Please pay attention to the following document, through which we provide you with information about the processing of your personal data and the rights related to the processing of your personal data in the context of our activities, i.e. in the context of the service provided to you. Any processing of personal data is governed by the applicable legislation, in particular the Personal Data Protection Act and Regulation No. 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC ("General Data Protection Regulation"). In accordance with the provisions of Article 13 et seq. of the General Data Protection Regulation, we provide you as so-called data subjects with the following information. This document is public and serves to inform you properly about the scope, purpose and duration of the processing of personal data and to inform you of your rights in relation to the protection of personal data.
WHO IS THE DATA CONTROLLER?
The personal data controller is NAREX Ždánice, spol. s r.o., with registered office at Městečko 250, Ždánice, Postal Code 696 32, VAT.:CZ25576909, registered in the Commercial Register maintained by the Regional Court in Brno under file No. C 35004 (hereinafter referred to as the "Company").
IN GENERAL - WHAT IS PERSONAL DATA?
Personal data is any information relating to an identified or identifiable natural person (human being) on the basis of which a specific natural person can be identified, directly or indirectly. Thus, personal data includes a wide range of information such as name, gender, age and date of birth, personal status, photograph (or any representation of likeness), birth number, place of residence, telephone number, e-mail, health insurance data, nationality, health data (physical and mental), as well as fingerprint, signature or IP address.
ON WHAT BASIS CAN WE PROCESS YOUR PERSONAL DATA?
Processing is lawful only if at least one of the following conditions is met and only to the extent applicable:
- the data subject has given consent to the processing of their personal data for one or more specific purposes;
- the processing is necessary for the performance of a contract to which the data subject is a party or for the performance of pre-contractual measures taken at the request of the data subject;
- the processing is necessary for compliance with a legal obligation to which the controller is subject;
- the processing is necessary for the protection of the vital interests of the data subject or of another natural person;
- the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- the processing is necessary for the purposes of the legitimate interests of the controller or of a third party, except where those interests are overridden by the interests or fundamental rights and freedoms of the data subject requiring the protection of personal data, in particular where the data subject is a child;
THE SCOPE OF PERSONAL DATA PROCESSED BY THE COMPANY
We inform you that the personal data of the data subjects are processed in the following scope: name, surname, address (street and number, municipality, postcode, country), telephone number, e-mail, VAT.
For e-shop customers, in addition to the above, the IP address and other data that the customer fills in his/her user account may also be processed. This processing is for the purpose of ensuring the quality functioning of the e-shop. For more information on the processing of personal data in the e-shop, please refer to the document Information on the processing of personal data of customers in connection with the operation of the e-shop.
THE PURPOSE AND LEGAL BASIS OF THE PROCESSING OF PERSONAL DATA
As a personal data controller, the Company processes and stores personal data of the data subject for the following purposes within the scope of its activities under the conditions and within the limits set by the applicable legislation, in particular in accordance with the provisions of Article 6(1)(b) of the General Data Protection Regulation:
- performance of the contractual relationship with the data subject as a customer
- keeping internal customer records
- legal obligation to the relevant institutions under the law
- sending newsletters based on customer consent
- sending newsletters on the basis of legitimate interest
- processing required for the necessary operation of the e-shop on the basis of legitimate interest
Newsletters can be sent to existing customers based on legitimate interest. The customer has the possibility to object to this and thus to stop receiving the newsletter. On the basis of consent, it is also possible to send newsletters to "non-customers", i.e. to those who only subscribe to the newsletter via the so-called double opt-in subscription
PERSONAL DATA PROCESSING TIME
Personal data will be processed for the period necessary to ensure mutual rights and obligations arising from the contractual relationship, as follows:
- For the period strictly necessary for the purposes arising from the contractual relationship and from the company's obligations under the law.
- For the purpose of sending newsletters for the duration of the consent given by the customer
ADDITIONAL INFORMATION ABOUT THE PROCESSING OF PERSONAL DATA
The personal data of the data subject are processed automatically in electronic form or manually by the company's employees. Personal data are also transmitted to carriers to the extent necessary for the delivery of the shipment.
The personal data of the data subject will be further processed by the following data processors:
- Shoptet, a.s., which is the operator of the e-shop and their suppliers. The principles of personal data processing in connection with the operation of the e-shop are set out in the document Information on the processing of personal data of customers in connection with the operation of the e-shop
- ALTEC a.s., which provides the administrator with a software solution and its management
- IZA a.s., which performs accounting audits
- BEST IMPACT Agency s.r.o., which provides marketing advice
INFORMATION ON THE RIGHTS OF DATA SUBJECTS
The data subject shall have the right to request the Controller to provide information on the processing of his/her personal data.
The data subject shall have the right to have inaccurate personal data concerning him/her corrected by the Controller without undue delay. Taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by providing an additional declaration. The data subject has the right to have the controller restrict the processing of personal data in the cases provided for in the General Data Protection Regulation.
The data subject has the right to object to the processing of personal data concerning him or her if the controller processes personal data on the following grounds:
- the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller
- processing is necessary for the purposes of the legitimate interests of the Controller or a third party,
- for direct marketing purposes,
- for scientific or historical research or statistical purposes.
The data subject shall have the right to obtain the personal data concerning him or her which he or she has provided to the controller in a structured, commonly used and machine-readable format and to transmit such data to another controller without hindrance from the controller, in the cases provided for in the General Data Protection Regulation.
If the data subject considers that there has been a breach of the law in relation to the protection of his or her personal data, he or she has the right to lodge a complaint with a supervisory authority. The supervisory authority in the Czech Republic is the Office for Personal Data Protection.
Address for enquiries in relation to the processing of personal data or to exercise the data subject's rights against the controller:
NAREX Ždánice, spol. s r.o.
Městečko 250, 69632 Ždánice