Privacy policy

Personal data protection

Effective 1 January 2021. This policy describes how we handle your personal data in line with GDPR.

1. Basic provisions

The data controller under Article 4(7) of Regulation (EU) 2016/679 (GDPR) is Vlastislav Kabeláč Čiháček, ID 69181888, registered office Na Vyhlídce 285, Tehov 251 01, Czech Republic (the "controller").

Controller contact:

Personal data means any information about an identified or identifiable natural person.

The controller has not appointed a data protection officer.

2. Sources and categories of personal data processed

The controller processes personal data you have provided or that the controller has obtained as part of fulfilling your order. This includes your identification and contact details and data necessary to perform the contract. The controller also processes cookies for:

  • measuring website traffic and creating visitor statistics;
  • basic website functionality.

You can use the website in a mode that does not allow the collection of behaviour data — either via your browser settings, or by changing your privacy settings here.

3. Legal grounds and purpose of processing

The legal grounds are:

  • performance of a contract under Art. 6(1)(b) GDPR;
  • the controller's legitimate interest in direct marketing under Art. 6(1)(f) GDPR;
  • your consent for direct marketing under Art. 6(1)(a) GDPR.

Purpose of processing: handling your order and exercising rights and obligations from the contractual relationship; sending commercial communications and other marketing.

The controller does not engage in automated individual decision-making within the meaning of Art. 22 GDPR.

4. Retention period

The controller retains personal data:

  • for the time necessary to exercise rights and obligations from the contractual relationship and to claim against them (15 years after termination);
  • until consent for marketing processing is withdrawn, no longer than 5 years where processing is based on consent.

5. Recipients of personal data

Processing is carried out by the controller; the following processors may also process the data on the controller's behalf:

  • Účetní do domu (accounting), Ke Hřišti 137, Radlík, Jílové u Prahy 254 01, ID 47537175;
  • Google LLC (Google Analytics) — anonymised traffic analytics;
  • Meta Platforms Ireland Limited (Meta Pixel) — ad campaign measurement;
  • Resend Inc. — transactional email delivery from the contact form;
  • Google Ireland Limited (Firebase Hosting) — site hosting.

Where data is transferred outside the EU, it is on the basis of standard contractual clauses under Art. 46 GDPR.

6. Your rights

Under the GDPR you have:

  • the right of access (Art. 15);
  • the right to rectification (Art. 16) and restriction of processing (Art. 18);
  • the right to erasure (Art. 17);
  • the right to object to processing (Art. 21);
  • the right to data portability (Art. 20);
  • the right to withdraw consent at any time, in writing or by email to the controller's address above.

You also have the right to lodge a complaint with the Czech Data Protection Authority (Úřad pro ochranu osobních údajů).

7. Data security

The controller declares it has taken all appropriate technical and organisational measures to secure personal data, including encryption, backups, security passwords and physical locks. Only authorised persons have access.

8. Final provisions

By submitting an order via the online order form, you confirm you have read these privacy terms and accept them in full.

The controller may amend these terms; the new version will be published on this website.

This policy is effective from 1 January 2021.

Change privacy settings