FastLajna
cs en Log in

Documents

  • Terms & Conditions
  • DPA
  • Price List
  • Privacy
  • Cookies
Terms & Documents →

Contents

  • Contents
  • 1. Controller and contact
  • 2. What data we process
  • 3. Purposes and legal grounds
  • 4. Recipients and transfers
  • 5. Login via a Google account
  • 6. Connecting a Google Calendar
  • 7. Handling of data from the Google interface (Limited Use)
  • 8. Data security
  • 9. Retention period
  • 10. Rights of natural persons
  • 11. Obligation to provide data
  • 12. Automated decision-making
  • 13. Changes to this document

Privacy

Effective from September 4, 2026 · version v2

Informative translation. The binding version is the Czech text; in case of any discrepancy, the Czech version prevails.

This document fulfils the information obligation under Art. 13 GDPR and Art. 3a.4 GTC.

Contents

  1. Controller and contact

  2. What data we process

  3. Purposes and legal grounds

  4. Recipients and transfers

  5. Login via a Google account

  6. Connecting a Google Calendar

  7. Handling of data from the Google interface (Limited Use)

  8. Data security

  9. Retention period

  10. Rights of natural persons

  11. Obligation to provide data

  12. Automated decision-making

  13. Changes to this document

This document explains how Fastlajna s.r.o. processes the personal data of website visitors, prospective customers, and Clients in its capacity as controller of personal data.

1. Controller and contact

The controller is Fastlajna s.r.o., with its registered office at Školská 1736/12, Nové Město, 110 00 Praha 1, Company ID (IČO) 29543908, registered in the Commercial Register maintained by the Municipal Court in Prague, file no. C 448213 (hereinafter the "Provider"). Enquiries and requests may be sent to hello@fastlajna.cz.

2. What data we process

Depending on the manner in which the Service is used, we may process:

  • identification and contact data, in particular first name, surname, e-mail, and telephone number;

  • company and registration data, in particular Company ID (IČO), Tax ID (DIČ), and business address;

  • customer account data, the login method, session identifiers, and identifiers of the customer account, Subscriptions, and invoices held with the PSP;

  • data on orders, Subscriptions, and invoices; the identifier (token) of the Payment Card provided by the PSP — the Provider does not store, and has no access to, the full Payment Card details;

  • the content of communication with customer support and the sales team;

  • technical and security data, in particular IP address, request time, browser type, request identifier, and security events;

  • choices stored in the browser as described in the document Information on Cookies and Local Storage;

  • the Google account identifier and e-mail address, where the Client logs in via a Google account (Art. 5);

  • data on the connected Google Calendar, in particular the e-mail address of the connected account, the scope of the permissions granted, and the encrypted access credentials to the Google interface (Art. 6);

  • records of acceptance of the contractual documentation, in particular the moment and version of the confirmed documents, the full text of the confirmed wording, the IP address, the browser identification (user-agent), and the interface language.

The Provider processes the data of Users (i.e., callers — the Client's customers within the meaning of Art. 1.4 GTC) in its capacity as processor; this processing is governed by the Data Processing Agreement (hereinafter the "DPA"), and this document does not apply to it.

3. Purposes and legal grounds

We process data for the purposes of:

  • responding to enquiries and taking steps prior to entering into an agreement;

  • creating and administering the customer account, providing the Service, customer support, and performance of the agreement;

  • invoicing, accounting, and compliance with other legal obligations;

  • securing the Service, preventing misuse, protecting legal claims, and operational diagnostics, on the basis of our legitimate interests;

  • documenting the conclusion of the agreement and the acceptance of the GTC and the DPA (performance of the agreement and legitimate interest in protecting legal claims; Art. 2.9 and 2.11 GTC);

  • sending commercial communications under § 7 of Act No. 480/2004 Sb.: to existing Clients on the basis of legitimate interest (§ 7(3) — offering the Provider's own similar services), otherwise only with prior consent; each communication can be declined simply and free of charge.

Where processing is based on consent, it may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

4. Recipients and transfers

We disclose data only to the extent necessary for the given purpose to the following categories of recipients:

  • the Payment Service Provider (PSP; Stripe) — payment and identification data; the PSP, to a defined extent, acts as an independent controller, in particular for fraud prevention and compliance with anti-money-laundering obligations (Art. 3a.2 GTC);

  • the hosting infrastructure provider (INTERNET CZ, a.s.);

  • Google LLC, if the Client connects a Google Calendar (Art. 6);

  • the provider of e-mail services for sending documents and communication (INTERNET CZ, a.s., operating the Forpsi service; operated in the Czech Republic);

  • public authorities, where disclosure is required by law.

