Privacy notice — Longevity Prezident
This notice explains what the Longevity Prezident health portal (https://app.karlovyvary.info) does with your personal data, on what legal basis, and how you stay in control of it.
It covers the portal only — the account, the health questionnaire, the walks and the watch. Booking a room, staying at the hotel and the hotel newsletter are covered by the hotel's own privacy policy: https://www.hotelprezident.cz/ru/zasady-ochrany-osobnich-udaju/
1. Who is responsible
The controller is HOTEL PREZIDENT - Šárová s.r.o., IČO 447 96 242, VAT ID CZ44796242, registered seat Sluneční 385/21, 360 04 Karlovy Vary, Česká republika, entered in the commercial register kept by Krajský soud v Plzni, oddíl C, vložka 16421.
The portal belongs to the wellness programme of Medical Wellness Hotel Prezident, Moravská 3, 360 01 Karlovy Vary.
Questions about your data, and any request under the rights listed in section 9: danyuk@hotelprezident.cz, +420 355 319 111.
We have appointed an external data protection officer. You can reach them directly at gdpr@hotelprezident.cz — including if you would rather not write to the hotel.
2. What we collect
- Account — e-mail, first and last name, interface language, password (stored only as a PBKDF2 hash, never in readable form). If you sign in with Google we receive your e-mail, name and Google account identifier — never your password. When the reception desk issues you a hotel watch kit, we also record your room number and, if you give one, a contact phone with the messenger you prefer (WhatsApp or Telegram) — for the length of the stay.
- Health questionnaire — age band, weight, height, the resulting BMI, your answers about the eleven health areas (including cardiovascular, metabolic, neurological, oncological, psychological problems, medication, alcohol and physical activity), the calculated score and risk level.
- Walks — start time, duration, distance, GPS track, heart rate, elevation, pace, calories and steps, whether recorded by a Garmin watch, imported from a .FIT file or recorded by your phone's browser.
- Longevity profile — sex, date of birth, height, weight, which wrist you wear the watch on, waist, resting and maximum heart rate, VO₂max reported by the watch.
- Drinking cure — the spring, dose and schedule prescribed by the spa doctor, your note of each serving taken, and whether you were at the spring (checked by GPS proximity, ~120 m).
- Food diary — what you write down about a meal: the dish, the hour, the calories and the protein, fat and carbohydrates, either typed by you or estimated from a photograph. If you photograph a meal, the photograph itself is stored on our server together with the entry, and it is sent to the provider of the AI model to be counted (section 6). Photograph the plate, not the people around it: whatever is in the frame is stored with it.
- Watch pairing — a six-character code that links your watch to your account. No password is ever entered on the watch.
- Garmin Connect link, only if you set one up with your own account — the identifier of your Garmin account and the access keys that let us receive your walks. From your own account we ask Garmin for walking activities and nothing else: no sleep, no stress, no continuous daily monitoring. You may disconnect in your account at any time, which stops any further transfer.
- Daily states, only if you were lent a watch by the hotel — sleep (duration, phases, score), night-time pulse variability, stress, Body Battery, resting and daily pulse, breathing rate, blood oxygen, steps and calories. These are read from the Garmin account that belongs to the hotel and to which the lent watch is paired, for the days of your stay only. If the scales in your room are connected ones paired to that same hotel account, your weigh-ins arrive the same way: the weight, and — where the scales measure it — body fat, muscle mass, body water and bone mass. They are shown to you in your cabinet and to the spa doctor, and they stay on your card after the watch is returned — see section 8.
- Technical data — the IP address in the server log, and the address that requested a password reset.
3. Health data
Most of section 2 is data about your health — a special category under Article 9 GDPR. We process it only with your explicit consent, given by a separate tick before the questionnaire, and for no purpose other than the ones in section 4.
You may withdraw that consent at any time in your account. Withdrawal stops further processing and, at your choice, deletes what is already stored; it does not affect what was lawful before.
The portal does not diagnose and does not prescribe. The risk level is a screening figure for choosing a walking route. The drinking cure is prescribed by the hotel's chief physician, MUDr. Milada Šárová, after an examination; the portal only stores and displays it.
4. Why we process it, and on what basis
- Running your account (sign-in, password recovery) — performance of a contract, Art. 6(1)(b).
- Assessing your risk level and assigning a walking route — your explicit consent, Art. 6(1)(a) and Art. 9(2)(a).
- Recording walks and showing your progress — the same consent.
- Reading the daily states of a watch lent to you, to follow how you tolerate the programme and to adjust it — the same consent, which you may withdraw at any time; the watch can also simply be returned.
- Keeping your food diary, and estimating the calories of a meal you photographed — your explicit consent, Art. 6(1)(a) and Art. 9(2)(a). What you eat during a treatment programme is health data like the rest of section 2, and the diary exists so that you and the spa doctor can see the day whole.
- Letting the spa doctor see your results in order to advise you and prescribe the drinking cure — the same consent; Art. 9(2)(h) where a treatment relationship exists.
- Sending your own figures to your e-mail each morning, if you ask for it — a separate, explicit consent you give by switching the letters on, and withdraw by one click in any of them.
- Keeping the service secure (logs, abuse prevention) — our legitimate interest in a working, non-abused service, Art. 6(1)(f).
