Personal Data Protection Policy

Personal Data Protection Policy

I. Basic Provisions

  1. The controller of personal data under Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter the "GDPR") is HOPA CZ, Company ID No.: 25502531, Tax ID No.: CZ25502531 (hereinafter the "Controller").

  2. The Controller's contact details are:

Address: Divnice 144, 763 21 Slavičín

Email: info@hopa.cz

Telephone: +420 577 342 630

3. Personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is a natural person who can be identified, directly or indirectly, in particular by reference to a particular identifier, such as a name, an identification number, location data, a network identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

4. The Controller has not appointed / has appointed a data protection officer. The data protection officer's contact details are: 

II. Sources and Categories of Personal Data Processed

  1. The Controller processes the personal data you have provided to it, or personal data the Controller has obtained in performing your order.

  2. The Controller processes your identification and contact data and the data necessary for the performance of the contract.

III. Legal Basis and Purpose of the Processing of Personal Data

  1. The legal basis for processing personal data is:
  • the performance of the contract between you and the Controller under Article 6(1)(b) of the GDPR,
  • the Controller's legitimate interest in providing direct marketing (in particular for sending commercial communications and newsletters) under Article 6(1)(f) of the GDPR,
  • your consent to processing for the purposes of providing direct marketing (in particular for sending commercial communications and newsletters) under Article 6(1)(a) of the GDPR in conjunction with Section 7(2) of Act No. 480/2004 Coll., on certain information society services, in the event that no order of goods or services has been placed.

2. The purpose of processing personal data is:

  • the handling of your order and the exercise of the rights and obligations arising from the contractual relationship between you and the Controller; when an order is placed, personal data are required that are necessary for the successful handling of the order (name and address, contact details), the provision of personal data being a necessary requirement for the conclusion and performance of the contract; without the provision of personal data, it is not possible to conclude the contract or for the Controller to perform it,
  • the sending of commercial communications and the carrying out of other marketing activities.

3. The Controller does not engage in / engages in automated individual decision-making within the meaning of Article 22 of the GDPR. You have given your express consent to such processing.

IV. Data Retention Period

  1. The Controller retains personal data:
  • for the period necessary to exercise the rights and obligations arising from the contractual relationship between you and the Controller and to assert claims arising from those contractual relationships (for a period of 15 years from the end of the contractual relationship),
  • until consent to the processing of personal data for marketing purposes is withdrawn, for a maximum of …. years, where personal data are processed on the basis of consent.

2. After the expiry of the personal data retention period, the Controller will erase the personal data.

V. Recipients of Personal Data (Subcontractors of the Controller)

  1. The recipients of personal data are persons: 
  • participating in the delivery of goods / services / execution of payments on the basis of the contract,
  • providing the service of operating the e-shop (Shoptet) and other services in connection with the operation of the e-shop,
  • providing marketing services.

2. The Controller does not intend / intends to transfer personal data to a third country (a country outside the EU) or to an international organisation. The recipients of personal data in third countries are providers of mailing services / cloud services. 

VI. Your Rights

  1. Under the conditions laid down in the GDPR, you have:
  • the right of access to your personal data under Article 15 of the GDPR,
  • the right to rectification of personal data under Article 16 of the GDPR, or to restriction of processing under Article 18 of the GDPR,
  • the right to erasure of personal data under Article 17 of the GDPR,
  • the right to object to processing under Article 21 of the GDPR, and
  • the right to data portability under Article 20 of the GDPR,
  • the right to withdraw consent to processing, in writing or electronically, to the address or email of the Controller given in Article III of this Policy.

2. You also have the right to lodge a complaint with the Office for Personal Data Protection if you believe that your right to the protection of personal data has been infringed.

VII. Personal Data Security Conditions

  1. The Controller declares that it has taken all appropriate technical and organisational measures to secure personal data.

  2. The Controller has taken technical measures to secure data storage and the storage of personal data in paper form, in particular …

  3. The Controller declares that only persons authorised by it have access to personal data.

VIII. Final Provisions

  1. By submitting an order from the online order form, you confirm that you have acquainted yourself with the personal data protection policy and that you accept it in its entirety.

  2. You agree to this Policy by ticking the consent box via the online form. By ticking the consent box, you confirm that you have acquainted yourself with the personal data protection policy and that you accept it in its entirety.

  3. The Controller is entitled to amend this Policy. It will publish the new version of the personal data protection policy on its website and will at the same time send you the new version of this Policy to your email address, which you provided to the Controller.