Privacy policy
This privacy policy provides information under Act No. 110/2019 Coll., the Personal Data Processing Act (hereinafter the "ZOU"), and Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "GDPR").
In this policy you will learn how we, Webotvůrci s.r.o., with its registered office at Houbalova 3023/8, Líšeň, 628 00 Brno, Company ID (IČ): 08320004, handle personal data when providing our services.
We are responsible for the processing of personal data related to visits to the Webmakeria website and to the fact that we provide you with services such as website development, custom development, website management, online store development on the Shoptet platform and others.
Who is the controller of your personal data?
The controller of your personal data is Webotvůrci s.r.o., with its registered office at Houbalova 3023/8, Líšeň, 628 00 Brno, Company ID (IČ): 08320004, registered in the Commercial Register kept by the Regional Court in Brno, file No. C 113072 (hereinafter the "Controller").
The Controller is also the owner and operator of the domain "www.webotvurci.cz".
Where to find us and how to contact us
You can find us at: Houbalova 3023/8, Líšeň, 628 00 Brno.
You can contact us at the email address jsme@webotvurci.cz or at the phone number +420 728 089 029.
Key terms
The controller, in this case Webotvůrci s.r.o., is the entity that determines the purposes and means of the processing of personal data, carries out the processing and is responsible for it. The controller may authorize or entrust a processor with the processing of personal data, unless a special act provides otherwise.
A processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller
Processing is any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Profiling is any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements.
A filing system is any structured set of personal data which is accessible according to specific criteria, whether centralized, decentralized or dispersed on a functional or geographical basis.
An information society service is a service within the meaning of point (b) of Article 1(1) of Directive (EU) 2015/1535 (19).
A supervisory authority is an independent public authority established by a Member State. In the Czech Republic, this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů).
Processing principles:
Personal data is processed fairly, lawfully and in a transparent manner for specified, explicit purposes.
Personal data is processed to an adequate, relevant and limited extent in relation to the purpose for which it is processed.
Measures are taken to ensure that personal data is accurate and, where necessary, kept up to date.
Personal data is processed for the period strictly necessary in relation to the specific purpose of the processing.
The processing of personal data is secured in an adequate manner appropriate to the purpose of the processing, so as to ensure a level of security corresponding to all risks, including the implementation of sufficient organizational and technical measures, so that integrity and confidentiality are maintained.
We inform you about the processing of your personal data in a comprehensible way
How do we process your personal data?
The Controller processes your personal data both manually and by automated means.
No automated evaluation or profiling takes place.
Personal data may be made available to authorized employees and contractors of the Controller where this is necessary for the performance of the contractual relationship and where it is strictly necessary for the performance of their work and contractual duties, and always only to the necessary and limited extent.
Personal data may be made available to processors with which the Controller has concluded a personal data processing agreement, and where applicable to other persons in accordance with the law and the EU Regulation.
The processing of personal data is secured in an adequate manner appropriate to the purpose of the processing, so as to ensure a level of security corresponding to all risks, including the implementation of sufficient organizational and technical measures, so that integrity and confidentiality are maintained.
The Controller uses only such processors which, having regard to the nature, context and category of the personal data and to their capabilities, provide sufficient guarantees of appropriate technical and organizational measures, so that the processing of personal data through the processor meets the requirements of the General Regulation (GDPR) and the protection of the rights of data subjects is ensured.
The company also uses in particular the following security measures:
- Organizational security
- ensuring the contractual liability of employees, external collaborators, suppliers and other third parties with access to personal data
- regular training of staff on the rules for handling personal data
- Technical measures
- Antivirus solution
- Network security solution
- Backup of important infrastructure and data
- Physical security
- Access control for personal data
- Physical security of the premises and of physical/digital data storage
If you use our services such as website management or certain types of custom development
When providing certain specific services, such as website management or certain types of custom development, we act in a dual role, as controllers and as processors of personal data.
As processors of personal data we will process data only on the basis of your instructions and in accordance with what you entrust us with (activities connected with handling the personal data of your customers). If you are a customer of a person to whom we provide our services, you acknowledge that it is that person's obligation to properly inform you about the processing of your personal data.
As controllers of personal data we will process personal data in the same way as if you use our other services, as set out below.
If you use our other services
As our customer or potential customer, you can contact us through the website /. You can use our services of website development, website management, custom development or an online store solution on the Shoptet platform. In this section you will learn how we will process your personal data in such a case.
What personal data do we process?