The processing of the personal data of Users (callers) is carried out by the Provider in its capacity as processor for the Client as controller; it is governed by the DPA, including the list of Sub-processors in Annex No. 1 to the DPA, and this document does not apply to it.

Data may be transferred outside the European Economic Area, in particular to the United States of America. The transfer relies primarily on standard contractual clauses under Commission Implementing Decision (EU) 2021/914; the recipient's certification under the EU-U.S. Data Privacy Framework is used as a supplementary safeguard (Art. 3a.3 GTC).

5. Login via a Google account

A customer account can be created, and subsequently logged into, also via a Google account.

Scope of data obtained. For this login method, the Provider requests only the openid and email scopes. From the Google account, it obtains and stores exclusively (i) the stable, non-public Google account identifier, and (ii) the e-mail address. The Provider neither obtains nor stores the name or the profile picture. The ID token issued by Google is verified by the Provider but is not stored.

Purpose of processing. Verification of identity upon login and the creation or provision of access to a customer account.

Legal ground. Performance of an agreement, or the taking of steps prior to entering into an agreement at the request of the data subject (Art. 6(1)(b) GDPR).

Retention period. For the duration of the customer account. Upon cancellation of the customer account, the data on the linked Google account are removed together with the account.

Recipients. The Provider does not pass the data obtained from the Google account on to further recipients. They are stored exclusively in the Provider's database operated with the hosting infrastructure provider referred to in Art. 4, who is a processor to this extent.

Relationship to an account set up with a password. A Google account may be linked to at most one customer account. If a customer account set up with a password already exists for the same e-mail address, the Provider will refuse to link the Google account.

Revocation of access. Access granted may be revoked at any time in the Google account settings at myaccount.google.com/permissions. After revocation, it will not be possible to log in via the Google account. The customer account with the Provider itself does not cease to exist and can continue to be used after a password has been set.

6. Connecting a Google Calendar

The Client may connect a Google Calendar to their Assistant. During a call, the Assistant then finds an available slot and writes the booking into the calendar.

Status of the parties. The data on the connection itself, set out below, is processed by the Provider as controller in relation to the Client. The data of Users (callers) written into the calendar in connection with a booking is processed by the Provider in its capacity as processor for the Client as controller; this processing is governed by the DPA.

Scope of permissions. The Provider requests only the following permissions (OAuth scopes):

  • https://www.googleapis.com/auth/calendar.events — reading and writing events in the connected calendar; necessary for determining availability and for creating, rescheduling, and cancelling a booking;

  • https://www.googleapis.com/auth/calendar.calendarlist.readonly — reading the list of the connected account's calendars (title, identifier, and access level) so that the Client can choose which calendar bookings are written to; until that choice is made, the primary calendar of the connected account is used. This permission does not allow the contents of the calendars to be read;

  • openid and email — identification of the account being connected, so that it is apparent in the application which account is connected and so that the same account is not connected twice.

The Provider does not request the full https://www.googleapis.com/auth/calendar scope, nor the scopes for calendar settings, for calendar sharing and permissions. The calendar scopes listed above are classified by Google as sensitive and are subject to Google's application verification.

Which calendar is used. The Provider reads and writes in a single calendar of the connected account only — the one the Client selects in the application from the account's list of calendars; until that choice is made, it is the account's primary calendar. The other calendars of the connected account are neither read nor written to.

Determining availability. Availability is determined under the event permissions. The Provider reads events strictly within the queried time range and uses them solely to count overlaps, so as to assess how many bookings the Client allows to run at once (for example, by the number of chairs) and, when rescheduling, to exclude the very booking being moved. The events read are then discarded and the Provider does not copy them into the database. For this query the Provider passes no event data to the Assistant at all, but only whether the requested slot is free, or a set of free time windows; never the titles, descriptions, attendees, or any other metadata of events.

Listing events. Where the Assistant is to find the caller's booking in order to tell them about it, reschedule it, or cancel it, it requests a list of events in the selected calendar within the queried time window, using the caller's telephone number as the search criterion. From the Google interface response the Provider selects only those events whose title or description contains the caller's telephone number; the Provider reads the event description for this verification but does not store it, does not display it, and does not pass it to the Assistant. For the events so selected it processes only the identifier, title, start and end of the event, whether it is an all-day event, and the event status; attendees and all other fields are discarded. Only the events selected in this way are passed to the Assistant, not the contents of the calendar as a whole; among them there may also be a booking the Client wrote into the calendar manually rather than the Assistant.

