Personal Data Processing Policy of Černá kostka, contributory organisation

(effective as of 13 April 2026)

PDF version

Update 10 September 2026

1. Introduction

Černá kostka, contributory organisation (the Controller) owns all rights and authorizations to:

  • the website of Černá kostka, contributory organisation available at https://www.cerna-kostka.cz/ and short-term and long-term online projects and applications running on subdomains cerna.fun,

  • the platform for AI innovation and education available at https://cerna.ai/ and short-term and long-term online projects and applications running on subdomains cerna.ai and on the domains and subdomains cernaaifestival.cz and aiakcemsk.cz

  • the website of the Moravian-Silesian Film Office available at https://www.filminnorthmoravia.com/,

  • the website of the project „Černá je podnikavá!“ of Černá kostka, contributory organisation, available at https://podnikava.cerna-kostka.cz/.

(hereinafter referred to as the Systems).

Černá kostka, contributory organisation processes the personal data of all users of the Systems who are natural persons (data subjects), regardless of whether these users use the Systems for their business or not (data subjects). Černá kostka, contributory organisation processes all personal data primarily for the purpose of providing the Systems services and for purposes related thereto.

Černá kostka, contributory organisation, ensures that the processing of personal data is lawful, fair, transparent, accurate, confidential, and that personal data is processed only to the extent necessary.

Černá kostka, contributory organisation, also ensures that personal data is properly secured and that all rules set out in the General Data Protection Regulation (hereinafter referred to as the „GDPR“) as well as other legal regulations in the field of handling and protecting personal data are complied with when processing personal data, and at the same time that all rules from the perspective of cybersecurity are complied with, both general regulations and recommendations, and specific requirements of System users resulting from their obligations.

More detailed information about the scope and method of processing personal data is provided in other articles of these policies.

2. Scope of personal data processed

Černá kostka, contributory organisation, processes in particular the identification and contact data of data subjects (name, surname, title, business name, identification number, tax identification number, place of residence, registered office, telephone number, e-mail address) and other personal data that data subjects enter into the Systems. The scope of the processed data is always determined by the personal data controller.

In addition, Černá kostka, contributory organisation, may in some cases also process personal data of a technical nature, such as cookies, IP address or other online identifiers, GPS location, etc. More detailed information about cookies can be found in this document below in the section Cookie information.

3. Position of controller vs. processor of personal data

For transparent information of personal data subjects, it is necessary to distinguish in what situation Černá kostka, contributory organisation, is in a specific situation towards personal data subjects. And whether it is the position of personal data controller or personal data processor (or another personal data processor in the case of so-called chaining).

3.1. Identification and contact details

Identification data of Černá kostka, contributory organisation, Company ID: 19581921, with its registered office at 28. října 2771/117, 702 00 Ostrava, Czech Republic, organization registered in the Commercial Register kept by the Regional Court in Ostrava, section Pr, insert 5380.

A representative of Černá kostka, contributory organisation, can be contacted in particular as follows:

  • Electronically (by e-mail)

  • In writing (correspondence address)

    • Černá kostka, contributory organisation, Pivovarská 1503/6, 702 00 Ostrava, Czech Republic

3.2. Data Protection Officer

On 1 June 2025, Černá kostka, contributory organisation, appointed its Data Protection Officer (hereinafter referred to as the “DPO”). Since 1 January 2026, this has been:

  • Name and surname of the officer: Ing. Soňa Macíčková

  • Contact details of the officer: e-mail: dpo@cerna-kostka.cz

3.3. Controller or processor of personal data

Černá kostka, contributory organisation, may be in the following positions from the perspective of personal data protection, always in relation to the purpose and legal basis for processing personal data.

A detailed breakdown of this position is provided in the following chapters, the basic division of the position is therefore:

  • Controller of personal data - in the case of ordinary browsing of the System from the perspective of the end user, displaying information pages, creating and administering a user account (without reservations).

  • Personal data processor - in the case of processing personal data on the basis of instructions from the controller - in particular based on a license agreement between Černá kostka, contributory organisation and the client of Černá kostka, contributory organisation. This concerns in particular the process of offering free dates of a specific service provider (i.e. the client of Černá kostka, contributory organisation) and the subsequent processes of creating and managing reservations.

