GDPR
Personal Data Processing Policy
Basic Information
1.1. Document content.
This Personal Data Processing Policy describes how we process the personal data of visitors, customers of the online store, and other individuals. Here you will learn, in particular, what personal data we process, why and on what basis we do so, to whom we disclose it, and what rights you have in relation to the processing. All personal data processing is carried out in accordance with the General Data Protection Regulation of the European Union No. 2016/679, commonly known as GDPR.
1.2. Our position.
All described personal data processing activities are carried out by the entrepreneur Daniel Leitner, with a registered office at Jiřího Wolkera 1324/24, 415 01 Teplice, IČO 03872408, registered in the Trade Register, DIČ CZ9109232517 (for better clarity, referred to as "we"). This means that we determine the purposes for which your personal data is collected, set the means of processing, and are responsible for its proper execution.
1.3. Scope of personal data processing. The personal data we process includes:
1.3.1. Identification data (especially name and surname, or identification number and tax identification number for entrepreneurs),
1.3.2. Contact data (especially address, email address, and phone number),
1.3.3. Order and transaction data (especially ordered goods and services, chosen payment and shipping methods, and other information related to the order),
1.3.4. Communication data (especially the content and other data associated with communication between us and you),
1.3.5. Registration and settings data (especially data related to your user account if you register with us, and data regarding the settings of our services),
1.3.6. Data on the use of our website (especially IP address, data on your device, data obtained through cookies, or data on your actions on our website),
1.3.7. Preference data (e.g., favorite scents and perfumes).
Why and how do we process your personal data?
2.1. Website functionality. If you visit our website, we process your personal data to ensure its proper functioning, based on our legitimate interest in providing our services via the internet.
2.2. User account. Based on the contract, we process your personal data when managing user accounts in our online store.
2.3. Improving and developing our services. We also process your personal data to measure website traffic and create statistics and records that help us evaluate and develop our services, based on our legitimate interest in monitoring website operations and optimizing our services.
2.4. Determining your satisfaction. We process your personal data to determine your satisfaction with our services, based on our legitimate interest in obtaining your feedback.
2.5. Security and testing. To protect our website and other services from cyberattacks and fraud, and to test new functionalities and changes to the website, we process your personal data based on our legitimate interest in securing and improving our services.
2.6. Protection of legal claims and internal control. We process your personal data based on our legitimate interests for the protection of legal claims and our internal records and control.
2.7. Sending marketing communications to customers. If we obtain your electronic contact details in connection with an order or our services, we may process your personal data to offer our goods and services through marketing communications, based on our legitimate interest in promoting our products, unless you have opted out of receiving such communications.
2.8. Sending marketing communications based on consent. With your consent, we process your personal data to send marketing communications.
2.9. Online advertising. To display personalized ads on our website and third-party websites, we may process data about your use of our website. Depending on the type of advertisement, the legal basis may either be our legitimate interest in promoting our products, or in some cases, consent, if we request and you decide to grant it.
2.10. Fulfilling our legal obligations. We also process your personal data for the purposes of and in compliance with our legal obligations, particularly in connection with providing information to public authorities.
2.11. Fulfilling and concluding contracts. We process your personal data based on and for the purpose of fulfilling our contractual obligations with you and for the conclusion of such contracts. This may also include processing the personal data of recipients and other users of goods and services.
2.12. Customer support. To handle your requests related to orders, we process your personal data based on our obligations to fulfill contracts concluded between us and you and for the conclusion of such contracts. When handling other requests, we process your personal data based on our legitimate interest in providing our services and ensuring appropriate support.
2.13. Data retention period. We retain personal data only for as long as necessary to achieve the stated purposes of personal data processing. After the purpose of the processing has ceased, we promptly delete the personal data. Typically, we store personal data for the duration of the limitation period (usually 3 years) and one year after its expiration to account for possible claims made at the end of the limitation period. Beyond that, the following specific retention periods apply:
2.13.1. Data associated with a user account is retained for the entire duration of the account's existence until it is deleted.
2.13.2. In the case of court and other proceedings, we process your personal data to the necessary extent for the duration of such proceedings and the remaining limitation period after its conclusion.
2.13.3. For sending marketing communications to customers, we process your personal data until you object to the sending of marketing communications.
2.13.4. For sending marketing communications based on your consent, we process your personal data until you revoke your previous consent to process personal data.
2.13.5. For fulfilling legal obligations, we process personal data for as long as necessary to fulfill these obligations.
To whom is personal data disclosed?
