Controller
Controller in accordance with Article 4 point 7 of the General Data Protection Regulation (EP 2016/679) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as “GDPR”) is:
4Each s.r.o., VAT Number: CZ24673692, based at Nad Kralovskou oborou 147/25, Praha 7, Czech Republic (hereinafter referred to as “controller”).
Contact information of the controller is:
- Nad Kralovskou oborou 147/25, Praha 7, Czech Republic
- Mail: 4each@4each.cz
- Phone: +420 212 242 233
A Personal Data Protection Officer (DPO) has been appointed:
- Ing. Vojtech Jankovsky
- Nad Kralovskou oborou 147/25, Praha 7, Czech Republic
- Mail: vjankovsky@4each.cz
- Phone: +420 212 242 233
Personal data categories and the purpose of processing
The controller processes data received from you to complete the order, specifically:
- Billing contact including name, email, address, and phone,
- Delivery contact including name, address, and phone,
- List of ordered products including number of pieces and price.
The controller processes data of registered users to make future orders easier, specifically:
- E-mail,
- List of contacts including name, address, and phone.
Retention time of data
The data necessary for the performance of the rights and obligations arising from the contractual relationship between the customer and the controller, and for the exercise of claims from such relationship, shall be kept by the controller for as long as is necessary (5 years after termination of the contractual relationship).
Data subject to personal data processing (i.e. Customer Account) will be kept by the controller for 3 years since the last login.
Data recipients
Data recipients are the following persons or companies:
- WeDeCom s.r.o., which ensures the operation of the e-shop, represented by Mr. Jiří Bláha
- Contractual carriers for goods delivery: Czech Post, DHL
- Accountant of 4Each s.r.o., Ms. Petra Ježdíková
- PayPal for on-line payment processing
Customer rights
The GDPR provides the following rights to you:
- The right to access your personal data
- The right to rectification
- The right to erasure
- The right to restrict processing
- The right to data portability
- The right to object
- The rights related to automated individual decision-making, including profiling
Security of personal data
The controller has taken all appropriate organizational and technical measures to prevent unauthorized access to personal data, its modification or loss, and unauthorized processing, in particular:
- Securing the web application against common attacks.
- Ensuring password login into the web application and instructing administrators to use strong passwords.
- Running websites on secure HTTPS.
- Limiting access to personal data only to authorized persons.
- Setting the relationship between the owner and the e-shop operator by a processing agreement.