  • Another personal data processor - or sub-processor, is a specific position where Černá kostka, contributory organisation, has concluded a license agreement with a processor that has its own license agreement with the controller. Černá kostka, contributory organisation, therefore provides the system as a subcontractor.

4. Purpose and legal basis for processing

4.1. Providing system services

Černá kostka, contributory organisation, processes personal data primarily for the purpose of providing the Systems services.

Černá kostka, contributory organisation, provides the systems on the basis of a license agreement. The processing of personal data for the purpose of providing the Systems services is therefore the processing of personal data for the purpose of concluding a license agreement and fulfilling the rights and obligations arising from the concluded license agreement. This processing is a necessary condition for providing the Systems services, where the specific purpose of the processing is determined by the controller (the subscriber of the system). Without such processing of personal data, Černá kostka, contributory organisation, could not provide the Systems services to users. In this case, Černá kostka, contributory organisation, is in the position of a processor (or another processor - depending on the parameters of the specific license agreement).

The processing of personal data for the above-mentioned purpose may be carried out by Černá kostka, contributory organisation, without any consent of the data subjects. The legal basis for this processing is the processing necessary for the performance of a contract to which the data subject is a party, or for taking measures prior to entering into a contract at the request of the data subject (see Article 6(1)(b) GDPR).

4.2. Setting up and maintaining a user account

A user account is a necessary condition for using some services of the Systems operated by the Controller. Černá kostka, contributory organisation, therefore assumes that each data subject who creates a user account is interested in using the Systems services at least temporarily. Even with free or trial use of the Systems services, a license agreement is concluded.

General business/operating conditions for the Systems are available at https://www.cerna-kostka.cz/storage/terms-and-conditions.pdf.

With regard to the above, Černá kostka, contributory organisation, will also process personal data for the purpose of setting up and maintaining a user account.

The legal basis for this processing is the processing necessary for the performance of a contract to which the data subject is a party, or for taking measures prior to entering into a contract at the request of the data subject (see Article 6(1)(b) GDPR).

4.3. Fulfillment of legal obligations of Černá kostka, contributory organisation

Černá kostka, contributory organisation, also processes personal data for the purpose of fulfilling its legal obligations.

These are in particular legal obligations arising for Černá kostka, contributory organisation, in particular from accounting and tax laws (e.g. the VAT Act). In addition, Černá kostka, contributory organisation, is obliged to be able to demonstrate that it processes personal data in accordance with generally binding legal regulations, in particular in accordance with the GDPR. This purpose of processing personal data also falls under the fulfillment of the legal obligations of Černá kostka, contributory organisation.

The processing of personal data for the above-mentioned purpose may also be carried out by Černá kostka, contributory organisation, without any consent of the data subjects. The legal basis for this processing is the fulfillment of a legal obligation to which Černá kostka, contributory organisation, as the controller of personal data, is subject (see Article 6(1)(c) GDPR).

4.4. Legitimate interests of Černá kostka, contributory organisation

Černá kostka, contributory organisation, is also authorized to process personal data for the purpose of:

  • customer records;

  • analysis of the use of the Systems by its users;

  • determination, exercise or defense of legal claims (in particular legal claims arising from a concluded license agreement).

The processing of personal data for any of the above purposes may be carried out by Černá kostka, contributory organisation, without any consent of the data subjects. The legal basis for this processing is the legitimate interest of Černá kostka, contributory organisation (see Article 6(1)(f) GDPR).

This processing is not possible only in cases where the interests or fundamental rights and freedoms of the data subjects requiring the protection of personal data take precedence over the interests of Černá kostka, contributory organisation.

A data subject may object at any time to the processing of personal data on the basis of the legitimate interest of Černá kostka, contributory organisation (see Article 21 GDPR).

4.5. Consent of data subjects

On the basis of consent to the processing of personal data, Černá kostka, contributory organisation, is authorized to process personal data for any purpose specified in the relevant consent. The legal basis for this processing is the consent of the data subjects to the processing of personal data (see Article 6(1)(a) GDPR).

Granting consent to the processing of personal data is entirely voluntary. Any failure to grant consent will not have any adverse consequences for the data subject.

Each data subject has the right to withdraw consent to the processing of personal data at any time, in particular:

  • by electronic notification sent to the e-mail address dpo@cerna-kostka.cz

  • by written notification sent to the address of the registered office of Černá kostka, contributory organisation

The withdrawal of consent does not affect the lawfulness of the processing of personal data in the period before the withdrawal of consent on the basis of which the processing of personal data was carried out.

