List your horse for free — three active listings on the Free plan, no card required. Create account

Personal data protection

Privacy Policy

How Equihorn handles personal data when operating the marketplace, contact forms, public profiles, subscriptions, and cookies.

Privacy

What data we process

We mainly process data needed to operate accounts, publish listings, handle enquiries, review reports, invoice paid services, and secure the platform.

Marketplace and listings

Who receives data

If you send an enquiry about a listing, your contact details and message are passed to the seller. Payment data for subscriptions and boosts is processed by Stripe.

Rights and liability

Your rights

You have the right of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You may also lodge a complaint with the Czech data protection authority.

General

1. Controller and scope

Who the controller is and which situations this policy covers.

The controller of personal data is ZONDY GROUP s.r.o.. The controller’s contact details are listed in this document and on the Imprint page.

This policy explains which personal data we process when you visit and use the Equihorn platform, register an account, publish listings, communicate with other users, purchase paid services, and use cookies.

Where a seller voluntarily includes personal data in a public listing or profile, that seller remains responsible for having a lawful basis to disclose it and for keeping it accurate, proportionate, and up to date.

Privacy

2. What personal data we process

An overview of the main categories of personal data created on the platform.

The exact scope depends on whether you are a visitor, registered user, seller, buyer, or payer of a paid service.

  • Account and identity data, especially name, email, phone number, login details, language preferences, organisation or stable details, and registration status.
  • Listing and public profile data, especially horse description, pedigree, location, price, photos, videos, and publicly displayed seller contact details.
  • Communication data, especially contact form submissions, content reports, support messages, and related metadata.
  • Payment and invoicing data, especially billing details, subscription status, order history, and information provided by the payment processor. We do not normally store card details ourselves; Stripe processes them.
  • Technical and security data, especially IP address, device and browser information, logs, cookies, and other information needed for operation, security, and performance measurement.
Marketplace and listings

4. Publicly displayed data and user-to-user sharing

Which data is public and which data is shared with other marketplace users.

Information that the seller voluntarily publishes in a listing or public profile is visible to platform visitors and may be indexed by search engines or displayed in the platform’s own editorial outputs.

If an interested user sends an enquiry through the contact form, we pass the sender’s name, email, phone number, and message to the seller so the seller can reply.

We do not publish the content of reports submitted about unlawful or problematic content. We may use it, however, for moderation, defence of rights, cooperation with authorities, or dispute handling involving affected persons.

Payments and plans

5. Recipients and processors

Who processes data for us and when it may be disclosed to third parties.

Personal data is processed primarily by the platform operator. Access is limited to persons and processors who genuinely need the data for the purposes described above and who are bound by appropriate confidentiality and security measures.

  • contracted hosting, infrastructure, storage, and technical support providers who help us run the platform,
  • payment service providers and related banks, especially Stripe, if the user pays for subscriptions or boosts,
  • communication or analytics tool providers where a given function is active and selected by the user through cookie settings or use of the service,
  • public authorities, courts, advisers, or insurers where disclosure is required by law or necessary to protect rights and legitimate claims.
Privacy

6. Transfers outside the EU and EEA

How we handle any transfers of personal data outside the European Economic Area.

Where we use suppliers outside the EU or EEA, we do so only if an adequate level of protection is ensured, particularly through an adequacy decision, standard contractual clauses, or another lawful mechanism under GDPR.

Security and retention

7. Retention period

How long we usually keep each category of personal data.

Retention periods are set according to the purpose, legal obligations, and the need to protect legitimate claims. When you request deletion of your account, it enters a 30-day recovery period during which it can be restored, and is then permanently anonymised; records we are legally required to keep, such as invoices, are retained for the statutory period even after the account is anonymised. After the relevant period ends, data is deleted, anonymised, or retained only to the extent required by law.

  • account and public profile data for the lifetime of the account and then for a reasonable period needed to protect legal claims, usually no longer than 3 years,
  • listings, photos, and related marketplace data for the period of publication and then for a reasonable archive period needed for disputes, statistics, and defence of rights,
  • enquiries, reports, and support communications usually for 24 to 36 months after the case is closed, unless longer retention is required by a dispute or by law,
  • invoicing and accounting records for the period required by law, typically 10 years,
  • security logs and technical records for the period necessary for security and operation, usually ranging from days to months unless a longer period is justified.
Rights and liability

8. Your rights

Which rights GDPR grants you and how to exercise them.

You can exercise the right to erasure and the right to data portability directly in your account settings — at any time you can request deletion of your account or download a machine-readable copy of your data. Other rights, or any questions, can be exercised via [email protected]. Before responding, we may reasonably verify your identity in order to protect the data of others.

If you believe the processing infringes the law, you have the right to lodge a complaint with the Czech Office for Personal Data Protection.

  • the right to access your personal data and obtain confirmation whether we process it,
  • the right to rectify inaccurate or incomplete data,
  • the right to erasure where the legal conditions are met,
  • the right to restriction of processing in situations defined by GDPR,
  • the right to data portability where processing is based on contract or consent and carried out by automated means,
  • the right to object to processing based on legitimate interests,
  • the right to withdraw consent at any time where processing is based on consent.
Cookies

9. Cookies and similar technologies

Which cookie categories we use and how consent can be changed.

We use necessary cookies for basic website operation and analytical or marketing cookies only to the extent you allow them through the cookie banner. Preferences can be changed at any time via the “Cookie settings” link in the footer.

Analytical cookies help us measure traffic and platform usage in an aggregated or pseudonymised manner. Marketing cookies may support personalised promotion and campaign measurement where the relevant tools are active on the website.

Rejecting optional cookies does not affect the core availability of the platform, but it may limit certain personalisation or performance measurement features.

Contact and disputes

10. Security and contact

How we protect data and who you can contact with requests or complaints.

We implement reasonable technical and organisational measures, including access controls, encrypted transfer, backups, monitoring, and internal procedures aimed at preventing unauthorised access, loss, or misuse.

If you have questions about personal data processing or wish to exercise your rights, contact us at [email protected] or by post at the registered address stated in this document.

The supervisory authority in the Czech Republic is the Office for Personal Data Protection. You may contact it if you are dissatisfied with how your request was handled or believe data protection rules have been breached.