Privacy notice — Longevity Prezident

1.7 · 2026-08-17

This notice explains what the Longevity Prezident health portal (https://app.karlovyvary.info) does with your personal data, on what legal basis, and how you stay in control of it.

It covers the portal only — the account, the health questionnaire, the walks and the watch. Booking a room, staying at the hotel and the hotel newsletter are covered by the hotel's own privacy policy: https://www.hotelprezident.cz/ru/zasady-ochrany-osobnich-udaju/

1. Who is responsible

The controller is HOTEL PREZIDENT - Šárová s.r.o., IČO 447 96 242, VAT ID CZ44796242, registered seat Sluneční 385/21, 360 04 Karlovy Vary, Česká republika, entered in the commercial register kept by Krajský soud v Plzni, oddíl C, vložka 16421.

The portal belongs to the wellness programme of Medical Wellness Hotel Prezident, Moravská 3, 360 01 Karlovy Vary.

Questions about your data, and any request under the rights listed in section 9: danyuk@hotelprezident.cz, +420 355 319 111.

We have appointed an external data protection officer. You can reach them directly at gdpr@hotelprezident.cz — including if you would rather not write to the hotel.

2. What we collect

3. Health data

Most of section 2 is data about your health — a special category under Article 9 GDPR. We process it only with your explicit consent, given by a separate tick before the questionnaire, and for no purpose other than the ones in section 4.

You may withdraw that consent at any time in your account. Withdrawal stops further processing and, at your choice, deletes what is already stored; it does not affect what was lawful before.

The portal does not diagnose and does not prescribe. The risk level is a screening figure for choosing a walking route. The drinking cure is prescribed by the hotel's chief physician, MUDr. Milada Šárová, after an examination; the portal only stores and displays it.

4. Why we process it, and on what basis

5. Automated evaluation

The risk level and the recommended heart-rate zone are calculated automatically from your answers, by the scoring rules of the hotel's spa programme. The result changes which routes are suggested to you — nothing else. It produces no legal effect, decides nothing about your treatment, and any spa doctor may override it. You can ask us to explain any figure you were shown. Some of what the portal writes for you is put into words by an artificial-intelligence model: the wording of the morning summary, the translation of a message from the doctor, the background of a walk postcard. The model is given figures and facts the portal already holds, and it decides nothing — not your risk level, not your pulse zone, not your programme. Section 6 says what is sent, to whom, and on what condition. The same model estimates the calories of a meal you photograph. That figure is an estimate read off a picture, not a measurement: the portal shows it with a range and you can correct it. Nothing in the portal prescribes a diet — what you should eat during a treatment programme is decided by the spa doctor and the dietitian.

6. Who else sees it

Your data is not sold, not shared for advertising, not used to train models, and not passed to anyone except:

7. Where it is stored

On our own server at Hostinger International Ltd., in a datacentre in Germany — inside the European Union. Your data leaves that server in exactly three cases, all of them named in section 6: Google sign-in, if you use it; the Garmin account a lent watch syncs into, which belongs to Garmin and lives on Garmin's servers in the United States under Garmin's own terms; and the depersonalised summary sent to the AI provider while that feature is switched on. For those transfers we rely on the standard contractual clauses of the recipient and, for the watch account, on the explicit consent you gave for the watch (Art. 49(1)(a) GDPR). Nothing else goes anywhere.

The portal has no advertising and no analytics trackers. The browser stores only what the portal itself needs to work — your session token and interface language.

8. How long we keep it

9. Your rights

You have the right to access your data, to correct it, to have it erased, to restrict or object to processing, to receive it in a portable machine-readable form, and to withdraw any consent at any time.

Two of these work as buttons in your account, with no waiting: Download my data gives you everything we hold about you as a JSON file, and Delete my account erases the account together with the questionnaires, walks, profile and prescriptions. For anything else write to danyuk@hotelprezident.cz; we answer within one month.

If you believe we handle your data unlawfully you may complain to the supervisory authority: Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, Česká republika, uoou.gov.cz.

10. How it is protected

All traffic runs over HTTPS. Passwords are stored as PBKDF2 hashes and password reset links only as a SHA-256 of the token, so a leaked database hands out neither. Guest and administrator roles are separated in the API: a guest can only ever reach their own records, and only an administrator account held by the spa doctor can prescribe a drinking cure.

11. Children

The portal is meant for adults. Do not create an account for anyone under 16.

12. Changes

This is version 1.7 of 2026-08-17. If we change what we do with your data, we raise the version and ask for your consent again the next time you sign in. Earlier versions are available on request.

HOTEL PREZIDENT - Šárová s.r.o. · danyuk@hotelprezident.cz