Consent to processing personal data


in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (hereinafter referred to as „GDPR“).
__________________________________________________________________________________

This Privacy and Data Processing Policy (hereinafter the „Policy“) describes which personal data of clients who are natural persons, or also other clients in relation to natural persons acting on their behalf (hereinafter the „Data Subject“), are processed by VEMOMI SPORT s.r.o., headquartered at No. 355, 512 46 Harrachov, Czech Republic, ID: 23969059, VAT ID: CZ23969059, registered in the Commercial Register maintained by the Regional Court in Ústí nad Labem, Section C, Entry 54933.


 (hereinafter the „Controller“).

This Policy sets out the types of personal data we collect and process when you use our services, as well as how your personal data is used, shared, and protected.  We hereby inform you below about the processing of your personal data and your rights in accordance with Art. 12 of the GDPR.

Personal data refers to information related to a natural person for the purposes of communication, ordering, order processing, and delivery of goods. We collect data such as residential address, order identification info, delivery address, IP address, phone number, and statistical data via Google Analytics (owned by Alphabet Inc.). Personal data such as national identification numbers are not collected.


PROCESSORS AND RECIPIENTS OF PERSONAL DATA

The Controller is entitled to transfer personal data to entities with which it has concluded a data processing agreement and who will process personal data for the Controller as its processors. Based on the above, the Controller may transfer personal data of the Data Subject to the following entities, or categories of entities:

- the contractual carrier selected by the buyer in the order form for the purpose of delivery, specifically:

  • DPD
  • DHL
  • Packeta
  • and relevant national postal services (e.g., Slovenská pošta, Poczta Polska)

- the operator of review portals such as Heureka Group a.s. or local equivalents, in the case of a purchase made from the Controller, under the conditions set out in the general business terms and conditions applicable to the purchase,

- the payment card issuer or payment service provider, in the case of a purchase made from the Controller, where the goods were paid for via a payment card or online payment gateway.


Furthermore, the Controller may transfer personal data related to the management of IT systems and marketing services to the following recipients:

  • Facebook Ireland Limited, IE9692928F
  • Google Ireland Limited, IE6388047V
  • Heureka Shopping s.r.o., IČO: 023 87 727
  • Seznam.cz, a.s., IČO: 261 68 685
  • SupportBox s.r.o., CZ27480381
  • WinShop software s.r.o., CZ26754657
  • ineShop s.r.o., CZ19668139


Personal data of the Data Subject are further transferred to the following categories of recipients:

- the Controller's suppliers,

- the Controller's employees,

- persons in another contractual relationship with the Controller (e.g., providers of marketing and advertising services, law firms, IT service providers),

- financial institutions and insurance companies,

- state authorities within the fulfilment of legal obligations set by relevant legal regulations.

The Controller undertakes not to provide the personal data of Data Subjects to recipients other than the processors and recipients defined above.


CATEGORIES OF PROCESSED PERSONAL DATA

The Controller is entitled to process, in particular, the following personal data of the Data Subject:

  • address and identification data used for unique and unmistakable identification of the Data Subject (e.g., name, surname, title, date of birth, permanent residence address, business address, delivery address, ID number, VAT ID) and data enabling contact with the Data Subject (e.g., contact address, phone number, fax number, email address, and other similar information),
  • descriptive data (e.g., bank connection, payment information, or credit card information),
  • images, photographs, and videos,
  • account login information, including the name under which the Data Subject appears on the internet, passwords, and unique user ID,
  • data provided beyond the scope of relevant laws processed within the framework of consent granted by the Data Subject (e.g., use of personal data for the purpose of recruitment procedures, use of personal data for the purpose of promotion, etc.),
  • personal settings (preferences) including settings in the field of marketing and the use of cookies by the Data Subject,
  • other data necessary for the performance of the contract,
  • other personal data provided to the Controller by the Data Subject.

Beyond the above, the Controller specifies what data is processed in connection with the behaviour of the Data Subject:

1) Website Visit

In the event that anyone visits the Controller's website, this person agrees that during their visit to the site, information about them is collected, such as IP address, browser and preferred language settings, visited web pages including the time of the visit. The Controller monitors the movement of the person on the website, especially which links are clicked. All this is done by the Controller for the purpose of personalizing the displayed content. When visiting the website, so-called cookies are also stored in the visitor's internet browser, which are subsequently read by the Controller.

