Privacy Policy 🛡️

1. Basic Information

1.1. Document Content

These personal data processing principles describe how we process the personal data of visitors, e-shop customers, and other individuals. You will learn here in particular what personal data we process, why and on what basis we do so, to whom we disclose it, and also what rights you have in connection with its processing. All personal data processing takes place in accordance with the European Union's General Data Protection Regulation No. 2016/679, commonly referred to as the GDPR.

1.2. Our Position

All the described personal data processing activities are carried out in the position of data controller by the entrepreneur Jiří Martinec, with registered office at Karla Hynka Máchy 736/7, 500 02 Hradec Králové 2, Czech Republic, ID No. 10725652, registered in the Trade Register, non-VAT payer (for greater clarity, hereinafter referred to as "we" or "us"). This means that we determine the purposes described below for which your personal data is collected, determine the means of processing, and are responsible for its proper execution.

1.3. Scope of Personal Data Processing

The personal data we process includes:

1.3.1. identification data (especially name and surname or identification number and tax identification number in the case of entrepreneurs),

1.3.2. contact details (especially address, email address, and phone number),

1.3.3. order and transaction data (especially ordered goods and services, selected payment and shipping method, and other information related to the order),

1.3.4. data on mutual communication (especially the content and other data associated with communication between us and you),

1.3.5. registration and settings data (especially data related to your user account, if you register with us, and data on the settings of our services),

1.3.6. data on the use of our website (especially IP address, data about your device, data obtained using cookies, or data on what you do on our website).

2. Why and how do we process your personal data?

2.1. Website Functioning

If you visit our website, we process your personal data to ensure its proper functioning based on our legitimate interest consisting in the provision of our services via the internet.

2.2. User Account

Based on the contract, we process your personal data when maintaining user accounts in our e-shop.

2.3. Improving and Developing Our Services

We also process your personal data for the purpose of measuring website traffic and creating statistics and records that serve us for the evaluation and development of our services, based on our legitimate interest consisting in monitoring traffic on the website and in the development and optimization of our services.

2.4. Ascertaining Your Satisfaction

To ascertain your satisfaction with our services, we process your personal data based on our legitimate interest, which consists in obtaining your feedback. For sending questionnaires, evaluating feedback, and analyzing market position, we provide the program operator with information about the purchased goods and your email address. Your personal data is not provided to any third party for their own purposes. In case of your objection, we will not send you the questionnaire further.

2.5. Security and Testing

To protect our websites and all other services against cyber attacks and fraud, and also for testing new functionalities and changes to the websites, we process your personal data based on our legitimate interest consisting in securing and improving our services.

2.6. Protection of Legal Claims and Internal Control

We process your personal data based on our legitimate interests for the purpose of protecting legal claims and our internal records and control.

2.7. Sending Commercial Communications to Customers

If we obtain your electronic contact details in connection with an order or our services, we may also process your personal data for the purpose of further offering our goods and services through commercial communications based on our legitimate interest consisting in our promotion, unless you have refused this sending.

2.8. Sending Commercial Communications Based on Consent

Based on your consent, we process your personal data for the purpose of sending commercial communications.

2.9. Online Advertising

For displaying advertisements tailored to you on our website and third-party websites, we may process data about the use of our website. Depending on the type of advertisement, the basis is either our legitimate interest consisting in our promotion, or in the case of some types of advertisements, it may be consent, if we ask you to grant it and you decide to grant it to us.

2.10. Fulfillment of Our Legal Obligations

We also process your personal data for the purposes and based on the fulfillment of our legal obligations associated especially with providing information to public authorities.

2.11. Performance and Conclusion of Contracts

We process your personal data based on and for the purpose of fulfilling our obligations arising from contracts concluded between us and you and for the conclusion of these contracts. For this purpose, we may also process the personal data of addressees and other recipients of goods and other possible services.

