Information on Personal Data Processing

Information on Personal Data Processing

 

under Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the “Regulation”)

 

Jitka Klett Fashion Design s.r.o., a company with its registered office at Haštalská 791/9, Staré Město, 110 00 Praha 1, Id. No.: 04892046 , registered in the Commercial Register kept by the Municipal Court in Prague under File No. C 255203, (hereinafter also “Controller”), as a personal data controller within the meaning of the Regulation, hereby provides information to its clients – physical persons - on the manner and scope of personal data processing, including the scope of data subjects’ rights related to processing of their personal data by Jitka Klett Fashion Design s.r.o.

This information on personal data processing refers to all and any processing of personal data of the Controller´s clients.

The Controller processes personal data in conformity with EU law, especially in conformity with the Regulation, and also in conformity with the relevant international treaties binding on the Czech Republic and in conformity with the relevant national laws.

 

What personal data are processed by the Controller, for what purpose and on what basis?

The Controller obtains personal data directly from the data subjects and from third parties (e.g. booking portals).

The Controller only processes personal data that the Controller has obtained in conformity with the applicable legal regulations; the Controller collects and processes such personal data only for the set purpose, within the scope and for the period necessary for attaining this set purpose, while taking into account the practical functioning of the Controller and its information and personnel capacities. The personal data processed and their purposes and the legal basis for processing differ according to the different kinds of activities of the Controller, as these cases are described in the tables below:

You have registered with us / Your have ordered goods from us

Where have we obtained your personal data from?

  • Your personal data were obtained directly from you or we have obtained them in course of our business relationship, e.g. from public sources (ARES, etc.)
  • If you were named as contact person by our customer, we have the data from the customer.

Personal data processed:

  • Identification data of the customer and data that are indispensable for the sale of goods.
  • Identification data of the person empowered to take over goods for the customer, e.g. her/his signature at the handover of the goods.

 

Legal basis for processing

  • We obtain the personal data as mentioned above from you and we process them on the legal grounds of execution and performance of the contract.

Purposes of processing

  • We process the personal data as mentioned above for the purpose of executing the contract on the sale of goods.

.

Information on the duty to provide personal data

  • The provision of personal data as mentioned above which we ask directly from you is a contractual requirement. Without such personal data, we cannot enter into a sales contract with you.

For how long will your personal data be processed?

  • In case you ordered only goods from us, we will process your personal data for the duration required by the law no. 536/1991 Coll., on accounting.
  • In case you registered with us, we will process your personal data for the whole duration of your registration and after its termination for the duration required by the act no. 536/1991 Coll., on accounting, beginning with the date of the last order of goods you placed with us.

Who we provide your personal data to?

  • Your personal data may, for purposes of accounting of the Collector, be provided to an external provider of accounting services.
  • Your personal data may be randomly accessible to external IT service providers in course of their services being performed for our company. These providers do not process your personal data.

 

 

Goods will be delivered to an address specified by you

Where have we obtained your personal data from?

  • We have your personal data directly from you or we have obtained them through your use of our IT systems (including e-shop), or in course of execution of our business relationship.

Personal data processed:

  • Identification data that are indispensable for the sending of goods and their delivery to our client (e.g. delivery address).

Legal basis for processing

  • We process the personal data from you on the legal grounds of performing a contract.

Purposes of processing

  • We process the personal data for the purposes of sending and delivering ordered goods.

Information on the duty to provide personal data

  • The provision of the personal data is required by the contract and, without being provided with these personal data from you, we cannot arrange delivery of the ordered goods to you.

For how long will your personal data be processed?

  • The above mentioned personal data are stored for the duration stipulated by the act no. 563/1991 Coll., on accounting, as amended, and act no. 235/2004 Coll., on value added tax, as amended, for at least the duration for which you can make claims for eventual defects of goods or other claims in accordance with statutory law, in particular the act no. 89/2012 Coll., Civil Code.

Who we provide your personal data to?

  • We share your personal data with delivery companies which perform for us the delivery of your ordered goods to the address indicated by you and with companies that secure for us the effective organisation of deliver of our goods via delivery service companies.
  • Your personal data may be randomly accessible to external IT service providers in course of their services being performed for our company. These providers do not process your personal data.

 

 

We issued an invoice for the goods / You paid for the goods and delivery

Where have we obtained your personal data from?

  • We have your personal data directly from you or we have obtained them through your use of our IT systems (including e-shop), and from financial service providers that execute the respective payment process.

Personal data processed:

  • Identification data of the customer and data that are indispensable for the registration of the payment, including information on the goods ordered.

Legal basis for processing

  • We process the personal data we obtain from you on the legal grounds of performing a contract and of fulfilling legal obligations under the act no. 563/1991 Coll., on accounting, act no. 235/2004 Coll., on value added tax and act no. 586/1992 Coll., on income tax.

Purposes of processing

  • We process the above-mentioned personal data for the purposes of invoicing and evidencing the payment of the purchase price.

