This website uses cookies to offer you the best experience on our website. By navigating the website, you accept our use of cookies as described at our Cookies Policy..

Privacy Policy

Updated on: 30.07.2026
The purpose of this Privacy Policy is to show our practices, purposes and safeguarding regarding your personal data. We also declare that we do not knowingly collect personal data of minors under the age of majority. Furthermore, we do not offer our services to bodies from any sanction lists. You should not contact us if your or your company name is listed in any sanction list.
We reserve the right to amend this Privacy Policy to comply with new legislation, data protection directives, or technological developments. Any substantial changes to the way we process your Personal Data will be communicated to you in advance, where required by law. We recommend that you review this Privacy Policy periodically to stay informed about how we protect your information.
By continuing to use our website and services after such updates, you acknowledge and agree to the revised terms of this Privacy Policy. If required by applicable law, we will seek your explicit consent for significant changes to the processing of your Personal Data.
For the purpose of the General Data Protection Regulation (GDPR) the Data Controller is SmartResearch
Our information and contact details:
SmartResearch s.r.o
Registration number: C 264037
Address: Lomnického 1705/9, Nusle, 140 00 Praha 4
Email: info@smartresearchsro.com
Data Protection Officer email: dpo@smartresearchsro.com
Personal Data
Personal Data is information that can be used to identify a natural person. This information can include your name, address, phone number, personal identification code, date of birth and other information that can be directly associated with your person. Indirectly associated with natural person information is not considered Personal Data.
There is also another category of Personal Data that can include, as per GDPR, Sensitive Data such as ethnicity, race, and health status. Sensitive Data is subject to more strict obligations regarding data protection.
Processing of data of job applicants
Data we collect
During recruitment processes we may receive some of your Personal Data directly from you. This data may include but is not limited to the following:
  • full name,
  • date of birth,
  • language skills,
  • email address,
  • place of residence,
  • phone number,
  • level of education,
  • educational institution,
  • work experience,
  • employment history.
The abovementioned information may be used by our Human Resources department to see if you meet the qualifications for the openings and to contact you for or with further information regarding your application. We would require explicit consent from the job applicant for processing of any information that is considered as Sensitive Data.
We will also request your consent to search for further information from publicly available sources in order to satisfy ourselves that there is nothing that can make the job applicant unsuitable for the available opening.
Purpose of use
The data collected from you and from other sources will be used to identify the candidate for the opening, determine your qualifications, evaluate, contact, and inform you of our decision or request additional information from you.
Legal basis
We rely on Art 6, 1, (f) GDPR which is our legitimate interest in recruitment of new employees as the lawful basis for processing your Personal Data during the recruitment process. We also rely on Art 6, 1, (a) – (c) GDPR which is your consent for processing of your Personal Data, precontractual and contractual purposes and our legal obligations. For information that is considered as Sensitive Data, we rely on Art 9, 2, (a), which is your explicit consent for processing of such data.
Storage period
Your Personal Data shall be kept for as long as it is necessary for the recruitment process. If you receive and accept an offer of employment as part of the recruitment process, we will store your Personal Data collected during the recruitment process for at least the duration of the employment.
Additionally, we may retain your Personal Data for up to one year to consider your application for other positions. We will request your consent to such retention.
Security
We take all reasonable steps to ensure the safety of your Personal Data. The information collected during the recruitment process will be limited to those who have a genuine need to know it. Processing of this data will only be done in an authorized manner by our employees who are subject to a duty of confidentiality.
Your Personal Data will be stored securely in our systems within the EU. We will only transfer your Personal Data to the third country with your informed consent or due to our legal obligations. You will be fully informed of such transfers prior to the relevant data processing.
Processing of data for contact purposes
Data we collect
By requesting contact from us, you will share some of your Personal Data through our online form. Such information includes but is not limited to:
  • full name,
  • email address,
  • subject of the request,
  • information from your message.
Information from your contact request will be received by the appropriate department. Provision of the abovementioned Personal Data is made voluntarily with your consent.
Purpose of use
Your Personal Data as well as the information included in your request will be used to contact you and provide you with relevant information in connection with your request. Communication may be used to provide more insight into our services, provide support to our customers, offer cooperation with us, and answer your other requests.
Legal basis
