General Data Protection Regulation

Basic Information
1.1. Document contents. This privacy policy describe how we process personal data of
visitors, customers of the online store, and other individuals. Here, you will find information
about what personal data we process, why and on what basis we do so, to whom we disclose
it, and also what rights you have in connection with its processing. All processing of
personal data is carried out in accordance with the General Data Protection Regulation (EU)
2016/679, commonly referred to as GDPR.
1.2. Our role. All described activities of personal data processing are carried out in the role
of controller by an entrepreneur Václav Polnický, based in Boleslavská 111, 50743 Sobotka,
the Czech Republic, ID number 87467101, recorded in the Trade Register, payer of VAT
(for better understanding, hereinafter referred to as "we"). This means that we determine
the purposes for which your personal data is collected, specify the means of processing, and
are responsible for its proper implementation.
1.3. Scope of personal data processing. The personal data we process includes:
1.3.1. identification data (especially name and surname or identification number
and tax identification number for entrepreneurs),
1.3.2. contact details (especially address, email address, and phone number),
1.3.3. data about orders and transactions (especially ordered goods and services,
selected payment and delivery method, and other order-related information),
1.3.4. data about communication (especially content and other data related to
communication between us and you),
1.3.5. registration and settings data (especially data related to your user account if
you register with us and data about the settings of our services),
1.3.6. data about the use of our website (especially IP address, device data, data
obtained through cookies, or data about your activities on our website).
Why and how we process your personal data?
2.1. Website functionality. If you visit our website, we process your personal data to
ensure its proper functioning based on our legitimate interest in providing our services via
the internet.
2.2. User account. We process your personal data based on a contract when managing
user accounts in our online store.
2.3. Improvement and development of our services. We also process your personal data
for the purpose of measuring website traffic, creating statistics, and records that help us
evaluate and develop our services. This is based on our legitimate interest in monitoring
website traffic and developing and optimizing our services.
2.4. Security and testing. To protect our websites and all other services from cyberattacks
and fraud and for testing new functionalities and website changes, we process your personal
data based on our legitimate interest in securing and enhancing our services.
2.5. Protection of legal rights and internal control. We process your personal data
based on our legitimate interests to protect legal rights and for our internal records and
control.
2.6. Fulfillment of legal obligations. We process personal data for the purpose of
fulfilling our legal obligations, including providing information to public authorities.
2.7. Contract performance and conclusion. We process personal data for the purpose of
fulfilling our obligations arising from contracts between us and you and for concluding such
contracts. This may also involve processing personal data of recipients and other recipients
of goods and other services.
2.8. Customer support. We process your personal data to deal with your order-related
requests on the basis of the obligation to perform the contracts concluded between us and
you and for the conclusion of these contracts. For handling other requests, if any, we
process your personal data on the basis of our legitimate interest in providing our services
and ensuring adequate support.
2.9. Retention period. We only store personal data for the time necessary to achieve the
stated purposes of personal data processing. Once the processing purpose is fulfilled,
personal data is promptly disposed of. Typically, we retain personal data for the duration of
the statute of limitations (usually 3 years) and one year after its expiration to account for
possible claims made at the end of the statute of limitations. In addition to the above, the
following special retention periods apply:
2.9.1. We retain data associated with user accounts for the entire duration of the
account's existence until it is deleted.
2.9.2. In case of legal proceedings and other disputes, we process your personal
data to the necessary extent for the entire duration of such proceedings and the
remaining part of the statute of limitations after its termination.
2.9.3. For fulfilling legal obligations, we process personal data for the time
necessary to fulfill these obligations.
Who are personal data transferred to?
3.1. Processors. We also use the services of other entities as processors to process
personal data only according to our instructions. These include in particular:
3.1.1. IT service providers and other technology suppliers,
3.1.2. providers of analytical and marketing tools,
3.1.3. communication tool providers,
3.1.4. customer satisfaction assessment program providers.
3.2. Controllers. We may disclose your personal data to other entities as controllers:
3.2.1. our suppliers involved in contract fulfillment, especially carriers and payment
system providers,
3.2.2. providers of advertising systems and social networks.
