GDPR

Privacy Policy

The company WhichWay s.r.o., with its registered office at Kaprova 42/14, Staré Město, 110 00 Prague, registered under file number C 368005/MSPH with the Municipal Court in Prague (hereinafter referred to as “WhichWay”), which operates this website, considers the protection and confidentiality of personal data to be of utmost importance. As a data controller, WhichWay processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (hereinafter referred to as the “GDPR”).

Identity and contact information of the data controller

The controller of personal data is WhichWay s.r.o., Company ID (IČO): 17190355 
Registered office: Kaprova 42/14, Staré Město, 110 00 Prague, Czech Republic. The company provides moving and related services.

WhichWay acts as the controller primarily in relation to personal data of authorized representatives and contact persons of customers and prospective customers. Such personal data are processed and stored in the customer database. WhichWay is also the controller of personal data relating to its employees and business partners.

If you have any questions regarding the processing of your personal data, you may contact us by e-mail at info@stehovani-ww.cz or in writing at the address of our registered office.

What Personal Data We Process and Why

WhichWay processes personal data exclusively for the purpose of providing services to customers, protecting its legitimate interests, and fulfilling legal obligations. We strive to process only accurate and up-to-date personal data. Therefore, please inform us of any changes to the personal data you have provided.

Personal data relating to employees, statutory representatives, contact persons, authorized representatives, customers, and prospective customers are obtained primarily directly from the data subject when entering into a contract or subsequently during the contractual relationship. Personal data arising from our mutual communication and interactions are managed under our internal personal data protection procedures.

As part of our activities, we process various types of information that can generally be divided into the following categories:

(a) Identification data, including, in particular, title, first name, last name, job title, and address for the purpose of entering into a contract;

(b) Kontaktní údaje, mezi něž řadíme zejména telefonní číslo, emailovou adresu a pracovní adresu elektronické pošty na pracoviště za účelem, potvrzení uzavření smlouvy, plnění služeb a zajištění komunikace v rámci obchodního jednání;

(c) Transaction data, which includes, in particular, payment data and, where applicable, other data arising from the services we provide to our customers and business partners;

(d) Data included in communications, which includes, in particular, any personal data provided by employees, statutory bodies, authorized or contact persons of business partners, customers, and potential customers in the course of their dealings with us, including any contact that has taken place between us, whether in person, by telephone, email, or online, as well as the actual content of the communication with the person in question (content of email communication) and the scope and manner of the service provided;

(e) Data necessary to improve the quality of our services, including the customer’s IP address and cookies when using the website.

The majority of personal data are processed for the purpose of providing moving and related services and ensuring customer support. The provision of personal data is necessary for handling inquiries, concluding contracts, and providing services. Without such data, we may not be able to process an inquiry or enter into a contractual relationship. Personal data may also be processed for communication purposes via e-mail, telephone, postal correspondence, or SMS in matters relating to inquiries, orders, complaints, or service requests.

For the purpose of secure and proper performance of contractual obligations, including verification of instructions provided by an authorized customer representative, we may process identification data, contact data, and transaction data. Providing such data is necessary for the performance of the contract.

For the purpose of offering related services and maintaining business relationships with customers and business partners, including sending commercial and non-commercial communications, we may process identification and contact data of statutory representatives, authorized persons, and contact persons. In such cases, providing personal data is neither a legal nor contractual obligation and failure to provide such data does not result in adverse consequences.

In certain cases, Czech legislation requires us to process personal data. This typically includes the retention of data required by tax and accounting regulations.

We process employees' personal data for the purpose of fulfilling legal obligations of the employer and maintaining payroll and personnel records. Personal data of successful job applicants are processed for recruitment purposes and the conclusion of employment contracts.

Legal Basis for the Processing of Personal Data

We process personal data primarily on the following legal grounds:

  • performance of the contract and the implementation of measures taken prior to the conclusion of the contract at the request of the data subject pursuant to Article 6(1)(b) of the GDPR,
  • compliance with the controller’s legal obligations under Article 6(1)(c) of the GDPR,
  • the controller’s legitimate interest pursuant to Article 6(1)(f) of the GDPR,
  • the data subject’s consent pursuant to Article 6(1)(a) of the GDPR, if required for a specific purpose.