We rely on Art 6, 1, (a) – (c) GDPR as the legal basis for processing your Personal Data for contact purposes, which is your consent, precontractual and contractual purposes and our legal obligations. The information provided by you for the purposes of communications will only be used for the purposes it was collected for.
Storage period
Your Personal Data shall be stored for as long as it is necessary to reply to your request and will be removed from our systems as soon as it is legally possible. We should point out that there are legal obligations for data retention and that in certain cases we must store your Personal Data for a longer period of time.
Security
We take all reasonable steps to ensure the safety of your Personal Data. The information collected during communications will be limited to those who have a genuine need to know it to respond to your request. Processing of this data will only be done in an authorized manner by our employees who are subject to a duty of confidentiality.
Your Personal Data will be stored securely in our systems within the EU. We will only transfer your Personal Data to the third country with your informed consent, for pre-contractual or contractual purposes or due to our legal obligations. You will be fully informed of such transfers prior to the relevant data processing.
Processing of data for contractual purposes
We process Personal Data of the third parties on behalf of our clients only if ordered and agreed to do so with the client based on a contract. For such purposes we will act as Data Processor and the client will act as Data Controller, as required by the GDRP, on a contractual basis.
All data processing related to the contractual relationship between us and the client shall be done in accordance with the documented instructions provided by the client. Volumes, types of data and purpose of processing should be documented and accepted prior to processing of any Personal Data on behalf of the client.
By assuming the role of a Data Processor, we understand the necessity and are obligated to take appropriate organizational and technological measures to protect Personal Data we process from any intentional or accidental manipulation, destruction, loss, and unauthorized access. We can assure you that we have incorporated all necessary measures to comply with the duty of confidentiality and legal obligations for data security.
As part of the contractual relationship, we may become aware of the Personal Data of the client’s employees. Processing of such data will be based on Art 6, 1, (a) – (c) GDPR, which is our legitimate interests in communications with our clients based on a contract between us and the client, consent of the person, contractual purposes, and our legal obligations. Such data may include email addresses, names, job titles, and phone numbers of the client’s representatives and contacts.
Surveillance
Data we collect
We use surveillance systems and security cameras on our premises. Data that we collect by using the said systems consists of video feed recordings and still images. Audio is not recorded due to regulations regarding CCTV and security cameras.
Purpose of use
CCTV and security cameras are used to ensure the safety of our premises, equipment, and data we process. We also use these surveillance systems to protect employees’ safety, physical integrity, health and property of our employees and third parties that are legally located on our premises.
Data obtained via surveillance systems may also be used to assist with investigations from authorized authorities regarding illegal acts, such as theft. The same applies to initiating legal proceedings and defending our legal interests.
Legal basis
Data generated from the usage of surveillance systems is processed according to Art 6, 1, (f) GDPR, which is our legitimate interest as Data Controller and Data Processor.
Storage period
Our systems automatically remove all recording within 15 days of the initial recording. We may retain this data for a longer period of time in cases where we find an incident within this time or cooperate with the authorities. Retained data will be removed from our systems as soon as it is legally possible.
Security
We take all reasonable steps to ensure the safety of your Personal Data. This data is only accessible by our authorized personnel in charge of security on the premises. We have incorporated all necessary organizational and technological measures to ensure the safety of your Personal Data.
Your Personal Data will be stored securely in our systems within the EU. We will not make this data available to third parties, unless legally obligated to, for example due to legal proceedings.
AI usage
We use certain artificial intelligence (AI) and automated tools to help us deliver, secure, and improve our services and to support our internal processes. This section explains how we use such tools in relation to the Personal Data we hold about you and what this means for you, in addition to the other provisions of this Privacy Policy. Where an AI tool processes your Personal Data, we do so only on one of the legal bases set out in this Privacy Policy and only to the extent necessary for the purpose concerned.
How we use AI
We may use AI or machine-learning tools for purposes such as automating routine internal and administrative processes, analyzing usage and performance data to improve our services, assisting with content filtering and moderation, and supporting security monitoring and the detection of fraud or misuse. We rely on Art 6, 1, (f) GDPR, which is our legitimate interest in operating, securing, and improving our services, as the legal basis for this processing, unless another legal basis stated in this Privacy Policy applies. We apply strict controls to ensure that Personal Data used by these tools is limited to what is necessary for the intended purpose, and, where possible, such data is anonymized or pseudonymized before it is processed.
AI in services provided on behalf of our clients