5. Direct marketing

5.1. In general

Processing of personal data for direct marketing purposes means processing of personal data for the purpose of sending commercial communications within the meaning of Act No. 480/2004 Coll., on certain information society services, as amended (hereinafter referred to as „Act No. 480/2004 Coll.“).

A commercial communication is any form of communication, including advertising and encouragement to visit the website of an online store, intended to directly or indirectly promote goods or services or the image of Černá kostka, contributory organisation (hereinafter referred to as the „Communication“).

The possibility of sending commercial communications may be regulated (limited) by a specific license agreement between Černá kostka, contributory organisation, and the service provider that uses the System on the basis of the given license agreement.

5.2. Method of sending messages

The processing of personal data for the purpose of sending Communications may be carried out by Černá kostka, contributory organisation, on the basis of the existence of a legitimate interest (see recital 47 GDPR). Likewise, the sending of Communications itself may be carried out by Černá kostka, contributory organisation, without consent (in accordance with Section 7(3) of Act No. 480/2004 Coll.), unless the data subject originally refused it (e.g. by ticking the box „I do not want to receive any e-mails from Černá kostka, contributory organisation“).

5.3. End of processing

Černá kostka, contributory organisation, will terminate the processing of personal data for direct marketing purposes without undue delay after the data subject expresses disagreement with such processing. Disagreement may be expressed, for example, in one of the following ways:

  • by unsubscribing from Communications (which is possible in every Communication);

  • by objecting to such processing (under the conditions of Article 21 of the GDPR).

Notwithstanding the above, Černá kostka, contributory organisation, will terminate the processing of personal data for direct marketing purposes no later than 2 years from the last active use of the System or login to the user account (whichever is later). Each active use of the System or login to the user account extends the processing period by another 2 years.

6. Categories of recipients of personal data

The recipient of personal data is anyone to whom Černá kostka, contributory organisation, provides personal data in connection with the above-mentioned purposes of processing personal data.

Černá kostka, contributory organisation, may provide personal data in particular to recipients whose services it uses, in particular, within the framework of the operation and maintenance of the System. These include entities providing accounting, printing and postal services, legal services, IT services, cloud services, services for sending Communications or operators of payment gateways and systems, etc.

These recipients will process personal data either as independent controllers (i.e. as entities that themselves determine the purposes and means of processing personal data, independently of Černá kostka, contributory organisation), or as processors (i.e. entities that process personal data for Černá kostka, contributory organisation, on the basis of its instructions).

In addition, Černá kostka, contributory organisation, will provide personal data to public authorities if this obligation is or will be imposed on it by generally binding legal regulations. However, public authorities exercising their investigative powers are not considered recipients.

6.1. Other processors of personal data and third parties to whom personal data is transferred

The specific other processors of personal data and third parties to whom personal data is transferred, whose services Černá kostka, contributory organisation, uses within the systems (or which are used directly by the data subject when using the systems' product), are in particular the following recipients of personal data:

  • Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, providing the reCaptcha Enterprise security feature.

  • Seznam.cz, a.s., Radlická 3294/10, 150 00 Prague 5, Company ID: 26168685, VAT number: CZ26168685, for the Sklik marketing channel.

  • The Rocket Science Group, LLC, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA, providing the Mailchimp email service.

  • Meta Platforms, Inc., One Hacker Way Menlo Park, CA 94025, USA, for advertising purposes on Meta's social media.

  • The Openstreetmap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom, providing map data for displaying the addresses of Černá kostka, contributory organisation, and the addresses of individual service providers.

  • Bankovní identita, a.s., Smrčkova 2485/4, 180 00 Prague 8 – Libeň, Company ID: 09513817, VAT number: CZ09513817, digital user verification provided by banks for identifying system users.

  • Perfect System, s.r.o., Radlická 3301/68, 150 00 Prague 5, Company ID: 26480981, operator of the ColosseumTIcket.cz portal, providing ticket sales for cultural and entertainment events and information about various cultural events.

  • Ecomail.cz, s.r.o., Na Příkopě 388/1, 110 00 Prague 1, Company ID: 02762943, providing email marketing.

  • Eventee s.r.o., Kopečná 940/14, 602 00 Brno, Company ID: 29307236, providing a platform for managing and organising events.