2.12. Customer Support

For handling your requests related to orders, we process your personal data based on the obligation to fulfill contracts concluded between us and you and for the conclusion of these contracts. When handling other possible requests, we process your personal data based on our legitimate interest consisting in the provision of our services and ensuring adequate support.

2.13. Storage Period

We store personal data only for the period strictly necessary to achieve the stated purposes of personal data processing. After the purpose of processing ceases, we promptly destroy the personal data. It generally applies that we store personal data for the duration of the limitation period (standardly 3 years) and one year after its expiration, with regard to possible claims asserted at the end of the limitation period. Beyond the above, the following specific storage periods apply:

2.13.1. We store data related to the user account for the entire duration of the account until its deletion.

2.13.2. In the case of judicial and other proceedings, we process your personal data to the necessary extent for the entire duration of such proceedings and the remaining part of the limitation period after their termination.

2.13.3. For sending commercial communications to customers, we process your personal data until you refuse to receive commercial communications.

2.13.4. For sending commercial communications based on your consent, we process your personal data until you withdraw your previous consent to the processing of personal data.

2.13.5. For the fulfillment of legal obligations, we process personal data for the period necessary to fulfill these obligations.

3. To whom is personal data transferred?

3.1. Processors

For personal data processing, we also use the services of other entities in the position of processors, who process personal data only according to our instructions. These are especially:

3.1.1. providers of IT services and other technology suppliers,

3.1.2. operators of analytical and marketing tools, such as Google Analytics (Google Ireland Limited, privacy policy available at https://policies.google.com/privacy) and Microsoft Clarity (Microsoft Corporation, privacy policy available at https://privacy.microsoft.com), which we use to analyze the use of our website, monitor traffic, create anonymized statistics, and optimize our services,

3.1.3. providers of communication tools,

3.2. Controllers

We may disclose your personal data to other entities in the position of controllers:

3.2.1. our suppliers involved in the performance of the contract, especially carriers and payment system operators,

3.2.2. operators of advertising systems and social networks.

3.3. Transfer outside the EU

In some cases, your personal data may be transferred outside the European Economic Area, either on the basis of an adequacy decision according to Art. 45 of the GDPR, appropriate safeguards according to Art. 46 of the GDPR, or an exemption according to Art. 49 of the GDPR.

4. Your Rights

4.1. Rights of the Personal Data Subject

Regarding your personal data, you have the right to:

4.1.1. request the correction of inaccurate or outdated personal data, so if you find that the personal data we process about you is inaccurate or incomplete, you have the right to have us correct or supplement it without undue delay,

4.1.2. request confirmation of whether processing is taking place, and if so, information regarding this processing to the extent stipulated in Art. 15 of the GDPR, and also a copy of the processed data (we are entitled to charge a fee determined to cover the necessary costs for further copies),

4.1.3. in some cases, you have the right to have us erase your personal data. We will erase your personal data without undue delay if we no longer need it for the purposes for which we processed it, or you exercise your right to object to the processing and we find that we no longer have any such legitimate interests justifying this processing, or it turns out that our processing of personal data has ceased to comply with generally binding regulations. This right, however, does not apply if the processing of your personal data is still necessary for the fulfillment of our legal obligation, archiving purposes, scientific or historical research, or for statistical purposes, or for the establishment, exercise, or defense of our legal claims.

4.1.4. exercise the right to restrict the processing of personal data. This right allows you to request in certain cases that your personal data be marked and these data not be subject to any further processing operations – but in this case not forever (as in the case of the right to erasure), but for a limited period. We must restrict the processing of personal data when you contest the accuracy of the personal data, until we agree on which data is correct, or when we process your personal data without a sufficient legal basis (e.g., beyond what we must process), but you prefer only their restriction before erasure (e.g., if you expect that you would provide us with such data again in the future anyway), or we no longer need the personal data for the above-mentioned processing purposes, but you require them for the establishment, exercise, or defense of your legal claims, or you object to the processing and we are obliged to restrict the processing of your personal data for the period during which we investigate whether your objection is justified.