Some of the services we provide are delivered on behalf of our clients and may involve processing Personal Data that belongs to our clients’ own customers, contacts, or end-users. Where such services involve AI or automated tools, we act as Data Processor and the client remains the Data Controller, as described in the section “Processing of data for contractual purposes”. Our obligations in that role, including any AI-specific safeguards, are set out in the data processing agreement concluded with the relevant client rather than in this Privacy Policy.
Training of AI models
We do not use any Personal Data submitted to or generated by our AI tools, including inputs, prompts, and outputs, to train, retrain, fine-tune, or otherwise develop any AI system or large language model, whether ours or a third party’s. We impose the same restriction contractually on every AI service provider we engage.
Human oversight and automated decisions
We do not take decisions that produce legal effects concerning you, or that similarly significantly affect you, based solely on automated processing without meaningful human involvement. In particular, we do not use AI or automated tools to evaluate, score, or rank job applicants; all assessment of applications is carried out by our authorized personnel. Should we ever be required or permitted to make such a decision under an exception provided by Art 22 GDPR, you would retain the right to obtain human intervention, to express your point of view, and to contest the decision.
Transparency and third-party AI providers
Where you interact with an AI system that we operate and this is not otherwise obvious, we will inform you that you are interacting with an AI system, in line with Art 50 of the EU AI Act. Where we use AI to generate or materially alter content that is made public, we will label that content as AI-generated or AI-altered where required by law. Some AI functionality is provided through third-party tools. Where these providers process Personal Data on our behalf, they are bound by the same confidentiality and data protection obligations as our other service providers, and any transfer of your Personal Data outside the EU is subject to the safeguards described in the “Data transfers” and “Data security” sections of this Privacy Policy.
Data breach
We implemented a variety of procedures to prevent possible data breaches. Should there be a suspected breach of data, we will notify you immediately as well as any regulator that we are legally required to notify. In cases of data breaches, we will offer our cooperation in mitigating any possible negative effects of such events.
Our employees are aware of their legal obligations regarding data protection and are bound by the duty of confidentiality. Our employees are trained according to our program, which aims to raise awareness of the latest laws, practices, and developments in data protection.
Due to the nature of the online data transfers, we cannot guarantee complete security for any data transmission, as any data transfer online can have security gaps. We do our best to protect your Personal Data. Please keep in mind that transmission of your Personal Data remains at your own risk.
Data transfers
We do not sell, share, trade, or otherwise make available your Personal Data to third parties.
The processing of your Personal Data will be made only within the European Union (EU). We may share in parts your Personal Data with third-party service providers to fulfill contractual obligations with client. As part of such transfer, client will be fully informed prior to data transfer. All necessary security measures shall be applied. We also guarantee that third-party service providers are subject to at least the same level of security obligations as we are.
We may be obligated to disclose your Personal Data to comply with legal processes. We may also disclose your Personal Data to protect your safety, our rights, and in response to requests from authorities. Furthermore, there may arise the need to transfer your Personal Data to the country outside of the EU, for example in the context of legal proceedings. You will be fully informed of such data transfers and their purposes prior to or during such processing.
We will request your consent for any data transfers mentioned above. We should point out that there may be situations where we are obligated to transfer your Personal Data even without your consent. However, we will notify you of such obligations prior to or during such data processing.
Data security
Our security practices comply with industry standards and legal requirements to safeguard your information both at rest and in transit. These practices include access control, data encryption, regular audits and incident response plan.
We utilize data minimization practices as required by GDPR. This practice allows us to collect, process, and store only the Personal Data necessary for the purposes explicitly stated in this Privacy Policy. By applying data minimization, we can prevent any excessive data leaks in the event of data breach. This measure is reviewed regularly in order to assess the necessity of collected data.
If it becomes necessary to transfer your Personal Data outside the EU, we ensure that appropriate safeguards are in place. Such measures include standard contractual clauses (SCC) approved by the European Commission, confirming that the recipient countries have adequate level of data protection and using other legally binding instruments for data protection.
Data breach response plan that was developed and adopted by us has detailed procedures in cases of any suspected data breach. Data breach response plan requires us to notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Art. 33, GDPR, informing affected individuals if the breach poses a threat to their rights and freedoms, preventing further breaches and implementing corrective measures.
Data subject rights
