Privacy policy

Effective from 22. 9. 2026

This Privacy Policy explains how Reconnect Foundation z.s. processes personal data of users of the RECONNECT 2026 application and related online services.

We process personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council ("GDPR"), applicable Czech data protection legislation and other applicable privacy laws.

1. Data controller

The data controller responsible for personal data processed through the RECONNECT 2026 application is:

Reconnect Foundation z.s.
Company ID (IČO): 23715197
Registered office: Štefánikova 95/24, 602 00 Brno, Czech Republic
Registered in the Register of Associations maintained by the Regional Court in Brno, Section L, File No. 31440

(the "Controller").

For questions concerning the processing of personal data, please contact us at: info@reconnect.cz

The Controller has not appointed a Data Protection Officer, as the appointment of a Data Protection Officer is not mandatory in view of the nature and scope of the processing carried out.

2. What personal data we process

The personal data we process depends on how you use the application.

2.1 Users without registration

If you use the application without creating an account, you may use features such as browsing the programme and saving favourite events.

Events marked as "My" may be stored locally on your device. In such cases, the Controller does not store this information on its servers or associate it with your identity.

For the technical operation of the application, however, certain necessary technical information may be processed, such as connection data, device information, browser information and operational logs.

2.2 Registered visitors

When you create a user account, we may process:

  • your email address;
  • your name or nickname, if provided;
  • information relating to your account;
  • events and other settings saved in the application;
  • technical and security information relating to the use of your account.

2.3 RECONNECT delegates

If you register as a RECONNECT delegate, we may process information provided during registration, including:

  • first and last name;
  • email address;
  • organisation or company;
  • professional position or role;
  • country;
  • accreditation-related information;
  • type of travel document, where required for the relevant purpose.

We may also process information that you voluntarily add to your delegate profile, including:

  • profile photograph;
  • professional biography;
  • links to websites and social media profiles;
  • other information you choose to make available as part of your profile.

As part of the networking functions, we may also process:

  • connection requests;
  • meeting requests;
  • information about scheduled meetings;
  • messages sent through the application;
  • information relating to the mutual exchange of contact details via QR code.

Please do not upload special categories of personal data within the meaning of Article 9 GDPR, or other sensitive personal information, unless the application expressly provides for such processing.

2.4 Newsletter

If you subscribe to the RECONNECT newsletter, we may process:

  • your email address;
  • your preferred language, where relevant;
  • information about your consent;
  • the date and time when consent was given and other technical information necessary to demonstrate valid consent.

2.5 Technical and security information

For the operation, security and protection of the application, we may process technical information such as:

  • IP address;
  • device and operating system information;
  • browser type and version;
  • login and logout times;
  • operational and security logs;
  • error and technical incident information.

We use this information primarily to ensure the availability, security and proper functioning of the application and to prevent misuse.

3. Why we process personal data and our legal bases

We process personal data only for specific and legitimate purposes.

3.1 Provision of application services

We process personal data in order to:

  • create and manage user accounts;
  • register and manage delegate accreditation;
  • provide access to the RECONNECT programme;
  • operate the delegate directory;
  • enable delegates to connect with one another;
  • send and receive messages;
  • arrange meetings;
  • exchange contact details;
  • send necessary email notifications relating to the use of the application.

The legal basis is performance of a contract or taking steps at your request prior to entering into a contract under Article 6(1)(b) GDPR.

3.2 Security and protection of the application

We may process personal data in order to:

  • protect the application against attacks and misuse;
  • prevent fraudulent or unauthorised activity;
  • resolve technical incidents;
  • protect users and the Controller;
  • ensure the security of our information systems.

The legal basis is our legitimate interest under Article 6(1)(f) GDPR.

3.3 Retention of delegate profiles for future RECONNECT editions

If you register as a delegate, we may retain your profile to a necessary extent after the current RECONNECT edition in order to:

  • maintain continuity of the professional directory;
  • facilitate ongoing networking between participants;
  • invite you to future RECONNECT editions;
  • contact you again in connection with RECONNECT.

The legal basis is the legitimate interest of the Controller under Article 6(1)(f) GDPR, in particular our interest in maintaining and developing a professional network within the music and creative industries.

You may object to this processing at any time. You may also request that your profile be hidden or permanently deleted.

3.4 Newsletter

We send the newsletter only on the basis of your consent under Article 6(1)(a) GDPR.

You may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

3.5 Analytics and marketing technologies

Where you provide the relevant consent through our cookie consent mechanism, we may use analytics and marketing technologies, including:

  • Google Analytics;
  • Google Ads / remarketing technologies.

These technologies may be used to measure traffic, analyse the use of the application and, where applicable, display RECONNECT-related advertising on other websites.

The legal basis is your consent under Article 6(1)(a) GDPR and applicable legislation governing cookies and similar technologies.

You may change or withdraw your consent at any time through Cookie Settings in the application.

4. Who can see your personal data

4.1 Delegate profiles

Delegate profiles are intended for professional networking and are accessible only to logged-in RECONNECT participants/delegates within the application.

You may hide your profile from the directory through the application where this function is available.

Information that you choose to publish in your profile will be available to other logged-in delegates.

4.2 Contact details

Your email address is not automatically disclosed to other delegates simply because you have created a profile.

Contact details may be disclosed to another delegate through the application's mutual contact exchange function when such an exchange takes place.

4.3 Messages and meetings

Messages sent through the application are intended for their respective recipient or recipients.

The Controller does not routinely access or process the content of messages for its own purposes. Technical access may nevertheless be possible to the extent necessary, in particular to ensure the operation of the service, resolve technical problems, investigate security incidents or misuse, or comply with a legal obligation.

