Privacy policy


1. Who is the controller of personal data?

The administrator is a person who alone or jointly with others determines the purposes and decides how personal data will be processed.

The administrator of personal data is:

Monika Staňková, ID number:07120893, with registered office Struhlovsko 1491, Hranice I-Město, 75301 Hranice

The administrator can be contacted at the email address yourmilitarystorieseshop@gmail.com or at +420 737665483 .


2. For what purpose do we need personal data?

The administrator processes personal data to:

a) ensuring the conclusion and subsequent fulfillment of the contractual obligation between the administrator and you (Art6 par1 letterb) GDPR)Other legal obligations arise from such a relationship, and the administrator must process personal data for this purpose as well (Art6 par1 letterc) GDPR)The processing of personal data is necessary to allow you to register on the administrator's website and create a user account, as well as to fulfill mutual obligations arising from the concluded contractWe also collect personal data for the purpose of processing any payments you must make for the ordered goodsWe may also send you email notifications about items we offer that are currently for sale.

b) for marketing purposes, so that the controller can best adapt the offer of its products and services and commercial communications regarding them to your needs, for this purpose the controller obtains your explicit consent (Art.6 par1 lettera) GDPR;

c) protection of their legitimate interests (Art6 par1 letterf) GDPR).

Providing personal data to administrators is generally a legal and contractual requirementRegarding the provision of personal data for marketing purposes, which does not constitute the fulfillment of a contractual and legal obligation of the administrator, your consent is requiredIf you do not give consent to the administrator to process personal data for marketing purposes, this does not mean that the administrator will refuse to provide you with its product or service based on the contract as a result.

3. What are our legitimate interests?

Personal data is also processed by the controller to protect its legitimate interestsThe administrator's legitimate interests are, in particular, proper fulfillment of all contractual obligations of the administrator, proper fulfillment of all legal obligations of the administrator, direct marketing, protection of the administrator's business and property.

In order to ensure the greatest possible protection of your privacy, you have the right to object to the processing of your personal data exclusively for the most necessary legal reasons or to the blocking of personal dataYou can read more about your rights related to the processing of personal data in Article 11 of this information memorandum.

4. How was the personal data obtained?

The administrator obtained personal data directly from you, especially when creating an order for goods, registering and creating a user account, from completed forms, mutual communication or from concluded contractsIn addition, personal data may also come from publicly available sources, registers and recordsFurthermore, the administrator could obtain personal data from third parties who are authorized to access and process your personal data and with whom they cooperate, as well as from information from social networks and the Internet that you yourself have placed there.

5. What categories of personal data are processed?

To ensure your satisfaction from the proper fulfillment of the obligation, to ensure the fulfillment of legal obligations, to ensure a personalized offer of goods and services of the administrator and for the other purposes listed above, the administrator processes the following categories of personal data:

a. basic identification data – name, surname, username, orresidence;

b. contact details – telephone number and e-mail address;

c. information about the use of the administrator's products and services - this is data about which products you have contracted with the administrator and which you are using now, including product settings, etc.;

d. information from mutual communication – information from e-mails, phone call records or other contact forms;

e. invoicing and transaction data – this is mainly information appearing on invoices, on agreed invoicing terms and received payments;

f. geolocation information - information from the Internet browser or mobile applications that you use;

6. What is the legal basis for processing personal data?

The legality of the processing is given by Article 6 para1 GDPR, according to which the processing is lawful if it is necessary for the fulfillment of the contract, for the fulfillment of the administrator's legal obligations, for the protection of the legitimate interests of the administrator, or the processing takes place on the basis of the consent you have given us.

The legality of the processing is also based, for example, on Act no563/1991 Coll., on accounting, according to which invoicing data is processed and stored, from Act no.89/2012 Coll., Civil Code, according to which the administrator defends his legitimate interests or from Act no.235/2004 Coll., on value added tax.

7. Will we pass on personal data to someone else?

Within the legal limits, we must provide personal data to state administration authorities, for example the tax administrator, courts, law enforcement authorities or capital market supervisory authorities, as well as to persons who will participate in the performance of the contractWe will also transfer personal data to processors in the field of marketing.

8. Will we transfer personal data to a third country or international organization?

We will not transfer personal data to countries outside the European Union or the European Economic Area, nor to any international organization.

9. How long will we store personal data?

Personal data will be processed and stored for at least the duration of the contractSome personal data required e.gfor tax and invoicing obligations, they will be kept longer, usually 5 or 10 years starting from the year following the creation of the stored fact.

