Personal Data Administrator
Okusaro s.r.o. is registered at Nad Šárkou 2069/25, 160 00 Praha 6 - Dejvice, company identification No. 05497574 as a data administrator shall process your personal data.
Type of Data Processed
Personal Data Provided By You
We process personal data provided by you.
If you order goods or services from us, we need the information which is referred to as mandatory in the ordering process (in particular your first name and surname, and delivery address). If we did not have this information we would not be able to deliver the goods. For the purposes of sale of goods or services, we also need your e-mail address, to which we shall send the order confirmation which serves as a confirmation of entering into the purchase agreement.
You can also fill in optional information when ordering goods or services. Such information helps us fulfill the concluded purchase agreement more efficiently. Providing optional information is voluntary.
After the goods are delivered, you may get an e-mail message with the request to evaluate the goods purchased.
If you contact us via the customer line or you send us a message, we shall also process your personal data stated in such communication.
Personal Data Obtained Other Than Directly from You
As part of joint marketing campaigns organized together with our business partners, we are entitled to process your personal data and we may combine them for the purposes of campaigns or of due performance of the agreement, as the case may be. In the event that your personal data is disclosed to a third party, we shall inform you in advance including informing you of the identity of such third party. If anyone discloses your personal data to us, you will have to be informed as well.
Personal Data of Third Persons Provided by You
In the event you provide us personal data of third persons, you are obliged to inform the person concerned and procure his/her consent to this Personal Data Protection Policy.
It may happen that you purchase goods from us, but you do not wish to collect them or make a complaint regarding such goods. You can define authorized persons in your user profile, who shall be entitled to collect or claim your goods. Thereby, you provide us their personal data.
Personal Data Processed Automatically
When you visit our website, we may collect certain information such the IP address, date and time of the visit to our website, information about your Internet browser, operation system or language settings. We may also process information about your conduct on our website, such as links opened or goods displayed. The details of your conduct on the web are anonymised for the maximum protection of your privacy and therefore we cannot match them with a particular person.
If you access our website from your mobile phone or a similar device or through one of our mobile applications, we can process information about your mobile device as well (mobile phone details, records of any application crash etc.).
We process cookies automatically.
What is a cookie file?
A cookie is a small text file created upon a visit to a website. It serves as a standard tool for the storage of information about visits to our website and how our website is used. Thus we can distinguish (but not identify) individual users and customize the content to individual preferences. Cookies are important and web browsing would be far more difficult without them.
What are cookies used for?
Cookies serve several purposes. We use the following cookies on our e-shop website:
- Technical cookies: We use technical cookies to ensure our e-shop works properly (e.g. for you to create a user profile, log in, and buy goods and services). The e-shop would not work without these cookies.
- Functional cookies: These help so that you do not have to log in and set your preferences repeatedly (e.g. setting the language in which our e-shop will be displayed). In these cases, your password is always encrypted. The use of these cookies is not absolutely necessary, but they make your visit to our online store more comfortable and user-friendly.
- Analytical cookies: Analytical cookies help us improve our online store, which ultimately benefits you. Analytical cookies on our website are collected by the Google Inc. script, which subsequently anonymises the data. The data ceases to be personal data after anonymisation: anonymised cookies cannot be matched with a particular user or person. We only work with anonymised cookies. Even if we wanted to, we would be unable to find out the way in which any particular user behaved on our website (sites visited, goods displayed etc.).
We also use the findings obtained from these cookies for advertising purposes; we may also display an ad that we consider relevant to you on other websites.
How You Can Control Which Cookies We Will Process
You can use one of the common browsers (e.g. Internet Explorer, Safari, Firefox, Chrome) with anonymous browsing switched on. This shall prevent storage of data concerning the sites visited. You can also block the storage of cookies in the browser. However, if you block the processing of technical and functional cookies, you will disable certain useful website functions.
Switching off analytical cookies makes it difficult for us to improve our online store experience.
If you access our website from a phone, tablet or similar device, you access the version optimised for such devices. Your personal data is processed similarly to the computer access.
Why We Collect and Process Your Personal Data
Your personal data is processed for the following reasons:
Purchase of goods and services: the primary purpose of processing your data is due dispatch and delivery of your order. If a problem occurs, we know who to contact from the data you provided.
