Skip to content
Back to quiz

Privacy Policy

1. Data Controller

Ensana s.r.o. (hereinafter "Ensana", "we", "us") is the data controller responsible for processing your personal data within the Vitality Program service and collected through the Ensana Vitality Quiz.

Contact: Ensana s.r.o., ID No. 05456274, registered office at: Na příkopě 392/9, Staré Město, 110 00 Praha 1, Czech Republic, Email: info@ensanahotels.com

Data Protection Officer — Email: dpo@ensanahotels.com

2. Data We Collect

When you use the Ensana Vitality Quiz, we may collect:

  • Email address (provided by you)
  • Quiz answers and calculated vitality score
  • Marketing consent preferences
  • Technical data (IP address, browser type, device information) via cookies (if technically necessary or separate consent is provided)

3. Purpose of Processing

We process your personal data to provide the Vitality Program service: this includes processing your quiz answers to generate your personalised vitality report and sending you ongoing personalised health, spa, and wellness recommendations and offers based on your score.

We use automated processing (profiling) of your quiz answers to ensure that the recommendations and offers we send you are relevant to your health and vitality needs.

4. Legal Basis

We process your data based on:

  • Explicit Consent (Art. 9(2)(a) GDPR) — for processing your health-related data (quiz answers) to provide the Vitality Program service, including the vitality report and subsequent personalised wellness recommendations.
  • Consent — for analytics and marketing cookies.
  • Legitimate interest — for technical website optimisation and general (non-personalised) service improvement.

5. Your Rights

Under GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict processing
  • Data portability
  • Object to processing
  • Withdraw consent at any time

To exercise your rights, contact us at info@ensanahotels.com or contact our DPO at dpo@ensanahotels.com.

6. Data Retention

We retain your personal data for as long as necessary to fulfil the purposes outlined above, unless a longer retention period is required by law. Marketing data is retained until you withdraw your consent. The period for which we process your data based on your consent will generally not exceed 3 years, unless you choose to opt out of our Vitality Program earlier.

7. Data Sharing

We may share your data with trusted service providers who assist us in operating our website, conducting our business, or serving our users. These parties are obligated to keep your information confidential.

8. Contact

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us at info@ensanahotels.com or contact our Data Protection Officer at dpo@ensanahotels.com.

You also have the right to lodge a complaint with a supervisory authority. The authority in the Czech Republic is Úřad pro ochranu osobních údajů (https://uoou.gov.cz/).

Last updated: May 2026