3.1. Processors. We also use the services of other entities as processors, who process personal data only according to our instructions. These include:
3.1.1. Providers of IT services and other technology suppliers,
3.1.2. Operators of analytical and marketing tools,
3.1.3. Providers of communication tools,
3.1.4. Operators of customer satisfaction programs,
3.1.5. Logistics partners.
3.2. Controllers. We may disclose your personal data to other entities acting as controllers:
3.2.1. Our suppliers involved in fulfilling the contract, particularly carriers and payment system operators,
3.2.2. Operators of advertising systems and social networks.
3.3. Data transfers outside the EU. In some cases, your personal data may be transferred outside the European Economic Area, either based on an adequacy decision under Article 45 of GDPR, appropriate safeguards under Article 46 of GDPR, or an exception under Article 49 of GDPR.
Your Rights
4.1. Data subject rights. Regarding your personal data, you have the right to:
4.1.1. Request the correction of inaccurate or outdated personal data. If you find that the personal data we process about you is inaccurate or incomplete, you have the right to have it corrected or supplemented without undue delay.
4.1.2. Request confirmation of whether processing is taking place and, if it is, to receive information about this processing as specified in Article 15 of GDPR, and also to receive a copy of the processed data (we may charge a fee for additional copies to cover necessary costs).
4.1.3. In some cases, you have the right to request that we delete your personal data. We will delete your personal data without undue delay if we no longer need it for the purposes for which we processed it, or if you exercise your right to object to processing and we find that we no longer have any legitimate interests that justify this processing, or if it turns out that our processing of personal data has ceased to comply with generally binding regulations. However, this right does not apply if the processing of your personal data is still necessary to fulfill our legal obligations, for archival purposes, scientific or historical research, or statistical purposes, or for the determination, exercise, or defense of our legal claims.
4.1.4. Exercise the right to restrict the processing of personal data. This right allows you to request, in certain cases, that your personal data be marked and not subject to any further processing—though not permanently (as in the case of the right to deletion), but for a limited time. We must restrict the processing of personal data when you dispute the accuracy of personal data until we agree on which data is correct, or when we process your personal data without sufficient legal basis (e.g., beyond what we are required to process), but you prefer restricting the data instead of deleting it (e.g., if you expect to provide us with such data in the future), or when we no longer need personal data for the stated purposes of processing, but you require it to determine, exercise, or defend your legal claims, or when you object to processing, and we are required to restrict the processing while we investigate whether your objection is justified.
4.1.5. Request the transfer of personal data in cases of processing based on your consent or a contract.
4.1.6. Object to the processing of personal data carried out based on our legitimate interest. We will stop processing your personal data unless we have compelling legitimate grounds to continue such processing. In the case of objections to marketing activities, we will discontinue those activities in any case.
4.1.7. At any time, express your objection to the processing of your personal data for the purpose of sending marketing communications, as well as withdraw your previous consent to the processing of personal data for other purposes, unless the processing is required for the fulfillment of our contractual obligations, compliance with our legal obligations, or other purposes based on our legitimate interests.
4.2. How to exercise your rights. You can exercise your rights in one of the following ways:
4.2.1. By email at our email address.
4.3. Right to file a complaint with the supervisory authority. If you believe that we have violated GDPR in processing your personal data, you have the right to file a complaint with the Office for Personal Data Protection, located at Pplk. Sochora 27, 170 00 Prague 7 (http://www.uoou.cz).
Cookies
5.1. Files stored on your device for later access (temporary files).
Our website may use cookies (and other similar technologies, such as Web Storage). This means that we store small data files in a designated area of your device's memory that allow us to provide you with the service and improve it further. For simplicity, we will refer to all these technologies as "cookies."
5.2. Cookies necessary for providing the service. Some cookies are technologically necessary for providing the service. This means that it is not possible to avoid storing them while maintaining the functionality of the service. These primarily include cookies for:
5.2.1. Saving your choices related to the order,
5.2.2. Saving website settings,
5.2.3. Logging into a user account,
5.2.4. Ensuring IT security.
5.3. Other types of cookies. We use some cookies to provide you with a better quality and more personalized service. As part of this, we may store cookies on your device:
5.3.1. To ensure website traffic analysis and usage, including third-party cookies,
5.3.2. For advertising purposes, to display tailored ads on our website and other websites, including third-party cookies,
5.3.3. To ensure connection with social networks, including third-party cookies,
5.3.4. To determine your geographical location.
5.4. Cookie settings. You can configure cookie settings through the settings available on our website. Through the relevant options on your device, you can configure the use of cookies on our website, for example, by blocking cookies if you disagree with their use on our website. If you use this option, you acknowledge that some parts of the service may not function correctly.