Privacy Principles
I. Basic Provisions
- The controller of personal data pursuant to Article 4(7) of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as “GDPR”) is Mgr. et Mgr. Zuzana Hübnerová, Identification Number: 05369339, with its registered office at Babice 533, 687 03, Czech Republic (hereinafter referred to as the “controller”).
- Contact details of the controller are as follows:
-
- e-mail: zuzana.hubner@gmail.com
- phone: +420 607 960 016
- Personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- The controller has not appointed a Data Protection Officer.
II. Sources and Categories of Processed Personal Data
- The controller processes personal data that you have provided to them or personal data that the controller has obtained based on fulfilling your order.
- The controller processes your identification and contact details, as well as data necessary for contract performance.
III. Legal Basis and Purpose of Personal Data Processing
- The legal basis for processing personal data is:
-
- the performance of a contract between you and the controller according to Article 6(1)(b) of the GDPR,
- the legitimate interest of the controller in providing direct marketing (particularly for sending commercial communications and newsletters) according to Article 6(1)(f) of the GDPR,
- your consent to processing for the purpose of direct marketing (particularly for sending commercial communications and newsletters) according to Article 6(1)(a) of the GDPR in conjunction with Section 7(2) of Act No. 480/2004 Coll., on Certain Information Society Services, in case there was no order of goods or services.
- The purpose of processing personal data is:
-
- fulfilling your order and performing rights and obligations arising from the contractual relationship between you and the controller; personal data required for successful order processing (name and address, contact) are requested during the order process, providing personal data is a necessary requirement for concluding and fulfilling the contract, and the contract cannot be concluded or fulfilled by the controller without providing personal data,
- sending commercial communications and engaging in other marketing activities.
- The controller does not engage in automated individual decision-making pursuant to Article 22 of the GDPR. You have provided explicit consent for such processing.
IV. Data Retention Period
- The controller retains personal data:
-
- for the period necessary for performing rights and obligations arising from the contractual relationship between you and the controller and asserting claims from these contractual relationships (for a period of 15 years from the termination of the contractual relationship),
- for the duration of the consent to process personal data for marketing purposes, no longer than 5 years if personal data is processed based on consent.
- After the retention period for personal data expires, the controller will erase the personal data.
V. Recipients of Personal Data (Subprocessors of the Controller)
- Recipients of personal data are:
- individuals involved in the delivery of goods/services/payment processing under a contract,
- individuals involved in ensuring service operations,
- and individuals providing marketing services.
- The controller does not intend to transfer personal data to a third country (a country outside the EU) or an international organization.
VI. Your Rights
- Under the conditions set forth in the GDPR, you have the right to:
-
- access your personal data according to Article 15 of the GDPR,
- rectify your personal data according to Article 16 of the GDPR, or restrict processing according to Article 18 of the GDPR.
- erase your personal data according to Article 17 of the GDPR,
- object to processing according to Article 21 of the GDPR,
- and data portability according to Article 20 of the GDPR.
- withdraw consent for processing in writing or electronically to the address or email of the controller mentioned in Article III of these terms.
- You also have the right to lodge a complaint with the Office for Personal Data Protection if you believe that your right to personal data protection has been violated.
VII. Data Security Conditions
- The controller declares that they have taken all appropriate technical and organizational measures to secure personal data.
- The controller has implemented technical measures to secure data storage and storage of personal data in physical form.
- The controller states that only authorized personnel have access to personal data.
VIII. Final Provisions
- By submitting an order through the online order form, you confirm that you are familiar with the terms of personal data protection and fully accept them.
- The controller is authorized to change these terms. The new version of the personal data protection terms will be published on their website or a new version will be sent to you via email at the address you provided to the controller.
These terms become effective on August 31, 2023.