Privacy policy
Effective 21 September 2026. This policy describes the actual behaviour of this website, not a template of what a website might do.
In one paragraph
This site sets no cookies, runs no analytics, carries no advertising pixel, loads nothing from a third-party server and writes nothing to your browser’s storage. The only personal data processed is what any web server unavoidably receives in order to send you a page — your IP address and the usual request headers — which is written to a log file and deleted after 14 days. If you email us, we process that email. That is the whole of it.
1. Who is responsible for your data
The controller, within the meaning of Article 4(7) of Regulation (EU) 2016/679 (GDPR), is:
Beatiful House s.r.o.
Záběhlická 1721/41
Záběhlice
106 00 Praha 10
Czech Republic
Company registration number (IČO): 27594327
VAT identification number (DIČ): CZ27594327
Email: info@vestrova.online
Given the nature and scale of this processing, no data protection officer is required under Article 37 GDPR and none has been appointed. Write to the address above with any data-protection question.
2. What we do not do
Stating this positively is more useful than a list of hedged possibilities, so:
- We set no cookies of any kind, first-party or third-party, essential or otherwise.
- We use no analytics. There is no Google Analytics, no Matomo, no Plausible, no server-side analytics package and no log-analysis product.
- We load no advertising or conversion pixel. There is no Meta pixel, no Microsoft UET tag, no Google Ads tag, no LinkedIn Insight tag.
- We use no browser storage. No localStorage, no sessionStorage, no IndexedDB, no Web SQL, no cache API used as storage.
- We attempt no fingerprinting. Nothing on this site reads your canvas, your audio stack, your fonts, your screen metrics or your installed plugins to build an identifier.
- We make no third-party requests. No web fonts, no CDN-hosted libraries, no remote images, no embedded video, no social buttons, no maps. Every file this site loads comes from vestrova.online.
- We run no A/B testing, no session recording and no heatmaps.
- We operate no mailing list and send no marketing email.
- We sell and share nothing. No personal data leaves this site to any advertiser, broker, network or partner.
Because we set no cookies and use no similar technology, Article 5(3) of the ePrivacy Directive (2002/58/EC) is not engaged, and there is nothing for you to consent to. This is why you do not see a consent banner. The cookie policy explains how to verify that claim in your own browser in under a minute.
3. What is unavoidably processed: server access logs
A web server cannot send you a page without receiving the request. Our server writes those requests to a log file, in the standard format used by nginx.
| Item | Detail |
|---|---|
| Data recorded | IP address; date and time of the request; the URL requested; HTTP status code and bytes sent; the referring URL, if your browser sends one; the user-agent string. |
| Purpose | Keeping the server running and secure: diagnosing errors, identifying broken links, and detecting and blocking abuse such as automated attacks. |
| Legal basis | Article 6(1)(f) GDPR, legitimate interests. The interest is operating and defending the service. We have weighed it against your interests and consider it proportionate, since the logs are used for nothing else and are short-lived. |
| Retention | 14 days. Logs rotate daily and are deleted after 14 rotations. |
| Not used for | Profiling, analytics, measuring audiences, building audience segments, advertising or any automated decision-making. |
| Recipients | Nobody outside the publisher and the hosting provider acting as a processor. Logs are not exported, sold or shared. |
4. If you email us
When you write to info@vestrova.online, we receive your email address, your name if you give it, and whatever you put in the message. We process it under Article 6(1)(b) or 6(1)(f) GDPR, as applicable, in order to answer you. We keep the correspondence for as long as the matter is live and for a reasonable period afterwards in case it resumes, and then delete it. Correspondence that creates a legal record — a formal complaint, a rights request, a legal notice — is kept as long as the relevant limitation period requires. We do not use your address for anything else and we do not disclose it to advertisers or partners.
5. What happens when you follow a partner link
This matters, so it gets its own section. When you click a link marked partner link, you leave this site and arrive at a page operated by the advertiser or its affiliate network. From that moment, their privacy policy applies and ours does not. They are very likely to set cookies, run analytics and track the visit; that is how affiliate attribution works.
What we do at our end:
- We send a referrer of
strict-origin-when-cross-origin, so the destination learns that you came fromhttps://vestrova.onlinebut not which page you were reading. - If you arrived at this site with a campaign parameter in the URL (for example
msclkidorutm_source, added by the ad platform that showed you the ad), our script copies that parameter onto the outgoing link so the advertiser can attribute the click. It is read from the address bar and passed on. It is never stored on your device and never recorded by us. - We receive no personal data back. We do not learn who you are, whether you bought anything, or what you paid. Commission reporting reaches us as aggregate counts.
If you would rather not be tracked by the advertiser, do not use the link: go to the seller’s site directly by typing its address. The price is the same. We would simply not be paid for that visit, and we would rather say so plainly than hide it.
6. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), including the right to object at any time to processing based on legitimate interests. Where processing is based on consent you may withdraw it at any time, although this site asks for no consent because it relies on none.
Exercise any of these by emailing info@vestrova.online. We answer within one month, and we do not charge. Be aware of one practical limit: server logs are indexed by IP address and nothing else. To act on an access or erasure request we would need the IP address and the approximate time of your visit, and even then we may be unable to identify you. Where Article 11 GDPR applies — we cannot identify a data subject from the data we hold — we will say so rather than ask you for additional data purely to make identification possible.
You may also lodge a complaint with a supervisory authority. Ours is the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), uoou.gov.cz. You may equally complain to the authority where you live or work.
7. Processors and international transfers
Our only processor is the hosting provider that operates the server, within the European Union. There is no analytics processor, no advertising processor, no tag manager and no CDN, because none of those things is present on this site. No personal data is transferred outside the EEA by us. What happens after you follow a partner link to another company’s site is governed by that company’s policy.
8. Children
This site is written for adults choosing consumer software. It is not directed at children, and we do not knowingly process the personal data of anyone under 16.
9. Security
The site is served over HTTPS. Because we hold almost no personal data, there is very little to breach: the smallest attack surface is the one you do not build.
10. Changes
If this policy changes, the effective date above changes with it. If a change were ever to mean we began collecting something — which we do not currently intend — we would say so in plain terms at the top of this page rather than adjusting a clause in the middle.