Customer care: if you address us with a question/issue, we have to process your personal data in order to answer/resolve it. The data may be transferred to third parties in certain cases (e.g. delivery company).
User account: thanks to the personal data entered in your user profile, you will be able to use a number of functions (e.g. if you enter your telephone number, we can easily inform you about the time of the order delivery). You can change the entered details at any time, except for the e-mail address that serves for signing into your user account.
- Electronic marketing: e-mail commercial communication is sent to you upon your consent. You can easily unsubscribe from our newsletters by adjusting your user profile settings, using our contact form.
- Marketing competitions: in some cases, the winner may be photographed or recorded mainly for the reason of transparency of our marketing competitions. Such processing of personal data is made on the grounds of our legitimate interest, which consists in the enhancement of credibility of the competitions for other competitors and increasing attractiveness of the competitions. You are entitled to raise an objection to such processing on our website.
- Customer reviews of goods and services: after you purchase products or services from us, your may be asked to evaluate them. You may also post a review on your own initiative.
Assertion of rights and legal claims and inspection by public authorities: we can also process your personal data in order to assert our rights and legal claims (e.g. in the event that we have an overdue invoice in your name). We may also process your data for inspections by public authorities and other serious reasons. Legal Grounds for Processing of Personal Data Conclusion and Performance of Agreement
A large part of your personal data are needed by us in order to conclude the purchase agreement or another contract for goods and services you intend to purchase. After the agreement is concluded, we process your personal data in order to duly deliver the purchased goods, or to render the purchased services. We have to process billing and delivery details in particular due to the above-mentioned legal grounds.
We also use your personal data to provide you the relevant content, which may be of interest to you. On the grounds of legitimate interest, we process particular personal data, which is processed automatically, and cookies.
We may also send you e-mails and text messages on the same legal grounds.
Due to the protection against illegal distribution and disclosure of the electronic book you purchased (or other electronic content), your first name, surname and address are displayed in the electronic book.
In case we process your personal data on these legal grounds, you are entitled to raise an objection to such on our website.
For the purposes of e-mail marketing, we process your personal data upon your consent. If you do not grant your consent and you are our customer, we can send you commercial newsletter even without your consent. In any case, you are entitled to reject such marketing communication simply by (a) adjusting you user profile settings, (b) using our contact form.
If you grant your consent to the personal data processing, you are entitled to withdraw it at any time through our contact form.
Transfer of Personal Data to Third Parties
Your personal data is transferred to third parties in the following cases:
- Delivery of goods: the carrier would not be able to deliver the goods ordered unless we transfer the information on where and to whom the goods should be delivered. This data is transferred to the carrier as entered in the order. Such data includes in particular your first name and surname, delivery address, telephone number where the carrier may contact you, and the amount to be paid on delivery, as the case may be. The carrier is only entitled to process the personal data we transfer for the purposes of delivery; the carrier must delete the personal data promptly afterwards.
- Payment Cards: Our company does not possess the details of payment cards used by you. The details of your payment cards are only available to the secure payment gateway and the relevant bank. When you pay by payment card from a mobile phone, you will be redirected to the secure payment gateway server. When you pay by payment card from a computer, iframe is used for interaction with the payment gateway server (the payment gateway site is displayed on our website and redirecting is not necessary). Thus, your card details are not sent to our company but directly to the payment gateway provider via secure transmission. The payment gateway transfers the data to the relevant bank for the payment to be effected, again via secure transmission.
- Public Authorities: in the event that we enforce our rights, your personal data may be transferred to a third party (e.g. an Attorney-at-Law). If we are obliged to transfer your personal data by virtue of law or upon a request by a public authority (e.g. Czech Police), we have to comply.
What Is the Period for Processing Your Personal Data?
We shall process your personal data for the entire duration of the contractual relationship between you and us.
In case your personal data processing is based on consent, your personal data shall be, in general, processed for 7 years or until such consent is withdrawn.
In case you subscribe to commercial communication, your personal data shall be processed for 7 years or until you express your disapproval of such communication. You can easily express your disapproval by adjusting your user profile settings, using our contact form.
Please note that the personal data necessary for the due rendering of services or for the fulfillment of all our duties, ensuing either from the contract between us or from generally binding legal regulations have to be processed regardless of whether you granted your consent for the period set out in the relevant legal regulations and in compliance therewith (e.g. tax documents must be processed for at least 10 years).
