I. BASIC PROVISIONS
1. The controller of personal data pursuant to Article 4(7) of the Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as “GDPR”) is Creative Heroes, Ltd., ID 248 52 996, with its registered office at Ocelkova 643/20, 198 00 Prague 9 (hereinafter referred to as the “controller”).
3. Personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
4. The controller has not appointed a Data Protection Officer..
II. SOURCES AND CATEGORIES OF PROCESSED PERSONAL DATA
1. The controller processes personal data provided by you or personal data obtained by the controller in connection with the fulfillment of your order.
2. The controller processes your identification and contact details, as well as data necessary for the performance of the contract.
III. LEGAL BASIS AND PURPOSE OF PROCESSING PERSONAL DATA
1. The legal basis for the processing of personal data is:
- the performance of a contract between you and the controller pursuant to Article 6(1)(b) of the GDPR,
- the legitimate interest of the controller in providing direct marketing (including the sending of commercial communications and newsletters) pursuant to Article 6(1)(f) of the GDPR,
- your consent to the processing for the purposes of direct marketing (including the sending of commercial communications and newsletters) pursuant to Article 6(1)(a) of the GDPR in conjunction with Section 7(2) of Act No. 480/2004 Coll., on Certain Information Society Services, if there has been no order of goods or services.
2. The purpose of processing personal data is:
- the fulfillment of your request, order, and the performance of rights and obligations arising from the contractual relationship between you and the controller; when placing an order, personal data necessary for successful order fulfillment (name, address, contact) are required, providing personal data is a necessary requirement for the conclusion and performance of the contract, and without providing personal data, it is not possible to conclude or fulfill the contract from the controller’s side,
- sending of commercial communications and other marketing activities.
3. The controller engages in automated individual decision-making within the meaning of Article 22 of the GDPR. You have given your explicit consent to such processing.
IV. RETENTION PERIOD OF DATA
1. The controller retains personal data for:
- the period necessary for the performance of rights and obligations arising from the contractual relationship between you and the controller and the assertion of claims under these contractual relationships (for a period of 15 years from the termination of the contractual relationship),
- the period until the withdrawal of consent to the processing of personal data for marketing purposes, but no longer than 15 years if personal data are processed based on consent.
2. After the expiration of the retention period, the controller will erase the personal data.
1. Recipients of Personal Data (Data Processor’s Subcontractors)
- The recipients of personal data are individuals involved in the delivery of goods/services/payment processing under the contract, individuals involved in ensuring service operations, and individuals providing marketing services.
2. The data processor intends to transfer personal data to a third country (a country outside the EU) or an international organization. Recipients of personal data in third countries include providers of advertising, hosting, mailing, or cloud services.
VI. YOUR RIGHTS
1. Under the conditions specified in the GDPR, you have the right to:
- Access your personal data according to Article 15 of the GDPR.
- Rectify your personal data or restrict processing according to Articles 16 and 18 of the GDPR, respectively.
- Erase your personal data according to Article 17 of the GDPR.
- Object to the processing of your personal data according to Article 21 of the GDPR.
- Data portability according to Article 20 of the GDPR.
- Withdraw your consent to the processing, in writing or electronically, to the address or email of the data controller specified in Article III of these terms.
2. Furthermore, you have the right to lodge a complaint with the Office for Personal Data Protection if you believe that your right to personal data protection has been violated.
VII. CONDITIONS FOR ENSURING PERSONAL DATA SECURITY
1. The data controller declares that appropriate technical and organizational measures have been taken to secure personal data.
2. The data controller has implemented technical measures to secure data storage and physical storage of personal data.
3. The data controller declares that only authorized persons have access to personal data.
VIII. FINAL PROVISIONS
1. Odesláním objednávky z internetového objednávkového formuláře potvrzujete, že jste seznámen/a s podmínkami ochrany osobních údajů a že je v celém rozsahu přijímáte.
2. By checking the consent box on the online form, you confirm that you have read and fully accept the terms of personal data protection.
3. The data controller is entitled to modify these terms. The new version of the personal data protection terms will be published on their website or sent to you via email provided to the data controller.
These terms come into effect on May 25, 2018.