PRIVACY
Privacy Policy
This policy explains how the public REKRUTME website processes personal data when you browse the site, use the contact form, send us email, or follow links to external project services.
Last updated: 8 August 2026
Privacy at a glance
No analytics or advertising
We do not use analytics, advertising pixels, behavioural profiling, or marketing cookies on the public website.
Contact data only when you send it
The public site does not collect athlete profiles or recruitment documents. The contact form is only for ordinary enquiries.
The application is separate
The future REKRUTME application is not yet collecting athlete data. Its product-data processing will be covered before that functionality launches.
01
Controller and contact
NovaSphere company s.r.o.
Na Hřebenkách 815/130, Smíchov
150 00 Praha 5
Czech Republic
Company ID (IČO): 63471965
VAT ID (DIČ): CZ63471965
NovaSphere company s.r.o. is the controller for personal data processed through the public REKRUTME website and its contact channels. Privacy requests may be sent to privacy@rekrutme.team.
02
Scope of this policy
This policy covers the public informational website at rekrutme.team, ordinary contact-form submissions, direct email correspondence, and the limited technical data needed to operate and secure the website.
The public website does not provide public user registration, comments, athlete profiles, application accounts, recruitment-file uploads, analytics, behavioural advertising, or marketing tracking.
The REKRUTME application is being developed separately on Amazon Web Services in the Frankfurt region. Before the application begins collecting athlete, academic, recruitment, identity, or other product data, this policy will be updated or supplemented with a product-specific privacy notice.
03
Data we process
When you browse the website: the web server may process standard technical information such as IP address, date and time, requested URL, HTTP status, referrer, browser/user-agent information, and security-related events. This information is used to deliver the site, diagnose errors, prevent abuse, and maintain security.
When you use the contact form: we process the fields you choose to submit, such as your name, email address, organisation, subject, and message. Please do not submit transcripts, passports or other identity documents, medical information, detailed student records, or other sensitive athlete data through the public contact form.
When you email us: we process the sender and recipient addresses, message headers, message content, attachments you intentionally send, and ordinary mail-delivery metadata needed to receive, send, secure, and reply to the correspondence.
04
Contact form and spam protection
The contact form is implemented with SureForms on our own WordPress installation. We configure the form so that successful submissions are not retained as form entries in the WordPress database after submission. A notification containing the submitted information is sent to our business mailbox.
To protect the form against spam and abuse, submissions are checked by Akismet, a service operated by Automattic. For spam screening, information such as the submitted form content, IP address, user agent, referrer, and site URL may be transmitted to Automattic.
We use contact-form data only to handle the enquiry, communicate with you, protect the service, and where relevant take steps relating to a potential business or project relationship. Contact details submitted through this form are not automatically added to a newsletter or marketing list.
05
Email infrastructure
Website-generated outbound email, including contact-form notifications, is sent using Amazon Simple Email Service (Amazon SES) in the AWS eu-central-1 (Frankfurt) region. Email routing requires processing of message headers, recipient information, delivery metadata, and the message content being transmitted.
REKRUTME business mailboxes are hosted in Google Workspace. Messages sent to REKRUTME addresses, including contact-form notifications after delivery, are therefore stored and processed within Google Workspace according to the account configuration and Google’s applicable contractual and data-protection terms.
06
Hosting and technical infrastructure
The public WordPress website is hosted on a Contabo VPS located in Germany. Website files, the WordPress database, and standard web-server/security logs are therefore hosted in the European Economic Area, subject to the actual VPS and backup configuration.
The future REKRUTME application is hosted separately on AWS in the Frankfurt region. At the date of this policy, the public website does not use the application to collect athlete or recruitment data.
07
Google Fonts
The website currently loads selected web fonts using the Google Fonts Web API. Google states that Google Fonts does not set or log cookies for this service. However, when your browser requests a font from Google, the request necessarily includes technical information such as your IP address, the requested URL, user-agent information, and the referrer page.
We use Google Fonts only to deliver the selected typography and not for analytics or advertising. The legal basis for this processing is our legitimate interest in providing a consistent and usable presentation of the website. To minimise third-party connections further, the same font files may be self-hosted in the future; if they are self-hosted, this direct transfer to Google Fonts will cease.
08
Cookies and similar technologies
The public website does not use analytics, advertising, behavioural tracking, or marketing cookies. WordPress and the contact-form/security components may use cookies, nonces, or similar short-lived technical mechanisms that are necessary for administration, security, form submission, or abuse prevention.