Display in the application. In the application the Provider shows the Client the contents of the selected calendar for a period the Client chooses: the title, start, and end of the event and a link to it in Google Calendar. Here too this covers every event in the selected calendar, not only bookings created by the Assistant. The data is retrieved from the Google interface anew on each display and is not stored in the database.

Purpose of processing. Determining available slots, creating, rescheduling, and cancelling a booking, telling the caller what is scheduled, and displaying the contents of the selected calendar in the application. The Provider does not use the permissions granted for any other purpose.

Legal ground. Performance of an agreement (Art. 6(1)(b) GDPR); connecting a calendar is a function of the Service that the Client activates of their own volition.

What is stored. The Provider's database stores the access and refresh token of the connected account (encrypted using the Fernet algorithm), the scope of the permissions granted, the e-mail address of the connected account, the moment of connection, the identifier and title of the calendar selected for writing bookings, and the configured number of concurrent bookings. The contents of the calendar are neither copied into the database nor synchronised into it; availability data and event data are retrieved from the Google interface anew for each query. The operational record of a call does, however, contain the inputs and results of the individual tool calls, and therefore also data on the booking created, rescheduled, or cancelled and the titles of the events found by searching for the caller's telephone number; for a call in which the Assistant created a booking, the title of that event is additionally stored so that the call is recognisable in the call overview. These records serve to document the course of the call, to handle complaints, and for operational diagnostics.

To whom the data is passed. The calendar data needed to conduct a specific call — that is, the availability of the slot and the data on bookings found by searching for the caller's telephone number — is passed to the Sub-processors that technically conduct the call (the voice platform and the language model provider listed in Annex No. 1 to the DPA), solely for the purpose of conducting that call. Apart from these recipients and the cases set out in Art. 4, the Provider does not pass calendar data to anyone.

Retention period. Tokens and connection data for the duration of the connection. If the Client disconnects the calendar in the application, the Provider deletes the encrypted tokens from its database and seeks revocation of the token with Google using reasonable efforts; upon cancellation of the customer account, the connection is removed together with the account. Operational records of calls are retained in accordance with Art. 9 and with the DPA.

Revocation of access. Access may be terminated at any time by disconnecting the calendar in the application or in the Google account settings at myaccount.google.com/permissions. After revocation, the Assistant will stop writing to and reading from the calendar; the events it previously wrote into the calendar remain there and the Client handles them itself. Deletion of the data obtained from the Google interface may be requested at hello@fastlajna.cz (Art. 10).

7. Handling of data from the Google interface (Limited Use)

The handling of data obtained from the Google API interface — both upon login under Art. 5 and when connecting a calendar under Art. 6 — is governed by the Google API Services User Data Policy, including its Limited Use requirements. In particular, the Provider:

  • uses this data solely to provide or improve features that are visible to the user and prominent in the application's user interface, namely the functions under Art. 5 and 6;

  • does not sell this data;

  • does not use it for advertising, ad targeting, or profiling;

  • does not use it to develop, improve, or train generalized artificial intelligence and/or machine learning models; it is passed to the language model solely for the purpose of conducting a specific call, and the Provider uses only such Sub-processor interfaces whose terms exclude training on the data passed to them;

  • does not pass it to other persons for purposes or to recipients other than those set out in Art. 4 and 6, and for compliance with a legal obligation, including disclosure in judicial, administrative or supervisory proceedings;

  • does not make it accessible for human review, except where necessary for securing the Service, complying with a legal obligation, or where the user has given express consent.

8. Data security

The Provider has implemented technical and organisational measures to secure personal data pursuant to Art. 32 GDPR, appropriate to the nature of the data processed. These measures also apply to data obtained from Google APIs (Google user data), including Google Calendar data. In particular:

  • Encrypted transmission. All communication with the website and the application takes place exclusively over HTTPS (TLS); unencrypted requests are redirected to the encrypted connection and the browser is served an HSTS header valid for one year, including subdomains. Communication with the interfaces of Subprocessors and of Google is likewise encrypted.

  • Protection of credentials. The access and refresh tokens for the Google interface are stored in the database in encrypted form only (Fernet, i.e. AES-128-CBC with HMAC-SHA256 integrity verification); the encryption key is held outside the database in the server environment. Passwords are stored only as a hash (bcrypt, 12 rounds), never in readable form. The login refresh token is likewise kept in the session store only as a hash (SHA-256).