Information on the duty to provide personal data

  • The provision of the above-mentioned personal data is a statutory and also a contractual requirement and, without being provided with these personal data from you, we cannot enable the purchase of the ordered goods.

For how long will your personal data be processed?

  • The personal data specified above are stored for the duration stipulated by the act no. 563/1991 Coll., on accounting, and the act No. 235/2004 Coll., on value added tax, , i.e. for at least 5 years.

Who we provide your personal data to?

  • We share the above personal data with our external accounting service providers.
  • Your personal data may be randomly accessible to external IT service providers in course of their services being performed for our company. These providers do not process your personal data.

 

 

 

You made a complaint regarding goods bought from us

Where have we obtained your personal data from?

  • We have your personal data directly from you or we have obtained them through your use of our IT systems (including e-shop).

Personal data processed:

  • Identification data of the customer and data on her/his order or purchase.

Legal basis for processing

  • We process the above-mentioned personal data on the legal grounds of fulfilling legal obligations under the act no. 89/2012 Coll., Civil Code, and act no. 634/1992 Coll., on protection of consumers.

Purposes of processing

  • We process the above-mentioned personal data for the purpose of processing your complaint regarding the purchased goods.

Information on the duty to provide personal data

  • Provision of above-mentioned personal data is a legal requirement. Without this data, we cannot process your complaint.

For how long will your personal data be processed?

  • The personal data specified above are stored for the duration it is possible to make complaints about defects or other claims in accordance with statutory law, in particular the act no. 89/2012 Coll., Civil Code..

Who we provide your personal data to?

  • Your personal data may be shared for accounting purposes with our external accounting service providers.
  • Your personal data may be randomly accessible to external IT service providers in course of performing their services for our company. These providers do not process your personal data.

 

 

 

Sending commercial messages and analysing customer preferences

Where have we obtained your personal data from?

  • We have your personal data directly from you or we have obtained them through your use of our IT systems (including e-shop).

Personal data processed:

  • Order history.
  • Data on your use of the services and contents on our web sites.
  • IP address and further technical identifications.
  • Email address.

Legal basis for processing

  • We process the email address and order history based on our legitimate interest to perform direct marketing.
  • Some data on your use of our web pages services and contents are processed based upon our legitimate interest to analyse the use of the different sales channels of our company.

Purposes of processing

  • We process the above-mentioned personal data for the purposes of direct marketing and analysis of the use of the different sales channels of our company.

 

For how long will your personal data be processed?

  • For the whole duration of your registration with our e-shop.

Who we provide your personal data to?

  • Your personal data may be shared with companies that provide marketing services for us and with Google LLC in connection with the usage of Google analytics services..

 

 

Marketing – contact with the customers, commercial events

Where have we obtained your personal data from?

  • We have your personal data directly from you or we have obtained them through your use of our IT systems (including e-shop) or in course of execution of our business relationship.

Personal data processed:

  • Identification data of the customer.
  • History and quantity of orders.
  • Contact data of customer.

Legal basis for processing

  • We process the above-mentioned data based on our legitimate interest to perform direct marketing.
  • Some of the mentioned data are being processed based upon your consent with personal data processing, which may be revoked.

Purposes of processing

  • We process the above-mentioned personal data for the purposes of direct marketing.
  • Some of the above-mentioned personal data are processed for the purpose of organising commercial events with our business partners.

Information on the duty to provide personal data

  • Provision of above-mentioned personal data for this purpose is neither required by contract nor by statutory law.

For how long will your personal data be processed?

  • For the whole duration of your registration with our e-shop, at least however for one (1) year from the date of your last purchase of goods.

Who we provide your personal data to?

  • Your personal data may in exceptional cases be shared with our business partners in connection with the organisation of joint commercial events.

 

 

In addition to the above, we are entitled to process any of your above-mentioned data as well as other personal data, which we collected, in the necessary extent, for use in case of a legal dispute between you and our company. The legal basis for processing in such case is our legitimate interest connected with claiming and defending our legal rights. All your personal data processed for such purpose will be shared with our lawyers.

 

Saving of registration access data on our servers

When accessing our internet pages, our IT system automatically registers the data of your computer system and saves them in so-called server logfiles.

The following data is collected there:

  • Date and time of access of our webpages
  • Name of requested content file
  • URL through which our pages were accessed
  • IP address
  • Amount of transferred data
  • Requesting provider
  • Operation system and web browser used

This data is not saved together with other personal data. The IP address theoretically allows identification of a specific user; however, an unambiguous identification of your person is not possible based on this information.

 

Saving in the server logfiles takes place to pursue the following legitimate interests:

  • Securing the safety of our IT system (crime prevention and computer forensic)
  • Securing undisturbed operation of our webpages
  • Optimization of our web pages

 

This data is not used for marketing purposes are deleted once they are not necessary any more for achieving the purpose, for which they were collected.