  • Wix.com Ltd., Nemal St. 40, Tel Aviv, Israel, providing web services.

  • Webvalley s.r.o., Janáčkova 1089/20, 702 00 Ostrava-Moravská Ostrava, providing web services.

  • Moodle Pty Ltd, Level 2, 88 Musk Avenue, Kelvin Grove QLD 4059, Australia, providing the Moodle e‑learning platform for online education and courses.

  • OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland, providing an AI service.

  • Railsformers s.r.o., Vřesinská 2371/33, 708 00 Ostrava-Poruba, Company ID: 24704440, as a provider of development, operational and hosting services.

  • Lovable Labs Sweden AB, Tunnelgatan 5, 11137 Stockholm, Sweden, providing a platform for building and operating web applications.

  • DBMA LTD (operating under the SuperScout and Tutti brands), 131 Finsbury Pavement, London EC2A 1NT, United Kingdom, providing online platforms and AI tools for searching, sharing and managing creative spaces and locations.

7. Personal data processing time

Černá kostka, contributory organisation, will process personal data only for the period necessary for the purpose of processing, but generally for a maximum of 2 years. The termination of one of the legal bases for processing personal data does not affect the processing of personal data (to the extent necessary) based on another legal basis (and for the relevant purpose).

The period of processing personal data may be regulated by a specific license agreement between Černá kostka, contributory organisation, and the service provider that uses the System on the basis of the given license agreement.

7.1. Providing system services

For the purpose of providing System services (fulfillment of the license agreement), Černá kostka, contributory organisation, will process personal data at least for the duration of the obligation under the license agreement.

7.2. Setting up and maintaining a user account

The user account can be cancelled at any time together with the termination of the use of the System services, based on a request to cancel the user account sent to one of the contact addresses listed in Article 3 above (in particular, the e-mail addresses dpo@cerna-kostka.cz and info@cerna-kostka.cz). In the event of termination of the use of services in any of the Systems, Černá kostka, contributory organisation, will terminate the processing of personal data entered into the user account no later than 2 years from the termination of the obligation under the license agreement (termination of use of the System) or from the last login to the user account, if the data subject is no longer using the System.

If the data subject has never started using the System services (e.g. has only created a user account), Černá kostka, contributory organisation, will cancel his/her user account and stop processing personal data entered into the user account immediately upon receipt and confirmation of an e-mail request sent to one of the contact addresses listed in Article 3 above, or no later than 2 years from the last login to the user account.

7.3. Fulfillment of legal obligations of Černá kostka, contributory organisation

For this purpose, in order to fulfill legal obligations, Černá kostka, contributory organisation, will process personal data for the duration of the relevant legal obligation, as set out in generally binding legal regulations (e.g. tax documents containing personal data must be stored by Černá kostka, contributory organisation, for a period of 2 years).

7.4. Legitimate interests of Černá kostka, contributory organisation

For the purpose of direct marketing (sending Communications), Černá kostka, contributory organisation, will process personal data until the time of expressing disagreement with such processing, but no longer than 2 years from the last termination of obligations under the license agreement (termination of use of the System) or logging into the customer account if the data subject does not use the System.

For the purpose of customer registration, Černá kostka, contributory organisation, will process personal data for a period of 2 years from the termination of obligations under the license agreement (termination of use of the System) or logging into the customer account, if the data subject does not use the System.

In order to analyze the use of the System by its users, Černá kostka, contributory organisation, will process personal data for a period of 2 years from the user's last login.

For the purpose of determining, exercising or defending legal claims, Černá kostka, contributory organisation, will process personal data for the duration of the relevant legal claim, but for a maximum period of 1 year after the expiry of the limitation period according to generally binding legal regulations. In the event of the initiation and duration of judicial, administrative or any other proceedings in which the rights or obligations arising from the relevant legal claim are addressed, the period of processing personal data for this purpose will not end before the final conclusion of such proceedings.

7.5. Consent of data subjects

For the purpose specified in the relevant consent to the processing of personal data (if the data subject has granted such consent to Černá kostka, contributory organisation), Černá kostka, contributory organisation, will process personal data until the consent is revoked, otherwise for a maximum of 2 years from the moment of granting consent to the processing of personal data.

