PRIVACY POLICY

Last update: 12.5.2025.

I. Basic Provisions

The controller of personal data pursuant to Article 4(7) of Regulation (EU) 2016/679 of The European Parliament and of The Council of the European Union (General Data Protection Regulation – "GDPR") is Ivana Mentlova s.r.o., Company ID: CZ02999536, with its registered office at Korunní 810/104, 101 00, Praha 10 - Vinohrady (hereinafter referred to as the “Controller”).

Contact details of the Controller:
address: Korunní 810/104, 101 00, Praha 10 - Vinohrady
e-mail: info@ivanamentlova.com

Personal data means any information relating to an identified or identifiable natural person. An identifiable person is someone who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, ID number, location data, an online identifier, or one or more factors specific to physical, physiological, genetic, mental, economic, cultural, or social identity.

The Controller has not appointed a data protection officer.

II. Sources and Categories of Personal Data Processed

The Controller processes:

  • personal data you provide (e.g. via contact or order forms or via newsletter subscription),
  • personal data collected during contract execution or website usage.

The data categories include:

  • identification and contact details (name, email, phone number, address),
  • data necessary for contract performance,
  • technical data (e.g. IP address, cookies, behavioral data on the website).

III. Legal Basis and Purpose of Processing Personal Data

The legal bases for processing your personal data are:

  • contract performance under Article 6(1)(b) of the GDPR,
  • the legitimate interest of the Controller in direct marketing under Article 6(1)(f) GDPR,
  • your consent for marketing purposes under Article 6(1)(a) GDPR in conjunction with Section 7(2) of Act No. 480/2004 Coll., on certain information society services, if no order has been placed.

Purposes of data processing:

  • processing your order, delivering goods, issuing invoices, and fulfilling related contractual obligations, when placing an order, personal data is required that is necessary for the successful processing of the order (name and address, contact), the provision of personal data is a necessary requirement for the conclusion and performance of the contract, without the provision of personal data, it is not possible to conclude the contract or for the controller to perform it,
  • sending commercial communications and conducting marketing activities (e.g. newsletters, product updates),
  • analyzing and improving the website and user experience.

The Controller does not carry out automated individual decision-making within the meaning of Article 22 of the GDPR.

IV. Data Retention Period

  • The Controller retains personal data:
    • for the duration of the contractual relationship and for 15 years following its termination for legal claim purposes,
    • for the duration of consent to personal data processing for marketing purposes, up to a maximum of 15 years.
  • After the retention period expires, the Controller will securely delete the data.

V. Data Recipients (Subcontractors)

Personal data may be shared with:

  • service providers involved in delivery, payment processing, or order execution,
  • IT service providers ensuring website operation and maintenance, hosting or cloud providers
  • marketing service providers (e.g. email platforms, CRM tools).

The Controller does not intend to transfer personal data to third countries (outside the EU) or to international organizations unless such providers (e.g. cloud or mailing services) meet GDPR adequacy or safeguard requirements.

VI. Your Rights

Under the GDPR, you have the following rights:

  • the right to access your personal data under Article 15 GDPR,
  • the right to rectification under Article 16 GDPR,
  • the right to erasure ("right to be forgotten") under Article 17 GDPR,
  • the right to restriction of processing under Article 18 GDPR,
  • the right to object to processing under Article 21 GDPR,
  • the right to data portability under Article 20 GDPR,
  • the right to withdraw your consent at any time by contacting the Controller in writing or electronically.

You also have the right to lodge a complaint with the Czech Data Protection Authority (www.uoou.cz) if you believe your rights under data protection law have been violated.

VII. Data Security Measures

The Controller declares that:

  • all appropriate technical and organizational measures have been taken to protect personal data (e.g. antivirus protection, password-protected systems),
  • appropriate technical measures to secure data storage and personal data storage in paper form, in particular anti-virus programs, password protection etc.
  • only authorized personnel have access to personal data, and all such individuals are bound by confidentiality.

VIII. Final Provisions

By submitting an order or giving your consent via the website, you confirm that you have read and accept this Privacy Policy in its entirety. You agree to these Privacy Policy by checking the consent box via the online form. By checking the consent box, you confirm that you are familiar with the Privacy Policy and that you accept it in its entirety.

The Controller reserves the right to amend this Privacy Policy. Any updated version will be published on the website and, where applicable, sent to your email address.

 

This Privacy Policy will take effect on May 12, 2025.