GDPR — Your Data Rights
In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) · 2026
Who We Are
ZORYX Team s.r.o. is the data controller within the meaning of GDPR Art. 4(7), responsible for the processing of personal data in connection with the ZORYX web application at zoryx.app and mobile application.
Data Protection Officer (DPO): Yauhen Zorych
DPO Email: yauhen.zorych@zoryx.app
General Contact: yauhen.zorych@zoryx.app
Phone: +420 776 540 503
Your Rights Under GDPR
📋 Right of Access (Art. 15)
You have the right to obtain confirmation of whether we process your personal data, and if so, to receive a copy of that data along with information about how and why it is processed.
✏️ Right to Rectification (Art. 16)
You have the right to have inaccurate personal data corrected without undue delay. This includes the right to have incomplete data completed.
🗑️ Right to Erasure — "Right to be Forgotten" (Art. 17)
You have the right to request the deletion of your personal data when: it is no longer necessary for the purpose it was collected, you withdraw consent, or it has been unlawfully processed.
⏸️ Right to Restriction of Processing (Art. 18)
You may request that we restrict processing of your data (i.e. store but not use it) while you contest its accuracy, while we assess your objection, or if processing is unlawful but you do not want erasure.
📦 Right to Data Portability (Art. 20)
Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your data in a structured, commonly used, machine-readable format (e.g. JSON).
🚫 Right to Object (Art. 21)
You have the right to object at any time to processing of your data that is based on legitimate interest, including profiling. We will cease processing unless we demonstrate compelling legitimate grounds.
↩️ Right to Withdraw Consent
Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before the withdrawal.
How to Exercise Your Rights
Send a request to our DPO at yauhen.zorych@zoryx.app. Please include:
- Your name or identifier used in the service (e.g. review pseudonym)
- The specific right you wish to exercise
- Any relevant details (e.g. clinic you reviewed, date of submission)
We will respond within 30 days. In complex cases, we may extend this by a further 2 months and will inform you accordingly.
Data Processing Purposes & Bases
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Displaying clinic reviews | Name, rating, comment | Consent (6.1.a) |
| Donor lead collection | Phone number | Consent (6.1.a) |
| Service analytics | IP (anonymised), device, pages | Legitimate interest (6.1.f) |
| AI chatbot responses | Chat messages (not stored) | Legitimate interest (6.1.f) |
| Security & fraud prevention | IP address, request rate | Legitimate interest (6.1.f) |
Supervisory Authority
You have the right to lodge a complaint with the Czech supervisory authority:
Úřad pro ochranu osobních údajů (ÚOOÚ)
Pplk. Sochora 27, 170 00 Praha 7
Web: www.uoou.cz
Email: posta@uoou.cz