Why does the information enter?
Name the user task, purpose, minimum fields, notice, choice, and any sensitive or high-risk information. Avoid collecting identifiers “just in case.” Validate Czech characters and allow correction where accuracy matters.
Who can see or change it?
Define roles around the job rather than organisational prestige. Separate routine use, administration, support, exports, and emergency access. Log important changes without turning logs into an unmanaged second dataset.
Which services receive a copy?
Inventory hosting, email, analytics, error monitoring, payments, identity, backups, AI tools, and support platforms. Record locations, subprocessors, remote access, transfer questions, contractual ownership, and a replacement plan.
When does the record stop being useful?
Set retention around the actual workflow. Account closure, abandoned requests, backups, exports, support attachments, and legal holds may need separate clocks. Deletion must be testable rather than a sentence in a policy.
Who handles a request or incident?
Assign intake, identity checks, search, correction, export, deletion, escalation, security investigation, and communication. The technical system should help the responsible people act; it does not decide their obligations.
Analytics is part of the same drawing.
This microsite uses its own GA4 property to measure visits and voluntary phone or email actions. Separate measurement helps reporting, but it does not erase any notice, consent, transfer, retention, or vendor decision that applies. Additional advertising or profiling tools are not implied by this setup.