Privacy notice — Longevity Prezident
This notice explains what the Longevity Prezident health portal (https://app.karlovyvary.info) does with your personal data, on what legal basis, and how you stay in control of it.
It covers the portal only — the account, the health questionnaire, the walks and the watch. Booking a room, staying at the hotel and the hotel newsletter are covered by the hotel's own privacy policy: https://www.hotelprezident.cz/ru/zasady-ochrany-osobnich-udaju/
1. Who is responsible
The controller is HOTEL PREZIDENT - Šárová s.r.o., IČO 447 96 242, VAT ID CZ44796242, registered seat Sluneční 385/21, 360 04 Karlovy Vary, Česká republika, entered in the commercial register kept by Krajský soud v Plzni, oddíl C, vložka 16421.
The portal belongs to the wellness programme of Medical Wellness Hotel Prezident, Moravská 3, 360 01 Karlovy Vary.
Questions about your data, and any request under the rights listed in section 9: gdpr@hotelprezident.cz, +420 355 319 111.
We have appointed an external data protection officer. You can reach them directly at gdpr@hotelprezident.cz — including if you would rather not write to the hotel.
2. What we collect
- Account — e-mail, first and last name, interface language, password (stored only as a PBKDF2 hash, never in readable form). If you sign in with Google we receive your e-mail, name and Google account identifier — never your password.
- Health questionnaire — age band, weight, height, the resulting BMI, your answers about the eleven health areas (including cardiovascular, metabolic, neurological, oncological, psychological problems, medication, alcohol and physical activity), the calculated score and risk level.
- Walks — start time, duration, distance, GPS track, heart rate, elevation, pace, calories and steps, whether recorded by a Garmin watch, imported from a .FIT file or recorded by your phone's browser.
- Longevity profile — sex, year of birth, waist, resting and maximum heart rate, VO₂max reported by the watch.
- Drinking cure — the spring, dose and schedule prescribed by the spa doctor, your note of each serving taken, and whether you were at the spring (checked by GPS proximity, ~120 m).
- Watch pairing — a six-character code that links your watch to your account. No password is ever entered on the watch.
- Garmin Connect link, only if you set one up — the identifier of your Garmin account and the access keys that let us receive your walks. We ask Garmin for walking activities and nothing else: no sleep, no stress, no continuous daily monitoring. You may disconnect in your account at any time, which stops any further transfer.
- Technical data — the IP address in the server log, and the address that requested a password reset.
3. Health data
Most of section 2 is data about your health — a special category under Article 9 GDPR. We process it only with your explicit consent, given by a separate tick before the questionnaire, and for no purpose other than the ones in section 4.
You may withdraw that consent at any time in your account. Withdrawal stops further processing and, at your choice, deletes what is already stored; it does not affect what was lawful before.
The portal does not diagnose and does not prescribe. The risk level is a screening figure for choosing a walking route. The drinking cure is prescribed by the hotel's chief physician, MUDr. Milada Šárová, after an examination; the portal only stores and displays it.
4. Why we process it, and on what basis
- Running your account (sign-in, password recovery) — performance of a contract, Art. 6(1)(b).
- Assessing your risk level and assigning a walking route — your explicit consent, Art. 6(1)(a) and Art. 9(2)(a).
- Recording walks and showing your progress — the same consent.
- Letting the spa doctor see your results in order to advise you and prescribe the drinking cure — the same consent; Art. 9(2)(h) where a treatment relationship exists.
- Keeping the service secure (logs, abuse prevention) — our legitimate interest in a working, non-abused service, Art. 6(1)(f).
5. Automated evaluation
The risk level and the recommended heart-rate zone are calculated automatically from your answers, by the scoring rules of the hotel's spa programme. The result changes which routes are suggested to you — nothing else. It produces no legal effect, decides nothing about your treatment, and any spa doctor may override it. You can ask us to explain any figure you were shown.
6. Who else sees it
Your data is not sold, not shared for advertising, not used to train models, and not passed to anyone except:
- the hotel's chief physician, MUDr. Milada Šárová, and the portal administrator — bound by medical confidentiality, and only for the purposes in section 4;
- our hosting provider — Hostinger International Ltd., as a processor, for keeping the server running in its German datacentre;
- Google — only if you choose to sign in with Google, and only the sign-in itself;
- our mail provider — only the address and the message when we send you a password reset;
- Garmin — if, and only if, you linked your Garmin account: the connection is made with your own Garmin login, we never see your Garmin password, and the data travels from Garmin to us rather than the other way round;
- map tile servers (OpenStreetMap Foundation, and mapy.com if enabled) — when a map is drawn, your browser requests tiles from them directly and they see your IP address. Your track is never sent to them.
7. Where it is stored
On our own server at Hostinger International Ltd., in a datacentre in Germany — inside the European Union. We do not transfer your data outside the EEA. The only exception is Google sign-in, if you use it, which runs under Google's own terms.
The portal has no advertising and no analytics trackers. The browser stores only what the portal itself needs to work — your session token and interface language.
8. How long we keep it
- Account — until you delete it.
- Questionnaires, walks, longevity profile, drinking cure — 3 years after your last activity, or until you withdraw consent or delete your account, whichever comes first.
- Password reset tickets — 60 minutes, then only as a used marker.
- Server logs — up to 90 days.
- Deletion is real deletion from the database, not hiding. Anything we must keep by law (accounting, if you were also a paying guest) is kept by the hotel under its own policy, not here.
9. Your rights
You have the right to access your data, to correct it, to have it erased, to restrict or object to processing, to receive it in a portable machine-readable form, and to withdraw any consent at any time.
Two of these work as buttons in your account, with no waiting: Download my data gives you everything we hold about you as a JSON file, and Delete my account erases the account together with the questionnaires, walks, profile and prescriptions. For anything else write to gdpr@hotelprezident.cz; we answer within one month.
If you believe we handle your data unlawfully you may complain to the supervisory authority: Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, Česká republika, uoou.gov.cz.
10. How it is protected
All traffic runs over HTTPS. Passwords are stored as PBKDF2 hashes and password reset links only as a SHA-256 of the token, so a leaked database hands out neither. Guest and administrator roles are separated in the API: a guest can only ever reach their own records, and only an administrator account held by the spa doctor can prescribe a drinking cure.
11. Children
The portal is meant for adults. Do not create an account for anyone under 16.
12. Changes
This is version 1.1 of 2026-07-27. If we change what we do with your data, we raise the version and ask for your consent again the next time you sign in. Earlier versions are available on request.