Because we do not intentionally use non-essential cookies on the public website, we do not ask visitors for marketing or analytics cookie consent. If this changes in the future, the website and this policy will be updated before such technologies are enabled.
09
Purposes and legal bases
Website delivery, security, logging and abuse prevention: our legitimate interests in operating, securing, troubleshooting, and protecting the website and its users (Article 6(1)(f) GDPR).
General enquiries and correspondence: our legitimate interests in answering communications and managing project relationships (Article 6(1)(f) GDPR). Where you contact us with a view to entering into a contract or taking pre-contractual steps, Article 6(1)(b) GDPR may also apply.
Spam screening: our legitimate interests in preventing spam, fraud, malicious submissions, and service abuse (Article 6(1)(f) GDPR).
Legal and compliance obligations: where retention or disclosure is required by applicable law, Article 6(1)(c) GDPR may apply.
10
Recipients and service providers
Depending on how you interact with the website, personal data may be processed by: Contabo for VPS hosting; Amazon Web Services for SES email delivery and, separately, future application infrastructure; Google Workspace for business email; Automattic / Akismet for spam screening; and Google Fonts when fonts are loaded directly from Google’s servers.
SureForms operates as a self-hosted WordPress component for this website. We configure it not to retain successful contact-form entries after submission. We do not sell personal data.
The site also links to external services such as Featurebase, GitHub, and F6S. If you follow those links, you leave rekrutme.team and the destination service processes data under its own privacy terms. Those services are not covered by this policy for your activity on their websites.
11
International transfers
The public website itself is hosted in Germany, and Amazon SES is configured in the Frankfurt AWS region. Some providers used for email, spam screening, font delivery, support, or their subprocessors may nevertheless process personal data outside the European Economic Area.
Where GDPR requires safeguards for an international transfer, we rely on the transfer mechanisms and contractual protections applicable to the relevant provider, such as an adequacy decision or Standard Contractual Clauses, as applicable. Provider infrastructure and subprocessor locations may change over time.
12
Retention
Web-server and security logs: we aim to retain routine logs for no longer than 30 days, unless a longer period is necessary to investigate a security incident, abuse, or technical failure.
SureForms contact entries: successful submissions are configured not to remain stored as entries in the WordPress database after submission.
Email correspondence: ordinary enquiries in Google Workspace are retained for up to 24 months after the last substantive interaction, unless a shorter period is appropriate or a longer period is needed for an active relationship, contractual matter, legal obligation, or the establishment, exercise, or defence of legal claims.
Spam-screening information: information processed by Akismet is retained according to Automattic’s applicable service and privacy terms.
13
Your rights
Subject to the conditions of applicable law, you may have the right to request access to your personal data, correction of inaccurate data, deletion, restriction of processing, data portability where applicable, and to object to processing based on legitimate interests. Where processing is ever based on consent, you may withdraw that consent without affecting processing carried out before withdrawal.
To exercise a privacy right, contact privacy@rekrutme.team. We may ask for information reasonably necessary to verify your identity before acting on a request.
You also have the right to lodge a complaint with the Office for Personal Data Protection of the Czech Republic (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic.
14
Is providing data mandatory?
Browsing the informational parts of the website does not require you to provide contact details. Providing contact-form or email information is voluntary, but without at least a return contact address and enough information to understand your enquiry, we may be unable to respond.
The public website does not use automated decision-making or profiling that produces legal or similarly significant effects.
15
Children and sensitive athlete information
REKRUTME concerns student-athlete recruitment, so some future users of the application may be minors. The public website and its contact form are not the channel for creating an athlete profile or submitting sensitive recruitment records.
Minors may use the public site to read information or send an ordinary enquiry, but they should not submit passports, identity documents, medical information, detailed academic records, transcripts, test documents, or similar sensitive material through the contact form or ordinary email. Before the application collects such data, dedicated age, consent/authorisation, access-control, retention, and product-privacy rules will be introduced.
16
Security
We use technical and organisational measures appropriate to the public website’s current scope, including HTTPS, restricted administrative access, server and application security controls, spam filtering, and service-provider security features. No internet service can guarantee absolute security.
If you discover a security issue, please use security@rekrutme.team rather than posting details publicly.
17
Changes to this policy
We may update this policy when the website, service providers, legal requirements, or REKRUTME product functionality changes. The current version will be published on this page with its revision date. Before the REKRUTME application begins collecting athlete or recruitment data, the privacy information will be expanded accordingly.
PRIVACY REQUESTS
Questions about your personal data?
Use the private privacy contact below. Do not post personal or security-sensitive information to Featurebase or GitHub.
