Privacy Policy
Personal Data Protection (GDPR)
Because we value your trust, our goal at GET Fashion s.r.o. is to protect your data and privacy. We want you to be absolutely sure that we handle your personal data not only in accordance with our obligations under privacy legislation, but also with due care and moral responsibility. We use the data generated by the use of our online shop in order to improve our services and to provide high quality service.
The data controller is:
Get Fashion s.r.o.
Roztylska 1860/1
Prague 14800
Comp. Reg. No. (IC): 05863198
VAT ID: CZ05863198
Purpose of the Processing:
- order processing
- complaint processing
- answering questions
- targeted offer of goods and services
- marketing events
Personal Data Recipients:
We protect your personal data carefully and use quality third-party tools in order to provide you with the best service. These tools process some of your data, but we always ensure that any service we work with also complies with all the terms and conditions and is GDPR compliant.
Our website also uses the Google Analytics service, which records visitor behaviour.
US |
Behaviour and traffic analysis, online advertising |
|
US |
Behaviour and traffic analysis, online advertising, customer support |
|
CZ |
On-line advertising |
|
CZ |
Marketing |
|
Leadhub |
CZ |
E-mail marketing |
Česká pošta |
CZ |
Delivery of orders |
GLS |
CZ |
Delivery of orders |
CZ |
Online payment gateway |
|
Zásilkovna |
CZ |
Delivery of orders |
DPD |
CZ |
Delivery of orders |
US |
Newsletter registration |
Privacy Policy
I.
Basic Provisions
- The personal data controller pursuant to Article 4, point 7 of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as "GDPR") is Get Fashion s.r.o., Comp. Reg. No. (IČ) 05863198, with its registered office at Roztylská 1860/1, Prague 14800 (hereinafter referred to as the "Controller").
- The contact details of the Controller are as follows
email: support@donlemme.com
- Personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, a network identifier or to one or more specific elements of the physical, physiological, genetic, mental, economic, cultural or social identity of such natural person.
- The Controller has not appointed any personal data protection officer.
II.
Sources and Categories of the Personal Data Processed
- The Controller processes personal data that you have provided to the Controller or personal data that the Controller has obtained on the basis of the fulfilment of your order.
- The Controller processes your identification and contact data and the data necessary for the performance of the agreement.
III.
Lawful Reason and Purpose of the Personal Data Processing.
- The lawful reason for the personal data processing is
- performance of the agreement between you and the Controller pursuant to Article 6(1)(b) of the GDPR,
- the legitimate interest of the Controller for the provision of direct marketing (in particular for sending commercial communications and newsletters) pursuant to Article 6(1)(f) of the GDPR,
- your consent to processing for the purposes of providing direct marketing (in particular for sending commercial communications and newsletters) pursuant to Article 6(1)(a) of the GDPR in conjunction with Section 7(2) of Act No. 480/2004 Sb., on certain information company services in the absence of an order for goods or services.
- The Purpose of the Personal Data Processing
- processing your order and exercising the rights and obligations arising from the contractual relationship between you and the Controller; when placing an order, it is required to provide personal data necessary for the successful processing of the order (name and address, contact); the provision of personal data is a necessary requirement for the conclusion and performance of the agreement; without the provision of personal data, it is not possible for the Controller to conclude or perform the agreement,
- sending commercial communications and other marketing activities.
- Automatic individual decision-making within the meaning of Article 22 of the GDPR takes place on the part of the Controller. You have given your explicit consent to such processing.
IV.
Data Retention Period
- The Controller shall retain the personal data:
- for the period necessary for the exercise of the rights and obligations arising from the contractual relationship between you and the Controller and the exercise of claims arising from that contractual relationship (for a period of 15 years from the termination of the contractual relationship).
- for the period until the consent to the processing of the personal data for marketing purposes is withdrawn, but no longer than 10 years if the personal data is processed based on your consent.
- After the expiry of the retention period, the Controller shall delete the personal data.
V.
Recipients of the Personal Data (Controller's Subagreementors)
- The recipients of the personal data are the persons
- involved in the delivery of goods and the execution of payments under the agreement,
- providing e-shop operation services (Shoptet) and other services in connection with the e-shop operation,
- providing marketing and accounting services.
- The Controller intends to transfer the personal data to a third country (non-EU country) or an international organisation. The recipients of the personal data in third countries are providers of mailing services and cloud services
VI.
Your Rights
- Under the terms and conditions set out in the GDPR, you have
- the right of access to your personal data pursuant to Article 15 of the GDPR,
- the right to rectification of your personal data pursuant to Article 16 of the GDPR, or restriction of processing pursuant to Article 18 of the GDPR.
- the right to erasure of personal data pursuant to Article 17 of the GDPR.
- the right to object to processing under Article 21 of the GDPR; and
- the right to data portability under Article 20 of the GDPR.
- the right to withdraw your consent to processing in writing or electronically to the address or email of the Controller set out in Article III hereof.
- You also have the right to file a complaint with the Office for Personal Data Protection if you believe that your right to personal data protection has been violated.
VII.
Personal Data Security Conditions
- The Controller declares that it has taken all appropriate technical and organisational measures to ensure the security of the personal data.
- The Controller has taken technical measures to secure data storage and the storage of personal data in paper form.
- The Controller declares that only persons authorised by it have access to the personal data.
VIII.
Final Provisions
- By submitting an order from the online order form, you confirm that you are aware of the Privacy Policy and that you accept it in its entirety.
- You agree to this Policy by ticking the consent box via the online order form. By checking the consent box, you confirm that you are aware of the Privacy Policy and that you accept it in its entirety.
- The Controller is entitled to change this Policy. It will publish the new version of the Privacy Policy on its website and will also send you the new version of the Privacy Policy to the email address you have provided to the Controller.
This Policy comes into force on 25th May 2018.