to create solutions that will support you even in the most complex situations. Let us know what's on your mind – and we'll propose a sensible way forward.