Ensuring the protection of customers' personal data

We implement technical, personnel, and other necessary measures to prevent unauthorized or accidental access to personal data, as well as its alteration, destruction, or loss; unauthorized transfers; other unauthorized processing; and any other misuse of personal data.

We provide our services exclusively through individuals whose personal and professional qualities offer sufficient assurance that they will properly comply with the terms and conditions governing the handling of personal data.

We have trained our employees on their obligation to maintain confidentiality regarding information obtained in the course of their work and on their obligation to protect the personal data of customers and third parties from misuse, loss, or unauthorized disclosure.

We maintain confidentiality regarding personal data and security measures, the disclosure of which would compromise the security of personal data, even after the termination of the contract.

Transfer of Personal Data

We use personal data exclusively to provide our services, protect it from misuse, and do not disclose it to third parties without prior notice or consent. Exceptions include external entities that provide support services to us and public authorities. We may or must disclose your personal data to them to the minimum extent necessary, for example in the following cases:

  • compliance with the relevant legal regulation or an enforceable request from a government agency,
  • enforcement of the relevant contractual terms and conditions, including investigation of any potential breaches thereof,
  • procedures aimed at addressing criminal offenses, technical issues, or security incidents; protecting against violations of rights, damage to property, or threats to the safety of employees, customers, or the public, as required or permitted by law; ensuring the provision of services and managing applications; and providing technical and IT services, as well as advisory and consulting services.

We provide personal data to authorized processors in accordance with our instructions. We require all such service providers (with the exception of public authorities) to process your personal data in accordance with the terms of data protection set forth in our contracts and applicable laws. We always ensure that we do not provide more data than is necessary to achieve the specific purpose of the processing.

Categories of personal data processors

In order to provide our services, personal data may be disclosed primarily to the following categories of processors:

  • web hosting and server service providers,
  • email and communication service providers,
  • IT support and information systems management providers,
  • accountants and tax advisors,
  • legal advisors,
  • providers of analytics and security tools for website operations,
  • backup and cloud service providers.


All processors are contractually obligated to protect personal data and process personal data only to the extent necessary to perform the agreed-upon services and in accordance with the controller’s instructions.

As a general rule, we do not transfer personal data to third countries outside the European Union. If such a transfer were to occur via certain technology providers, it would take place only after ensuring an adequate level of personal data protection in accordance with the GDPR.

Retention period and method for personal data

We process and store the personal data of customers, prospective customers, and third parties only for as long as is necessary to fulfill the purpose for which it was collected, or for the period specified by law.

The specific retention periods are, in particular:

  • Data from contact and inquiry forms – for a period of 12 months from the date of submission, unless a contractual relationship is established.
  • Customer data related to the performance of the contract – for the duration of the contractual relationship and for a period of 10 years following its termination, for the purpose of protecting the controller’s rights and legitimate interests.
  • Accounting and tax documents – for the period specified by applicable laws, typically 10 years.
  • Communication with customers (via email, phone, or in writing) – for the time necessary to process the request and, thereafter, for a maximum of 3 years from the end of the communication.
  • Job applicants' data – for the duration of the selection process, or for up to 12 months after its conclusion, subject to the applicant's consent.


Once the applicable retention period has expired, personal data is securely deleted, anonymized, or destroyed in accordance with the controller’s internal procedures.

We store personal data electronically on the controller’s secure devices or with trusted service providers, and physically only on the controller’s premises under the supervision of authorized personnel.

Rights of data subjects

You have the right to ask us to confirm whether we are processing personal data concerning you. Where applicable, you may contact WhichWay to exercise your right to access personal data, correct inaccurate data, complete incomplete data, or request erasure or restriction of processing. You have the right to object to processing, exercise your right to data portability, and exercise other rights under the General Data Protection Regulation.

The right to file a complaint with the supervisory authority

If you believe that the processing of your personal data violates data protection laws, you have the right to file a complaint with the supervisory authority.

The supervisory authority in the Czech Republic is:

Úřad pro ochranu osobních údajů
Pplk. Sochora 27
170 00 Praha 7 – Holešovice

Web: https://www.uoou.cz

Changes to these rules

We review this document regularly and reserve the right to make changes to it. If any changes to the rules affect your rights, we will notify you in an appropriate manner.

Last updated: June 11, 2026