Privacy policy
This site sets no cookies, loads no third-party resources and runs no analytics. The only personal data it processes is what the web server unavoidably records in order to serve a page. This policy sets that out in full.
1. Controller
BELGOROD s.r.o.
Rybná 716/24, Staré Město, 110 00 Praha 1, Czech Republic
IČO 14223155 · DIČ CZ14223155
info@cresthub.online
We are the controller of the processing described below within the meaning of Article 4(7) of Regulation (EU) 2016/679 (GDPR), read with Act No. 110/2019 Coll. We have not appointed a data protection officer: we do not meet any of the criteria in Article 37(1), and we are telling you that rather than inventing a post. Data protection enquiries go to the address above.
2. What we actually process
One thing: web server access logs. That is the complete list.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| IP address, date and time, URL requested, HTTP status, bytes sent, referring URL, browser user-agent string | Serving the page; detecting and mitigating attacks, scraping and abuse; diagnosing server faults | Art. 6(1)(f) GDPR — our legitimate interest in keeping the site up and secure | Log files rotate daily and 14 rotations are kept, so no entry survives beyond 15 days |
| Your email address and whatever you write, if you email us | Answering you; recording a correction | Art. 6(1)(f) GDPR — our legitimate interest in replying to correspondence; Art. 6(1)(c) where we must keep a record | 24 months from the last message in the thread |
Our legitimate interest assessment, in short
We keep access logs because a public web server without them cannot be defended or debugged. The interest is ordinary and the intrusion is small: the logs are not linked to any identifier, not enriched, not profiled, not used for advertising, not shared, and not kept beyond a fortnight. You would reasonably expect a website to do this. You can still object under Article 21 — see section 8.
3. What we do not process
- No cookies. None, of any category, including a consent cookie — there is no consent to record because there is nothing to consent to.
- No localStorage, sessionStorage or IndexedDB. Nothing is written to your device at all.
- No analytics. No Google Analytics, no Microsoft UET, no self-hosted analytics, no pixels, no beacons.
- No third-party requests. Fonts, images, stylesheets and scripts are all served from this domain. No font CDN sees your IP address.
- No accounts, no forms, no newsletter, no comments. There is nowhere on this site to submit anything.
- No profiling and no automated decision-making within the meaning of Article 22.
- No special-category data under Article 9, and no children's data sought under Article 8.
The cookie policy gives you a recipe for checking these claims yourself in your browser, which is a better assurance than our saying so.
4. Where the data goes: recipients
We use no processors for the website's own operation, with one unavoidable exception:
- Our hosting provider, which operates the server the logs sit on and therefore acts as a processor under Article 28. It is identified, so far as we have been able to establish it, in the legal notice.
We do not sell personal data, we do not share it with advertising networks, and we do not disclose it to anyone else except where a Czech public authority compels us by law.
5. International transfers
The server that hosts this site is located in Buffalo, New York, in the United States (IP {HOST_IP}, announced under {HOST_ASN}). Every visit therefore involves a transfer of personal data — your IP address, at minimum — to a third country outside the European Economic Area, within the meaning of Chapter V of the GDPR.
We disclose this rather than leaving it implied, because a reader in the EU is entitled to know that the server they are talking to is not in the EU.
Outstanding: the operator must confirm which transfer mechanism covers this arrangement — whether the hosting provider is certified under the EU–US Data Privacy Framework, or whether Standard Contractual Clauses under Article 46(2)(c) are in place in the hosting contract, together with a transfer impact assessment. Until that is confirmed, we are not going to assert a safeguard we have not seen. A copy of whichever instrument applies is available on request to {EMAIL}.
6. Leaving this site through a partner link
Two buttons on this site are paid links. Nothing is stored on your device when you use one, and our redirect page sets no cookie. But once you leave, the myLead affiliate network and then the game publisher's own site process your visit as independent controllers under their own policies, and will normally set identifiers of their own in order to attribute a registration.
We receive no personal data back from them — only aggregate counts in a dashboard. Their processing is theirs, not ours, and it begins only if you choose to click. See the affiliate disclosure.
7. Retention, in one line
Access logs: at most 15 days, by automatic rotation, with no manual archive. Email: 24 months from the last message. Nothing else is kept because nothing else is collected.
8. Your rights
Under Articles 15 to 22 of the GDPR you may ask us to:
- Access the personal data we hold about you, with a copy (Art. 15).
- Rectify data that is inaccurate or incomplete (Art. 16).
- Erase it (Art. 17).
- Restrict our processing of it (Art. 18).
- Receive it in a portable format (Art. 20) — note that this right only bites on processing based on consent or contract, and ours is based on legitimate interest, so in practice it will not apply here.
- Object to processing based on legitimate interest, on grounds relating to your particular situation (Art. 21). This is the right that actually applies to our access logs.
A frank note on access and erasure. Our logs are keyed to nothing but an IP address and a timestamp. If you ask us for a copy of your data or for its deletion, we will need you to tell us the IP address and the approximate time of your visit before we can find anything, and we cannot verify that the address was yours. Article 11 of the GDPR covers this situation: where a controller cannot identify the data subject, the access and erasure rights may not be exercisable. In practice, waiting fifteen days achieves deletion more reliably than writing to us.
There is no consent anywhere in this policy, so there is no consent for you to withdraw. If a tracker is ever added to this site, a consent banner will appear with it, this page will be updated before it does, and withdrawal will be available in one click from the footer of every page.
We answer requests within one month, extendable by two further months for complex requests, and free of charge unless a request is manifestly unfounded or excessive (Art. 12).
Data of deceased persons
The GDPR does not apply to the personal data of deceased persons (Recital 27), and Czech law has not extended it to them. Unlike France, Czech law provides no mechanism for leaving directives about the fate of your data after death, and we are not going to imply that it does. Personality rights after death are dealt with separately under sections 82 and 83 of the Civil Code, and a close relative may act on them.
9. Complaints
Raise it with us first at {EMAIL}. You are entitled to go straight to a supervisory authority without doing so.
Lead supervisory authority, as our sole establishment is in
the Czech Republic:
{UOOU}
If you live in another EU or EEA country, you may instead complain to your own national supervisory authority, which will coordinate with the Czech office under the GDPR's cooperation procedure. You also have a right to an effective judicial remedy under Article 79.
10. Changes to this policy
The version and date at the top of this page change whenever the policy does. A change that introduces any new processing — a tracker, an analytics tool, a form — will be published here before it is deployed, not after.