GDPR - Terms of personal data protection
I. Personal Data Protection
1.1. By submitting an order through the online order form for the supply of goods and services, the user confirms that they are familiar with the personal data protection terms, that they agree with their wording, and that they accept them in full.
1.2 The Provider is the controller of users’ personal data pursuant to Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to as “GDPR”). The Provider undertakes to process personal data in accordance with legal regulations, in particular the GDPR.
1.3. Personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is a natural person who can be identified, directly or indirectly, in particular by reference to a specific identifier, such as a name, identification number, location data, online identifier, or to one or more specific elements of the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
1.4 When placing an order, personal data necessary for the successful processing of the order are required (name and address, contact details). The purpose of processing personal data is to process the user’s order and to exercise the rights and obligations arising from the contractual relationship between the Provider and the User. The purpose of processing personal data is also to send commercial communications and carry out other marketing activities. The legal basis for processing personal data is the performance of a contract pursuant to Article 6(1)(b) GDPR, compliance with a legal obligation of the controller pursuant to Article 6(1)(c) GDPR, and the legitimate interest of the Provider pursuant to Article 6(1)(f) GDPR. The legitimate interest of the Provider is the processing of personal data for direct marketing purposes.
1.5 For the performance of the licence agreement, the Provider uses the services of subcontractors, in particular a mailing service provider (personal data are stored in third countries) and a web hosting provider. The subcontractors have been verified in terms of secure personal data processing. The Provider and the web hosting subcontractor have concluded a personal data processing agreement, under which the subcontractor is responsible for the proper security of the physical, hardware and software perimeter, and therefore bears direct responsibility towards the user for any leakage or breach of personal data.
1.6 The Provider stores the user’s personal data for the period necessary to exercise the rights and obligations arising from the contractual relationship between the Provider and the user and to assert claims arising from these contractual relationships (for a period of 15 years from the termination of the contractual relationship). After this period expires, the data will be deleted.
1.7 The user has the right to request from the Provider access to their personal data pursuant to Article 15 GDPR, rectification of personal data pursuant to Article 16 GDPR, or restriction of processing pursuant to Article 18 GDPR. The user has the right to erasure of personal data pursuant to Article 17(1)(a) and (c) to (f) GDPR. The user also has the right to object to processing pursuant to Article 21 GDPR and the right to data portability pursuant to Article 20 GDPR.
1.8 The user has the right to lodge a complaint with the Office for Personal Data Protection if they believe that their right to personal data protection has been violated.
1.9 The user is not obliged to provide personal data. However, the provision of personal data is a necessary requirement for concluding and performing the contract, and without providing personal data, it is not possible to conclude the contract or for the Provider to perform it.
1.10 The Provider does not carry out automated individual decision-making within the meaning of Article 22 GDPR.
1.11 An interested party in using the Provider’s services, by completing the contact form:
- 1. agrees to the use of their personal data for the purposes of electronically sending commercial communications, advertising materials, direct sales, market surveys and direct product offers by the Provider and third parties, but not more often than once a week, and at the same time
- 2. declares that the sending of information pursuant to point 1.11.1 is not considered unsolicited advertising within the meaning of Act No. 40/1995 Coll., as amended, because the user expressly agrees to the sending of information pursuant to point 1.11.1 in connection with Section 7 of Act No. 480/2004 Coll.
- 3. The consent under this paragraph may be withdrawn by the user at any time in writing at info@shekel.cz.
- Necessary cookies - Cookies strictly necessary to ensure the operation of the website and internet services. Consent is not required for the use of these cookies.
- Analytical and marketing cookies - Consent is required for the use of other cookies. Cookies falling into this category are used mainly for anonymous tracking of traffic and user activity on our websites. This allows us to monitor what customers like and improve our services.
1.12.1 Specifically, we use the following cookies:
Necessary cookies
| Cookies | Purpose |
|---|---|
| externaFontsLoaded | Helps us load fonts |
| NOCHACHE | Helps with website loading speed |
| PHPSESSID | Used to identify login |
| previousURL | Stores the previously visited page |
| referal | Helps identify the previous source of visits |
| mccid a mceid | Internal information to ensure the proper operation of the website |
| SRV_id | Internal information to ensure high availability |
| CookiesOK | Consent to the use of cookies |
Analytical cookies
| Cookies (service) | Purpose | |
|---|---|---|
| Google Analytics | Helps us measure and evaluate the success of the website | Google Analytics service terms |
| Smartlook a Smartsupp | Helps us measure and evaluate the success of the website and communicate with clients | Smartlook and Smartsupp service terms |
| Google Optimize | We use it to evaluate the success and improve the website | Google Optimize service terms |
If the user grants consent to analytical or marketing cookies, some data may be processed by Google. More information about how Google uses data can be found at: https://business.safety.google/privacy/.
Marketing cookies
| Cookies (purpose) | Purpose | |
|---|---|---|
| Google Adwords | We use Adwords for ad targeting | Google Adwords service terms |
| Seznam Sklik | We use Sklik for ad targeting | Sklik service terms |
| Facebook audience | We use Facebook for ad targeting | Facebook service terms |
| Ecomail | We use Ecomail for ad targeting | Ecomail service terms |
| We use Linkedin for ad targeting |
II. Rights and Obligations between the Controller and Processor (Data Processing Agreement)
2.1 The Provider is a processor within the meaning of Article 28 GDPR in relation to the personal data of the users’ clients. The User is the controller of these data.