8. Rights of data subjects

Each data subject has, among others, the following rights:

  • the right to access personal data (under the conditions of Article 15 of the GDPR)

  • the right to rectify personal data (under the conditions of Article 16 GDPR)

  • the right to erasure of personal data (under the conditions of Article 17 of the GDPR)

  • the right to restrict the processing of personal data (under the conditions of Article 18 GDPR)

  • the right to object to processing (under the conditions of Article 21 GDPR)

  • the right to data portability (under the terms of Article 20 GDPR)

  • the right to file a complaint with the supervisory authority (i.e. the Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, e-mail posta@uoou.cz)

  • the right to withdraw consent to the processing of personal data

9. Cookie information

We, Černá kostka, contributory organisation, ID number: 19581921, with our registered office at 28. října 2771/117, 702 00 Ostrava, Czech Republic, entered in the Commercial Register kept by the Regional Court in Ostrava, section Pr, insert 5380, as the controller, processor or other processor (depending on the specific situation) of personal data, would like to inform you that for the purpose of:

  • measuring website traffic,

  • creating statistics regarding the traffic to our websites and the behavior of visitors to our websites,

  • the proper functioning of our websites,

  • adapting our websites to your needs,

  • finding out which pages and features visitors to our website use most often,

  • improving the use of our servers,

we use small amounts of data that are stored on your end device (so-called cookies). You can learn more about cookies, for example, from the following sources of information:

Cookies are used by almost every website in the world, and in general, they are a useful service because they increase the user-friendliness of a repeatedly visited website (they allow your computer to remember the pages you have visited and your preferred settings for each page).

9.1. Advertising cookies

Cookies are used to improve your user experience on websites by allowing websites to identify your browser, either for the duration of your visit (using session cookies) or for repeat visits (using persistent cookies). This is useful, for example, when displaying your shopping cart, browsing history, hiding commercial messages, logging in, etc.

Our website also uses cookies for behaviorally targeted advertising, which allows us to tailor advertising to ensure it is relevant to you, based on the areas you view on our website and the geographic location of your IP address. These cookies are placed by third-party advertising networks with our consent.

We use the following cookies on our website:

  • Technical – first-party, short-term. They ensure basic technical functionality of the website, i.e. logging in, remembering settings, using services, etc.

  • Statistical and diagnostic (e.g. Google Analytics) – first-party, long-term. They are used to generate anonymous statistics about the use of the website. We use them to better customize the site for you. In Google Analytics, we only use those analytical functions that do not collect data necessary for profiling website users (age, gender, interests, IP address, etc.).

  • Advertising, first and third party. These are cookies of advertising systems of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4 - Ireland, Seznam.cz a.s., Radlická 3294/10, Prague 5 - Smíchov 150 00 and Meta Platforms Ireland Limited, Inc. 1601 Willow Rd, Menlo Park, CA 94025 (third party, long-term). These cookies are used for marketing profiling. Thanks to them, we are able to stay in touch with you, for example, through personalized advertising on social networks. They are used for targeted advertising, whether repeated (remarketing, retargeting) or behavioral. That is, if advertising must be displayed (as the main income for the website and the creation of its content), then the user/reader should be shown offers that may actually interest them.

9.2. General cookies

You can set up the comprehensive use of cookies using your internet browser. Most internet browsers automatically accept cookies by default. However, you can refuse cookies by adjusting your internet browser settings. You can find more information about how to do this on the following pages:

At the same time, in accordance with applicable legislation, we allow you to approve the use of all cookies, or select them (with the exception of necessary technical cookies) according to your preferences directly in the system.

However, technical cookies that are necessary for the functionality of our website will only be kept for the time strictly necessary for the functioning of the website.

You can object to the processing of cookies under the terms of Article 21 of the GDPR. You can send your objection to Černá kostka, contributory organisation, or its Data Protection Officer via one of the contact addresses listed in Article 3 of this Policy. If you object to the processing of technical cookies, the full functionality and compatibility of our website cannot be guaranteed.

Cookies that are collected for the purpose of measuring traffic to our websites and creating statistics regarding their traffic and visitor behavior on the websites are processed in an almost anonymized form, which allows your identification, but only with considerable and professional effort.

All cookies are stored for the period specified below for each type of cookie.

