Privacy
🇨🇿 Read in CzechLast updated: 19 August 2026
The short version
There are no analytics, no advertising, no third-party trackers and no cookie banner — because there is nothing to consent to. We collect the least we can get away with, and we say exactly what that is below.
Who is the controller
OmNexis s.r.o., IČO 02800888, Pražská 69/17, 273 43 Buštěhrad, Czech Republic, is the controller of personal data processed through chci.eu. You can reach us at info@omnexis.com.
We have not appointed a Data Protection Officer. Our processing is not large-scale, is not systematic monitoring, and does not involve special categories of data, so Article 37 GDPR does not require one.
What we process, why, and on what basis
your email address, the content of your submission, and a salted hash of your IP address. The email lets us come back to you if a submission is unclear; the IP hash enforces the daily submission limit that keeps the site usable. Legal basis: our legitimate interest in running a moderated catalogue and preventing abuse (Article 6(1)(f) GDPR). The raw IP address is never stored — only an irreversible salted hash — and the hash is deleted after 30 days.
your email address, display name and language, received from Vrse, plus a record of the entries you like. Legal basis: performance of the agreement to provide you an account (Article 6(1)(b) GDPR). You can delete the account at any time by writing to us.
our web server records the IP address, time, requested address, response code and browser identification for each request, as every web server does. These are kept for 14 days and used only to diagnose faults and identify attacks. Legal basis: legitimate interest in the security and stability of the service (Article 6(1)(f)).
We do not build profiles, we do not track you across sites, we do not sell or share data for advertising, and there is no automated decision-making with legal effect under Article 22 GDPR.
Cookies
chci.eu sets two cookies, both strictly necessary or explicitly requested by you, which is why no consent banner appears:
— set only when you sign in, so you stay signed in. Deleted when you sign out.— set only when you pick a language, so your choice survives the next click. Expires after one year.
Neither cookie is used to track, profile or advertise. Under section 89(3) of Czech Act No. 127/2005 Coll. and the ePrivacy Directive, cookies that are strictly necessary to provide a service the user has requested do not require consent.
Who else sees the data
- — hosting, as our processor, in the EU.
- — only if you sign in. Vrse is our own identity service, run by us in the EU on the same legal basis as this site, and it tells us a permanent identifier, your email address and your display name. It uses passkeys, so no password exists to be stolen, and no data leaves the EU.
Sign-in with Google was offered until August 2026 and has been removed. No data is sent to Google, and everything except liking entries works without an account at all.
We use no other processors, and we transfer data to no one else. We do not sell data to anyone, at any price.
How long we keep things
- Submission emails and content: kept while the entry is live, so the record of where it came from survives. Rejected submissions are kept for 12 months and then deleted.
- IP hashes: 30 days.
- Web server logs: 14 days.
- Account data: until you delete the account.
Your rights
Under the GDPR you may ask us for access to your data, for its rectification or erasure, for restriction of processing, for portability, and you may object to processing based on legitimate interest. Where processing rests on consent, you may withdraw it at any time without affecting what was done beforehand.
Write to info@omnexis.com and we will answer within one month. We do not charge for this.
If you think we have handled your data badly, you can complain to the Úřad pro ochranu osobních údajů (ÚOOÚ), Pplk. Sochora 27, 170 00 Praha 7, www.uoou.cz.
Security and breaches
The site runs on a hardened server inside the EU, over TLS only, with passwords stored as scrypt hashes and IP addresses only ever as salted hashes. Backups stay on the same EU infrastructure.
If a breach occurs that is likely to result in a risk to your rights, we will report it to the ÚOOÚ within 72 hours and tell you directly where the risk is high, as Articles 33 and 34 GDPR require.
Children
This site is not directed at children and we do not knowingly collect data from them. An account requires signing in with Vrse, which has its own age requirements.
This page is available in English and Czech. The Czech version is authoritative for Czech legal purposes.