GDPR Personal Data Processing Agreement
CUSTOMER INFORMATION ABOUT PERSONAL DATA PROCESSING
We are very happy and highly appreciate the fact that you are about to become one of our satisfied customers. However, the process of purchasing goods online is far more complex than it might look at first glance, especially as far as security of data is considered. Security of data and especially security of our Customers’ personal data is thus a high-priority of ours and we take it very seriously.
That is why We METALSHOP.CZ, s.r.o., based in: Bystřice 174, 73995 Bystřice, Czech Republic, CRN: 28574699, E-mail: email@example.com, tel.: +44 330 808 2232 (hereafter referred as “the Company”, or “We”), as the E-shop administrator of metal-shop.eu
(hereafter referred as “the E-shop”), do everything to the best of our abilities to ensure that your personal data entrusted to us are both safe and processed in accordance with all the applicable regulations and laws. An integral part of any such process is also transparency and awareness about one’s rights, for the sake of which We wish to inform you about how are your personal data processed and about your consequential rights.
1. PURPOSES OF PROCESSING AND ITS LEGAL BASIS
Your personal data are going to be processed for purposes of realization of a Purchase contract, therefore for the following purposes:
- to ensure order completion;
- to ensure delivery of goods;
- to ensure the fulfilment of all the consequential rights resulting from defective performance or related to reimbursement in case of damage;
- to ensure our Company’s fulfilment of legal obligations, especially in terms of bookkeeping;
The legal basis for personal data processing are terms of contract, entered by our Company and You and all the applicable legal obligations, especially those resulting from the Civil Code of the Czech Republic. Unless otherwise stated, your E-mail address only is used for the purposes of direct marketing. In this instance, the legal basis is our Company’s legitimate interest in this type of processing. You can read about how to easily unsubscribe from this type of direct marketing below. Legitimate interest may be considered a legitimate reason in instances in which We are going to make claims against You.
2. CATEGORIES OF INVOLVED PERSONAL DATA
For purposes of order completion, its delivery and other fulfilment of all the consequential rights, We are going to process Your: name and surname, phone number and E-mail, address and mailing address, content of Your order and information related to Your order and to its completion; in case of business purchase, We are also going to process name of the company, Company Registration Number (CRN) and Value Added Tax Identification Number (VATIN). We may also process information about damage and faulty performance in claim-related cases.
Cookies are small pieces of data sent from a website and stored on the user’s device (PC, cell phone etc.). Cookies allow us to run our E-shop properly and ensure its comfortable use. Specific cookies also help us offer more relevant products to our customers or provide us with statistical data about E-shop’s traffic.
Our website uses advanced cookie bar where you can learn about specific types of cookies used and comfortably adjust which cookies you wish to use and which you do not. You can also adjust your cookies settings and delete them in your browser.
4. RECIPIENTS OF PERSONAL DATA AND FORWARDING TO THIRD COUNTRIES
Unless otherwise stated, your personal data are not going to be shared with or made accessible to third parties, with only exceptions mentioned in this paragraph below. We can be obliged to provide your personal data to the state authorities in accordance with applicable law (e.g. the Police of the Czech Republic). Furthermore, your personal data are going to be processed by the following processor, the company Next CRE s.r.o. (Ltd.), based at Poštovní 244 street, Staré Město, ZIP: 73961 Třinec, Czech Republic, CRN: 29396239 (hereafter referred as “the Operator”), which provides us with services related to the E-shop’s administration and service. In order that the Operator is able sufficiently manage E-shop’s proper function, the Operator also uses services of additional processors cooperating with the Operator. Moreover, your personal data may be also processed by a provider of hosting services, specifically by the company VSHosting s.r.o. (Ltd.), based at Sodomkova 1579/5 street, Hostivař, ZIP: 10200 Prague 10, Czech Republic, CRN: 61505455.
The Operator also uses sophisticated services (cookies etc.), that process information that are not usually considered as personal data, for You, as a person, cannot be identified through them. The goal of these services is to provide analysis associated with E-shop’s administration and to ensure E-shop’s comfortable functioning as well as offer more relevant products to individual target groups. In case that We would be able to identify you through these services thanks to either an accidental occurrence, technological development or legal interpretation, or in case that We would be able to assign additional personal data from these services to You, as an identified person, let us introduce you to additional parties:
We do not forward to, nor do we share your personal data with any third country or international institution that do not provide requisite private data protection. One exception may be, in case of operators of some services associated with E-shop’s administration, the forwarding of personal data to the United States of America. Nonetheless the parties featuring in these instances always comply with the conditions of EU – US Privacy Shield, which is an international legal framework ensuring appropriate standard of handling of personal data and their protection in the United States of America. You can read more about this mechanism here: https://www.privacyshield.gov
5. INFORMATION ABOUT YOUR RIGHTS IN RELATION TO PERSONAL DATA
You have many rights in relation to the personal data processing. You can contact us at any time, either via mail or E-mail, both of which are mentioned above; and demand a confirmation about whether your personal data are being processed and if they indeed are, you are going to be granted an access to your personal data as well as to additional information about them. You have also the right to demand correction of inaccurate information or completion of incomplete personal data. You can, at any time, demand deletion of your personal data, granted there is a reason for this action; or you can also ask to limit your personal data processing, should there be a reason for this action also. You have the right to your personal data and You have the right of transfer to another administrator. You have the right to raise an objection in cases that your personal data procession is based on our legitimate interest. As an objection is also considered the action of simply unsubscribing from direct marketing, which is going to be allowed to you within all the marketing messages sent to you. Your personal data are processed fairly and in a transparent way. However, you always have the right to turn to the European offices for Personal Data Protection in any given EU country. All the necessary information as well as direct contacts are at your disposal and accessible from following website: https://ec.europa.eu/info/law/law-topic/data-protection_en
6. ADDITIONAL INFORMATION ABOUT PROCESSING