Privacy Policy

I. Basic Provisions

1. The controller of personal data under Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the “GDPR”) is Veronika Baranková, Company ID: 86976494 / VAT ID: CZ8361090430, with registered office at Františkova 911/17, Prague 14, 198 00, Czech Republic (the “Controller”).

2. Controller’s contact details:
Františkova 911/17, Prague 14, 198 00, Czech Republic
E-mail: info@odlito.cz

3. Personal data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

4. The Controller has not appointed a Data Protection Officer.

II. Sources and Categories of Processed Personal Data

1. The Controller processes personal data that you provide or data obtained as a result of fulfilling your order.

2. The Controller processes the following categories of personal data:

  • Identification and contact details (name, address, e-mail, phone),

  • Data necessary for the performance of the contract,

  • Data obtained from public sources or from communication with you.

 

III. Legal Grounds and Purpose of Processing Personal Data

1. The legal grounds for processing personal data are:

  • Performance of a contract between you and the Controller under Article 6(1)(b) GDPR,

  • The Controller’s legitimate interest in direct marketing under Article 6(1)(f) GDPR,

  • Your consent to processing for marketing purposes under Article 6(1)(a) GDPR in conjunction with Section 7(2) of Act No. 480/2004 Coll., if no order has been placed.

 2. The purposes of processing personal data are:

  • Processing your order and exercising the rights and obligations arising from the contractual relationship,

  • Sending commercial communications and conducting marketing activities.

 3. The Controller does not carry out automated individual decision-making within the meaning of Article 22 GDPR.

 

IV. Period of Data Retention

1. The Controller retains personal data:

  • For the period necessary to exercise rights and obligations arising from the contractual relationship and to assert claims (up to 15 years from the termination of the contract).

 2. After this period, personal data will be securely deleted.

 

V. Recipients of Personal Data (Processors)

1. Recipients of personal data are persons:

  • Involved in the delivery of goods/services/payment processing,

  • Ensuring the operation of the e-shop (e.g., Shoptet),

  • Providing marketing services.

 2. The Controller may transfer personal data outside the EU if using foreign providers of mailing or cloud services (e.g., Ecomail – e-mail marketing service, Google). Such transfers are carried out in accordance with the GDPR, based on adequacy decisions or standard contractual clauses.

 

VI. Your Rights

1. Under the GDPR, you have the right to:

  • Access personal data under Article 15 GDPR,

  • Rectification under Article 16 GDPR, or restriction of processing under Article 18 GDPR,

  • Erasure of personal data under Article 17 GDPR,

  • Object to processing under Article 21 GDPR,

  • Data portability under Article 20 GDPR,

  • Withdraw consent to processing at any time, in writing or electronically to the contacts specified in Section I of this Policy.

 2. You also have the right to lodge a complaint with the Office for Personal Data Protection if you believe your rights have been violated.

 

VII. Security of Personal Data

1. The Controller declares that all appropriate technical and organizational measures have been taken to secure personal data.

2. Electronic data are protected by antivirus software, strong passwords, and a secure connection (HTTPS).

3. Access to personal data is restricted to persons authorized by the Controller.

 

VIII. Final Provisions

1. By submitting an order, you confirm that you have read this Privacy Policy and that you accept it in full.

2. You agree to this Privacy Policy by checking the box in the form. By doing so, you confirm that you have been acquainted with the wording of this Policy.

3. The Controller is entitled to unilaterally amend this Policy. The new version will be published on the website and may be sent to the email address you provided.

 

These Privacy Policy terms are effective as of 1 January 2025.

privacy-policy-2025-01-01.pdf