Privacy Policy
Wealth Authority Media is an EU-based educational publisher. As a company headquartered in the European Union, we operate under one of the strictest data protection regimes in the world. Your personal data is handled in accordance with Regulation (EU) 2016/679 (the “GDPR”) and Act No. 110/2019 Coll. of the Czech Republic, on the processing of personal data (the “Czech Data Protection Act”).
This Privacy Policy describes how MEDIA CHYTŘE s.r.o. (the “Company,” “we,” “us,” or “our”), operating the Wealth Authority Media brand at wealthauthoritymedia.com (the “Website”), collects, uses, discloses, and protects personal data of visitors and customers (“you,” “your,” or “User”) — wherever in the world you are located.
1. Data Controller
| Entity | MEDIA CHYTŘE s.r.o. |
|---|---|
| IČO | 07583532 |
| DIČ | [TBD — confirm with accountant if VAT registered; if yes: CZ07583532] |
| Registered seat | Jaurisova 515/4, Michle, 140 00 Praha 4, Czech Republic, European Union |
| Registered at | Zapsána v Obchodním rejstříku vedeném u Městského soudu v Praze, C 303516 |
| Date of incorporation | 2 November 2018 |
| Datová schránka (Data Box ID) | irpnqnr |
| Contact email | support@wealthauthoritymedia.com |
We have not appointed a Data Protection Officer (DPO) as we are not legally required to do so under Article 37 of the GDPR.
2. What Personal Data We Collect
2.1 Data you provide directly
- Identity & contact data: first name, last name, email address, country (collected when you subscribe to our newsletter, request the free Wealth Authority Blueprint, or place an order).
- Billing data: billing address, country, post code (collected at checkout for invoicing and tax compliance).
- Communications: the content of any email, support ticket, or message you send us.
2.2 Data collected automatically
- Technical data: IP address, browser type and version, operating system, device type, screen resolution, time zone, language settings, referrer URL.
- Usage data: pages visited, time spent on each page, scroll depth, click events, form interactions, traffic sources (UTM parameters).
- Cookies & similar technologies: see our Cookie Policy for the full list.
2.3 Data we receive from third parties
- Stripe — payment confirmation, last 4 digits of card, card brand, billing country (we never see or store full card numbers).
- Meta (Facebook/Instagram) — aggregated ad performance metrics; we may match hashed email addresses for advertising audiences (custom audiences and lookalikes).
3. Why We Process Your Data and Legal Bases
| Purpose | Categories of data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Delivering digital products you purchased | Identity, contact, billing, transaction | Contract performance — Art. 6(1)(b) |
| Issuing invoices and complying with Czech tax/accounting law | Billing, transaction | Legal obligation — Art. 6(1)(c) |
| Sending the free Wealth Authority Blueprint | Identity, contact | Contract performance (free service) — Art. 6(1)(b) |
| Marketing emails about new products and content | Identity, contact, usage | Consent — Art. 6(1)(a) (opt-in) |
| Website analytics, fraud prevention, security | Technical, usage | Legitimate interest — Art. 6(1)(f) |
| Targeted advertising (Meta Pixel, custom audiences, retargeting) | Technical, usage, hashed identifiers | Consent — Art. 6(1)(a) (cookie banner) |
| Responding to your support requests | Identity, contact, communications | Legitimate interest — Art. 6(1)(f) |
4. Recipients & Processors
We share your personal data only with carefully selected third parties (“processors”) that help us operate the Website and deliver our services. Each processor is bound by a Data Processing Agreement (DPA) under Article 28 of the GDPR.
| Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Stripe Payments Europe Ltd. | Payment processing | Ireland (EU) / USA | EU SCCs + DPA |
| Cloudflare, Inc. | DNS, CDN, DDoS protection, edge compute (Workers) | USA (global edge) | EU SCCs + DPA |
| Meta Platforms Ireland Ltd. | Advertising, Pixel, Conversions API | Ireland (EU) / USA | EU SCCs + DPA |
| Google Ireland Ltd. | Google Analytics 4, Google Tag Manager | Ireland (EU) / USA | EU SCCs + DPA |
| MailerLite Ltd. | Email marketing, transactional email | Ireland (EU) | DPA (EU-based) |
| Forpsi (INTERNET CZ, a.s.) | Domain registration, mailbox hosting (support@) | Czech Republic (EU) | DPA (EU-based) |
| Cloudflare, Inc. | Static website hosting (Cloudflare Pages), DNS, CDN, DDoS protection | United States (with EU edge nodes) | SCCs (Standard Contractual Clauses) |
| Hostinger International Ltd. | WordPress / WooCommerce checkout hosting | Lithuania (EU) / Germany (EU) | DPA (EU-based) |
5. International Transfers
Some of our processors are located in or transfer data to the United States. For all such transfers, we rely on the European Commission’s Standard Contractual Clauses (SCCs, Decision (EU) 2021/914) together with supplementary technical and organisational measures (encryption in transit and at rest, pseudonymisation where applicable). You may request a copy of the relevant SCCs by emailing support@wealthauthoritymedia.com.
6. How Long We Keep Your Data
| Category | Retention period |
|---|---|
| Customer accounts and order data | 10 years (Czech Act on Accounting, §31) |
| Tax invoices | 10 years (Czech VAT Act, §35) |
| Newsletter subscribers | Until you withdraw consent (one-click unsubscribe) |
| Support correspondence | 3 years from the date of last contact |
| Website analytics data | 14 months (GA4 default), then deleted or aggregated |
| Server access logs | 30 days (security purpose) |
| Marketing cookies | Up to 13 months (per ePrivacy guidance) |
7. Your Rights Under the GDPR
As a data subject, you have the following rights regarding your personal data:
- Right of access (Art. 15) — to obtain confirmation of whether we process your data and a copy of it.
- Right to rectification (Art. 16) — to have inaccurate or incomplete data corrected.
- Right to erasure / “right to be forgotten” (Art. 17) — to have your data deleted, subject to certain legal exceptions.
- Right to restriction of processing (Art. 18).
- Right to data portability (Art. 20) — to receive your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21) — to processing based on legitimate interest, including objection to direct marketing at any time.
- Right to withdraw consent (Art. 7(3)) — at any time, without affecting the lawfulness of processing before withdrawal.
- Right to lodge a complaint with the Czech Data Protection Authority: Úřad pro ochranu osobních údajů (ÚOOÚ), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic.
To exercise any of these rights, email us at support@wealthauthoritymedia.com. We will respond within one month of receiving your request, in line with Article 12(3) of the GDPR.
8. Automated Decision-Making
We do not engage in automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
9. Children
The Website and our products are intended for adults aged 18 and over. We do not knowingly collect personal data from children under 16. If you become aware that a child has provided us with personal data, please contact us and we will take steps to delete it.
10. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include HTTPS encryption (TLS 1.3), Cloudflare WAF and DDoS protection, encrypted backups, role-based access controls, and regular security reviews. Despite our efforts, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the most recent revision. Material changes will be notified by email (where you have an account or active subscription) or by a prominent notice on the Website at least 14 days before they take effect.
12. Contact
For any questions about this Privacy Policy or our data practices:
MEDIA CHYTŘE s.r.o.
Jaurisova 515/4, Michle, 140 00 Praha 4, Czech Republic, European Union
IČO: 07583532
Zapsána v Obchodním rejstříku vedeném u Městského soudu v Praze, C 303516
Email: support@wealthauthoritymedia.com