1. Controller and contact
Artlex Consult s.r.o., IČO 17286417, Prague, Czech Republic, operating under the LEX ARTA brand (“LEX ARTA”, “we”, “us”), is the controller of personal data processed in connection with this website, enquiries and its own client administration, unless an engagement document states otherwise.
Privacy enquiries and data-subject requests may be sent to info@artlexconsult.com.
2. Personal data we process
Depending on how you interact with us, we may process:
- identity and contact data, including name, role, organisation, email address, telephone number and postal address;
- enquiry and engagement data, including correspondence, instructions, documents, meeting records and deliverables;
- corporate and compliance information required for conflict checks, client acceptance, sanctions screening or other due diligence;
- billing and transaction data, including invoicing information and payment history;
- technical and security data, such as IP address, device and browser information, access timestamps and server logs;
- marketing preferences where you choose to receive communications.
3. Purposes and legal bases
We process personal data only where a lawful basis applies. The relevant basis depends on the context:
- Contract and pre-contractual steps: responding to a service request, preparing a proposal, delivering agreed services, communicating about an engagement and administering payment.
- Legal obligations: accounting, tax, record-keeping and any compliance duties applicable to Artlex.
- Legitimate interests: managing enquiries and client relationships, protecting legal rights, preventing misuse or fraud, securing the website, improving operations and maintaining business records. We assess those interests against the rights and interests of affected individuals.
- Consent: where consent is specifically requested, including optional direct marketing or non-essential cookies. Consent may be withdrawn at any time without affecting earlier lawful processing.
4. Sources of data
Most information is obtained directly from you, your employer or the client for whom you act. Where relevant and lawful, we may also obtain information from public registers, public websites, professional advisers, counterparties and specialist screening or verification providers.
5. Recipients and service providers
We may disclose personal data, where necessary, to IT and hosting providers, communication and document-management providers, payment and banking providers, accountants, auditors, insurers, professional advisers, specialist compliance providers, authorised local counsel and public authorities. Access is limited to what is reasonably required for the relevant purpose.
Website enquiries are transmitted through our Beget-hosted form and email infrastructure for delivery to our business mailbox. Where a third party processes data on our behalf, we use contractual and organisational safeguards appropriate to the processing.
6. International transfers
Some providers or project participants may be located outside the European Economic Area. Where personal data is transferred to a country without an applicable adequacy decision, we use a lawful transfer mechanism where required, such as the European Commission’s standard contractual clauses, together with supplementary measures where appropriate.
7. Retention
We retain personal data only for as long as necessary for the purpose for which it was collected and to meet applicable legal, accounting, limitation and compliance requirements. Retention depends on the type of record, the engagement and applicable law. Data that is no longer required is deleted, anonymised or securely archived with restricted access.
8. Your rights
Subject to the conditions and limits in applicable law, you may request access, rectification, erasure, restriction, data portability or object to processing. You may withdraw consent where processing relies on consent. You also have the right to lodge a complaint with the Office for Personal Data Protection of the Czech Republic (Úřad pro ochranu osobních údajů) or another competent supervisory authority.
We may need to verify your identity before acting on a request. Some information may need to be retained where required by law or necessary for the establishment, exercise or defence of legal claims.
9. Security
We use technical and organisational measures intended to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. No internet transmission or storage method is completely secure, so absolute security cannot be guaranteed.
10. Website logs and cookies
This version of the website does not intentionally use analytics or advertising cookies. Essential technical processing may still occur to deliver and secure the website, including hosting logs and network-security controls. If non-essential cookies or similar technologies are introduced, this policy and the consent mechanism should be updated before activation.
11. Third-party links
This website may link to third-party websites. Their operators are responsible for their own privacy practices, and their policies should be reviewed separately.
12. Changes to this policy
We may update this policy to reflect changes in law, services or processing. The current version and update date will be published on this page.