The collected cookies may be processed by other processors:

As part of the optional simplified registration or login to user systems, these processors may also (when using the so-called Single Sign-On system by the aforementioned processors) create and handle additional cookies in accordance with their contractual terms and conditions available here:

In accordance with the GDPR, you have the following rights from a cookie perspective - see Article 8 of this Personal Data Processing Policy - Rights of data subjects.

For other cookie arrangements, we follow our personal data processing policy set out in the previous chapters of this document.

9.3. List of cookies for individual systems

The list of cookies that may (but may not, depending on the functions of the System used by the personal data subject) be processed in the systems is provided in the following subchapters for individual Systems.

You can change your cookie settings at any time in the cookie settings in the footer or on the Systems pages.

9.3.1. Cookies for the System https://www.cerna-kostka.cz/

Necessary technical cookies

Name

Expiration

Who has access to the information (us or another processor)

Description

Security

cernakostka_session

1 day

us

Web application session cookie – ensuring website functionality and maintaining the user session.

Secure=yes; HttpOnly=yes; SameSite=Lax

XSRF-TOKEN

session

us

Protection against CSRF attacks (secure submission of forms/requests).

HttpOnly=yes (according to the listing); SameSite=Lax

cc_cookie

1 year

us

Storing and proving cookie consent choices (category, date, consent UUID, revision).

HttpOnly=yes; SameSite=Lax

Analytical cookies

Name

Expiration

Who has access to the information (us or another processor)

Description

Security

_ga

2 years

us, third party (Google Ireland Limited)

Google Analytics 4 – user differentiation for traffic measurement.

Medium level

_ga_MMKFCQ18PN

2 years

us, third party (Google Ireland Limited)

GA4 cookie to store session information and statistics for a specific tracking ID.

Medium level

Marketing/advertising cookies

Name

Expiration

Who has access to the information (us or another processor)

Description

Security

_fbp

1 day

us, third party (Meta Platforms Ireland Limited)

Meta Pixel – browser identifier for measurement/remarketing and attribution (if marketing is enabled).

SameSite=Lax; Medium level

APISID

1 year

us, third party (Google Ireland Limited)

Google identifier – security and functionality of Google services (reCAPTCHA/YouTube/Maps), and personalization depending on context.

High level

SAPISID

1 year

us, third party (Google Ireland Limited)

Identification/security (and, depending on the context, personalization) of Google services (YouTube/Maps).

High level

HSID

1 year

us, third party (Google Ireland Limited)

Google security cookie (protection against abuse).

Secure=yes; High level

SID

1 year

us, third party (Google Ireland Limited)

Google security/identification cookie.

High level

SSID

1 year

us, third party (Google Ireland Limited)

Google security/identification cookie.

Secure=yes; HttpOnly=yes; High level

NID

6 months

us, third party (Google Ireland Limited)

Saving preferences and (depending on settings) personalization in Google services, often in connection with YouTube.

Secure=yes; HttpOnly=yes; SameSite=None; Medium level

__Secure-1PAPISID

1 year

us, third party (Google Ireland Limited)

Security and identification within Google services.

Secure=yes; High level

__Secure-1PSID

1 year

us, third party (Google Ireland Limited)

Google security/identification cookie.

Secure=yes; HttpOnly=yes; High level

__Secure-3PAPISID

1 year

us, third party (Google Ireland Limited)

3rd party Google identifier (YouTube/Google services) – personalization according to settings.

Secure=yes; SameSite=None; High level

__Secure-3PSID

1 year

us, third party (Google Ireland Limited)

3rd party Google identifier – contextual personalization/security.

Secure=yes; HttpOnly=yes; SameSite=None; High level

9.3.2. Cookies for the System https://cerna.ai/

Necessary technical cookies

Name

Expiration

Who has access to the information (us or another processor)

Description

Security

CookieScriptConsent

1 month

us

This cookie is used by the Cookie-Script.com service to remember visitors' cookie consent preferences. It is necessary for the Cookie-Script.com cookie banner to work properly.

High – contains no personal data, transmitted encrypted (HTTPS)

Analytical cookies

Name

Expiration

Who has access to the information (us or another processor)

Description

Security

_ga

1 month, 1 year

us, third party (Google Ireland Limited)

Google Analytics 4 – user differentiation for traffic measurement.

High – contains only a random ID, contains neither name nor e-mail

_ga_C8GWXJEGWJ

1 month, 1 year

us, third party (Google Ireland Limited)

GA4 cookie to store session information and statistics for a specific tracking ID.

