Principles of personal data processing

Administrator contact details

Name: Exportio s.r.o.

Registered address: Zbožská 113, Poděbrady 29001

ID: 19776683

Email: info@exportio.cz

The processing of personal data takes place in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (hereinafter referred to as the “Regulation”), the Act on the Processing of Personal Data and Act No. 480/2004 Coll., on certain information society services, as amended.

1. Concepts

Data subject: The natural person (consumer and self-employed person) to whom the personal data relates (hereinafter also “you” or “customer”);

Personal data: All information about an identified or identifiable customer; an identifiable customer is a natural person who can be identified directly or indirectly, in particular by reference to a specific identifier, such as a name, identification number, location data, network identifier, or to one or more specific elements of the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person (hereinafter referred to as “data” or “information”);

Controller: The entity that determines the purpose and means of processing personal data, carries out the processing and is responsible for such processing. The controller of personal data is Exportio s.r.o. (hereinafter also “we”);

Processor: Entity that processes personal data for the controller on the basis of the law or on behalf of the controller, on the basis of a personal data processing contract (hereinafter also “business partner” or “partner”);

Website: Website available at www.exportio.cz;

Purpose of personal data processing: The reason why personal data is processed. Such reasons may include, for example, the performance of the contract, the management of user accounts, the handling of complaints and complaints, the sending of commercial communications (newsletters) or the display of advertisements based on the interests of customers;

Cookies: Short text files stored by your web or mobile browser. Most cookies contain a unique identifier, so called. Cookie ID. This is a string of characters assigned by websites and servers to the browser that saved the cookie. This allows websites and servers to distinguish and identify individual browsers. Cookies are used to improve the functioning of the website, to evaluate its traffic and to better target marketing activities. If you browse our website, we assume that you consent to our use of these files.

Third country: States outside the European Economic Area, which consists mainly of the Member States of the European Union and Iceland, Liechtenstein and Norway.

2. What personal data is processed?

We and our contractual processors process the following personal data, respectively categories of personal data, following the relevant legal title and purpose of the processing:

a) identification and address data: e.g. name, surname, delivery or other contact address, address of collection point, place of business, ID number, VAT number;

(b) electronic contact details: e.g. telephone number, e-mail address;

c) other electronic data: IP address, cookies;

d) other personal data related to the contractual relationship: bank account number, order history;

e) other personal data: typically data provided by the customer in the order form or in other documents and when communicating with us, including later updates.

3. What is the origin of personal data?

We process data that you provide to us, for example, when ordering our services, registering a user account, communicating with us or subscribing to a newsletter.

Typically, these are:

  • identification and address data;
  • electronic contact details;
  • other personal data related to the contractual relationship.

Furthermore, data that we obtain automatically as a result of your browsing of our website.

Typically, these are:

  • cookies
  • the website from which you came to our website;
  • IP address;
  • date of access and time of access;
  • search queries;
  • http and https response code;
  • groups of data transmitted;
  • an indication of the browser and the operating system of the computer.

4. Why are personal data processed?

Your personal data may be processed for the following purposes:

  • Fulfillment of the contractual relationship
  • Manage customer accounts
  • Customer communication, satisfaction ratings, publication of reviews, book recommendations, handling of suggestions, complaints and complaints
  • Sending business messages and offering our goods
  • Direct marketing and creation of personalized content and advertising
  • Improving the quality of our goods and services, analysing the traffic on our website and your behaviour on the website
  • Running a customer competition and delivering prizes
  • Protecting our rights, property or safety or the rights, property or safety of others
  • Accounting and tax purposes

Fulfillment of other legal obligations Your personal data may be processed on the basis of the following legal grounds:

  • Performance of the contract
  • Fulfillment of a legal obligation
  • The controller's legitimate interest in sending commercial communications
  • Consent to the sending of commercial communications
  • The processing of personal data for the purpose of fulfilling the contractual relationship, accounting and tax purposes and the fulfilment of other legal obligations are statutory or contractual requirements. If you intend to place an order through our website, you are obliged to provide us with your personal data for these purposes.