3.3. Transfer outside the EU. In some cases, your personal data may be transferred
outside the European Economic Area, either based on an adequacy decision according to
Article 45 of the GDPR, appropriate safeguards under Article 46 of the GDPR, or exceptions
under Article 49 of the GDPR.
Your rights
4.1. Rights of the data subject. Regarding your personal data, you have the right to:
4.1.1. request the rectification of inaccurate or outdated personal data. If you find
that the personal data we process about you is inaccurate or incomplete, you have
the right for us to promptly correct or complete it,
4.1.2. request confirmation of whether processing is taking place and, if so,
information about this processing to the extent specified in Article 15 of the GDPR,
as well as a copy of the processed data (additional copies may be subject to a fee to
cover necessary costs),
4.1.3. in some cases, have your personal data erased. We will erase your personal
data without undue delay if we no longer need it for the purposes for which we
processed it, or if you exercise your right to object to processing and we determine
that there are no legitimate interests justifying such processing, or if it turns out
that the processing of personal data carried out by us is no longer in compliance
with applicable regulations. However, this right will not apply if the processing of
your personal data is still necessary for the fulfillment of our legal obligation,
archiving purposes, scientific or historical research, statistical purposes, or the
establishment, exercise, or defense of legal claims,
4.1.4. exercise the right to restrict the processing of personal data. This right
allows you to request that your personal data be marked and that these data not be
subject to any further processing operations - however, not indefinitely (as in the
case of the right to erasure), but for a limited period. We must restrict the
processing of personal data when you dispute the accuracy of personal data until we
agree on which data is correct, or when we process your personal data without
sufficient legal basis (e.g., beyond what we are required to process), but you prefer
only to restrict it (e.g., if you expect to provide us with such data in the future), or if
we no longer need your personal data for the above-mentioned processing purposes,
but you require it for the establishment, exercise, or defense of your legal claims, or
if you object to the processing and during the period of verification, your objection is
deemed legitimate, we are obligated to restrict the processing of your personal data,
4.1.5. request the trasmit of personal data in cases of processing based on your
consent or a contract,
4.1.6. raise an objection to the processing of personal data carried out on the basis
of our legitimate interest. We will cease processing your personal data if we do not
have compelling legitimate reasons for such processing to continue. In the case of
objections to marketing activities, these activities will be terminated in any case,
4.1.7. express your disagreement with the processing of your personal data for the
purpose of sending commercial communications, and you can also revoke your
previous consent to the processing of personal data for another purpose unless it
concerns processing for the purpose of fulfilling our contractual obligations,
performing our legal obligations, or another purpose arising from our legitimate
interests.
4.2. Exercising your rights. You can exercise your rights in one of the following ways:
4.2.1. by email at to shop@pokemon4u.eu.
4.3. Right to lodge a complaint with the supervisory authority. If you believe that we
have violated the GDPR in the processing of your personal data, you have the right to lodge
a complaint with the Office for Personal Data Protection, located at Pplk. Sochora 27, 170 00
Praha 7, the Czech Republic (http://www.uoou.cz).
Cookies
5.1. Cookies stored on your device for future access (temporary files). Our websites
may use cookie technology (and possibly other technologies based on a similar principle,
such as Web Storage). This means that we store small data files in a reserved space on your
device, which allow us to provide you with a service and further improve it. For simplicity,
we will refer to all these technologies as "cookies."
5.2. Cookies necessary for providing the service. Some cookies are technologically
necessary for providing the service. This means that it is not possible to avoid storing them
while maintaining the functionality of the service. These include cookies for:
5.2.1. storing your choices related to ordering,
5.2.2. storing website settings,
5.2.3. user account login,
5.2.4. ensuring IT security.
5.3. Other types of cookies. We use some cookies to provide you with a higher quality
service that is more tailored to your preferences. As part of this, we may store cookies on
your device for:
5.3.1. ensuring website traffic analysis and usage, including third-party cookies,
5.3.2. for advertising purposes to display customized advertising on our and other
websites, including third-party cookies,
5.3.3. ensuring integration with social networks, including third-party cookies,
5.3.4. determining your geographical location.
5.4. Cookie storage settings. Within the relevant settings of your device, you can
configure the use of cookies on our website, such as blocking cookies if you do not agree
with their use on our website. If you choose this option, please be aware that some parts of
the service may not function correctly.