Personal Data Protection and Processing Policy

pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27th April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), which entered into force on 25 May 2018 and is generally known by the abbreviation GDPR


 

This personal data protection and processing policy (hereinafter referred to as the "Policy") describes which personal data of customers who are natural persons, or other customers in relation to natural persons acting on their behalf (hereinafter referred to as the "Data Subject"), are processed during the business activities of the company Bohempia s.r.o., with registered office at Praha 8, Karlín, Sokolovská 105/76, Postal Code 186 00, ID No.: 038 27 879, registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, File 238253 (hereinafter referred to as the "Data Controller").

This Policy sets out the types of personal data we collect and process when you use our services, as well as the manner in which your personal data is used, shared, and protected. Here you will also find an explanation of the options you have regarding your personal data and how you can contact us. We hereby inform you below about the processing of your personal data and about your rights in accordance with Art. 12 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), which entered into force on 25 May 2018 and is also referred to as GDPR (hereinafter also referred to as "GDPR").

Personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

The Data Controller has not appointed a Data Protection Officer.

 

PROCESSORS AND RECIPIENTS OF PERSONAL DATA

The Data Controller is entitled to transfer personal data to entities with which it has concluded a personal data processing agreement and which will process personal data for the Data Controller as its processors. Based on the above, the Data Controller is entitled to transfer personal data of the Data Subject to the following entities, or categories of entities:

  • KODAP Jablonec, s.r.o., ID No.: 250 02 554, with registered office at Podhorská 710/7, 466 01 Jablonec nad Nisou, registered in the Commercial Register maintained by the Regional Court in Ústí nad Labem, Section C, File 10634
  • Techpartners s.r.o., ID No.: 191 14 192, with registered office at Kozomínská 621, 250 70 Postřižín, registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, File 381644.

Personal data of the Data Subject are further transferred to the following recipients/categories of recipients:

  • employees of the Data Controller,
  • persons in another contractual relationship with the Data Controller (e.g., providers of marketing and advertising services, law firms, e-mailing service providers),
  • e-shop platform provider Shoptet, a.s., ID No.: 289 35 675, with registered office at Dvořeckého 628/8, Břevnov, 169 00 Praha 6, registered in the Commercial Register maintained by the Municipal Court in Prague, Section B, File 25395,
  • companies involved in the dispatch of payments,
  • companies involved in the dispatch of goods,
  • state authorities within the scope of fulfilling legal obligations set forth by relevant legal regulations.

 

CATEGORIES OF PROCESSED PERSONAL DATA

The Data Controller is entitled to process mainly the following personal data of the Data Subject:

  • address and identification data used for clear and unambiguous identification of the Data Subject: first name, last name, billing address, delivery address, ID No., Tax ID No., and data enabling contact with the Data Subject: e.g., phone number and e-mail address,
  • descriptive data: bank details, payment information, or credit/debit card information,
  • account login information, including the name under which the Data Subject acts on the Internet and a unique user ID,
  • data provided beyond the scope of relevant laws processed within the consent granted by the Data Subject (e.g., use of personal data for the purpose of personnel proceedings, use of personal data for promotional purposes, and similar),
  • personal settings (preferences) including settings in the area of marketing and the use of cookies by the Data Subject.

 

PURPOSES AND LEGAL BASIS FOR PERSONAL DATA PROCESSING

The Data Controller processes personal data of the Data Subject for the following purposes:

  1. entering into a contract and performance under the contract, pre-contractual negotiations, pursuant to Article 6(1)(b) of the GDPR,
  2. compliance with a legal obligation to which the Data Controller is subject under generally binding legal regulations, pursuant to Article 6(1)(c) of the GDPR (e.g., the Data Controller's obligation to retain accounting and tax documents),
  3. the establishment, exercise or defense of legal claims of the Data Controller, pursuant to Article 6(1)(f) of the GDPR,
  4. sending commercial communications, pursuant to Article 6(1)(f) of the GDPR on the grounds of the Data Controller's legitimate interest in direct marketing,
  5. other marketing purposes of the Data Controller associated with offering products and services; sending information about organized events, products, services and other activities (e.g., via newsletters, telemarketing), pursuant to Article 6(1)(a) of the GDPR.