2.2 These terms regulate mutual rights and obligations in the processing of personal data to which the Provider gained access as part of the performance of the licence agreement concluded by accepting the general terms and conditions at www.jewish-eshop.cz and all miniwebsites www.01010101.cz (hereinafter referred to as the “licence agreement”) concluded with the User on the date of creation of the user account.
2.3. The Provider undertakes to process personal data for the User to the extent and for the purpose set out in Articles 2.4 - 2.7 of these terms. The means of processing will be automated. As part of processing, the Provider will collect personal data, store them on information carriers, retain them, block them and dispose of them. The Provider is not entitled to process personal data contrary to or beyond the scope set out in these terms.
2.4 The Provider undertakes to process personal data for the user in the following scope:
- ordinary personal data,
- special categories of data pursuant to Article 9 GDPR,
which the User obtained in connection with their own business activity.
2.5. The Provider undertakes to process personal data for the user for the purpose of providing the Shoptet e-shop platform in the form of a licence agreement.
2.6. Personal data may be processed only at the workplaces of the Provider or its subcontractors pursuant to Article 2.8 of these terms, within the territory of the European Union.
2.7. The Provider undertakes to process the personal data of the User’s clients for the User, all for the period necessary to exercise the rights and obligations arising from the contractual relationship between the Provider and the User and to assert claims arising from these contractual relationships (for a period of 15 years from the termination of the contractual relationship).
2.8 The User grants permission to involve a subcontractor as another processor pursuant to Article 28(2) GDPR, namely the hosting provider of the Shoptet application. The User further grants the Provider general permission to involve another personal data processor in the processing; however, the Provider must inform the user in writing of all intended changes concerning the acceptance of additional processors or their replacement and provide the user with the opportunity to object to these changes. The Provider must impose on its subcontractors acting as personal data processors the same personal data protection obligations as those set out in these terms.
2.9. The Provider undertakes that the processing of personal data will be secured in particular as follows:
- Personal data are processed in accordance with legal regulations and on the basis of the User’s instructions, i.e. for the performance of all activities necessary to provide the Shoptet e-shop platform in the form of a licence agreement.
- The Provider undertakes to technically and organisationally secure the protection of processed personal data so that unauthorised or accidental access to the data, their alteration, destruction or loss, unauthorised transfers, other unauthorised processing, as well as other misuse, cannot occur, and so that all obligations of a personal data processor arising from legal regulations are continuously ensured in terms of personnel and organisation throughout the period of data processing.
- The technical and organisational measures adopted correspond to the level of risk. Through these measures, the Provider ensures the ongoing confidentiality, integrity, availability and resilience of processing systems and services, and restores the availability of and access to personal data in a timely manner in the event of physical or technical incidents.
- The Provider hereby declares that the protection of personal data is subject to the Provider’s internal security regulations.
- Only authorised persons of the Provider and subcontractors pursuant to Article 2.8 of these terms will have access to personal data. The Provider will determine the conditions and scope of data processing for these persons, and each such person will access personal data under their unique identifier.
- Authorised persons of the Provider who process personal data under these terms are obliged to maintain confidentiality regarding personal data and security measures whose disclosure would compromise their security. The Provider shall ensure their demonstrable commitment to this obligation. The Provider shall ensure that this obligation of the Provider and authorised persons continues even after the termination of an employment or other relationship with the Provider.
- The Provider will assist the user through appropriate technical and organisational measures, where possible, in fulfilling the user’s obligation to respond to requests to exercise the rights of data subjects set out in the GDPR; likewise in ensuring compliance with obligations pursuant to Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to the Provider.
- After the termination of the provision of performance associated with processing pursuant to Article 2.7 of these terms, the Provider is obliged to delete all personal data or return them to the User, unless it is obliged to store personal data under a special law.
- The Provider shall provide the User with all information necessary to demonstrate that the obligations under this agreement and the GDPR have been fulfilled, and shall allow audits, including inspections, carried out by the User or another auditor authorised by the user.
2.10 The User undertakes to promptly report all facts known to them that could adversely affect the proper and timely performance of obligations arising from these terms to and to provide the Provider with the cooperation necessary for the performance of these terms.
III. Final Provisions
3.1 These terms cease to be valid upon expiry of the period specified in Articles 1.6 and 2.7 of these terms.
3.2 The User agrees to these terms by checking the consent box through the online form. By checking the consent box, the user declares that they have read these terms, that they agree with them and that they accept them in full.
3.3 The Provider is entitled to amend these terms. The Provider is obliged to publish the new version of the terms on its website without undue delay, or send the new version to the User at their email address.
3.4. Contact details of the Provider for matters concerning these terms: +420 777 181 077 - info@shekel.cz
3.5 Relationships not expressly regulated by these terms are governed by the GDPR and the legal order of the Czech Republic, in particular Act No. 89/2012 Coll., the Civil Code, as amended.
These terms take effect on 18 May 2018.
