0in cart

 Information on Personal Data Processing

1.    Basic Provisions
  • The personal data controller according to Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and Council (GDPR) on the protection of natural persons regarding the processing of personal data and the free movement of such data is Bobánek s.r.o., Company ID: 08532451, with registered office at Králíčkova 4267, Havlíčkův Brod 58001 (hereinafter “the controller”).

Controller contact details:

  • Address: Králíčkova 4267, Havlíčkův Brod 58001, Czech Republic
  • Email: info@bobanek.eu
  • Phone: +420 799 991 227

Personal data means all information relating to an identified or identifiable natural person. An identifiable natural person is one who can be directly or indirectly identified, especially by reference to an identifier such as a name, identification number, location data, network identifier, or to one or more factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity.

The controller has not appointed a Data Protection Officer.

2.  Sources and Categories of Personal Data Processed
  • The controller processes personal data that you have provided or that the controller has obtained in connection with fulfilling your order. The controller processes your identification and contact data and any data necessary to fulfill the contract.
3.    Legal Basis and Purpose of Personal Data Processing

The legal basis for processing personal data is:

  • Performance of a contract between you and the controller under Article 6(1)(b) GDPR.
  • The controller’s legitimate interest in providing direct marketing (e.g., sending commercial announcements and newsletters) under Article 6(1)(f) GDPR.
  • Your consent to processing for the purpose of direct marketing (e.g., sending commercial announcements and newsletters) under Article 6(1)(a) GDPR in connection with §7(2) of Act No. 480/2004 Coll. on certain information society services if no purchase has been made.

The purpose of processing personal data is:

  • Fulfilling your order and exercising rights and obligations arising from the contractual relationship between you and the controller. Providing personal data is necessary for concluding and fulfilling the contract; without it, the contract cannot be concluded or performed.
  • Sending commercial announcements and performing other marketing activities.

No automated individual decision-making under Article 22 GDPR takes place.

4.    Data Retention Period

The controller retains personal data:

  • For the period necessary to exercise rights and obligations arising from the contractual relationship and claims from such contracts (up to 15 years after the end of the contractual relationship).
  • Until consent for marketing purposes is revoked, but no longer than 5 years if data are processed based on consent.
  • Po uplynutí doby uchovávania osobných údajov správca osobné údaje vymaže.

After the retention period, personal data will be deleted.

5.    Recipients of Personal Data (Controller’s Subcontractors)

Recipients of personal data include:

  • Shipping companies and other entities involved in delivering goods or processing payments under the purchase contract.
  • Entities providing technical services related to the operation of the e-shop, including software operation and data storage/backups.
  • Entities providing marketing services.

Your personal data may also be collected by third parties, including Smartsupp.com s.r.o. (VAT CZ03668681), ComGate a.s. (ID 26508842), Heureka Shopping s.r.o. (VAT CZ02387727), Zásielkovňa s.r.o. (ID 28408306), Smartlook.com s.r.o. (VAT CZ09508830).

6.    Data Subject Rights – Your Rights

Under GDPR, you have the right to:

  • Access your personal data (Art. 15 GDPR).
  • Rectify your personal data (Art. 16 GDPR) or restrict processing (Art. 18 GDPR).
  • Erase your personal data (Art. 17 GDPR).
  • Object to processing (Art. 21 GDPR).
  • Data portability (Art. 20 GDPR).
  • Withdraw consent for processing at any time, in writing or electronically, to the controller’s address or email provided above.

You may also lodge a complaint with the Office for Personal Data Protection if you believe your rights have been violated.

Providing personal data is not mandatory except when necessary for concluding and performing the contract. Without it, the contract cannot be concluded or performed.

7.    Personal Data Security Measures

The controller declares that appropriate technical and organizational measures have been implemented to secure personal data, including data storage in paper form. Access to personal data is limited to authorized personnel who are obliged to maintain confidentiality.

8.    Final Provisions

By placing an order via the online order form, you confirm that you have read and accepted these personal data protection terms.

The controller may update these terms and will publish the new version on the website and send it to the email you provided.

These terms are effective from 07.02.2023.

Back to Top
Product has been added to your cart