Privacy Policy
Informace o zpracování osobních údajů.
I. Introductory Provisions
This document, “Information on the Processing of Personal Data” (hereinafter referred to as the “Processing Information”), has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the GDPR), together with Act No. 110/2019 Coll., on the Processing of Personal Data, and related legislation.
Through this document, SHD Lipno s.r.o. provides information on the processing of personal data to its customers, business and non-business partners, employees, and job applicants whose personal data it processes.
Basic Terms
Personal Data – in particular:
First name and surname, title, company registration number, tax identification number, academic title, residential address, delivery address, telephone number, e-mail address, data box ID, IP address (when visiting the website), bank account number, network, electronic and other identifiers and data by which a data subject is identified or can be identified.
The above list of personal data may not be exhaustive, for example if you provide us with documents containing additional personal data (this mainly concerns personal data that we do not specifically request but process as part of complete documents). We may also process personal data that you provide to us through e-mail, telephone, or personal communication.
Data Controller: SHD Lipno s.r.o., Jindřišská 937/16, 110 00 Praha 1, Company ID No.: 17838266, contact e-mail: info@lipnovista.com.
Data Subject: A natural person whose personal data is processed by the Controller. This includes the Controller’s customers, business and non-business partners, employees, and job applicants.
The Data Controller hereby provides Data Subjects with information regarding the processing of personal data and their rights related to such processing.
The Controller has not appointed a Data Protection Officer.
II. Method of Processing Personal Data
The Controller processes personal data either directly or through processors. The Controller obtains your personal data either from you, from publicly available sources (registers and records), from public authorities, or on the basis of specific legal regulations. Processors process personal data in accordance with the Controller’s instructions and ensure the same level of protection as the Controller.
We process personal data both in paper form and by electronic means. In both cases, we adhere to the principles of secure personal data processing. As part of personal data protection, we have implemented technical and organizational measures designed to protect processed personal data and prevent unauthorized access, damage, loss, destruction, unauthorized processing, and other forms of misuse.
The Controller retains personal data for the period necessary to exercise the rights and obligations arising from the contractual relationship between you and the Controller and for the enforcement of claims arising from such contractual relationships, for the duration of the Controller’s legitimate interest, or until consent to the processing of personal data is withdrawn where processing is based on consent. Upon expiration of the retention period, the Controller shall delete the personal data.
III. Legal Basis and Purpose of Personal Data Processing
The Controller processes your personal data solely for the purposes of entering into and performing contractual relationships between you and the Controller, or for taking steps prior to entering into a contract. The provision of personal data is a necessary requirement for the conclusion and performance of a contract; without the provision of personal data, it is not possible to conclude or perform the contract. The Controller also processes your personal data for the purpose of complying with legal obligations arising in particular from regulations governing taxation, accounting, and employment relationships, as well as for maintaining a contact database, sending commercial communications, and carrying out other marketing activities.
The legal basis for the processing of personal data is:
- Performance of a contract between you and the Controller.
- The Controller’s legitimate interest in the proper operation of the company and related activities, as well as its business and marketing activities.
- Compliance with legal obligations – for example, in connection with employment regulations, accounting requirements, etc.
- Your consent, for the purposes specified in the relevant consent to the processing of personal data.
IV. Additional Information
- You acknowledge that the processing of personal data by the Controller begins or has begun at the moment personal data is provided to the Controller.
- You acknowledge that personal data will continue to be processed and retained to the extent necessary even after the termination of processing based on the current legal basis (e.g. a contractual relationship, withdrawal of consent, etc.), if required by law or where further processing is in the legitimate interest of the Controller. Such subsequent processing will continue for the period necessary with regard to potential inspections and the enforcement of rights before competent courts. Data is always retained at least for the duration of the applicable limitation period, extended by one year to ensure adequate protection of the Controller’s interests, and, where applicable, for the duration of judicial or administrative proceedings concerning the Controller’s rights or obligations. Special retention and disposal periods arising from legal regulations also apply.
- You have provided accurate and truthful information.
- Your personal data will not be transferred to third countries or international organizations, except where required by law or where you have been informed of such transfer.
- No automated decision-making or automated profiling takes place in the processing of personal data.
- Recipients of your personal data may include:
- Persons involved in the delivery of goods, provision of services, or processing of payments under a contract.
- Persons who, in accordance with our instructions as the Controller (personal data processors), provide technical and organizational services, including software operation, data storage, accounting, tax, and related services.
- Persons providing marketing services.
- In exceptional cases, external auditors, tax advisors, legal representatives, or other persons where necessary for the recovery or accounting of receivables or for the protection of our legitimate interests.
V. Rights Related to the Processing of Personal Data
- If the processing of personal data is based on your consent, you have the right to withdraw your consent to the processing of personal data. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. Withdrawal of consent also does not affect the processing of personal data based on any other legal basis.
- Under the conditions set out in the GDPR, you also have the right to:
- Be informed about the processing of your personal data and request detailed information regarding the nature and scope of such processing.
- Request access to your personal data from the Data Controller.
- Request correction of the personal data provided.
- Request the erasure of personal data provided – requests are assessed with regard to the legal basis for the processing of personal data.
- Request restriction of the processing of personal data.
- Request the transfer of your personal data to another controller.
- Lodge a complaint with the Office for Personal Data Protection at Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, website: https://www.uoou.cz/.
- You may also object to the processing of your personal data. If the Data Controller does not comply with your objection, you have the right to contact the Office for Personal Data Protection directly. This provision does not affect your right to contact the Office for Personal Data Protection directly with your complaint.
- Your requests will be handled without undue delay and no later than 30 days from the date the request is submitted.
- The Data Controller is entitled, in the case of manifestly unfounded or repetitive requests, to charge a reasonable fee reflecting administrative costs or to refuse to comply with such requests.
VI. Final Provisions
- All legal relationships arising in connection with the processing of personal data shall be governed by the laws of the Czech Republic and the relevant provisions of the GDPR.
- The Data Controller may amend or supplement this document at any time. The current version is available on the Controller’s website.
- These Information on the Processing of Personal Data shall become effective as of 1 June 2026.