2) Purchase of Goods in the E-shop

The most frequently provided data are those obtained through the form for ordering goods or other services on the Controller's web interface. These are mainly data necessary for the conclusion of the purchase contract and performance under it (identification data, contact data, data created on the basis of the duration of the contract – purchased goods, volume of services provided, customer segment).

3) User Account

In the event that the data subject wishes to use the advantages of a user account, it is necessary to register for it. The user account is secured by a password chosen by the Data Subject. The Controller does not have access to this password and, in the event of its loss, is therefore unable to send it to the Data Subject; the Controller is only able to generate a form for entering a new password. The Data Subject has access to their personal data within their user account and can modify it if necessary. Within the user account, the Data Subject can view the history of completed orders, purchased products, as well as unfinished orders, whereby an unfinished order remains stored until the next login to the user account. The Data Subject can also save their favorite products. In the event that the Data Subject is registered, identification data, contact data, demographic data, login data (without the actual password), and data created on the basis of the duration of the contract, including complaints and returned goods, are processed.

4) Subscription to Commercial Communications – Newsletter

The Data Subject can subscribe to commercial communications on the web interface davidsport.eu. A commercial communication, the so-called "Newsletter", is also sent to the data subject in connection with ordering goods. It is subsequently possible to refuse the receipt of these communications at any time via the unsubscribe link located in the footer of every email containing these commercial communications. In this case, the Controller processes identification data, contact data, and demographic data.

5) Use of the Availability Monitoring Service

In the event that goods in the Controller's e-shop are not in stock, a potential buyer can set up availability monitoring. In such a case, the Controller informs the Data Subject upon the restoration of the product's availability at their email address, which is processed for this reason.

6) Social Media Integration

In the event that the Data Subject is logged into any social network (e.g., Facebook, Instagram) and visits the Controller's web interface, data linking may occur. The Controller uses these plugins for marketing purposes and ad personalization.

7) Participation in Contests and Marketing Campaigns

In the event that the Data Subject decides to participate in a contest or other marketing campaign organized by the Controller, identification and contact data necessary for the execution of the campaign and the delivery of the prize are processed.


PURPOSES AND LEGAL BASIS FOR PROCESSING

The Controller processes the personal data of the Data Subject for the following purposes:

a) Performance of a contract: Processing for the purpose of order fulfilment, delivery of goods, and customer communication.

b) Compliance with legal obligations: Storage of data for accounting, tax, and archiving purposes in accordance with legal regulations.

c) Legitimate interest – Marketing: Sending commercial communications (newsletters) to existing customers.

d) Legitimate interest – Security: Protection of the Controller's property, debt collection, and prevention of fraudulent activities.

e) Consent: Processing for ad personalization, analytics (cookies), and sending updates to non-customers.


DATA PROCESSING PERIOD

Personal data will be processed only for the period necessary for the purpose of their processing. With regard to the above:

  • for the purpose under point a) above, personal data will be processed until the termination of obligations under the contract (this does not affect the Controller's possibility to subsequently process this personal data to the necessary extent for the purpose under point b), c), d) and/or e) above),
  • for the purpose under point b) above, personal data will be processed for the duration of the relevant legal obligation of the Controller,
  • for the purpose under point c) above, personal data will be processed until the end of the 3rd calendar year following the termination of obligations under the contract,
  • in the event of the commencement and duration of judicial, administrative, or other proceedings in which the rights or obligations of the Controller in relation to the relevant Data Subject are addressed, the processing period for the purpose under point c) above shall not end before the conclusion of such proceedings,
  • for the purpose of sending commercial communications under point d) above, personal data will be processed until the Data Subject expresses their disagreement with such processing,
  • for the purposes under point e) above, personal data will be processed for the period for which the Data Subject granted consent to the Controller according to the separately approved consent to the processing of personal data. The Data Subject acknowledges that before the expiry of this period, the Controller may contact them for the purpose of renewing their consent.

No later than by the end of the calendar quarter following the expiry of the processing period above, the relevant personal data for which the purpose of processing has ceased will be destroyed (by shredding or other means ensuring that unauthorized persons cannot access the personal data) or anonymized.


METHOD OF PERSONAL DATA PROCESSING

The processing of personal data is carried out by the Controller. The processing is performed at its premises and headquarters by individual authorized employees of the Controller or by Processors. The processing takes place via computer technology or manually for personal data in paper form, while observing all security principles for the management and processing of personal data.