According to GDPR, you as a data subject have the following rights regarding processing of Personal Data:
  • Right of access. According to Art 15 GDPR, the data subject shall have the right to obtain confirmation from the controller as to whether or not personal data concerning them is being processed along with the categories and purposes of data processed.
  • Right to rectification. According to Art 16 GDPR, the data subject shall have the right to obtain from the controller the rectification of inaccurate personal data concerning them and the right to have incomplete personal data completed.
  • Right to be forgotten. According to Art 17 GDPR, the data subject shall have the right to obtain from the controller the erasure of personal data concerning them. Parts of personal data may be legally obligated to be retained by the controller and shall be erased as soon as legally possible.
  • Right to restriction of processing. According to Art 18 GDPR, the data subject shall have the right to restrict the processing of personal data by the controller.
  • Right to data portability. According to Art 20 GDPR, the data subject shall have the right to receive the personal data concerning them, which they provided to the controller, in a structured, commonly used, and machine-readable format and have the right to transmit those data to another controller.
  • Right to object. According to Art 21 GDPR, the data subject shall have the right to object to processing of personal data concerning them. This right can be exercised by revoking your consent.
Furthermore, every data subject shall have the right to lodge a complaint with a supervisory authority in their state or habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data related to them infringes GDPR, according to Art 77 GDPR.
You can exercise your rights under GDPR by contacting us via methods indicated at the beginning of this Privacy Policy.
Cookies
Our website uses cookies which make the usage of our website more efficient and pleasant. By visiting our website, you consent to the use of essential cookies. Other cookies, such as functional, marketing, and analytical are subject to your consent.
What are cookies?
Cookies are small text files that are generated from your interaction with the website. They are stored by your browser and transmitted between browser and server at each interaction. These files are placed in your browser when you visit the website.
Cookies are used to ensure that the website works as intended, to store your preferences and to recognize that you have already visited the website. They allow us to tailor your experience with the website to your liking, analyze the usage of the website and improve our offer accordingly.
What information is collected with cookies?
Depending on your cookie settings either on the website or on your device we may collect some information through cookies, which includes without limitation IP address, operating system, device information, location, and similar data. This information, however, does not provide us with a natural person’s identity.
How do we use cookies?
When you visit the website, we will place several cookies on your device. They will help with displaying the website, remembering your preferences, and enabling the functions of the website.
We use essential cookies, that cannot be rejected due to their need for the website to work properly. Without such cookies the website will not function as intended and may not work at all.
There are cookies that allow specific functions on the website to be displayed correctly, which are functional cookies. They are not considered as essential since the website will operate as intended even without them. These cookies can be rejected if you wish to do so.
Analytic cookies are used to collect information from visitors of the website in order to understand how visitors navigate and use our website. Analytic cookies help us to improve the website and our offer. These cookies can be rejected if you wish to do so.
Marketing cookies are used to personalize advertising based on your browsing history and services used. Information from marketing cookies may be used by our advertising partners to show you relevant advertising on other websites. These cookies can be rejected if you wish to do so.
How do we use Google Analytics?
This website uses Google Analytics, a web analytics service offered by Google Inc., that tracks and reports website traffic. Google Analytics uses cookies to report on visitors’ activity on the website. Information in such reports is anonymous and cannot be assigned to any visitor directly. Moreover, your IP address will be anonymized prior to the data processing and will not be merged with any information from Google.
Google may transfer this information to third parties if required by legal obligations or if third parties are processing this data on behalf of Google based on a contract.
You may at any time reject the use of cookies from Google Analytics by either rejecting them on the website or by managing your browser settings. However, rejecting cookies on the website will still contribute to the analytics by sending “cookieless pings” to Google Analytics. Such pings contain non-identifiable and aggregated information as device type, conversion type, time of day, and browser type.
When using cookies provided by third-party services like Google, data may be transferred to countries outside the EU. In such cases, we ensure appropriate safeguards, such as Standard Contractual Clauses, are in place.
Further information regarding Google Privacy Policy can be found here
How long do cookies last?
Generally, there are two types of cookies: session cookies and persistent cookies.
Session cookies only last as long as your online session. Such cookies are removed from your browser and device once you close your browser or close the website.