5. How long are personal data processed?

Your personal data is processed:

  • for the period necessary to exercise the rights and obligations arising from the contractual relationship between you and us and to assert claims arising from such contractual relationships (4 years);
  • for the period necessary to fulfill the legal obligation (accounting documents 5 years, tax documents 10 years);
  • for the duration of our legitimate interest in sending commercial communications (2 years from the last opening of the commercial communication);
  • for the duration of your consent (no more than 4 years from the date of its granting, or 4 years from the last order).

To whom is the personal data disclosed? The following categories of our partners (recipients) may have access to your personal data:

  • Providers of transport of goods
  • Providers of accounting and tax advice
  • IT Service and Hosting Providers
  • Providers of security and integrity of our services and websites
  • Analytical service providers
  • Customer Support Assistance Service Providers
  • Payment gateway providers (payment card providers)
  • Legal service providers, solicitors
  • Print and postal service providers
  • Partners working with us in loyalty programs, conferences, seminars and other events
  • Partners who provide direct marketing for us and partners and operators of technical solutions that allow us to show you personalized content and advertising
  • Public authorities

6th. Is personal data transferred outside the EU?

The controller does not intend to transfer personal data to a third country (outside the European Economic Area) or to an international organization. Recipients of personal data in third countries are:

  • Partners to whom we provide data for the purpose of analysing traffic to our website, your behaviour on the website and business conversions
  • Providers of IT services and hosting, incl. cloud services
  • Mailing service providers

7. How are personal data processed?

Personal data are processed manually and automatically. We keep proper records of all processing activities in accordance with the relevant legislation. You are not subject to any decision based solely on automated processing, including profiling, that would have legal effects for you or would affect you in a similar way significantly. We do not create profiles from your personal data in order to analyze or predict your preferences, interests, economic situation, reliability, location or movement (a typical example of profiling is monitoring the behavior of website visitors in order to track their preferences so that the merchant can reach them in the future with an offer tailored to them).

8. What are the rights of data subjects?

To exercise your rights, please contact us through our contact details, which are set out at the beginning of this policy. In connection with the processing of your personal data, you have the following rights (Art. 15 to 21 GDPR):

  • Right of access to personal data
  • Right to rectification of inaccurate and incomplete personal data
  • Right to erasure of personal data
  • Right to restrict the processing of personal data
  • Right to data portability
  • Right to object to processing
  • Right to information about automated decision-making, including profiling

If we process your personal data on the basis of your consent, you have the right to withdraw this consent at any time by sending an e-mail to info@exportio.cz. You also have the right to lodge a complaint with the supervisory authority, which is the Office for Personal Data Protection, with its registered office in Pplk. Sochova 27, 170 00 Prague 7, tel.: 234 665 111, web: www.uoou.cz.

9. How are cookies processed?

Processed cookies can be divided according to validity into:

  • temporary cookies (so-called session cookies), which remain stored in your browser only until you close your browser
  • persistent cookies (so-called persistent cookies) that remain stored in your browser for a long time until they expire or until you manually delete them (the duration of the cookies in your browser depends on the settings of the cookie itself and the settings of your browser).

And according to the functions on:

  • essential, which are necessary for the functionality of our website,
  • preferential, which allow our website to remember information that changes how the website behaves or looks (e.g. your preferred language or region where you are located), these cookies are not strictly necessary for the functioning of our website, but increase the functionality and practicality of its use;
  • analytical, which help us to analyze your experience on our website (the so-called User Experience (User Experience) and that allow us to understand how you use our website. We do not use third-party cookies that monitor multiple websites so that we can provide you with personalized content and advertising on third-party websites and other sales channels.

10. Are children's data also processed?

Our website is not intended for children under the age of 16. Therefore, we do not intentionally collect their personal data. If we find that we have inadvertently obtained personal information about children under the age of 16, we will take steps to delete such data as quickly as possible, except where we are bound by applicable law to retain it.

11. Conclusion

Legislation as well as our business strategy and related ways of processing your personal data may change. If we decide to update this policy, we will post the changes on our website and notify you of the changes. We will inform you in advance in the event of a more fundamental change in this policy or in the event that we are required to do so by law. We ask that you read this policy carefully and review it regularly when you continue to communicate with us or use our website.