The data obtained through the user account or in a similar way are processed for the period of using our services and then usually for 5 years after cancellation. Basic identification data and the information why the user account was cancelled or information which is a part of operational advance deposits are usually stored for the relevant period.
Personal Data Security
Your personal data is safe with us. We have adopted adequate technical and organizational measures in order to prevent unauthorized access and misuse of your personal data.
At Okusaro we are concerned about the protection of your personal data. Therefore we regularly check and improve our security. All communication between your device and our web servers is encrypted. Logins are hashed and your data is only stored on servers in secure data centers with limited, carefully controlled and audited access.
We try to use such safety measures that provide sufficient security based on state-of-the-art technology. The safety measures adopted are regularly updated.
Personal Data of Children Younger Than 16 Years of Age
Our on-line store is not intended for children under 16. A person under 16 is allowed to use our on-line store only upon consent of his or her parent or guardian.
What Are Your Rights Related to Personal Data Protection?
In relation to your personal data, you have in particular the right to withdraw your consent to the processing of your personal data at any time, the right to correct or supplement your personal data, the right to request restriction of processing, the right to raise an objection to or a complaint of the processing of your personal data, the right to access your personal data, the right to request the transfer of your personal data, the right to be informed of a breach of security of your personal data and, under certain conditions, the right to the deletion of certain personal data we process about you ("the right to be forgotten").
Changes and Amendments
You control your personal data mainly through your user account. Here you can delete or change the basic information about yourself and change the settings concerning commercial communication (or unsubscribe), etc. You can also contact us through e-mail.
In case you believe that your personal data has been processed incorrectly, you can contact us through e-mail. However, it will be faster and more efficient for you to correct the personal data by yourself in your user profile.
Pursuant to the amendment to Act No. 235/2004 Coll., On Value Added Tax, it is not possible to change data in an already issued invoice as of 1 January 2013. The invoice details can only be changed if you have not yet received and paid for the goods.
You can ask us to send you an overview of your personal data. Please contact us using e-mail.
You also have the right to access the following information concerning your personal data:
- What are the purposes of processing your personal information
- What are the categories of the affected personal data
- Who is the recipient of your personal data, besides you
- What is the planned period of storage of your personal data
Whether you have the right to claim the correction or deletion, restriction of personal data processing or to raise an objection to such processing Information on the source of the personal data in case we did not obtain them from you.
You may also claim the deletion of your personal data (this shall not apply to data in documents that are subject to the obligation of archiving under the law (e.g. invoices or credit notes). In case we need your personal data to determine, execute or defend our legal claims, your request may be rejected (e.g. if we have an overdue invoice in your name or if the complaint procedure is in progress).
Please note that the essential details of your payment card are not stored by our company; they are stored at the payment gateway. Therefore, we are not able to delete such data; you have to address the payment gateway which mediated the payment (see section Transfer of personal data to third parties > Payment Cards).
You are entitled to the deletion of data in the following cases:
- The personal data is not needed for the purposes for which it was being processed
- You have withdrawn your consent under which the data was processed and there is no further legal grounds for being processed
- You have objected to the processing of personal data and you believe that after assessing your objection, it will become clear that your interest in the particular situation prevails over ours
- The personal data has been processed unlawfully
- The deletion obligation is stipulated by a special legal regulation
- The personal data concerns a person under 16
How to exercise your right to deletion? Please contact us.
Raising an Objection
Certain personal data is processed on the grounds of our legitimate interest (see section “Legal grounds for processing of personal data”). In case you have concrete reasons, you are entitled to raise an objection to the processing of this personal data.
Restriction of Processing
In case (a) you deny the accuracy of your personal data, (b) your personal data is processed unlawfully, (c) we do not need your personal data for processing purposes, but it is needed to determine, execute or defend your legal claims, or (d) you raised an objection under the preceding paragraph, you shall be entitled to us restricting the processing of your personal data.
In such cases, we may process your personal data only upon your consent (except for the storage or backup of the personal data concerned).
Lodging a Complaint
If you believe that your personal data has been processed unlawfully, you are entitled to lodge a complaint at the Office for Personal Data Protection. However, we will appreciate if you address us first and we can try to resolve your concerns. You can always easily contact us through e-mail.