Privacy policy
Last revised: September 25, 2026
Sichh is an online platform with offers of work, courses and services. To run it we process personal data of people who create an account here and, to the extent necessary, of those who only browse the catalogue. Below is what that data is, why we process it and what rights you have.
Who processes the data
The data controller is [DOPLNIT: název provozovatele], company ID [DOPLNIT: IČO], registered at [DOPLNIT: sídlo].
For anything concerning personal data write to [DOPLNIT: e-mail]. We have not appointed a data protection officer - Art. 37 GDPR does not require us to.
What data we process
Depending on what you do on Sichh:
- Account: email, first and last name, phone, language, role (worker or company), password (stored only as a hash that cannot be turned back into the password), registration date and last sign-in.
- Worker profile: photo, description, trades, years of experience, languages, documents, city and your CV if you upload one.
- Company profile: name, company ID, type of entity, address, contacts, logo, description, links to social networks and data from the ARES register (registered name, address and whether the entity is still active). For self-employed individuals this is personal data.
- Listings, applications and enquiries, and messages between the company and the worker or customer.
- Company reviews and company replies, reports about listings and reviews and how they were resolved.
- Saved searches, saved listings and email notification settings.
- In the mobile app: the device identifier for push notifications and the device language.
- Technical data: IP address and browser details recorded at every sign-in, kept for account security.
- Server logs: IP address, time and page address of every request. They are kept by the hosting provider for operation and security, including for visitors without an account.
Where the data comes from
You give us most of the data yourself. We complete company and self-employed details from the Czech public register ARES using the company ID you enter. Some data may come from other users: reviews of your company, messages they write to you, or a report about your content.
Why, and on what legal basis
- Running your account, publishing listings, connecting the parties, messages and notifications about activity in your account (new application, message, invitation, decision about a listing) - performance of a contract (Art. 6(1)(b) GDPR). The service cannot be provided without this data.
- Checking the company ID in ARES and re-checking it regularly, checking listings and reviews, account security and preventing abuse - our legitimate interest in protecting users from non-existent companies and fraudulent listings (Art. 6(1)(f) GDPR).
- Handling reports of illegal content and giving reasons for content decisions - legal obligation under the Digital Services Act (Art. 6(1)(c) GDPR).
- Publishing reviews with the author's first name and initial - the legitimate interest of other users in learning about people's experience with a company (Art. 6(1)(f) GDPR).
- Email alerts about new listings matching a saved search - your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time in account settings or via the link in the email footer.
- Issuing and keeping tax documents for paid services - legal obligation (Art. 6(1)(c) GDPR).
Who receives the data
When you apply to a listing or send an enquiry, the company that published it sees your profile, contact details and CV if you uploaded one. That is the whole point of the service, but it is worth knowing up front: an application means handing your data to that particular company, which then handles it as a controller in its own right.
Without an application, only you can see your worker profile, unless you switch on the option that lets other companies see it too. Company profiles, listings and reviews with the author's first name and initial are public - visible to anyone, even without an account. Depending on the company's settings, its contact details may be visible only to people it has invited.
The site administrator has access to all data, including messages. They look into messages only when handling a report or a suspicion of abuse.
Data is processed on our behalf by technical suppliers: server and database hosting, website hosting, email delivery, storage of uploaded files and push notification delivery, and for notifications in the mobile app also Apple and Google. All of them are bound by a data processing agreement; we will send you the list of specific suppliers on request.
We do not sell data to anyone and do not pass it on for advertising. We provide it to public authorities only where the law requires us to.
Transfers outside the European Union
Data is stored on servers in the European Union. Some suppliers, however, are US companies and may access the data from there. Such transfers rely on the European Commission's adequacy decision (EU-US Data Privacy Framework) and, where a supplier is not certified, on standard contractual clauses approved by the Commission. We will send you a copy of these safeguards on request.
How long we keep it
- Account data and everything attached to it - for as long as the account exists.
- Once you delete the account, the data is erased immediately, including uploaded files and the applications, messages and reviews you wrote. It cannot be restored. Anything a company saved from your application outside Sichh (a downloaded CV, for example) is then in its hands.
- IP address and browser details from sign-ins - no longer than 30 days, then erased together with the sign-in token.
- Copies of sent emails and push notifications - 30 days after sending, to deal with delivery problems.
- Device identifier for push notifications - for as long as you use the app; once the service stops recognising it (after you uninstall the app, for example), we erase it.
- Server logs at the hosting provider - [DOPLNIT: doba uchování záznamů].
- Tax documents are kept for 10 years as the Czech VAT Act requires. This applies after the account is deleted as well.
Your rights
You have the right of access to your data, to have it corrected or erased, to restriction of processing, to data portability and to withdraw consent. Withdrawing consent does not affect processing carried out before the withdrawal.
Right to object: you can object at any time, on grounds relating to your particular situation, to processing based on legitimate interest. We will then stop processing unless we demonstrate compelling legitimate grounds that override your interests, or need the data to establish or defend legal claims.
Two rights you exercise yourself, right away: in account settings you can download all your data as a JSON file and delete your account for good in the same place. For the rest write to our email. We reply within one month; for complex requests the period may extend to three months, but we will tell you in advance.
If you believe we handle your data wrongly, you can complain to the supervisory authority: Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, uoou.cz.
Automated decision-making
We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you (Art. 22 GDPR), and we do not profile you. Automated content checks - company ID verification, listing text checks, the profanity filter and temporary hiding of a listing after reports - are described in the Terms of use. Blocking accounts and permanently removing content is always done by a person.
Cookies
We only use cookies the site cannot work without: sign-in and language choice. There are no tracking, analytics or advertising cookies on Sichh, and we do not embed third-party elements that would set them. Details are on the separate cookies page.
Security
Passwords are stored only as a hash (Argon2id), connections run over HTTPS, and sign-in is held by cookies that scripts on the page cannot read. Emails and push notifications do not contain the text of messages or reviews. Only the operator has access to the database. If a data breach occurs that poses a high risk to you, we will let you know without undue delay.
Age
A Sichh account is for people aged 15 and over. Do not create one for anybody younger; if we find that an account belongs to a younger child, we delete it.
Changes
We may change this text when what happens to the data changes. The date of the last revision is shown at the top; we will email you about any substantial change.