Personal data that are important for exercising the administrator's legitimate interests will be kept for a maximum of 5 years from the end of the contractual relationship with the administrator.

Personal data processed for marketing purposes will be kept for a maximum of 3 years from their acquisition.

Personal data will never be kept longer than the statutory maximumAfter the archiving period has expired, personal data will be securely and irretrievably destroyed in such a way that it cannot be misused.

10. What are your rights related to the processing of personal data and how can you exercise them?

The administrator does everything to ensure that your data is processed properly and, above all, securelyYou are guaranteed the rights described in this article, which you can exercise with the administrator.

11. How can you exercise your rights?

You can exercise individual rights by sending an e-mail to the address yourmilitarystorieseshop@gmail.com or by calling the phone number +420 737665483You can also exercise your rights in the form of a written request sent to our correspondence address to the address of the data controller listed above.

All communications and statements regarding your rights are provided by the administrator free of chargeHowever, if the request would be clearly unfounded or unreasonable, especially because it would be repeated, the administrator is entitled to charge a reasonable fee taking into account the administrative costs associated with providing the requested informationIn case of repeated application of the request to provide copies of processed personal data, the controller reserves the right to charge a reasonable fee for administrative costs for this reason.

The administrator will provide you with a statement and possibly information about the measures taken as soon as possible, but within one month at the latestThe administrator is entitled to extend the deadline by two months if necessary and taking into account the complexity and number of requestsThe administrator will inform you about the extension, including the reasons.

12. The right to information about the processing of your personal data

You are entitled to request information from the administrator as to whether or not personal data is being processedIf personal data is processed, you have the right to request information from the controller, in particular, about the identity and contact details of the controller, his representative and, where applicable, the personal data protection officer, about the purposes of processing, about the categories of personal data concerned, about the recipients or categories of recipients of personal data, about authorized administrators, about the list of your rights, about the possibility to contact the Office for Personal Data Protection, about the source of processed personal data and about automated decision-making and profiling.

If the controller intends to further process your personal data for a purpose other than that for which it was obtained, it will provide you with information about this other purpose and other relevant information before the said further processing.

13. Right of Access to Personal Data

You are entitled to request information from the controller as to whether your personal data is being processed or not, and if so, you have access to information about the purposes of processing, categories of personal data concerned, recipients or categories of recipients, the period of storage of personal data, information about your rights ( the right to request correction or erasure from the administrator, restriction of processing, to object to this processing), the right to file a complaint with the Office for Personal Data Protection, information about the source of personal data, information about whether automated decision-making and profiling takes place, and information regarding the used procedure, as well as the meaning and expected consequences of such processing for you, information and guarantees in case of transfer of personal data to a third country or international organizationYou have the right to provide copies of processed personal dataHowever, the rights and freedoms of other persons may not be adversely affected by the right to obtain this copy.

14. Right to Rectification

If, for example, there has been a change of residence, telephone number or other fact that can be considered personal data, you have the right to request from the administrator the correction of the processed personal dataIn addition, you have the right to supplement incomplete personal data, including by providing an additional statement.

15. Right to restriction of processing

The administrator processes your personal data only to the extent strictly necessaryHowever, if you feel that the administrator, e.gexceeds the above stated purposes for which it processes personal data, you can submit a request that your personal data be processed exclusively for the most necessary legal reasons or that personal data be blockedYour request is then subject to an individual assessment and you will be informed in detail about its processing.

16. Right to object and automated individual decision-making

If you find out or just believe that the administrator is processing personal data in violation of the protection of your private and personal life or in violation of legal regulations (provided that the personal data is processed by the administrator on the basis of public or legitimate interest, or is processed for purposes of direct marketing, including profiling, or for statistical purposes or for the purposes of scientific or historical significance), you can contact the administrator and ask him to explain or eliminate the objectionable situation that has arisen.

You can also object directly to automated decision-making and profiling.

17. The right to file a complaint with the Office for Personal Data Protection

You can at any time contact the supervisory authority, namely the Office for the Protection of Personal Data, with headquarters in Plk.Sochora 27, 170 00 Prague 7, website https://www.uoou.cz/ .

18. Right to withdraw consent

You have the right to revoke your consent to the processing of personal data at any time, either by filling out the form/unchecking the box/sending a revocation to the administrator's address or by using the link in the e-mail communication.

Document issued on 11/07/2022.