High – anonymous session identifier, encrypted transmission

Marketing/advertising cookies

Name

Expiration

Who has access to the information (us or another processor)

Description

Security

IDA

1 year

us, third party (Meta Platforms Ireland Limited)

Behaviour tracking for advertising targeting.

Standard – third-party tracking cookie, transmitted over SSL/TLS.

_gcl_au

3 months

us, third party (Google Ireland Limited)

Google conversion linker / attribution – storing information for measuring campaign effectiveness and attributing conversions (depending on tag settings).

Medium level

9.3.3. Cookies for the System https://www.filminnorthmoravia.com/

Necessary technical cookies

Name

Expiration

Who has access to the information (us or another processor)

Description

Security

XSRF-TOKEN

Session

third party (Wix)

Cookie for detecting fraudulent calls (protection against CSRF).

Yes – security cookie

hs

Session

third party (Wix)

Security cookie for Hive (legacy).

Yes – security cookie

svSession

12 months

third party (Wix)

Cookie for security, stability and basic website functions.

Yes – security cookie

SSR-caching

24 hours

third party (Wix)

Performance cookie for page rendering (server-side rendering).

-

bSession

24 hours

third party (Wix)

Cookie for measuring system efficiency.

-

server-session-bind

Session

third party (Wix)

API protection cookie.

Yes – security cookie

wixLanguage

6 months

third party (Wix)

Stores the visitor's preferred language.

-

client-session-bind

Session

third party (Wix)

API protection cookie.

Yes – security cookie

Analytical cookies

Name

Expiration

Who has access to the information (us or another processor)

Description

Security

_ga

2027-03-30

us, third party (Google Ireland Limited)

Google Analytics 4 – user differentiation for traffic measurement.

(the listing does not mention Secure/HttpOnly); Medium level

_ga_MMKFCQ18PN

2027-03-30

us, third party (Google Ireland Limited)

GA4 cookie to store session information and statistics for a specific tracking ID.

(the listing does not mention Secure/HttpOnly); Medium level

Marketing/advertising cookies

Name

Expiration

Who has access to the information (us or another processor)

Description

Security

_fbp

2026-05-24

us, third party (Meta Platforms Ireland Limited)

Meta Pixel – browser identifier for measurement/remarketing and attribution (if marketing is enabled).

SameSite=Lax; Medium level

APISID

2027-03-30

us, third party (Google Ireland Limited)

Google identifier – security and functionality of Google services (reCAPTCHA/YouTube/Maps), and personalization depending on context.

High level

SAPISID

2027-03-30

us, third party (Google Ireland Limited)

Identification/security (and, depending on the context, personalization) of Google services (YouTube/Maps).

High level

HSID

2027-03-30

us, third party (Google Ireland Limited)

Google security cookie (protection against abuse).

Secure=yes; High level

SID

2027-03-30

us, third party (Google Ireland Limited)

Google security/identification cookie.

High level

SSID

2027-03-30

us, third party (Google Ireland Limited)

Google security/identification cookie.

Secure=yes; HttpOnly=yes; High level

NID

2026-08-25

us, third party (Google Ireland Limited)

Saving preferences and (depending on settings) personalization in Google services, often in connection with YouTube.

Secure=yes; HttpOnly=yes; SameSite=None; Medium level

__Secure-1PAPISID

2027-03-30

us, third party (Google Ireland Limited)

Security and identification within Google services.

Secure=yes; High level

__Secure-1PSID

2027-03-30

us, third party (Google Ireland Limited)

Google security/identification cookie.

Secure=yes; HttpOnly=yes; High level

__Secure-3PAPISID

2027-03-30

us, third party (Google Ireland Limited)

3rd party Google identifier (YouTube/Google services) – personalization according to settings.

Secure=yes; SameSite=None; High level

__Secure-3PSID

2027-03-30

us, third party (Google Ireland Limited)

3rd party Google identifier – contextual personalization/security.

Secure=yes; HttpOnly=yes; SameSite=None; High level

9.3.4. Cookies for the System https://aiakcemsk.cz/

Necessary technical cookies

Name

Expiration

Who has access to the information (us or another processor)

Description

Security

__cf_bm

30 minutes

us, third party (Cloudflare, Inc, Lovable Labs Incorporated)

Used to support Cloudflare bot management. Helps distinguish genuine visitors from malicious or suspicious requests, thereby protecting the website.

