This site is intended to inform you, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, on the protection of individuals with regard to the processing of personal data (GDPR), of what information we collect about you. for what reason and how we use your information, what are your rights regarding the personal data we use and how you can exercise it with us in accordance with the GDPR regulation.
What information do we collect about you?
In the order register, we process your personal data in the range of:e-mail, full name, telephone, address. We first need the data to process the order. After fulfilling our obligations under the contract, we use personal data from the order register for other purposes. It is in our legitimate interest to maintain a complete record of orders for legal protection against future disputes. Due to the statutory warranty period for the quality of goods, the limitation period and the setting and systematics of the court system, including the time limits for the limitation period for claims, we must process your data from the order register for a period of 6 years. We also use the data from the order register to fulfill our legal obligation to archive documentation due to possible financial control, for a period of 10 years. In the user records, we process your personal data to the extent that you provide it to us when registering or editing the profile, when included in the waitlist, when creating an order. It is in our legitimate interest to maintain a database of users. The database will also allow individual customers to manage and manage your profile during registration on the website. In addition to registration purposes, we also use this database to identify people when dealing with the customer center, when handling complaints, when processing orders at dispensaries or for marketing purposes (you can find out more about them below). We also use the data for processing for marketing purposes. We describe this personal data in detail below. Due to user records, we keep personal data for a period of 5 years from your last order. We also use your personal data for reasons of transport (fulfillment of our obligations under the contract). We hand over this data to the transport companies and, when handing over, we will create a log on the handover, which serves as a backup in the event of a handover error via the information system.
How do we use the data for marketing purposes?
For marketing purposes, we process your contact details, which you fill in when ordering, registering or subscribing to business messages, and which we use to send business messages and to make the messages we send more relevant. We strive to provide you with information from us and to inspire you, so it is important for us to know your reaction to these messages, and therefore we retain feedback about them. Of course, you can unsubscribe from our business messages at any time or change the frequency of their sending. After a complete logout (from all information channels), we will no longer use your contact personal data to send business messages. In order to provide you with the most pleasant customer experience possible and so that we can constantly improve our services, we store data that helps us find out what you are specifically interested in, what you like. We do not want to offer you goods that do not interest you and it is not your style. On the contrary, we want to draw your attention to news from your favorite brand or to discounts in your preferred categories. Your opinion is important to us and is our driving force. We therefore carefully store the feedback we receive from you in the form of answers to questions from questionnaires. We are interested in how satisfied you are with our website. We also want to reward you for your loyalty and thank you for the favor you have shown us for a long time. It is in our legitimate interest of the merchant to monitor this information with individual customers, especially if, based on such monitoring, we can offer you significant benefits and thus appreciate your loyalty. We use all personal data used in marketing for legal reasons of legitimate interest and we store them for marketing purposes for a period of 5 years from your last order. Because we are aware that data about what you are specifically interested in, what you like and your feedback on sending business messages may be perceived as more sensitive data, we only store them for 2 years from the time this data we get.
To whom do we pass data?
Your personal data is used exclusively for our internal needs, and only for the above reasons. However, we do not only provide all the necessary services regarding personal data on our own, we also use the services of third parties (specialized companies). We have a contract with third parties to whom we provide your personal data, on the basis of which we are able to secure and protect your personal data protection rights. At the same time, we do not pass on personal data to any third party for the purpose of their further processing.
Where do we store data?
In the data center of our company. Data center security is fully compliant with GDPR. Access to systems mediating the personal data of our customers is allowed only to a limited number of internal users, for whom it is necessary due to the scope of their work. These may include, for example, employees working in the customer care department, order processing, etc. Individual employees always have access only to the amount of personal data that they necessarily need for their work. Access to all critical systems processing our customers' personal data is restricted only within the internal network.
What GDPR gives you the rights and how to use them here
The right to make information available and the right to correct it
The right to object to the processing of personal data
Even if we process your personal data on the basis of our legitimate interest, you have the right to object to such processing, including objections to the processing of personal data that we process for direct marketing purposes. To do this, send a message to the e-mail address firstname.lastname@example.org If you file such an objection, we will evaluate without undue delay to what extent we can in accordance with the law justify our reasons for processing your personal data through your objections and how we will in the meantime, handle your personal data. Until we provide you with our legitimate reasons for processing, we will not further process your personal data.
The right to restrict work with personal data
You have the right to request that we limit any processing of your personal data, including its deletion, so that we stop handling it:If you let us know that the personal data we collect is inaccurate, until our accuracy is verified. If the processing of your personal data is illegal and you, instead of deleting it, you will ask by sending a message to the e-mail address email@example.com to restrict their use. If we no longer need your personal data to provide our services, but you will need it to exercise your rights. If you object to processing under the paragraph above, until we verify that our reasons for processing outweigh your interests.
The right to be forgotten (right to delete personal data)
In the event that you find that we are processing your personal data:although their processing is no longer necessary for the purposes for which we obtained it; and/or you object to the paragraph above and we will not be able to prove to you legitimate reasons for their processing which outweigh your interests, your rights and freedoms or the exercise or defense of legal claims; and/or we process the data unjustifiably for any other reason, you have the right to request that we delete the personal data processed in this way without undue delay from your notification of such facts by sending a message to the e-mail address firstname.lastname@example.org. However, we may not delete data at your request if their processing is necessary for the exercise of the right to freedom of expression and information, for the fulfillment of any of our legal obligations or for performing a task performed in the public interest or for determining, exercising or defending our legal claims.
Right to provide data in machine readable form
If you send us a message to the e-mail address email@example.com to provide us with your personal data processed by us, we will send it to you in a structured commonly used and machine-readable format (eg * .xls, * .csv, or in a similar format). If you ask us to send your personal data to another personal data controller, we will of course comply with your request.
The right to unsubscribe from sending commercial messages at any time
If you no longer want to receive business messages from us, you can prevent them from being sent either by clicking on the link that is part of each business message.
The right to withdraw consent to the sending of commercial communications at any time
In the event that we want your consent to the processing of personal data from you as part of our special events, you can withdraw this consent at any time without giving reasons. You can withdraw your consent either in the manner more precisely described in the consumer competition rules, or always by sending a revocation of consent to the e-mail address firstname.lastname@example.org.
The right to lodge a complaint with the Office for Personal Data Protection
In the event that, in your opinion, we do not fulfill all our legal obligations arising in connection with the processing of your personal data, please contact our Customer Care Center. If our colleagues do not help you, of course you have the right to contact the Office for Personal Data Protection, either at the address of the seat of the office:Lt. Col. Sochora 27, Prague 7, postal code 170 00, by e-mail email@example.com or by any other means accepted by the Office for Personal Data Protection. More information about the office can be found on the website www.uoou.cz.