Privacy Policy
Basic Provisions
The controller of personal data under Article 4, point 7 of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as "GDPR") is Dáváme s.r.o., Business ID 07058497, with its registered office at Bartůňkova 2349/3a, Chodov, 149 00 Prague 4 (hereinafter referred to as "Controller").
Personal data refers to any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
Sources and Categories of Processed Personal Data
The Controller processes personal data that you have provided or personal data obtained by the Controller based on the fulfillment of your order. The Controller processes your identification and contact details and any data necessary for contract fulfillment.
Legal Basis and Purpose of Processing Personal Data
The legal basis for processing personal data is the performance of a contract between you and the Controller pursuant to Article 6(1)(b) GDPR, the legitimate interest of the Controller in direct marketing (especially for sending commercial communications and newsletters) pursuant to Article 6(1)(f) GDPR, your consent to processing for direct marketing purposes (especially for sending commercial communications and newsletters) pursuant to Article 6(1)(a) GDPR in conjunction with Section 7(2) of Act No. 480/2004 Coll., on certain services of the information society, in the event that no order for goods or services has been placed.
The purpose of processing personal data is to process your order and fulfill rights and obligations arising from the contractual relationship between you and the Controller. When placing an order, personal data is required for successful order fulfillment (name, address, contact information). Providing personal data is a necessary requirement for contract conclusion and fulfillment. Without providing personal data, it is not possible to conclude or fulfill the contract. The data is also processed for sending commercial communications and for marketing activities.
Data Retention Period
The Controller retains personal data for the time necessary to exercise rights and obligations arising from the contractual relationship between you and the Controller and for the enforcement of claims from these contractual relationships (for a period of 5 years after the termination of the contractual relationship).
For marketing purposes, the data is retained until consent to processing is withdrawn, but no longer than 5 years if processed based on consent.
After the retention period expires, the Controller will erase the personal data.
Recipients of Personal Data (Controller’s Subcontractors)
Recipients of personal data include entities involved in the delivery of goods/services or payment processing based on a contract, entities ensuring service operation, entities providing marketing services.
The Controller does not intend to transfer personal data to a third country (a country outside the EU) or an international organization. The recipients of personal data in third countries include providers of mailing or cloud services.
Your Rights
Under GDPR, you have the following rights: The right to access your personal data under Article 15 GDPR, the right to rectify personal data under Article 16 GDPR or restrict processing under Article 18 GDPR, the right to erase personal data under Article 17 GDPR, the right to object to processing under Article 21 GDPR, the right to data portability under Article 20 GDPR, the right to withdraw consent to processing in writing or electronically at the Controller’s address or email stated in Article III of this policy.
Additionally, if you believe your data protection rights have been violated, you have the right to file a complaint with the Data Protection Authority.
Personal Data Security Measures
The Controller declares that it has implemented all appropriate technical and organizational measures to secure personal data. The Controller has taken technical measures to secure data storage and physical document storage. The Controller declares that personal data is only accessible to authorized personnel.
Final Provisions
By submitting an order through the online order form, you confirm that you have read and fully accept the privacy policy. The Controller reserves the right to amend these terms. Any new version of the privacy policy will be published on the Controller’s website or sent to the email address you provided.