Privacy
🇨🇿 Read in CzechLast updated: 19 August 2026
The short version
There are no analytics, no advertising, no third-party trackers and no cookie banner — because there is nothing to consent to. We collect the least we can get away with, and we say exactly what that is below.
Who is the controller
OmNexis s.r.o., IČO 02800888, Pražská 69/17, 273 43 Buštěhrad, Czech Republic, is the controller of personal data processed through chci.eu. You can reach us at info@omnexis.com.
We have not appointed a Data Protection Officer. Our processing is not large-scale, is not systematic monitoring, and does not involve special categories of data, so Article 37 GDPR does not require one.
What we process, why, and on what basis
your email address, the content of your submission, and a salted hash of your IP address. The email lets us come back to you if a submission is unclear; the IP hash enforces the daily submission limit that keeps the site usable. Legal basis: our legitimate interest in running a moderated catalogue and preventing abuse (Article 6(1)(f) GDPR). The raw IP address is never stored — only an irreversible salted hash — and the hash is deleted after 30 days.
your email address, display name, profile picture URL and language, received from Google, plus a record of the entries you like. Legal basis: performance of the agreement to provide you an account (Article 6(1)(b) GDPR). You can delete the account at any time by writing to us.
our web server records the IP address, time, requested address, response code and browser identification for each request, as every web server does. These are kept for 14 days and used only to diagnose faults and identify attacks. Legal basis: legitimate interest in the security and stability of the service (Article 6(1)(f)).
We do not build profiles, we do not track you across sites, we do not sell or share data for advertising, and there is no automated decision-making with legal effect under Article 22 GDPR.
Cookies
chci.eu sets two cookies, both strictly necessary or explicitly requested by you, which is why no consent banner appears:
— set only when you sign in, so you stay signed in. Deleted when you sign out.— set only when you pick a language, so your choice survives the next click. Expires after one year.
Neither cookie is used to track, profile or advertise. Under section 89(3) of Czech Act No. 127/2005 Coll. and the ePrivacy Directive, cookies that are strictly necessary to provide a service the user has requested do not require consent.
Who else sees the data
- — hosting, as our processor, in the EU.
- — only if you choose to sign in with Google. In that case Google processes your sign-in as an independent controller under its own privacy policy, and tells us your email address, name and profile picture. Google may transfer data to the United States; it participates in the EU–US Data Privacy Framework, which the European Commission has recognised as providing an adequate level of protection. If you would rather not involve Google, simply do not use that button — everything except liking entries works without an account.
We use no other processors, and we transfer data to no one else. We do not sell data to anyone, at any price.
How long we keep things
- Submission emails and content: kept while the entry is live, so the record of where it came from survives. Rejected submissions are kept for 12 months and then deleted.
- IP hashes: 30 days.
- Web server logs: 14 days.
- Account data: until you delete the account.
Your rights
Under the GDPR you may ask us for access to your data, for its rectification or erasure, for restriction of processing, for portability, and you may object to processing based on legitimate interest. Where processing rests on consent, you may withdraw it at any time without affecting what was done beforehand.
Write to info@omnexis.com and we will answer within one month. We do not charge for this.
If you think we have handled your data badly, you can complain to the Úřad pro ochranu osobních údajů (ÚOOÚ), Pplk. Sochora 27, 170 00 Praha 7, www.uoou.cz.
Security and breaches
The site runs on a hardened server inside the EU, over TLS only, with passwords stored as scrypt hashes and IP addresses only ever as salted hashes. Backups stay on the same EU infrastructure.
If a breach occurs that is likely to result in a risk to your rights, we will report it to the ÚOOÚ within 72 hours and tell you directly where the risk is high, as Articles 33 and 34 GDPR require.
Children
This site is not directed at children and we do not knowingly collect data from them. An account requires a Google account, which has its own age requirements.
This page is available in English and Czech. The Czech version is authoritative for Czech legal purposes.