top of page

Privacy Policy​

The controller of personal data pursuant to Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter: “GDPR”) is:

......................................................
Company ID:...............................
Registered office:  ......................................................
(hereinafter referred to as the “Controller”).

Contact details of the Controller

 

Address: ................................
Email: .............................................
Phone: ............................................

Personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or one or more specific elements of the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

The Controller has not appointed / has appointed a Data Protection Officer. The contact details of the Data Protection Officer are: 

Sources and Categories of Processed Personal Data

The Controller processes personal data that you have provided or personal data obtained based on the fulfillment of your order.

The Controller processes your identification and contact details and data necessary for the performance of the contract.

III. Legal Basis and Purpose of Processing Personal Data

The legal basis for processing personal data is:

  • performance of a contract between you and the Controller pursuant to Article 6(1)(b) GDPR;

  • the Controller’s legitimate interest in providing direct marketing (especially for sending commercial communications and newsletters) pursuant to Article 6(1)(f) GDPR;

  • your consent to processing for direct marketing purposes (especially for sending commercial communications and newsletters) pursuant to Article 6(1)(a) GDPR in conjunction with Section 7(2) of Act No. 480/2004 Coll., on Certain Information Society Services, in cases where no order for goods or services has been made.

Purpose of processing personal data:

  • processing your order and exercising rights and obligations arising from the contractual relationship between you and the Controller; personal data required when placing an order (name, address, contact details) are necessary for successful order processing; providing personal data is a mandatory requirement for concluding and fulfilling a contract, and without providing personal data it is not possible to conclude or perform the contract;

  • sending commercial communications and carrying out marketing activities.

 

The Controller does not / does carry out automated individual decision-making pursuant to Article 22 GDPR. You have provided your explicit consent for such processing.

IV. Data Retention Period

The Controller retains personal data:

  • for the period necessary to exercise rights and obligations arising from the contractual relationship and to assert claims under such relationships (for 15 years after termination of the contractual relationship);

  • until consent to processing personal data for marketing purposes is withdrawn, but no longer than 10 years if processing is based on consent.

After the retention period expires, the Controller will delete personal data.

V. Recipients of Personal Data (Controller’s Subcontractors)

Recipients of personal data include persons:

  • involved in the delivery of goods/services/payment processing under a contract;

  • providing e-shop operation services (Shoptet) and related services;

  • providing marketing services.

The Controller does not / does intend to transfer personal data to a third country (outside the EU) or an international organization.

Recipients of personal data in third countries may include providers of mailing services and cloud services.

VI. Your Rights

Under the conditions set out in GDPR, you have:

  • the right to access your personal data under Article 15 GDPR;

  • the right to rectification of personal data under Article 16 GDPR or restriction of processing under Article 18 GDPR;

  • the right to erasure under Article 17 GDPR;

  • the right to object under Article 21 GDPR;

  • the right to data portability under Article 20 GDPR;

  • the right to withdraw consent at any time in writing or electronically to the address or email of the Controller specified above.

You also have the right to file a complaint with the supervisory authority if you believe your right to personal data protection has been violated.

VII. Conditions of Personal Data Security

The Controller declares that it has taken all appropriate technical and organizational measures to secure personal data.

The Controller has implemented technical measures to secure data storage and storage of personal data in paper form.

The Controller declares that only authorized persons have access to personal data.

VIII. Final Provisions

By submitting an order through the online order form, you confirm that you have read and accepted these Privacy Policy terms in full.

You express your agreement by checking the consent box in the online form. By checking the consent box, you confirm that you have read and fully accept these Privacy Policy terms.

The Controller is entitled to amend these terms. The new version of the Privacy Policy will be published on the website and simultaneously sent to the email address provided by you.

These terms become effective as of April 1, 2026.

bottom of page