  • Storage encryption. The server's data storage is encrypted at block level (LUKS). This measure protects the data in the event of theft or unauthorised removal of the medium; it does not replace database-level encryption, which the Provider has not implemented.

  • Access control. Every data request requires an authenticated login; the connected-calendar records are bound in the database to a specific customer account and every query is restricted to the account of the signed-in user. Access to the production environment is limited to persons who need it to operate the Service and is technically bound to an SSH key (see the Infrastructure bullet).

  • Session management. The access token is valid for 30 minutes and a login for a maximum of 7 days. The refresh token is delivered in a cookie with the HttpOnly, Secure and SameSite flags, so it is not accessible to scripts in the browser. A session can be invalidated at any time by logging out.

  • Security of the Google connection. The authorisation request is protected by a single-use random state parameter valid for 10 minutes, which is verified upon return from the Google interface (CSRF protection); at the same time it is checked that the necessary scope was in fact granted. When the calendar is disconnected, the Provider deletes the encrypted form of the token from its database and seeks revocation of the token with Google using reasonable efforts; a failed revocation is logged.

  • Minimisation. Calendar content is neither stored nor synchronised into the database (Art. 6); from the Google interface responses, only the fields necessary for the given function are processed and the remainder is discarded.

  • Interface resilience. Login and calendar operations are protected by request rate limiting, the application sends security headers (X-Content-Type-Options, X-Frame-Options, Referrer-Policy), and it accepts requests only from the Provider's designated domains.

  • Infrastructure. The application and the database run on servers in a data centre in the Czech Republic (Art. 4). The server is protected by a firewall and remote access is possible only with an SSH key; password login and direct root login are disabled. The development and production environments are separated into distinct databases.

  • Personal data breach. In the event of a personal data breach, the Provider proceeds pursuant to Art. 33 and 34 GDPR; where the breach concerns User data processed on behalf of the Client, the procedure under the DPA applies.

  • Currency of the measures. The measures set out in this Article reflect the state of the Service as at the effective date of this document; the Provider adapts them on an ongoing basis to the development of the Service and to the state of the art.

9. Retention period

We retain data only for as long as necessary for the given purpose:

  • enquiry data for the duration of handling the business relationship and thereafter for the period necessary to document the communication and protect legal claims;

  • customer account data and data on the provision of the Service for the duration of the contractual relationship and thereafter for the duration of the relevant limitation periods;

  • accounting and tax documents for the period stipulated by law; historical invoices and billing records are for this reason not deleted even after cancellation of an Assistant or termination of the Agreement (Art. 3a.4 GTC);

  • the authentication session for at most 7 days from the last issuance of a refresh token (the refresh_token cookie), unless withdrawn earlier;

  • technical and security records for a period appropriate to their purpose and the severity of the recorded event;

  • records of acceptance of the contractual documentation for the duration of the contractual relationship and thereafter for the duration of the relevant limitation periods (Art. 2.11 GTC).

Specific data may be retained for longer if necessary for legal proceedings, a review by a public authority, or compliance with a legal obligation.

10. Rights of natural persons

Under the conditions of the GDPR, you have the right of access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interest, and withdrawal of consent. You also have the right to lodge a complaint with the Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Praha 7, uoou.gov.cz.

Send your request to hello@fastlajna.cz. Before handling the request, we may verify the requester's identity by reasonable means.

11. Obligation to provide data

We need data marked as mandatory to handle an enquiry, enter into an agreement, or provide the relevant function. Without them, we may be unable to handle the request. Other data are voluntary.

12. Automated decision-making

In administering visitors, prospective customers, and customer accounts, we do not carry out automated individual decision-making with legal or similarly significant effects.

13. Changes to this document

The current version is always available on this page. We will announce significant changes affecting existing Clients in an appropriate manner.

Want to try FastLajna?

Get started
FastLajna

AI phone assistant for Czech small businesses and local operations.

Terms & Documents

  • Terms & Conditions
  • DPA
  • Price List
  • Privacy
  • Cookies

Contact

  • General enquiries: hello@fastlajna.cz
  • Technical support: tech@fastlajna.cz
  • +420 728 436 188

© 2026 Fastlajna s.r.o. · Školská 1736/12, Nové Město, 110 00 Praha 1, Czech Republic · Company ID 29543908 · File No. C 448213, Municipal Court in Prague

Your privacy

We always use essential technologies for sign-in, security and language settings. With your consent we also use analytics cookies (Google Analytics) to understand traffic and improve the site. Without consent, analytics stays off.

Cookie information