5. Automated evaluation
The risk level and the recommended heart-rate zone are calculated automatically from your answers, by the scoring rules of the hotel's spa programme. The result changes which routes are suggested to you — nothing else. It produces no legal effect, decides nothing about your treatment, and any spa doctor may override it. You can ask us to explain any figure you were shown. Some of what the portal writes for you is put into words by an artificial-intelligence model: the wording of the morning summary, the translation of a message from the doctor, the background of a walk postcard. The model is given figures and facts the portal already holds, and it decides nothing — not your risk level, not your pulse zone, not your programme. Section 6 says what is sent, to whom, and on what condition. The same model estimates the calories of a meal you photograph. That figure is an estimate read off a picture, not a measurement: the portal shows it with a range and you can correct it. Nothing in the portal prescribes a diet — what you should eat during a treatment programme is decided by the spa doctor and the dietitian.
6. Who else sees it
Your data is not sold, not shared for advertising, not used to train models, and not passed to anyone except:
- the hotel's chief physician, MUDr. Milada Šárová, and the portal administrator — bound by medical confidentiality, and only for the purposes in section 4;
- our hosting provider — Hostinger International Ltd., as a processor, for keeping the server running in its German datacentre;
- Google — only if you choose to sign in with Google, and only the sign-in itself;
- our mail provider — the address and the message: a password reset, and, only if you switched the daily letters on, the figures they carry. E-mail is not a confidential channel, which is why those letters are off unless you ask for them and can be stopped from inside any of them;
- Garmin — if you linked your own Garmin account: the connection is made with your own Garmin login, we never see your Garmin password, and the data travels from Garmin to us rather than the other way round. If instead you were lent a hotel watch, the account it syncs to belongs to the hotel and carries a neutral watch number, not your name: so that the watch computes calories and pulse zones correctly, we write into that hotel account your sex, year of birth (as January 1st — the exact date never leaves the portal), height, weight and watch wrist, and your measurements sync into it while you wear the watch, as do the readings of the connected scales in your room;
- the provider of the AI model — Google, and only while the hotel keeps that feature switched on: to put your morning summary into words, to translate a message the doctor wrote for you, to draw the background of a walk postcard, and to estimate the calories of a meal you photographed. The summary is stripped of identity before it travels: it carries your age, your sex and the figures, and never your name, your date of birth or your e-mail address. A message from the doctor travels as written, because that is what has to be translated. A photograph of a meal travels as taken, with no name attached, and is sent only when you press the camera button. None of this is sent at all until the hotel has confirmed a data-processing agreement with the provider that forbids reuse and model training;
- map tile servers (OpenStreetMap Foundation, and mapy.com if enabled) — when a map is drawn, your browser requests tiles from them directly and they see your IP address. Your track is never sent to them.
7. Where it is stored
On our own server at Hostinger International Ltd., in a datacentre in Germany — inside the European Union. Your data leaves that server in exactly three cases, all of them named in section 6: Google sign-in, if you use it; the Garmin account a lent watch syncs into, which belongs to Garmin and lives on Garmin's servers in the United States under Garmin's own terms; and the depersonalised summary sent to the AI provider while that feature is switched on. For those transfers we rely on the standard contractual clauses of the recipient and, for the watch account, on the explicit consent you gave for the watch (Art. 49(1)(a) GDPR). Nothing else goes anywhere.
The portal has no advertising and no analytics trackers. The browser stores only what the portal itself needs to work — your session token and interface language.
8. How long we keep it
- Account — until you delete it.
- Questionnaires, walks, longevity profile, drinking cure — 3 years after your last activity, or until you withdraw consent or delete your account, whichever comes first.
- Food diary, and the photographs in it — the same 3 years as the rest of your health data, or until you withdraw consent or delete your account. A photograph is deleted together with its entry, from the disk and not only from the list, the moment you delete that meal.
- Daily states from a lent watch — they stay on your card after the watch is returned, so that on your next stay your history continues; like the rest of your health data, at most 3 years after your last activity, and gone the moment you withdraw consent or delete the account. The kit itself is erased before it goes to anybody else: the next guest cannot see your data on it, and its recorded walks and weigh-ins are deleted from the hotel's Garmin account. One thing we cannot delete there is the daily history itself: Garmin offers no way to remove sleep, stress, pulse or steps from an account. Those days stay in the hotel's Garmin account, under Garmin's own terms, even after we have erased our own copy — nobody is shown them, because the portal only ever reads the days of the stay of the guest who is holding that kit. If you want them gone from Garmin as well, write to danyuk@hotelprezident.cz: we pass the request on and tell you what Garmin answers.
- Password reset tickets — 60 minutes, then only as a used marker.
- Server logs — up to 90 days.
- Deletion is real deletion from the database, not hiding. Anything we must keep by law (accounting, if you were also a paying guest) is kept by the hotel under its own policy, not here.
9. Your rights
You have the right to access your data, to correct it, to have it erased, to restrict or object to processing, to receive it in a portable machine-readable form, and to withdraw any consent at any time.
Two of these work as buttons in your account, with no waiting: Download my data gives you everything we hold about you as a JSON file, and Delete my account erases the account together with the questionnaires, walks, profile and prescriptions. For anything else write to danyuk@hotelprezident.cz; we answer within one month.
If you believe we handle your data unlawfully you may complain to the supervisory authority: Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, Česká republika, uoou.gov.cz.
10. How it is protected
All traffic runs over HTTPS. Passwords are stored as PBKDF2 hashes and password reset links only as a SHA-256 of the token, so a leaked database hands out neither. Guest and administrator roles are separated in the API: a guest can only ever reach their own records, and only an administrator account held by the spa doctor can prescribe a drinking cure.
11. Children
The portal is meant for adults. Do not create an account for anyone under 16.
12. Changes
This is version 1.7 of 2026-08-17. If we change what we do with your data, we raise the version and ask for your consent again the next time you sign in. Earlier versions are available on request.