For this purpose, the Controller has taken technical and organizational measures to ensure the protection of personal data, in particular measures to prevent unauthorized or accidental access to personal data, its alteration, destruction or loss, unauthorized transfers, unauthorized processing, as well as other misuse of personal data. All entities to which personal data may be made available respect the right of Data Subjects to privacy and are obliged to proceed in accordance with applicable legal regulations regarding the protection of personal data.


INFORMATION PROVIDED TO DATA SUBJECTS UNDER GDPR

In connection with the processing of their personal data, Data Subjects have a number of rights, including the right to request from the Controller:

  • access to their personal data (under the conditions of Art. 15 GDPR),
  • rectification or erasure of personal data (under the conditions of Art. 16 or Art. 17 GDPR),
  • restriction of processing of personal data (under the conditions of Art. 18 GDPR),
  • the right to object to the processing of personal data (under the conditions of Art. 21 GDPR),
  • the right to data portability (under the conditions of Art. 20 GDPR),
  • the right to withdraw consent to the processing of personal data, in writing or electronically to the address or email of the Controller provided in this Policy.

If the Data Subject finds or believes that their personal data is being processed in a way that violates the protection of their private and personal life or in violation of legal regulations, they have the right to contact the Controller with a request for explanation and/or rectification. The request must be submitted in writing by sending a letter or email to the Controller's contact details: Info@davidsport.cz.

If the Data Subject's request is found justified, the Controller will immediately rectify the situation. This is without prejudice to the Data Subject's possibility to contact the supervisory authority directly: The Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, +420 234 665 111, www.uoou.cz.


COOKIE USAGE POLICY

The Controller's website uses cookies. Cookies are small text files that can be used by websites to make the user experience more efficient.

The Controller uses cookies to personalize content and ads, provide social media features, and analyze traffic. Information about your use of the website is also shared with the Controller's social media, advertising, and analysis partners, who may combine it with other information provided by users or collected during the use of their services.

The law states that the Controller may store cookies on the user's device if they are strictly necessary for the operation of the site (see Necessary cookies section) without the user's consent. For all other types of cookies, the user's consent is required, the full text of which can be found HERE, and which can be withdrawn at any time HERE.
 

Types of cookies

Technical
Technical cookies are necessary for the proper functioning of the e-shop and all the features offered. They allow, among other things, keeping products in the cart while you decide, displaying a list of favorite products, filtering products, and saving privacy settings. By being present on the e-shop, you agree to technical cookies; therefore, they cannot be deactivated. Technical cookies help make a website usable by providing basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

Cookies can be blocked = disabled, but part of the site may not display correctly, and some parts may not function at all. Cookie settings for the most commonly used browsers can be found here:

Analytical
Analytical cookies are essential for the Controller to measure the performance of the e-shop and advertising campaigns. Using cookies, the Controller tracks the number of visitors and where they came from. When processing data, the Controller does not use identifiers that would show a specific customer or user; aggregate information is sufficient. Disabling these cookies will not affect your shopping but will prevent us from analyzing the e-shop's performance in connection with your visit and optimizing settings for smooth operation. These cookies serve to improve website functionality. They are used, for example, to understand how visitors interact with the site and usually help provide information on metrics such as visitor count, bounce rate, traffic source, etc. Analytical cookies also allow visitors to easily find what they are looking for and can serve to improve website performance and speed.

Preferential
These cookies allow the Controller to provide the most convenient and individualized environment for your e-shop shopping. They enable the Controller to offer products matching your preferences or previous purchases, and avoid showing unwanted information about events and products that do not meet your needs. Preferential cookies allow the website to remember information that changes the way the site behaves or looks, such as the preferred language or the region the user is in.

Advertising
Advertising cookies are used by the Controller to display correct content or ads in designated areas. The Controller and its partners use these cookies to publish relevant content on the Controller's site and third-party websites. For these purposes, pseudonymized profiles are created. These profiles do not use information that could identify a specific person; they only use pseudonymized data. If you do not consent to these cookies, you will not receive content tailored to your preferences. Advertising cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for individual users, making them more valuable for publishers and third-party advertisers.


CONCLUSION

The Controller reserves the right to change the rules for the protection and processing of personal data at any time and in any way, with the current status always being posted on the website www.davidsport.eu.