New in Our Offer
Improve Your Mobility and Fitness

This 8-day stay is designed for those who wish to address their health concerns early, effectively, and without long waiting times.

see more
Arrival
Departure
Adults
Promo code

Privacy Policy (GDPR)

This policy explains how Reitenberger, s.r.o. processes personal data of website visitors and clients.

1. Data Controller

The data controller is:

Reitenberger, s.r.o.
Michelská 300/60, 140 00 Prague, Czech Republic
Company ID (IČO): 27940861
Email: tomas.barak@reitenberger.cz
Phone:+420731454001

2. What personal data we process

We process only the data you provide to us or that is generated when you use our website, typically:

  • identification and contact details (name, email, phone),
  • data related to your stay reservation and requested services,
  • billing details and information necessary for payments and accounting,
  • communications (content of messages sent via forms or email),
  • technical data (IP address, cookies, device/browser information).

Special categories of data (health data)

In connection with spa services, health-related information may be processed. We process such data only to the extent necessary and with increased protection.

3. Purposes and legal bases

3.1 Reservations and service delivery

Purpose: handling reservations, entering into and performing contracts, providing accommodation and spa services, handling changes and complaints.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and, where applicable, Art. 6(1)(c) GDPR (legal obligation).

3.2 Health data (spa services)

Purpose: providing spa/health-related services.

Legal basis: Art. 9(2)(h) GDPR (health or social care/services) together with the relevant legal basis under Art. 6 GDPR (typically contract performance or legal obligation).

3.3 Contact and enquiry forms

Purpose: responding to enquiries sent via the website.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in communicating with prospects and clients) or Art. 6(1)(b) GDPR (steps prior to entering into a contract).

3.4 Compliance with legal obligations

Purpose: accounting, tax obligations, archiving of records and other statutory duties.

Legal basis: Art. 6(1)(c) GDPR (legal obligation).

3.5 CCTV

Purpose: protection of property, safety of persons and prevention of unlawful conduct.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest).

3.6 Website analytics (Google Analytics)

Purpose: measuring and improving website performance and user experience.

Legal basis: consent for analytics cookies (typically Art. 6(1)(a) GDPR), granted via the cookie banner (cookie settings).

4. Reservations via Bookolo

Online reservations are provided through the external booking system Bookolo. When you proceed to the booking form, your personal data may also be processed by this provider under its own terms (as an independent controller or processor).

We recommend reviewing Bookolo’s privacy information.

5. Data retention

  • reservation/contract data: for the duration of the contract and as long as necessary afterwards,
  • accounting and tax records: for the period required by law (often up to 10 years),
  • enquiries and communication: for as long as necessary to handle and document the request,
  • CCTV recordings: only as long as necessary, typically a matter of days, unless needed for an incident,
  • analytics cookies: depending on your cookie settings and individual cookie lifetimes.

6. Recipients of personal data

Your personal data may be shared, to the extent necessary, with:

  • IT and hosting providers,
  • the booking system provider (Bookolo),
  • accountants and tax advisors,
  • public authorities where required by law.

We have appropriate data processing agreements in place with our processors.

7. Transfers outside the EEA

In connection with Google Analytics, data may be transferred outside the European Economic Area. Such transfers are governed by the provider’s terms and your cookie/consent settings.

8. Cookies

We use cookies to ensure website functionality and for analytics (Google Analytics). Optional cookies can be accepted or rejected via the cookie banner (cookie settings). Some functional cookies may be necessary for the website to work properly.

9. Your rights

You have the right to:

  • access your personal data (Art. 15 GDPR),
  • rectification (Art. 16 GDPR),
  • erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • object to processing based on legitimate interest (Art. 21 GDPR),
  • withdraw consent at any time (where processing is based on consent),
  • lodge a complaint with the supervisory authority.

The supervisory authority in the Czech Republic is the Office for Personal Data Protection.

10. How to exercise your rights

To exercise your rights, please contact us at tomas.barak@reitenberger.cz. We may request identity verification to prevent unauthorized access.

11. Security

We apply appropriate technical and organizational measures to protect personal data against loss, misuse and unauthorized access.

12. Updates

We may update this policy from time to time. The current version is always available on this page.

Last updated: 19 February 2026

Reitenberger Spa Medical
Ibsenova 92, 353 01 Mariánské Lázně
Czech Republic
Cookie settings Privacy policy