Secure, HttpOnly, Medium level

session-id

30 minutes

us, third party (Lovable Labs Incorporated)

Session cookies are used by the server to store information about the user's activities on the site so that they can easily continue where they left off.

Secure, Medium level

sp_t

1 year

us, third party (Lovable Labs Incorporated + Spotify AB)

It is required to ensure the functionality of the integrated Spotify plugin.

Secure, Medium level

sp_landing

1 day

us, third party (Lovable Labs Incorporated + Spotify AB)

It is required to ensure the functionality of the integrated Spotify plugin.

Secure, HttpOnly, Medium level

Analytical cookies

Name

Expiration

Who has access to the information (us or another processor)

Description

Security

_ga

400 days

us, third party (Google Ireland Limited)

Google Analytics 4 – user differentiation for traffic measurement.

(the listing does not mention Secure/HttpOnly); Medium level

_ga_W7ESC2VE3G

400 days

us, third party (Google Ireland Limited)

GA4 cookie to store session information and statistics for a specific tracking ID.

(the listing does not mention Secure/HttpOnly); Medium level

9.3.5. Cookies for the System https://cernaaifestival.cz/

Necessary technical cookies

Name

Expiration

Who has access to the information (us or another processor)

Description

Security

cc_cookie

1 hour

us

It saves the user's choice regarding cookie consent and prevents the cookie banner from being displayed repeatedly.

Secure, Medium level

Analytical cookies

Name

Expiration

Who has access to the information (us or another processor)

Description

Security

_ga

400 days

us, third party (Google Ireland Limited)

Google Analytics 4 – user differentiation for traffic measurement.

(the listing does not mention Secure/HttpOnly); Medium level

_ga_00LSSLEQ23

400 days

us, third party (Google Ireland Limited)

GA4 cookie to store session information and statistics for a specific tracking ID.

(the listing does not mention Secure/HttpOnly); Medium level

9.3.6. Cookies for the System https://podnikava.cerna-kostka.cz/

Necessary technical cookies

Name

Expiration

Who has access to the information (us or another processor)

Description

Security

cc_cookie

1 hour

us

It saves the user's choice regarding cookie consent and prevents the cookie banner from being displayed repeatedly.

Secure, Medium level

Analytical cookies

Name

Expiration

Who has access to the information (us or another processor)

Description

Security

_ga

2 years

us, third party (Google Ireland Limited)

Google Analytics 4 – user differentiation for traffic measurement.

Medium level

_ga_MVF8NVBEFX

2 years

us, third party (Google Ireland Limited)

GA4 cookie to store session information and statistics for a specific tracking ID.

Medium level

10. Cooperation with the professional community

Černá kostka, contributory organisation, also consults with representatives of the professional community on aspects of personal data protection. Subsequently, Černá kostka, contributory organisation, implements processes and procedures to improve organizational and technical measures leading to adequate protection of personal data. Representatives of the professional community are highly professional entities for personal data protection:

You can read more about the collaboration here:

11. Further information on the processing of personal data

In case of questions regarding the processing of personal data or in case of exercising the rights of the data subject specified in Article 8 of these principles, Černá kostka, contributory organisation, or its Data Protection Officer can be contacted via one of the contact addresses specified in Article 3 of these principles.

General information about the processing of personal data can also be found on the website of the Office for Personal Data Protection available at www.uoou.cz.

This Policy became effective on 13 April 2026.

Want more information?

icon at info@cerna-kostka.cz

Don't miss more news

Odesláním formuláře souhlasíte se zpracováním osobních údajů

Spolufinancováno EU Ministerstvo Životního Prostředí
Moravskoslezský kraj Černá kostka Ostrava

Projekt Černá kostka je spolufinancován Evropskou unií a z rozpočtu statutárního města Ostravy.

Moravskoslezský kraj příspěvková organizace Moravskoslezský kraj

Černá kostka je příspěvkovou organizací zřizovanou Moravskoslezským krajem.

Partneři projektu

Vědecká knihovna v Ostravě
Moravskoslezské Inovační Centrum
VŠB-TUO
Green Light - VŠB
Life coala

Projekty Černé kostky

Projekt cerná.ai konference Projekt mediální olympiáda Projekt Film office