4.4 Technical service providers

We use specialised technical and other service providers who may process personal data on our behalf to the extent necessary to provide their services. These include, in particular:

  • Base44 – the platform used to operate the application, including hosting, database, authentication and related technical services.
  • Google – analytics and marketing services, only to the extent permitted by your consent.
  • Mailchimp / The Rocket Science Group LLC (part of the Intuit group) – newsletter distribution.

Where applicable, we have entered into appropriate data processing agreements with processors in accordance with Article 28 GDPR.

4.5 Independent controllers

Some services related to RECONNECT may be operated by other entities acting as independent data controllers.

In particular, ticket and pass purchases through SMS Ticket are subject to the privacy practices of that provider. Personal data processed by SMS Ticket for the purposes of its own services is not processed by the Controller under this Privacy Policy.

5. Transfers of personal data outside the EU/EEA

Some of our technical service providers may process personal data or have access to personal data outside the European Economic Area, including in the United States.

Where this occurs, we ensure that transfers are carried out in accordance with the GDPR, including on the basis of:

  • an adequacy decision of the European Commission, where applicable, including the EU-U.S. Data Privacy Framework;
  • the European Commission's Standard Contractual Clauses (SCCs);
  • or another transfer mechanism permitted by the GDPR.

Individual service providers may maintain their own lists of sub-processors and provide additional information regarding international transfers in their contractual documentation and privacy policies.

6. How long we retain personal data

We retain personal data only for as long as necessary for the relevant purpose or for as long as required by applicable law.

Delegate profiles

Delegate profile information, including name, organisation, professional role, country, photograph, biography, links and contact details, may be retained for the purposes of continuing networking and preparing future RECONNECT editions, but no later than 31 December 2027, unless deleted earlier or you object to such processing.

You may object to this processing at any time or request deletion of your profile.

Messages, meetings and contact exchanges

Messages, meeting information and information relating to contact exchanges are retained until 31 January 2027, unless longer retention is necessary for security purposes, the handling of an incident, the establishment, exercise or defence of legal claims, or compliance with a legal obligation.

User accounts

Personal data relating to registered visitors is retained until the account is deleted, and in any event no later than 31 December 2027, unless longer retention is required for a legal reason.

Newsletter

Personal data used for newsletter distribution is retained until you withdraw your consent.

Information concerning the giving or withdrawal of consent may be retained for as long as necessary to demonstrate compliance with our legal obligations.

Technical and security logs

Technical and operational logs are retained for as long as necessary to ensure the secure operation and protection of the application, generally for a period of several weeks, unless longer retention is justified by a security incident, legal claim or legal obligation.

7. Cookies and local storage

The application may use cookies, local storage and similar technologies.

Strictly necessary technologies

Technologies that are strictly necessary for the operation of the application may be used without your consent where they are genuinely necessary to provide a service you have requested. These may include technologies used for:

  • maintaining your login session;
  • security functions;
  • language preferences;
  • storing your privacy preferences;
  • locally storing favourite events;
  • other technical functions necessary for the operation of the application.

Analytics and marketing technologies

Analytics and marketing cookies and similar technologies are used only with your prior consent.

These may include Google Analytics and Google technologies used for remarketing.

You may change or withdraw your consent at any time through Cookie Settings.

Refusing analytics or marketing technologies does not prevent you from using the basic functions of the application.

8. Security of personal data

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, loss, destruction or other misuse.

These measures include, where appropriate, access controls, secure data transmission, protection of user accounts and other security measures appropriate to the nature of the personal data processed and the risks associated with such processing.

Although we take reasonable measures to protect personal data, no transmission or storage of information over the internet can be guaranteed to be completely secure.

9. Your rights

Subject to the conditions set out in the GDPR, you have the right to:

  • obtain confirmation as to whether we process your personal data and access such data;
  • request correction of inaccurate or incomplete personal data;
  • request erasure of your personal data;
  • request restriction of processing;
  • receive your personal data in a structured, commonly used and machine-readable format and, where the relevant conditions are met, request its transfer to another controller;
  • object to processing based on our legitimate interests;
  • withdraw consent at any time where processing is based on consent;
  • not be subject to a decision based solely on automated processing, including profiling, where the conditions of Article 22 GDPR are met.

Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

If you object to processing based on our legitimate interests, we will stop processing your personal data for that purpose unless we can demonstrate compelling legitimate grounds for continuing the processing or the processing is necessary for the establishment, exercise or defence of legal claims.

10. How to exercise your rights

You can submit requests or questions concerning the processing of your personal data to: info@reconnect.cz

Please indicate which right you wish to exercise and, where relevant, which application or account your request concerns.

Where we have reasonable doubts concerning your identity, we may request additional information necessary to verify your identity.

We will respond without undue delay and, in principle, within one month of receiving your request. Where permitted by the GDPR, this period may be extended by a further two months. We will inform you of any such extension.

11. Right to lodge a complaint

If you believe that your personal data is being processed in breach of applicable data protection laws, you have the right to lodge a complaint with a supervisory authority. In the Czech Republic, the competent supervisory authority is:

Office for Personal Data Protection (Úřad pro ochranu osobních údajů)
Pplk. Sochora 27
170 00 Prague 7
Czech Republic
www.uoou.gov.cz

Lodging a complaint does not affect any other rights or remedies available to you.

12. Changes to this privacy policy

We may update this Privacy Policy from time to time, in particular in connection with changes to the application's functionality, technologies used or applicable legal requirements.

The current version of this Privacy Policy will always be available within the RECONNECT application.

Where a change has a significant impact on the way we process your personal data, we will take reasonable steps to inform you of the change.

Last updated: 22 September 2026

Cookies

We use cookies to understand how you use the app and to show you RECONNECT ads. Without consent we only store what is technically necessary. More