 

 

Use of Cookies

In order to make your visit to our web pages as attractive as possible, we use so-called cookies on various pages. Cookies are little text files that are saved on your end device. Some of the cookies we use are again deleted after the end of the session of your web browser, i.e. after you close the browser. Other cookies stay on your device and allows us to identify your browser at your next visit to our web pages (permanent cookies). The data saved in our cookies are not connected with your personal data (name, address, etc.). You can set up your web browser in such way that you will be informed about the installation of cookies and may decide on their acceptance or you can exclude their acceptance in certain cases or generally. In case you do not accept cookies, some functions of our web pages may be limited or inaccessible to you.

 

Facebook, Instagram, Pinterest

Our web pages may contain social plugins of the social networks “Facebook” (Facebook Inc., 1601 S. California Ave, Palo Alto, California 94304, USA), “Instagram” (Instagram LLC., 1601 Willow Road, Menlo Park, CA 94025, USA), and “Pinterest” (Pinterest Inc., 808 Brannan Street, San Francisco, CA 94103, USA). It is possible that personal data about accessed web pages are collected by these plugins, passed on to the respective provider and connected with the respective service to the web page visitor.

 

The Collector does not collect any personal data via social plugins. To prevent transfer of data to service providers in the USA without knowledge of the user, we use a technical solution called Shariff on our pages. Thanks to this, the respective social plugins are initially integrated only as graphics on web pages. These graphics contain a link to the web page of the respective plugin provider. Only after clicking on the graphic, you will be redirected to the service of the respective provider. Thanks to this solution, personal data are not automatically shared with the respective service providers while visiting our web pages. If you click on the graphic of one of the social plugins, your personal data may be transferred to the respective provider and saved there.  If you do not click on these graphics, no transfer of data from you to the providers occurs.

 

After you click on the social plugin, the respective provider gets the information that you visited a specific one of our web pages. Please be aware that for this to happen, you neither need to have an account with the respective provider, nor be logged in. In case you have a user account with the respective provider and are logged in at the time of your visit to our web pages, data collected by the social plugin is directly matched with your user account. In case you do not wish matching with your user account, you need to log out before clicking on any of the social plugins.

The Collector has no influence whatsoever on if and to what extent the social network providers collect personal data. We do not have information on the extent, purpose or storage duration of data by these providers. It however is to be expected that they will collect at least the IP address and information about your device are used and stored via social plugins. It is also possible that these providers use cookies.

 

Information on the extent and purpose of collection of the respective services providers, as well as on additional processing and usage may be found in the sections on data protection on the web pages of these providers, where you can obtain information about your data protection rights and set-up options for protection of your privacy:


a) Facebook Inc., 1601 S California Ave, Palo Alto, California 94304, USA https://en-gb.facebook.com/policy.php
c) Instagram LLC., 1601 Willow Road, Menlo Park, CA 94025, USA https://help.instagram.com/519522125107875?helpref=page_content
e) Pinterest Inc., 808 Brannan Street, San Francisco, CA 94103, USA https://about.pinterest.com/de/privacy-policy

 

 

What are rights of the data subject?

Within the meaning and under the conditions of Article 15 of the Regulation, the data subject is entitled to request that the Controller enable access to the subject’s personal data which are being processed. In such a case, the Controller shall provide the data subject with a copy of the personal data in csv, doc or pdf format.

In case of a change in the personal data or their inaccurate processing and if the legal regulations, internal regulations of the Controller, the contract or other documents do not indicate the duty to report and prove the change in the personal data to the Controller, the data subject may request that the Controller rectify the inaccurate personal data or supplement incomplete personal data. The Controller may request that it be proven that the proposed data are correct.

The data subject may also request that the Controller erase his/her personal data or to limit their processing. The Controller shall carry out the requested erasure or limitation of processing unless the Regulation or some other law stipulates otherwise.

Further, the data subject is entitled to obtain his/her personal data provided to the Controller, which the Controller processes on the basis of a need for their processing for the purposes of performing the contract or on the basis of consent of the data subject, in an automated form, i.e. in electronic form in a structured, commonly used and machine-readable format, and to submit these data to another controller (right to personal data portability). In case of exercise of this right, the Controller shall send the personal data in csv format.

The data subject has the right to object to the processing of all his/her personal data if they are processed on the legal grounds of legitimate interest. The Controller shall in such case not further process these personal data.

 

The data subject may exercise all of the above described rights by using the form accessible on the internet pages www.jkklett.com, www.jkklett.cz and send it filled out to the email address office@jitkaklett.com

 

Furthermore, the data subject has the right to lodge a complaint with the supervisory authority, which in the Czech Republic is the Office for Personal Data Protection (www.uoou.cz).   

If personal data processing is based on granted consent, the data subject has the right to revoke his/her consent at any time. However, revocation of such consent shall in no way prejudice the lawfulness of processing based on the consent granted before its revocation.

The data subject may revoke his/her consent with the processing of personal data, if he/she is registered in the e-shop, to the Controller by using the specified order “revocation of consent with data processing” accessible on the internet pages www.jkklett.com, www.jkklett.cz and send the filled-in form to the email address office@jitkaklett.com or by clicking on the link in the newsletters.

 

 

 

 

 

 

*

Back shopping