Persistent cookies stay on your device even after you end your online session. Depending on the specific cookie files, they can remain on your device from 1 day to up to 1 year or longer. These cookies are used to remember you, your preferences on the website, and which webpages you have already visited.
Detailed information on how long each cookie file lasts can be found further in this document.
How to manage cookies?
Cookies preferences can be managed by either adjusting browser settings or by changing cookie settings on the website.
You can manage your cookie settings on the website by clicking on the “Manage” button on the initial cookie consent request, which is located in the header of the website when you visit the website for the first time or by clicking on the dedicated cookie box. There you can find information regarding cookies we use and the option to accept or reject the use of cookies by categories. We should point out that you cannot reject essential cookies as they are used to display the website to you in a working state.
The browser setting allows you to remove all cookies, reject cookies and be notified when cookies are used. You can reject all cookies by altering settings of your browser, but it may lead to this and other websites to not functioning properly or not functioning at all. As every browser has different user interfaces, we provide following links to help you with locating and managing your browser’s cookie settings:
What cookies do we use?
The following is a list of all cookie files that may be placed on your device when you interact with the website. Details include the name of the file, storage period and a brief description of the purpose of each cookie file we use.
Name Duration Host Description
AEC 6 months google.com Ensure that requests within a browsing session are made by the user, and not by other sites
APISID 1 year google.com Personalizes Google ads on websites based on recent searches and interactions
HSID 1 year google.com Used to authenticate users, to ensure that only the actual owner of an account can access that account
NID 6 months google.com Contains a unique ID that Google uses to remember your preferences and other information, such as your preferred language, how many search results you wish to have shown per page, and whether or not you wish to have Google's SafeSearch filter turned on
OTZ 17 days google.com This cookie is used to support Google’s advertising services
S Session google.com Stores certain information used to help improve services, including the pages users visit most often and whether users get error messages from certain pages.
SAPISID 1 year google.com Google enables this cookie to collect user information for videos hosted by YouTube
SEARCH_SAMESITE 6 months google.com This cookie is used for the correct sending of data to Google
SID 1 year google.com Google uses security cookies to authenticate users, prevent fraudulent use of login credentials, and protect user data from unauthorized parties
SIDCC 1 year google.com Google Analytics uses this security cookie to protect a user’s data from unauthorized access
SOCS 1 year google.com Used to track the consents that the user has granted to Google for the privacy settings and the configuration of the related cookies
SSID 1 year google.com Google enables this cookie to collect user information for videos hosted by YouTube
__Secure-1PSID 1 year google.com Used for targeting purposes to build a profile of the website visitor's interests in order to display relevant and personalized Google advertising
__Secure-1PAPISID 1 year google.com Used for targeting purposes to build a profile of the website visitor's interests in order to display relevant and personalized Google advertising
__Secure-1PSIDTS 1 year google.com Used for targeting purposes to build a profile of the website visitor's interests in order to display relevant and personalized Google advertising
__Secure-1PSIDCC 1 year google.com Used for targeting purposes to build a profile of the website visitor's interests in order to display relevant and personalized Google advertising
__Secure-3PSIDCC 1 year google.com Used for targeting purposes to build a profile of the website visitor's interests in order to display relevant and personalized Google advertising
__Secure-3PSIDTS 1 year google.com Used for targeting purposes to build a profile of the website visitor's interests in order to display relevant and personalized Google advertising
__Secure-3PAPISID 1 year google.com Used for targeting purposes to build a profile of the website visitor's interests in order to display relevant and personalized Google advertising
__Secure-3PSID 1 year google.com Used for targeting purposes to build a profile of the website visitor's interests in order to display relevant and personalized Google advertising
alert Session smartresearchsro.com Stores whether the visitor has accepted the cookie notice banner (used as a fallback when session storage is unavailable).
lang 12 hours smartresearchsro.com Stores the visitor’s preferred language for the website.
_GRECAPTCHA 6 months google.com Used by Google reCAPTCHA to perform risk analysis and protect forms from spam and abuse.
_ga 2 years smartresearchsro.com Used by Google Analytics to distinguish users.
_gid 24 hours smartresearchsro.com Used by Google Analytics to distinguish users.
_gat 1 minute smartresearchsro.com Used by Google Analytics to throttle the request rate.
ga* 2 years smartresearchsro.com Used by Google Analytics to maintain session state.

Contact Us

Our office is located in Prague. Feel free to contact us.

Contact us

Please use the contact form below to contact us, if you have any questions or you would like to send a cooperation offer.

SmartResearch s.r.o.

Lomnického 1705/9, Nusle, 140 00 Praha 4, Czech Republic

Message successfully sent
  • Quotation
  • Services
  • Cooperation
  • Vacancies
  • Other