Last updated: October 1, 2026
This Policy explains how personal data is processed when you use Scoutzy. Scoutzy is currently a free, non-commercial personal project operated by Karel Ježek; this does not reduce applicable data-protection rights.
This Policy is provided in clear language for account users and people answering public forms. An organisation using Scoutzy projects must give its own privacy information to the people whose records or form answers it manages.
Karel Ježek is the controller for Scoutzy account, security, service-administration, and support-correspondence data. Contact: [email protected]. Access to production data is limited to Karel Ježek and specifically authorised personnel with a service, support, or maintenance need.
For personal data entered into an organisation's project—including attendee, parent or guardian, event, attendance, inventory, project-user, inventory-holder and form-response data—the organisation is the controller and Scoutzy is its processor. Public respondents can submit answers without a Scoutzy account. Using a Team to administer project access does not change that responsibility. The organisation decides why the data is used and responds to those data subjects. The controller–processor obligations are in the Data Processing Agreement.
To create and use an account, you must provide a username, email address, password, and confirmation that you accept the Terms. Your phone number and profile-picture URL are optional. We also process the technical and security information needed to operate and protect the service. If you do not provide required account information, we cannot create or operate your account.
We use the information we collect to:
For account and service-administration data, our legal bases are performance of the free service requested by you, legitimate interests in securing and operating Scoutzy, and legal obligations where applicable. We do not treat acceptance of these Terms as GDPR consent for processing that relies on another basis. For project data, the organisation as controller determines the lawful basis and any Article 9 condition needed, including for people whose names are recorded as external inventory holders.
Scoutzy does not use profiling or make decisions about people based solely on automated processing that produce legal effects or similarly significant effects.
The live Scoutzy database and rolling technical backups are stored on a Contabo VPS in a selected EU region. Backups are limited to seven daily copies. This setup is not presented as separate disaster recovery.
Current measures include password hashing, HTTPS where the service is accessed over HTTPS, HTTP-only session cookies, login and reset rate limits, project roles with module-scoped access, Team project-access controls, additional protection for birth dates and parent or guardian contacts, limited production access, and minimised audit logs. No system can guarantee absolute security; measures are reviewed as the service develops.
Account data is kept while the account is active. Self-service account deletion removes memberships and reset tokens and erases or pseudonymises account information without deleting controller-owned project content; linked form answers lose the account link. Form responses are kept until the organisation deletes them, the form, the Forms module, or the project; each form states the organisation's chosen retention notice. Closing or archiving a form stops new answers but retains existing ones. A project owner may disable a module while retaining its data, or permanently delete that module’s data after explicit confirmation. An owner may also export a project and request its deletion; access stops immediately, live project data is permanently deleted after a 30-day recovery period, and it may remain in rolling backups for up to seven additional days. Expired reset tokens are removed promptly, invitations are removed after expiry or decline under the 30-day retention routine, and minimised audit logs are removed after 90 days. Support correspondence is reviewed and deleted manually within 12 months unless a longer period is necessary for a specific legal claim or obligation.
Hosted registrations may wait for manual approval. A pending applicant can request withdrawal and erasure through [email protected].
We do not sell personal data or use project data for advertising. A form's questions and organisation-provided notice become visible to anyone with its public link when the organisation chooses public sharing; responses remain available only to authorised project Admins and the Owner. Project logos and optional form images are loaded directly from image URLs chosen by the organisation, so the image host receives the visitor's IP address and standard request data. Data may otherwise be disclosed only as follows:
The current providers and their roles are also listed in the Data Processing Agreement:
You have the right to:
For account, security, or support data, email [email protected]; we may need to verify your identity. Requests about a form answer, attendee, guardian, checkout holder, or other project record should normally go to the organisation responsible for that project as controller; its contact is shown on each form. Scoutzy will reasonably assist the organisation under the Data Processing Agreement. You may complain to the Czech Data Protection Authority (Úřad pro ochranu osobních údajů) at uoou.gov.cz.
Accounts are available only to authorised staff aged 15 or older. A user aged 15–17 must have their organisation’s authorisation and any parent or guardian authorisation required for accepting these Terms. Public form respondents need no Scoutzy account and face no account age gate. Organisations remain responsible for any lawful basis, notices, consent, or safeguarding duties when collecting information from or about minors; Scoutzy does not decide these matters for them.
Because project data can include minors’ dates of birth and parent or guardian contact details, an organisation using Scoutzy may need to carry out a Data Protection Impact Assessment (DPIA) under Article 35 GDPR for its own processing. On request, Scoutzy will provide the organisation with the information reasonably necessary to support that assessment, consistent with the assistance obligations described in the Data Processing Agreement.
We may update this Policy for legal, security, provider, or service changes. The current version and date will be published here. Material processor changes are handled under the Data Processing Agreement.
If you have questions or concerns about this Privacy Policy, please contact us at:
For the current legal identity and contact details of the Scoutzy operator, see the Legal Notice.