PRINCIPLES OF PERSONAL DATA PROCESSING
By filling in an order, signing up for commercial communications or browsing our website www.mojerukavice.cz , you are enabling the operator of an online shop (Osičková Ludmila) IčO: 29124042 (hereinafter referred to as the “Administrator” or the “Data Controller”) to use your personal data. This website has the task of informing you, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data (GDPR), what information we collect about you, why and how we use your information, what your rights are with regard to our personal data and how you can exercise them with us in accordance with the GDPR Regulation.
WHAT INFORMATION ARE WE GATHERING ABOUT YOU?
In the order register we process your personal data in the range of e-mail, full name, phone, address and price. We first need the data for processing the order, i.e. for performance of the contract. Once the contract is fulfilled, we use the personal data from the order log for other purposes. It is in our legitimate interest to maintain the entire order register for legal protection against future disputes. Due to the statutory guarantee period for the quality of goods, the limitation period and the functioning of the judicial system, we have to process your data from the order register for 6 years. We also use the data from the order log to fulfill our legal obligation to archive documentation for possible financial control, for 10 years.
We process your personal data in the User Register to the extent that you provide it to us when registering or editing a profile, when adding to a waitlist, when creating an order or when linking your account to social networks. It is in our legitimate interest to maintain a database of users, in addition to allowing individual customers to maintain and manage their profile as part of their registration on the website. In addition to registration purposes, we also use this database for identification of persons when dealing with the customer centre, when handling complaints or when processing orders at dispensaries or for marketing purposes (you can find out more about these below). We also use the data for processing for marketing purposes. The description of these personal data is discussed in detail below. We hold personal data for the purpose of user registration for 5 years from your last completed order.
We also use your personal data for transport (fulfilment of our part of the contract). We pass these data on to shipping companies, and upon transmission, we create a log that serves as a backup in case of a transmission error via the information system. For reasons of possible complaints from both the customer and the carrier, we process this data for the purpose of providing transportation for a period of 5 years from the creation of the order.
Saving personal data from your order will allow us to make it easier for you to purchase more and to pre-fill the data previously used in your electronic basket. In order to facilitate purchase, we process personal data on the basis of the legal title of legitimate interest and keep them in databases together with other data, i.e. for 5 years from the execution of your last order.
WHAT DATA DO WE USE FOR MARKETING PURPOSES?
For marketing purposes, we process your contact details, which you fill in when ordering or signing up for commercial communications, and which we use to send commercial communications. We try to keep you entertained and inspired by our information, which is why it is important for us to know your reaction to these messages and why we retain feedback about them. Of course, you can opt out of our commercial communications at any time. After full logout (from all information channels), we will no longer use your contact personal data to send business communications.
Your opinion is important to us and is our driving force. The feedback we receive from you is therefore carefully stored. We are interested in how satisfied you are with our goods, website, carriers and much more. We also need to monitor the use of discount vouchers that you apply to us. We are trying to protect us and you from their misuse and at the same time it allows us to solve problems with vouchers operationally with the help of a customer centre.
We also want to reward you for your loyalty and thank you for the favor you have shown us in the long term. In order to know which of the special benefits you are entitled to, we need to know, among other things, how much money you order and purchase from us, how much of the ordered goods you return and how long you have been our customer. It is in our legitimate interest as a trader to monitor this information with individual customers, especially when we can offer you substantial benefits based on such monitoring and thus appreciate your loyalty.
We use all personal data used in marketing for legal reasons of legitimate interest and keep it for marketing purposes for 5 years from your last order.
TO WHOM WE PASS YOUR DATA?
Your personal data is used exclusively for our internal needs and only for the above reasons. However, we do not only provide all necessary services regarding personal data ourselves, we also use the services of third parties (specialised companies). We have a contract with third parties to whom we provide your personal data, under which we are able to secure and protect your data protection rights.
As part of your order, personal data are therefore transferred to e-commerce solution companies and transport companies:
In addition to ordering, we process your personal data in third party information, analysis and marketing systems that we absolutely need for our business, such as:
WHAT RIGHTS DOES GDPR GIVE YOU AND HOW TO USE THEM IN OUR COUNTRY?
Right of access to and rectification of information
RIGHT TO OBJECT TO THE PROCESSING OF PERSONAL DATA
Even if we process your personal data based on our legitimate interest, you have the right to object to such processing, including to the processing of personal data that we process for direct marketing purposes. You can do this by sending a message to the e-mail address email@example.com. If you make such an objection, we will evaluate without undue delay to what extent we can legally assert the validity of our reasons for processing your personal data over the objections you have raised and how we will handle your personal data in the meantime. Until we can prove to you our legitimate reasons for processing, We will not process your personal data further.
RIGHT TO RESTRICT WORK WITH PERSONAL DATA
You have the right to request that we restrict any processing of your personal data, including their deletion, i.e. that we stop disposing of them:
RIGHT TO BE FORGOTTEN (RIGHT TO DELETE PERSONAL DATA)
In case you find that we process your personal data:
you have the right to request that we delete the personal data thus processed without undue delay from your notification of such facts by sending a message to the e-mail address firstname.lastname@example.org. However, we cannot delete the data even at your request if their processing is necessary for the exercise of the right to freedom of expression and information, for the fulfilment of one of our legal obligations or for the fulfilment of a task performed in the public interest or for the determination, exercise or defence of our legal claims.
RIGHT TO PROVIDE DATA IN MACHINE-READABLE FORM
If by sending a message to email@example.com you ask us to provide you with your personal data processed by us, we will send it to you in a structured commonly used and machine-readable format (e.g. *.xls, *.csv, or similar format). If you ask us to send your personal data to another data controller, We will, of course, grant your request.
THE RIGHT TO UNSUBSCRIBE FROM SENDING COMMERCIAL MESSAGES AT ANY TIME
In case you no longer want to receive commercial communications from us, you can avoid sending them either by clicking on the link included in each commercial communication or by modifying the subscription in your profile created by registering on our website.
THE RIGHT TO WITHDRAW CONSENT TO THE SENDING OF COMMERCIAL COMMUNICATIONS AT ANY TIME
In case we want your consent to the processing of personal data as part of our special events, you can withdraw this consent at any time, even without giving reasons. You can withdraw your consent either in the manner more precisely described in the rules of the consumer competition, or always by sending a withdrawal of consent to the e-mail address firstname.lastname@example.org
RIGHT TO LODGE A COMPLAINT WITH THE DATA PROTECTION AUTHORITY
If, in your opinion, we do not fulfil all our legal obligations arising from the processing of your personal data, please contact our Customer Care Centre. If our colleagues do not help you, you are of course entitled to contact the Office for Personal Data Protection, either at the address of the Office's seat: Pplk. Sochora 27, Praha 7, ZIP code 170 00, e-mail email@example.com or any other way that the data protection authority will accept. Further information about the Office can be found on the website www.uoou.cz.