Processing and protection of personal data at EXOT HOBBY s.r.o.
This Personal Data Processing Policy is effective as of May 1, 2023 and replaces the previous Privacy Policy.
If you are our customer, newsletter subscriber or website visitor, you entrust us with your personal data. We are responsible for the protection and security of this data. Please familiarize yourself with the privacy policy, principles and rights you have in relation to the GDPR (EU General Data Protection Regulation - EU Regulation 2016/679).
1. who is the administrator?
We are the company EXOT HOBBY s.r.o., ID No. 26061414, registered office in Černá v Pošumaví 180, 382 23 Černá v Pošumaví, registered in the Commercial Register of the District Office in Č. Budějovice, section C, insert 11552, which operates, among other things, an e-shop. We process your personal data as an administrator, i.e. we determine how and for what purpose the personal data are processed and how long they are stored, and we select other processors to assist us in the processing.
Contact details
If you wish to contact us during the processing of your order, you can contact us at +420 380 744 281 or +420 608 774 281 or by e-mail: exothobby@exothobby.cz.
2. the legal ground for the processing of personal data
We declare that, as the administrator of your personal data, we comply with all legal obligations imposed by applicable laws, in particular the Data Protection Act and the GDPR:
- we process your personal data only on the basis of a valid legal ground, in particular a legitimate interest, the performance of a contract, a legal obligation or consent,
- we comply with the obligation to inform pursuant to Article 13 of the GDPR before we start processing personal data,
- we will enable and assist you to exercise and fulfill your rights under the Data Protection Act and the GDPR.
3. scope of personal data and purpose of processing
We process personal data that you entrust to us for the following reasons (to fulfill these purposes):
- Provision of services and fulfillment of a contract
We need your personal data to the following extent: billing information, e-mail, telephone number or correspondence address for the performance of the contract (e.g. delivery of goods by post or courier to your address).
- Accounting
If you are a customer, we need your personal data (invoice data) to comply with the legal obligation to issue and record tax documents.
- Marketing - sending informational messages (newsletters)
We use your personal data (name and e-mail) to send you commercial communications after you have expressed your consent (interest). If you are our customer, we do so out of legitimate interest, because we reasonably believe that you are interested in our news.
You can unsubscribe from receiving our email messages at any time.
- Cookies
When you browse our website, we may record your IP address, how long you stay on the website and which page you come from. We consider the use of cookies to measure website traffic and to customize the presentation of the website as a legitimate interest of our administrator, as we believe that it allows us to provide you with an even better service. Cookies for advertising targeting are processed only on the basis of your consent. Our website can also be visited in a mode that does not allow the collection of personal data. You can disable the use of cookies on your computer in your Internet browser or use the anonymous mode of the website browser.
4. duration of the storage of personal data
We retain your personal data for the duration of the limitation periods, unless the law provides for a longer retention period or we have determined otherwise in individual cases.
5. security and protection of personal data
We protect personal data as much as possible by using modern, state-of-the-art technologies. We protect them as if they were our own. We have taken and maintain all possible (currently known) technical and organizational measures to prevent the misuse, damage or destruction of your personal data.
Disclosure of personal data to third parties
Your personal data is accessible to our employees and partners who are committed to confidentiality and trained in the security of personal data processing. We perform most processing ourselves and do not require third parties to do so. For some specific processing that we cannot perform internally, we use the services and applications of processors that specialize in processing and are GDPR compliant.
These are providers of the following platforms and services:
- Direct Parcel Distribution CZ s.r.o., Modletice 135, 251 01 Říčany u Prahy, ID No.: 61329266, registered in the Commercial Register at the Municipal Court in Prague, Section C, Insert 52346, as a transport company.
- Czech Post s.p., Politických vězňů 909/4, 225 99 Prague 1
- Zásilkovna.cz s.r.o., with its registered office in Českomoravská 2408/1a, 190 00 Prague 9, registered in the Commercial Register of the Municipal Court in Prague, Section C, insert 139387, as a transport company
It is possible that in the future we may decide to use other applications or processors to facilitate and improve the quality of processing. However, we promise you that in such a case, we will place at least the same demands on the processor for security and quality of processing as we do on ourselves when selecting them.
Transfer of data outside the European Union
We process data only in the European Union or in countries that provide an adequate level of protection based on a decision of the European Commission.
6. your rights regarding the protection of personal data
You have a number of rights in connection with the protection of personal data. If you wish to exercise any of these rights, please contact us by email: exothobby@exothobby.cz.
You have the right to information, which is already fulfilled by this information page with the privacy policy.
Thanks to the right of access, you can contact us at any time and we will document within 30 days which personal data we process and why.
If something changes or you discover that your personal data is outdated or incomplete, you have the right to have your personal data completed and amended.
You can exercise your right to restrict processing if you believe that we are processing your inaccurate data, if you believe that we are processing unlawfully but do not want to delete all your data, or if you have objected to the processing. You can limit the scope of personal data or the purposes of processing (e.g. by unsubscribing from the newsletter you limit the purpose of processing for sending commercial communications).
Right to erasure (to be forgotten)
Another right you have is the right to erasure (to be forgotten). We do not want to forget you, but you have the right to do so if you wish. In this case, we will delete all your personal data from our system. We need 30 days to ensure your right to erasure.
In some cases, we are bound by a legal obligation, e.g. we have to keep records of tax documents issued for a period set by law. In such case, we will, therefore, delete all personal data that is not bound by another law.
Complain to the Office for Personal Data Protection
If you believe that we are not handling your data in accordance with the law, you have the right to complain to the data protection authority. We would be very pleased if you would first inform us of this suspicion so that we can do something about it and correct any abuses.
Unsubscribe from newsletters and commercial communications
If you are a customer with us, we will send you emails with suggestions, articles or offers of products and services based on your legitimate interest. If you are not yet a customer, we will only send them to you based on your request and consent. In any case, you can stop receiving our emails by clicking on the unsubscribe link in each email.
7. confidentiality
We would like to assure you that our employees and partners who process your personal data are obliged to maintain the confidentiality of personal data and security measures, the disclosure of which would jeopardize the security of your personal data. This confidentiality continues even after the contractual relationship with us has ended. Your personal data will not be disclosed to third parties without your consent.