4.1.5. request the portability of personal data in cases of processing based on your consent or based on a contract,

4.1.6. object to the processing of personal data that takes place on the basis of our legitimate interest. We will stop processing your personal data unless we have serious legitimate reasons to continue such processing. In case of objection to marketing activities, we will stop these activities in any case,

4.1.7. express your disagreement with the processing of your personal data for the purpose of sending commercial communications at any time, just as you can withdraw your previous consent to the processing of personal data for another purpose at any time, unless the processing is for the purpose of fulfilling our obligations arising from contracts, for the purpose of fulfilling our legal obligations, or for another purpose arising from our legitimate interests.

4.2. Method of Exercising Rights

You can exercise your rights in one of the following ways:

4.2.1. by email to contact@mattcha.store.

4.3. Right to Lodge a Complaint with a Supervisory Authority

In the event that you become convinced that the GDPR has been violated on our part during the processing of your personal data, you have the right to lodge a complaint with the Office for Personal Data Protection, which is located at Pplk. Sochora 27, 170 00 Prague 7 (http://www.uoou.cz).

5. Cookies

5.1. Files Stored on Your Device for Later Access (Temporary Files)

Our websites may use cookie technology (and possibly other technologies based on a similar principle, such as Web Storage). This means that we store small data files in a dedicated area of your device's memory that allow us to provide and further improve the service for you. For simplicity, we will hereinafter refer to all these technologies only as "cookies".

5.2. Cookies Necessary for Service Provision

Some cookies are technologically necessary for the provision of the service. This means that their storage cannot be avoided while maintaining the functionality of the service. These include especially cookies for:

5.2.1. storing your choices in connection with the order,

5.2.2. storing website settings,

5.2.3. logging in to the user account,

5.2.4. ensuring IT security.

5.3. Other Types of Cookies

We use some cookies so that we can provide you with a better quality service that is more tailored to your preferences. As part of this, we may store cookies on your device:

5.3.1. for ensuring the analysis of traffic and use of the website, including third-party cookies such as Google Analytics or Microsoft Clarity; these cookies help us understand how you interact with the page (e.g., which parts are most visited, how you navigate the page) and we use the data to identify areas that need improvement,

5.3.2. for advertising purposes to display customized advertising on our and other websites, including third-party cookies,

5.3.3. ensuring connection to social networks, including third-party cookies,

5.3.4. for customizing our website to you; these cookies store details of your actions to tailor your next visit to the site,

5.3.5. for determining your geographical location.

5.4. Cookie Storage Settings

You can set your cookie preferences through the settings available on our website at https://mattcha.store/#_cookies. Within the relevant options of your device, you can set the use of cookies on our website, for example, by blocking cookies if you do not agree with their use on our website. If you use this option, you acknowledge that some parts of the service may not function correctly.

6. Shopify

6.1. Services

We operate the store and website, including all related information, content, features, tools, products, and services, to provide you, the customers, with a tailored shopping experience (hereinafter referred to as the "Services"). We use the Shopify platform (hereinafter referred to as "Shopify") which allows us to provide the Services to you.

6.2. Relationship with Shopify

The Services are hosted by Shopify, which collects and processes personal data about your access and use of the Services to provide and improve the Services for you. The information you provide to the Services will be transferred to and shared with Shopify and third parties, who may be located in countries other than where you reside, for the purpose of providing and improving the Services for you. In addition, to protect, develop, and improve our business, we use certain enhanced features of Shopify that involve data and information derived from your interactions with our store, together with other merchants and with Shopify. To provide these enhanced features, Shopify may use personal data collected about your interactions with our store, other merchants, and Shopify. In these circumstances, Shopify is responsible for the processing of your personal data, including responding to your requests to exercise your rights regarding the use of your personal data for these purposes. To learn more about how Shopify uses your personal data and your potential rights, you can visit the Shopify Consumer Privacy Policy. Depending on where you live, you may exercise certain rights regarding your personal data here. Link to the Shopify Privacy Portal.