Data Protection Policy
AND.
Basic Provisions
- The controller of personal data under Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to as the "GDPR") is Pavla Najmanova, ID No. 66901481, VAT No. CZ7953120318, with registered office at Na Klaudiance 781/19, Podoli, 147 00 Prague 4 (hereinafter referred to as the "controller").
- The controller's contact details are:
address: Na Klaudiánce 781/19, Podolí, 147 00 Praha 4
e-mail: info@designpn.cz - Personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
II.
Sources and Categories of Processed Personal Data
- The controller processes personal data that you have provided to him/her or personal data that the controller has obtained on the basis of fulfilling your order.
- The controller processes your identification and contact details and data necessary for the performance of the contract.
III.
Legal Basis and Purpose of Personal Data Processing
- The legal basis for processing personal data is
▪︎ the performance of the contract between you and the controller pursuant to Article 6(1)(b) GDPR,
▪︎ the legitimate interest of the controller in providing direct marketing (in particular for sending commercial messages and newsletters) pursuant to Article 6(1)(f) GDPR,
▪︎ your consent to the processing for the purposes of providing direct marketing (in particular for sending commercial messages and newsletters) pursuant to Article 6(1)(a) GDPR in conjunction with Section 7(2) of Act No. 480/2004 Coll., on Certain Information Society Services, if no order for goods or services has been placed. - The purpose of processing personal data is
▪︎ the processing of your order and the performance of rights and obligations arising from the contractual relationship between you and the controller; when placing an order, personal data that is necessary for the successful processing of the order (name and address, contact) is required, the provision of personal data is a necessary requirement for the conclusion and performance of the contract by the controller, without the provision of personal data, it is not possible to conclude or perform the contract by the controller,
▪︎ sending commercial messages and conducting other marketing activities. - The administrator does not engage in automated individual decision-making within the meaning of Article 22 of the GDPR. You have given your express consent to such processing.
IV.
Data retention period
- The administrator keeps personal data
▪︎ for the time necessary to fulfill rights and obligations arising from the contractual relationship between you and the administrator and to enforce claims arising from these contractual relationships (for 15 years from the termination of the contractual relationship).
▪︎ for the period until the consent to the processing of personal data for marketing purposes is revoked, no more than 10 years, if personal data is processed on the basis of consent. - After the expiration of the data retention period, the administrator will delete the personal data.
IN.
Recipients of personal data (administrator's subcontractors)
- The recipients of personal data are individuals
▪︎ involved in the delivery of goods / services / payment processing based on the contract,
▪︎ involved in ensuring the operation of services,
▪︎ providing marketing services. - The administrator does not intend to transfer personal data to a third country (a country outside the EU) or an international organization. Recipients of personal data in third countries are providers of mailing services / cloud services.
VI.
Your Rights
-
Under the conditions set out in the GDPR, you have the following rights:
▪︎ the right to access your personal data according to Article 15 of the GDPR,
▪︎ the right to rectification of personal data according to Article 16 of the GDPR, or the right to restrict processing according to Article 18 of the GDPR,
▪︎ the right to erasure of personal data according to Article 17 of the GDPR,
▪︎ the right to object to processing according to Article 21 of the GDPR,
▪︎ the right to data portability according to Article 20 of the GDPR, and
▪︎ the right to withdraw consent to the processing of personal data in writing or electronically to the address or email of the controller specified in Article III of these terms. -
Furthermore, you have the right to file a complaint with the Office for Personal Data Protection if you believe that your right to personal data protection has been violated.
VII.
Personal data security conditions
- The administrator declares that he has taken all appropriate technical and organizational measures to secure personal data.
- The administrator has taken technical measures to secure data storage and storage of personal data in paper form, in particular the use of antivirus programs, secure backup storage, secure access passwords, etc.
- The administrator declares that only authorized persons appointed by him have access to personal data.
VIII.
Final provisions
- By submitting an order from the online order form, you confirm that you have become acquainted with the conditions of personal data protection and that you accept them in their entirety.
- By checking the consent box on the online form, you confirm that you have become acquainted with the conditions of personal data protection and that you accept them in their entirety.
- The controller is entitled to change these terms and conditions. The new version of the terms of personal data protection will be published on the controller's website, or a new version of these terms will be sent to the email address you provided to the controller.
These terms and conditions become effective on February 14, 2023.