RIHA legal
RIHA legal — law firm

Privacy

Privacy notice

How RIHA legal processes data when you visit the static website, communicate directly, or receive legal services.

Paid booking link status

Online booking is available through hosted Cal.com. After choosing a booking action, you continue to hosted Cal.com operated by Cal.com, Inc. in the United States. Cal.com handles availability and booking and sends an operational booking confirmation; Stripe handles payment, Cal Video uses Daily.co, and Cal.com identifies Twilio for e-mail and SMS notifications in its public privacy policy. The static RIHA legal website does not receive this data.

The booking action leads directly to the approved service page; no booking or payment data is entered on this website.

View consultation options →

Controller and contact

The Controller is RIHA legal advokátní kancelář s.r.o., Company ID 21006601, registered office at Moulíkova 2239/3, 150 00 Praha 5, data box cfiuk4i. Legal services are provided by JUDr. Vojtěch Říha, Ph.D., Czech Bar registration no. 18591.

Send privacy questions and requests to vojtech.riha@riha-legal.com, call +420 606 182 522, use the data box, or write to the registered office.

Contact the Controller →

Scope of this notice

The website is static, has no local contact or booking form, and sets no analytics or marketing cookies. Contact takes place directly by e-mail, phone, data box or post.

Do not send sensitive documents by ordinary e-mail without prior agreement; we will select a secure delivery method for the matter.

Do not place sensitive materials in public booking or payment fields; arrange a secure delivery method directly with the firm.

Cookies and browser storage

On first load, this website writes no HTTP cookie, localStorage or sessionStorage. We use neither HTTP cookies nor localStorage. Only when the visitor expressly chooses to close the notice for this session is the notice version saved to sessionStorage; we use no analytics or marketing storage.

The value remains in sessionStorage for the https://vojtechriha.com origin during the browser-managed page session. It survives reload and may be restored with the session by browser session-restore features; it normally ends when the tab or window closes and can be cleared immediately in Privacy settings. When the version changes, an older value is ignored until it is overwritten, cleared, or the page session ends.

The storage is used solely to carry out the visitor’s express choice to hide the current notice for this session. In this exact limited scope it is storage necessary for a service expressly requested by the user under Section 89(3) of Czech Act No. 127/2005 Coll., not consent to analytics or marketing.

The sessionStorage value is not transmitted in HTTP requests, does not leave the browser, does not enter ordinary request logs, and is provided to no recipient. RIHA legal is the controller for this local purpose; separate processing of technical and security request data is described in the other sections of this notice.

  • key and value: riha_privacy_notice=2026-07-15-v1; the value contains no user or device identifier;
  • controller and scope: RIHA legal advokátní kancelář s.r.o.; origin https://vojtechriha.com; browser-managed page session;
  • purpose and lifetime: remember the express hiding of the current notice version for the page session; normally until the tab or window closes, subject to browser session restore;
  • transmission and recipients: the value is not transmitted in HTTP, does not enter ordinary request logs, does not leave the browser, and is provided to no recipient;

Categories of personal data

We process only data proportionate to the specific purpose and the way you contact us.

  • technical and security data for the static website, such as IP address, time, requested URL, browser identifier and security event;
  • identity and contact data, communication content, and preferred appointment or contact method;
  • data necessary for the legal service, contractual and accounting records; special-category data only where necessary and supported by a condition under Article 9 GDPR.

Purposes and legal bases

We do not use consent as a blanket basis for handling an enquiry or providing legal services.

  • website security and availability — legitimate interest under Article 6(1)(f) GDPR;
  • handling an enquiry, arranging and providing legal services — pre-contractual steps and contract performance under Article 6(1)(b) GDPR;
  • accounting, tax and professional obligations — Article 6(1)(c) GDPR;
  • security and establishing, exercising or defending claims — Article 6(1)(f), and for necessary special categories in particular Article 9(2)(f) GDPR.

Categories of recipients

Access is limited to authorised attorneys and staff bound by confidentiality. External providers may receive only data necessary for technical, communications, accounting or security activities.

In the hosted booking flow, Cal.com, Inc. provides availability, booking and an operational booking confirmation; Stripe, including Stripe Payments Europe, Limited depending on the payment-account location, processes payment; Cal Video uses Daily.co, and the Cal.com public privacy policy identifies Twilio for e-mail and SMS notifications.