We process the data that you provide to us yourself. This is data provided by filling in a form on the website, sent by email or by phone, or provided by concluding a contract. These are in particular the following categories:
- identification data (e.g. first name, surname, Company ID (IČ), VAT ID (DIČ), date of birth)
- contact data (e.g. email address, phone number)
- address data (e.g. registered place of business, permanent residence address, delivery address)
- data necessary for carrying out payments and posting them in the accounts (e.g. account number, bank code, IBAN, SWIFT)
- information about the contract and about its performance by both contracting parties, by you and by us (e.g. information about the contract including the date of conclusion, the duration, the date and reason for termination, and further a description of the transaction, the price of the services)
- other electronic data
- information about the cookies used,
- the website from which you came to our website;
- information about the browser and the operating system of the computer
- information about the extent and manner of use of the services (e.g. order history).
- For what purposes and for how long do we process your personal data?
Conclusion of a contract and performance of the contractual relationship
Purpose: We process personal data primarily for the purpose of concluding a contract and performing contractual obligations and the related communication with you. For this purpose, we process the following ordinary personal data: first name, surname, academic title, Company ID (IČO), address, email, phone, services provided or received, contractual documents.
Legal basis: The processing of personal data for the purpose of performing the contractual relationship is justified by the contractual relationship between you and us. In this case, the provision of personal data is a contractual requirement without which the contract cannot be concluded.
Storage period: We process this personal data for the duration of the contractual relationship, at most two years after it ends. After the contractual relationship ends, some data may then be retained for the purposes of complying with legal obligations or for the purposes of a legitimate interest.
Employee recruitment
Purpose: For the purposes of employee recruitment, we may also process your CVs and the personal data that you voluntarily send us as part of the given selection procedure.
Legal basis: We process your personal data for the purposes of carrying out the selection procedure for a specific position and of possibly entering into an employment relationship between you and us in relation to that position.
Storage period: We process this personal data for a maximum of two months after the end of the selection procedure. If we want to process your CV also for the purpose of future selection procedures, we will ask you for consent to the processing of personal data. In that case, we will process your personal data for a maximum of two years from the consent given.
Accounting and tax purposes
Purpose: We also process your personal data in order to comply with legal obligations. In particular, keeping accounts, meeting tax obligations and other legal regulations. For this purpose, we process in particular the following data: first name, surname, academic title, Company ID (IČO), address, account number, the date and amount of the payment made, services used and provided.
Legal basis: We handle this personal data mainly for the purposes of performing the concluded contract. Performance of contractual obligations typically occurs where, on the basis of the concluded contract, we have to record invoices or other tax documents in our accounts pursuant to Act No. 563/1991 Coll., on Accounting.
Storage period: We process this personal data for the period laid down by the relevant legal regulation, but at most two years after such an obligation ends.
Protection of our rights, property or safety, or the rights, property or safety of other persons
Purpose: We may also process personal data for the purposes of protecting our legitimate interests. A legitimate interest can cover a whole range of situations. That is why we inform you about the legitimate interests for which we process personal data. A legitimate interest is the protection and assertion of our rights and legal claims, in particular those arising from concluded contracts or from harm caused.
Legal basis: The processing of personal data for the purpose of protecting our rights, property or safety, or the rights, property or safety of other persons, is justified by compliance with legal obligations, or by our legitimate interest in protecting our rights, property or safety, or the rights, property or safety of other persons. In this case, the provision of personal data is not a statutory or contractual requirement. You are therefore under no obligation to provide us with your personal data for this purpose.
Storage period: For these purposes we process personal data for a maximum of 10 years after the end of the contractual relationship or after our last contact, if no contract was concluded. This period is set with regard to the limitation periods for claims, taking into account that we may not learn of a claim brought before a court at the very moment the other party brings it. For these purposes, data from contracts and from our mutual communication is retained.
Direct marketing and offering of services
Purpose: A further legitimate interest is direct marketing and the offering of services. For sending commercial communications we will process the following personal data of our clients: first name, surname, email. The sending of commercial communications is governed by Act No. 480/2004 Coll., and you can stop receiving these communications at any time in a simple manner by email.
Legal basis: The processing of personal data for the purpose of direct marketing is justified by your consent, or by our legitimate interest in direct marketing. In this case, the provision of personal data on the basis of your consent is voluntary, but without it we would not be able to provide you with personalized content and advertising. You may withdraw your consent at any time. In this case, the provision of personal data is not a statutory or contractual requirement. You are therefore under no obligation to provide us with your personal data for this purpose.
Storage period: The storage period of the data is determined by the duration of your consent.
Who else processes your personal data?
