Your GDPR Rights
Effective from February 1, 2026
1. Overview
As a user of kansei.works, you are entitled to specific rights regarding your personal data under Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") and Act No. 110/2019 Sb. (Czech Personal Data Processing Act). koncal studio s.r.o. ("Data Controller") is committed to facilitating the exercise of these rights. This page explains each right in detail and how to exercise it. These rights apply to all personal data we process about you, whether collected directly or through your use of the Service.
2. Right of Access (Article 15 GDPR)
You have the right to obtain confirmation from us as to whether your personal data is being processed and, if so, to access that data along with the following information: the purposes of processing, the categories of personal data concerned, the recipients to whom data has been or will be disclosed, the envisaged retention period, the existence of your other rights (rectification, erasure, restriction, objection), the right to lodge a complaint with the supervisory authority, the source of the data if not collected directly from you, and the existence of automated decision-making. We will provide the first copy of your data free of charge. Additional copies may be subject to a reasonable administrative fee.
3. Right to Rectification (Article 16 GDPR)
You have the right to request correction of inaccurate personal data without undue delay. You also have the right to have incomplete personal data completed, including by providing a supplementary statement. You can update most of your personal data directly within your kansei.works account (profile settings, entity details, client information). For data you cannot modify directly, contact us at dpo@kansei.works and we will make the corrections within 30 days.
4. Right to Erasure (Article 17 GDPR)
You have the right to request the deletion of your personal data without undue delay in the following circumstances:
- The data is no longer necessary for the purposes for which it was collected or processed
- You withdraw consent on which the processing is based (where consent is the legal basis) and there is no other legal basis for the processing
- You object to the processing and there are no overriding legitimate grounds for the processing, or the data has been unlawfully processed
5. Right to Restriction of Processing (Article 18 GDPR)
You have the right to request restriction of processing of your personal data in the following cases: (a) you contest the accuracy of the data, for a period enabling us to verify the accuracy, (b) the processing is unlawful and you oppose erasure and request restriction instead, (c) we no longer need the data but you require it for the establishment, exercise, or defense of legal claims, or (d) you have objected to processing pending verification of whether our legitimate grounds override yours. When processing is restricted, we will only store the data and will not further process it without your consent, except for the establishment, exercise, or defense of legal claims, protection of another person's rights, or important public interest reasons.
6. Right to Data Portability (Article 20 GDPR)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format (JSON, CSV) and to transmit it to another controller without hindrance. This right applies to data you have provided to us, processed on the basis of consent or contract, and processed by automated means. You can export your data at any time through Settings > Data Export in the kansei.works application. The export includes invoices, clients, expenses, projects, and all associated data in standard formats.
7. Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data which is based on our legitimate interests (Article 6(1)(f) GDPR), including profiling based on those provisions. Upon receiving an objection, we will cease processing the data unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims. Where personal data is processed for direct marketing purposes, you have the right to object at any time, and we will cease processing for such purposes without exception.
8. Right Not to Be Subject to Automated Decisions (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. kansei.works uses AI features (AI assistant, OCR processing) that involve automated data processing. However, no automated decisions are made that produce legal effects or similarly significant effects — all AI outputs are presented as suggestions for your review and require explicit user action to implement. If you have concerns about automated processing, contact us at dpo@kansei.works.
9. How to Exercise Your Rights
You can exercise any of the above rights through the following channels:
- Email: Send your request to dpo@kansei.works with the subject "GDPR Rights Request" and specify which right you wish to exercise. Include your account email for identification
- In-app: For access and portability, use Settings > Data Export. For rectification, update your data directly in your account. For account deletion (erasure), use Settings > Account > Delete Account
- Written request: Send a signed letter to the registered office of koncal studio s.r.o. at Lýskova 2073, Prague 5, Czech Republic. We may request identity verification for written requests to protect your data
10. Response Timeline
In accordance with Article 12(3) GDPR, we will respond to your request without undue delay and in any event within one (1) month of receipt. If your request is complex or we receive a large number of requests, we may extend the response period by a further two (2) months, in which case we will inform you of the extension and the reasons within the first month. If we cannot comply with your request, we will inform you of the reasons and of your right to lodge a complaint with the supervisory authority. Responses to requests are provided free of charge. For manifestly unfounded or excessive requests (particularly repetitive requests), we may charge a reasonable fee or refuse to act, in accordance with Article 12(5) GDPR.
11. Right to Lodge a Complaint with UOOU
If you believe that the processing of your personal data violates the GDPR or Czech data protection law, you have the right to lodge a complaint with the Office for Personal Data Protection (Urad pro ochranu osobnich udaju, UOOU). Contact: Pplk. Sochorova 27, 170 00 Praha 7, Czech Republic, telephone: +420 234 665 111, web: www.uoou.cz, email: posta@uoou.cz. You may also lodge a complaint with the supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.
12. Data Protection Officer
For any questions regarding the processing of your personal data or to exercise your GDPR rights, you may contact our Data Protection Officer at dpo@kansei.works. The DPO is responsible for monitoring compliance with the GDPR and Czech data protection legislation, advising on data protection impact assessments, and serving as the contact point for the supervisory authority (UOOU). You may contact the DPO directly and confidentially on any matter related to the processing of your personal data.