Privacy Policy
Basic Provisions
The controller of personal data within the meaning of Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as the “GDPR”) is GIGA OPTIK s.r.o., Company ID 07274165, with its registered office at Nádražní 129, Mnichovice, 251 64, registered in the Commercial Register, file number C 298167/MSPH, maintained by the Municipal Court in Prague (hereinafter referred to as the “Controller”).
Contact details of the Controller:
GIGA OPTIK s. r. o.
Komerční 466
251 01 Nupaky
Email: info@gigaoptik.com
Personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
The Controller has not appointed a Data Protection Officer.
Sources and Categories of Processed Personal Data
The Controller processes personal data that you have provided to the Controller, or personal data that the Controller has obtained as a result of fulfilling your order:
GIGA OPTIK s. r. o.
Komerční 466
251 01 Nupaky
Email: info@gigaoptik.com
The Controller processes your identification, contact, and contractual data.
Legal Basis and Purpose of Processing Personal Data
The lawful grounds for processing personal data are:
-
performance of a contract between you and the Controller pursuant to Article 6(1)(b) GDPR,
-
compliance with a legal obligation of the Controller pursuant to Article 6(1)(c) GDPR,
-
the Controller’s legitimate interest in providing direct marketing (in particular for sending commercial communications and newsletters) pursuant to Article 6(1)(f) GDPR,
-
your consent to processing for direct marketing purposes (in particular for sending commercial communications and newsletters) pursuant to Article 6(1)(a) GDPR in conjunction with Section 7(2) of Act No. 480/2004 Coll., on certain information society services, if there is no order for goods or services.
The purposes of processing personal data are:
-
processing your order and exercising the rights and obligations arising from the contractual relationship between you and the Controller; when placing an order, personal data necessary for its successful processing (name, address, contact details) are required — providing personal data is a necessary requirement for the conclusion and performance of the contract; without providing personal data, it is not possible to conclude or perform the contract by the Controller,
-
compliance with legal obligations to the state,
-
sending commercial communications and other marketing activities.
The Controller does not engage in automated decision-making or profiling.
Data Retention Period
The Controller will store personal data:
-
for the period necessary to exercise the rights and obligations arising from the contractual relationship between you and the Controller and to assert claims arising from such contractual relationship (for a period of 15 years after the end of the contractual relationship),
-
until consent to processing for marketing purposes is withdrawn, but for no more than 15 years, if personal data are processed on the basis of consent.
After the retention period expires, the Controller will delete the personal data.
Recipients of Personal Data (Subcontractors)
Recipients of personal data are persons:
-
involved in the delivery of goods/services and processing of payments under the contract,
-
providing e-shop operation services (Shoptet) and other services related to e-shop operation,
-
providing marketing services.
The Controller does not intend to transfer personal data to a third country (non-EU country) or an international organisation.
Personal Data Processors
GIGA OPTIK s.r.o. processes personal data primarily on its own but also through carefully selected processors for certain support functions. Personal data are made available only to authorised employees and managers of GIGA OPTIK s.r.o. or authorised partners of the processor, and only to the extent necessary for processing purposes.
Current list of our processors:
-
IMP net, s.r.o. – Company ID 28351801 – Web hosting services
-
Delta computer systems s.r.o. – Company ID 27953181 – IT and email hosting services
-
Servis podnikateľa s.r.o. – Company ID SK47164662 – Business software solution management
-
Inste.CZ s.r.o. – Company ID 27212041 – IT services
-
GOOGLE IRELAND LIMITED – VAT IE6388047V – Remarketing
-
Seznam.cz – Company ID 26168685 – Remarketing
-
Facebook – VAT IE9692928F – Remarketing
-
Zacílená reklama s.r.o. – Company ID 07761449 – Remarketing
-
Heureka.cz – Company ID 02387727 – “Verified by Customers” service
Possibly another provider of services and software applications for processing, but currently not used by the Controller.
Your Rights
Under the GDPR, you have:
-
the right to access your personal data under Article 15 GDPR,
-
the right to rectification under Article 16 GDPR, or restriction of processing under Article 18 GDPR,
-
the right to erasure under Article 17 GDPR,
-
the right to object to processing under Article 21 GDPR,
-
the right to data portability under Article 20 GDPR,
-
the right to withdraw consent to processing in writing or electronically to the address or email of the Controller specified in Article III of these conditions.
You also have the right to lodge a complaint with the Data Protection Authority if you believe your right to personal data protection has been violated, or to take legal action.
Personal Data Security Conditions
The Controller declares that all appropriate technical and organisational measures to secure personal data have been taken.
The Controller has adopted technical measures to secure data storage and personal data in paper form.
The Controller declares that personal data are accessible only to persons authorised by the Controller.
Final Provisions
By placing an order via the online order form, you confirm that you have read the Privacy Policy and that you accept it in its entirety.
You agree to these terms by checking the consent box via the online order form. By checking the consent box, you confirm that you have read the Privacy Policy and that you accept it in its entirety.
The Controller has the right to amend these conditions. The new version of the Privacy Policy will be published on its website and also sent to the email address you have provided to the Controller.
These conditions shall take effect on 1 May 2024.