 

DURATION OF PERSONAL DATA PROCESSING

Personal data will be processed only for the time necessary given the purpose of their processing. With regard to the above:

  • for the purpose under letter a) above, personal data will be processed until the termination of obligations under the contract (this does not affect the Data Controller’s option to subsequently further process these personal data – to the necessary extent for the purpose under letters b), c), d) and/or e) above),
  • for the purpose under letter b) above, personal data will be processed for the duration of the relevant legal obligation of the Data Controller,
  • for the purpose under letter c) above, personal data will be processed until the expiry of the 4th calendar year following the end of the warranty period under the contract (if a quality guarantee was agreed upon in the contract), but at least until the expiry of the 5th calendar year following the termination of obligations under the contract,
  • in the event of initiation and continuation of judicial, administrative, or other proceedings in which rights or obligations of the Data Controller in relation to the relevant Data Subject are resolved, the period of personal data processing for the purpose under letter c) above shall not end before the conclusion of such proceedings,
  • for the purpose of sending commercial communications under letter d) above, personal data will be processed until the Data Subject expresses disagreement with such processing,
  • for the purposes under letter e) above, personal data will be processed for the period for which the Data Subject granted consent to the Data Controller according to a separately expressed consent to the processing of personal data. In this case, the Data Subject acknowledges that before the expiry of this period, the Data Controller may contact them for the purpose of renewing their consent.

At the latest by the end of the calendar quarter following the expiry of the processing period above, the relevant personal data whose purpose of processing has ceased to exist will be disposed of (by shredding or another method that ensures unauthorized persons cannot become acquainted with the personal data) or anonymized.

METHOD OF PERSONAL DATA PROCESSING

The processing of personal data is carried out by the Data Controller. The processing is carried out at the Data Controller's registered office, or at other places of business of the Data Controller, by individual authorized employees of the Data Controller, or Processors. The Data Controller may collect or obtain personal data through its website at www.bohempia.eu, forms, electronic or telephone contact, personal meetings, or otherwise. Processing takes place via computer technology, or manually for personal data in paper form, in compliance with all security principles for the management and processing of personal data. For this purpose, the Data Controller has adopted technical and organizational measures to ensure the protection of personal data, in particular measures to prevent unauthorized or accidental access to personal data, their alteration, destruction or loss, unauthorized transfers, unauthorized processing, as well as other misuse of personal data. All entities to which personal data may be made accessible respect the Data Subjects' right to privacy protection and are obliged to act in accordance with applicable legal regulations concerning personal data protection. 

Automated individual decision-making or profiling will not be performed based on the provided data. Personal data of Data Subjects will not be transferred to third countries.

 

INFORMATION PROVIDED TO DATA SUBJECTS UNDER GDPR

In connection with the processing of their personal data, Data Subjects have a number of rights, including the right to request from the Data Controller:

  • access to their personal data (under the conditions of Art. 15 GDPR),
  • rectification or erasure of personal data (under the conditions of Art. 16 or Art. 17 GDPR),
  • restriction of processing of personal data (under the conditions of Art. 18 GDPR),
  • object to the processing of personal data (under the conditions of Art. 21 GDPR),
  • the right to data portability (under the conditions of Art. 20 GDPR),
  • the right to withdraw consent to the processing of personal data, in writing or electronically to the address or email of the Data Controller specified in this Policy.

If a Data Subject discovers or believes that their personal data is being processed in violation of the protection of the private and personal life of the Data Subject or in violation of legal regulations, they have the right to contact the Data Controller with a request for explanation and/or remedy. The request must be submitted in writing by sending a letter or email to the Data Controller's contact details: info@bohempia.eu. 

If the request of the Data subject is found to be justified, the Data Controller will immediately remedy the defective state. This shall not affect the right of the data subject to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement (Art. 77(1) GDPR). In the Czech Republic, this authority is the Office for Personal Data Protection, located at Pplk. Sochora 27, 170 00 Praha 7, tel. +420 234 665 800, www.uoou.cz.

CONCLUSION

The Data Controller reserves the right to modify the Personal Data Protection and Processing Policy at any time and in any way, with the current effective version always being placed on the website www.bohempia.eu.