Nomad Society Logo
  • Story Driven Worlds
  • Thematic Tales
  • Locations
  • Shop
  • 0
0
  • Story Driven Worlds
  • Thematic Tales
  • Locations
  • Shop
  • 0
    Basket
  • Loading...

Browse

  • Homepage
  • About
  • FAQs

Policies

  • Privacy Policy
  • Refund Policy

Contact

info@onceuponprague.com

Connect

© Once Upon Prague 2026

Privacy Policy for Once Upon Prague

Effective Date: July 20, 2025

1. Introduction

Welcome to Once Upon Prague (“we,” “us,” or “our”). We operate a business dedicated to Tabletop Role-Playing Games (TTRPGs) and Game Nights, including services suitable for children. This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you interact with our website, book our services, attend our events, or otherwise communicate with us.

We are committed to protecting your privacy and handling your personal data in a transparent and lawful manner, in accordance with the General Data Protection Regulation (GDPR) and other applicable privacy laws.

2. Who We Are

  • Name: Once Upon Prague
  • Location: Novákových 358/12, 180 00 Praha 8-Palmovka
  • Contact Email: info@onceuponprague.com
  • Website: www.onceuponprague.com
  • IČO: 23335271

3. Data We Collect and How We Collect It

We may collect personal data from you in various ways, including when you:

  • Visit our website
  • Book an event or service
  • Sign up for our newsletter
  • Contact us via email, phone, or social media
  • Participate in surveys or provide feedback

The types of personal data we may collect include:

  • Identity Data: Name, surname.
  • Contact Data: Email address, phone number, billing address.
  • Transaction Data: Details about products/services you have purchased from us. Regarding payments, we do not directly process or store your credit card details. When you checkout, we will provide you with payment instructions (including QR code or bank transfer details) via email. We will then process and reconcile payments made to our bank account. We may receive your bank name and the name associated with the transfer during this process for transaction verification.
  • Technical Data: Internet Protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
  • Usage Data: Information about how you use our website, products, and services (e.g., pages visited, events viewed, links clicked).
  • Marketing and Communications Data: Your preferences in receiving marketing from us and your communication preferences.

4. How We Use Your Personal Data (Purposes and Lawful Basis)

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

Purpose of ProcessingType of Data UsedLawful Basis for ProcessingTo fulfill bookings & provide services: Processing your orders, sending payment instructions (QR code/bank transfer details), confirming event attendance, reconciling payments, and delivering the services you have requested.Identity, Contact, TransactionNecessary for the performance of a contract with you.To manage our relationship with you: Notifying you about changes to our terms or privacy policy, asking you to leave a review or take a survey.Identity, Contact, Marketing & CommsNecessary for our legitimate interests (e.g., to keep our records updated, to study how customers use our services).To improve our website, products/services, marketing, customer relationships, and experiences: For data analysis, testing, system maintenance, support, reporting, and hosting of data.Technical, UsageNecessary for our legitimate interests (e.g., to define types of customers for our services, to keep our website updated and relevant).To send you marketing communications: Sending newsletters or promotional offers you have opted-in to receive.Contact, Marketing & CommsYour consent (where required by law); or Necessary for our legitimate interests (to develop our services and grow our business) if you are an existing customer and we have a soft opt-in.To enable you to participate in a competition or complete a survey.Identity, Contact, Usage, Marketing & CommsPerformance of a contract with you; or Necessary for our legitimate interests (e.g., to study how customers use our services).To administer and protect our business and website: Including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data.Identity, Contact, Technical, UsageNecessary for our legitimate interests (for running our business, network security, to prevent fraud).To comply with legal or regulatory obligations: Where we are required to retain certain information by law.All relevant data typesNecessary for compliance with a legal obligation.

5. Data Sharing and Disclosure

We may share your personal data with the following categories of recipients:

  • Service Providers: Third-party companies that perform services on our behalf, such as website hosting, email delivery, analytics (e.g., Google Analytics), and customer support. These providers are obligated to protect your data and only use it for the services they provide to us.
  • Financial Institutions: Your bank or our bank involved in the processing of your bank transfer payments for reconciliation purposes.
  • Legal & Regulatory Bodies: If required by law, court order, or governmental regulation, we may disclose your personal data.
  • Business Transfers: In connection with any merger, sale of company assets, or acquisition of all or a portion of our business by another company.

We will not sell, rent, or trade your personal data to third parties for their marketing purposes without your explicit consent.

6. International Transfers (Outside the EEA)

As we operate in the Czech Republic (within the European Economic Area – EEA), if we transfer your personal data outside the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

  • We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.
  • Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe (Standard Contractual Clauses).
  • Where providers are based in the US, we may transfer data to them if they are part of the EU-US Data Privacy Framework (if applicable and valid), which requires them to provide similar protection to personal data shared between the EU and the US.

7. Data Security

We have implemented appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have procedures in place to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

8. Data Retention

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

9. Your Legal Rights Under GDPR

Under certain circumstances, you have rights under data protection laws in relation to your personal data. These include the right to:

  • Request access to your personal data (commonly known as a “data subject access request”).
  • Request correction of the personal data that we hold about you.
  • Request erasure of your personal data.
  • Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms.1
  • Request restriction of processing of your personal data.2
  • Request the transfer of your personal data to you or to a third party.3
  • Withdraw consent at any time where we are relying on consent to process your personal data. This will not affect the lawfulness of any processing carried out before you withdraw your consent.

If you wish to exercise any of the rights set out above, please contact us using the details provided in Section 2.

You also have the right to make a complaint at any time to the Office for Personal Data Protection (Úřad pro ochranu osobních údajů – UOOU), the Czech supervisory authority for data protection issues. We would, however, appreciate the chance to deal with your concerns before you approach the UOOU, so please contact us in the first instance.

10. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your Browse experience, analyze site traffic, and understand where our audience is coming from.

  • What are cookies? Cookies are small text files that are placed on your computer or mobile device when you visit a website.
  • How we use them: We use cookies for essential website functionality, analytics (e.g., Google Analytics to understand website usage), and potentially for marketing purposes.
  • Managing cookies: You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly.

11. Third-Party Links

Our website may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.

12. Children’s Privacy

Once Upon Prague offers services that are suitable for children. We are committed to protecting the privacy of children.

  • For bookings and data collection: We primarily aim to collect personal data related to bookings and payments from parents, guardians, or adult supervisors.
  • When data from a child is collected: If we collect any personal data directly from a child under the age of 16, we will do so only with the verifiable consent of a parent or guardian, or when the data is necessary for the provision of a service requested by the parent/guardian.
  • Parental Rights: Parents and guardians have the right to review the personal data collected from their child, to request its deletion, and to refuse any further collection or use of their child’s data. To exercise these rights, please contact us using the details in Section 14.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The “Effective Date” at the top of this policy indicates when it was last revised. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your data. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the “Effective Date.”

14. Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us:

  • Email: info@onceuponprague.com