We have written agreements concluded with our processors, in which the performance of obligations in the area of personal data protection is agreed, so that your data stays safe.
We will provide you with an up-to-date list of such processors on request. As at the date on which this privacy policy was drawn up, our processors are:
- Google Cloud EMEA Limited, Velasco, Clanwilliam Place, Dublin 2, Ireland, VAT ID (DIČ): IE3668997OH, providing an information society service (cloud)
- ACTIVE 24, s.r.o., Sokolovská 394/17, 186 00 Praha 8, Company ID (IČO): 25115804, providing an information society service
- DigitalOcean, LLC, 101 Avenue of the Americas, New York, NY 10013, VAT ID: EU528002224
providing an information society service - Fakturoid s.r.o., V Pláni 532/7, Praha – Lhotka, 142 00, Company ID (IČO): 04656679, providing accounting services
- Accounting firm, bookkeeping and payroll
The following categories of partners (recipients) may have access to your personal data: those who provide us with their services, who ensure the technical operation of a particular service, and operators of technologies that we use for our services:
- Providers of accounting and tax advisory services
- Providers of IT services and hosting, including cloud storage
- Providers of security and integrity of our services and websites
- providers of legal services, attorneys
We would like to inform you that we will always honor your right to obtain information about to whom, when and for what purpose your personal data was disclosed.
Personal data may also be made available to the relevant administrative authorities where the law imposes such an obligation on us (in particular in the case of an inspection in which the authority concerned is entitled to require personal data to be produced, or to authorities active in criminal proceedings and others).
Your rights and obligations in connection with the processing of personal data
- The data subject is obliged to provide the controller only with true and accurate personal data and to inform the controller of any change to them.
- The data subject is obliged to provide the controller with verification of the data provided.
- The data subject has the right to request access to their personal data from the controller.
- The data subject has the right to rectification of the personal data provided.
- The data subject has the right to erasure of the personal data provided.
- The data subject has the right to restriction of the processing of personal data.
- The data subject has the right to data portability.
- The data subject has the right to object.
- If the data subject's consent is required for the processing of personal data, the data subject may withdraw it at any time, in accordance with the rules set out below.
Where can you exercise your rights?
You can exercise your rights:
- In person, by prior arrangement, at the company's main premises at Houbalova 3023/8, Líšeň, 628 00 Brno, after proving the identity of the data subject
- By email, from the address from which consent was given or which was entered during registration or in previous communication and is under the applicant's control, sent to the Controller's email jsme@webotvurci.cz. Further verification of the applicant's identity may be required.
- By postal mail (the signature must be officially verified).
The data subject (user) has the right to lodge a complaint with the supervisory authority if they believe that the processing of personal data by the association infringes personal data protection legislation. You can lodge a complaint with the supervisory authority – the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, tel.: 234 665 111, www.uoou.cz.
Transfers of information to third countries
If we process personal data in third countries (outside the European Union (EU) or the European Economic Area (EEA)), if this happens in connection with the use of third-party services, or if personal data is transferred or disclosed to third parties, we do so in order to fulfill our (pre)contractual obligations, on the basis of your consent, on the basis of legal obligations or of our legitimate interest. On the basis of legal or contractual obligations, we process or transfer personal data to a third country only where the special conditions of Article 44 et seq. of the GDPR are met. This means that the processing is carried out, for example, on the basis of special safeguards, such as the officially recognized establishment of an adequate level of personal data protection equivalent to the EU level, or compliance with officially recognized special contractual obligations (so-called "standard contractual clauses").
Obligations of the controller
- The Controller has the right to verify the truthfulness and accuracy of the personal data provided.
- The Controller is obliged to provide the data subject with information about the extent and manner of the personal data provided, if the data subject so requests. The Controller will do so without undue delay, at the latest within 30 working days.
- In the case of repeated and unfounded requests, the Controller has the right to charge a fee for providing them.
- The Controller will provide the information in electronic form, unless the data subject requests otherwise.
Conclusion
If you have any further questions about the processing of your personal data, you can contact us at the email jsme@webotvurci.cz. By sending a message to this email or a written request to our address given in this document, you can also directly exercise your rights.
Our business strategy and the related methods of processing your personal data may change. If we decide to update this policy, we will post the changes on our website. If a significant change in the processing of personal data occurs, we will inform you by email or on our website. We ask you to read this policy carefully and to check it regularly in your further communication with us or when using our website.
The current wording of this document can be found at "www.webotvurci.cz".
This information on the processing of personal data forms part of the general terms and conditions.
The personal data processing policy was drawn up and approved by the company's managing director on August 8, 2022.