  • static hosting and security logs
  • office e-mail and telecommunications infrastructure
  • external booking service
  • external payment service
  • online meeting provider
  • transactional e-mail provider
  • accounting, security, backup and IT services to the extent necessary for their task;
  • courts, public authorities and other authorised recipients where disclosure is required by law or necessary for a legal claim.

Processing outside the European Economic Area

Some technical or communications infrastructure providers may process data outside the EEA. Such a transfer is permitted only in compliance with Chapter V GDPR, in particular under an adequacy decision or another applicable safeguard.

Cal.com, Inc. is established in the United States, and its public privacy policy states that data provided outside the United States is transferred to and processed in the United States and that no transfer takes place without adequate controls. For the specific RIHA legal account, the DPA determines the applicable Chapter V safeguard; the account-specific subprocessor chain must be evidenced by that DPA together with the current subprocessor list. The Cal.com public privacy policy does not itself prove that account-specific mechanism. Stripe's public DPA provides that accounts outside the Americas contract with Stripe Payments Europe, Limited in Ireland, that data may be transferred globally including to Stripe, LLC in the United States, and that the Data Privacy Framework or Standard Contractual Clauses apply under its Data Transfers Addendum. The Cal.com public privacy policy identifies Twilio for e-mail and SMS notifications and Daily for Cal Video. Twilio's public DPA describes mechanisms including the Data Privacy Framework and Standard Contractual Clauses and expressly states that its Binding Corporate Rules do not apply as a transfer mechanism to SendGrid Services. Daily makes a DPA available to customers; those public documents do not prove which countries, roles, onward recipients and Chapter V mechanism Cal.com actually uses for RIHA legal account data.

Retention criteria

We retain data only as long as necessary for the purpose. The period depends on statutory archiving duties, professional rules, operational and security needs, the duration of the legal service, infrastructure settings and limitation periods for protecting claims.

  • ordinary technical logs until the operational and security need ends; an incident record for its investigation and protection of claims;
  • an enquiry that does not lead to a legal service until resolved and for no more than six months after the last substantive communication, unless longer retention is necessary for a specific claim;
  • the client file, including the contract confirmation and booking record, for five years after the legal service ends; accounting and tax records for ten years after the end of the period in which the supply took place; where a dispute or another specific duty applies, until final resolution or for the longer statutory period;
  • The Cal.com public privacy policy states that data is retained only as necessary for the service, legal obligations, disputes and enforcement of agreements; the account settings must confirm the specific technical period. Stripe states that in most jurisdictions it keeps data obtained from merchants for five or more years after the business relationship ends or the last transaction, whichever is later. Twilio states that SendGrid retains an e-mail body as long as needed for delivery, with retries taking no more than 72 hours. For scheduled sending, the body may be retained for up to six days, random content samples for up to seven days, most recipient and activity data for no more than 37 days, and some pseudonymised, re-identifiable event data for up to one year. Daily.co states that session-operation logs are retained according to the Daily domain plan; account evidence must confirm the actual plan and settings of the domain used through Cal.com. These provider periods do not replace the RIHA legal client-file periods stated above.

Source of data and whether it is required

We obtain data mainly from you. In legal work it may also come from your representative, an opposing party, a public authority or public register. We provide Article 14 information where required and not prevented by a specific statutory exception or professional secrecy.

Data necessary for identity, contact and the legal service is a contractual or statutory requirement; without it, the enquiry may not be assessable or the service may not be provided.

Rights

Subject to the GDPR, you have rights of access (Article 15), rectification (16), erasure (17), restriction (18), recipient notification (19), portability (20), objection (21), and protection against solely automated decisions with legal or similarly significant effects (22). Where consent is exceptionally used, it may be withdrawn without affecting prior lawfulness.

Rights are not absolute, especially where data must be retained by law or for legal claims. After verifying identity, we respond without undue delay and generally within one month. Send a request to vojtech.riha@riha-legal.com or another Controller contact.

Right to complain

Under Article 77 GDPR, you may complain to the Czech supervisory authority, the Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, e-mail posta@uoou.gov.cz, data box qkbaa2n. Contacting RIHA legal first is not a condition of complaining.

Czech supervisory authority complaint information →

Automated decision-making

RIHA legal performs no solely automated decision-making or profiling with legal or similarly significant effects on the static website or when deciding whether to provide legal services.

Last legally reviewed on 15 July 2026.

Privacy settings

This website does not use analytics or marketing cookies.

Technically necessary storage
After dismissal · page session
Analytics cookies
Not used
Marketing cookies
Not used