Add your deal, information or promotional text

privacy policy

1. INTRODUCTORY INFORMATION 

2. DATA CONTROLLER AND CONTACTS 

3. PROCESSING OF PERSONAL DATA WHEN BROWSING THE WEBSITE 

4. FORGOTTEN BASKET 

5. PROCESSING OF PERSONAL DATA WHEN MAKING A PURCHASE ON THE E-SHOP 

6. PROCESSING OF PERSONAL DATA WHEN SENDING NEWSLETTERS TO EXISTING CUSTOMERS 

7. PROCESSING OF PERSONAL DATA WHEN SENDING NEWSLETTERS BASED ON CONSENT, QUIZ, OR SURVEY SUBMISSION 

8. PROCESSING OF PERSONAL DATA WHEN USING CONTACTS ON THE WEBSITE 

9. PROCESSING OF PERSONAL DATA FOR COMPLIANCE WITH LEGAL OBLIGATIONS 

10. PROCESSING OF PERSONAL DATA FOR THE PROTECTION OF THE CONTROLLER'S RIGHTS AND DEFENSE AGAINST CLAIMS 

11. INFORMATION ABOUT THE RIGHTS OF DATA SUBJECTS 

12. SECURITY 

13. PROCEDURE FOR EXERCISING RIGHTS, FILING COMPLAINTS 

14. FINAL PROVISIONS 

 

  

1. Introductory Information 

1.1. This document, the Statement on the Processing of Personal Data (“Information”), serves to provide all necessary information regarding the processing of personal data on the website and e-shop https://aniball.eu/ ("website").   

1.2. By browsing the website and, if applicable, by providing consent that refers to this Information, you declare that you have read, understood, and agree with the Information. 

1.3. The company processes personal data in accordance with applicable legal regulations, particularly in accordance with the European Parliament and Council Regulation No. 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“GDPR”). 

  

2. Data Controller and Contacts 

  

2.1. The data controller is RR Medical s.r.o., with its registered office at Jihlavská 671/7, 664 41 Troubsko, ID: 01999541, registered in the Commercial Register maintained by the Regional Court in Brno, Section C, Insert 79982 (hereinafter referred to as the "Controller" or "Company"). 

  

2.2. Contact details of the Controller: 

2.2.1. Address for correspondence: RR Medical s.r.o., 664 41 Popůvky, Vintrovna 478/5b; 

2.2.2. E-mail address: hello@aniball.eu;

2.2.3. Telephone: +420 734 751 794. 

2.3. The person responsible for handling requests regarding the processing of personal data: info@aniball.cz. 

  

3. Processing of Personal Data When Browsing the Website 

  

3.1. Personal data is not processed when browsing the website. 

3.2. Information about cookies and similar technologies is available here. 

   

4. Forgotten Basket 

4.1. Purposes for processing personal data: If you provide us with your email and consent, we enable the forgotten basket feature to facilitate the completion of a purchase. If the purchase is not completed, a reminder to finish the purchase will be sent twice by email. 

4.2. Legal basis for processing: Consent is voluntarily given by entering your email without submitting the order. Providing your email is voluntary, but without it, this feature cannot be used. 

4.3. Categories of personal data concerned: email, information about the items in the basket. 

4.4. Recipients/categories of recipients: only contractually authorized processors from the categories of: technical solution providers, cloud services, IT services, shipping companies, auditors, legal services, accounting services.  

4.5. Retention period for personal data: 2 calendar days. 

4.6. Source of personal data: the subject. 

  

5. Processing of Personal Data When Making a Purchase on the E-shop 

5.1. Purposes for processing personal data: If an order is placed or a contract is concluded, it is necessary to retain personal data for the purpose of fulfilling the contract, including processing the order, control, delivery, handling complaints or claims, and other related tasks. 

5.2. Legal basis for processing: Contract performance, without which the order cannot be processed.  

5.3. Categories of personal data concerned: identification data, contact details, information about the ordered goods, date and time of the order, and other contract-related information and communication.   

5.4. Recipients/categories of recipients: only contractually authorized processors from the categories of: technical solution providers, cloud services, IT services, shipping companies, auditors, legal services, accounting services. 

5.5. Transfer outside the EU: Service providers like Google Ireland Limited, Shopify International Limited, where data may be transferred to the USA based on standard contractual clauses. Use of express checkout services requires registration with the service provider, who is an independent data controller responsible for personal data processing.  

5.6. Retention period for personal data: during the contract term and two years after for handling claims and other obligations. 

5.7. Source of personal data: the subject. 

    

6. Processing of Personal Data When Sending Newsletters to Existing Customers 

6.1. Purposes for processing personal data: If you purchase from the e-shop, we will regularly send you tailored offers of similar products electronically or by post, based on your previous purchases and interests. We also monitor newsletter openings and clicks on relevant links for effectiveness. 

 6.2. Legal basis for processing: Legitimate interest, against which objections may be raised. 

 6.3. Categories of personal data concerned: identification and contact data, purchase details. 

 6.4. Recipients/categories of recipients: only contractually authorized processors from the categories of: technical solution providers, cloud services, IT services, shipping companies, auditors, legal services, accounting services. 

 6.5. Transfer outside the EU: Email service provider Klaviyo, Inc., USA, with protection ensured through standard contractual clauses. 

 6.6. Retention period for personal data: indefinitely, until a request to stop receiving commercial communications is made. 

 6.7. Source of personal data: the subject.   

7. Processing of Personal Data When Sending Newsletters Based on Consent, Quiz, or Survey Submission 

7.1. Purposes for processing personal data: With your consent, we will regularly send you tailored offers of our products, information about our activities, and interesting offers from cooperating companies, based on your activities on the e-shop and website, and possibly your previous purchases. 

7.2. Legal basis for processing: Legitimate interest, against which objections may be raised. 

 7.3. Categories of personal data concerned: identification and contact data, purchase details, answers provided in quizzes or surveys. 

7.4. Recipients/categories of recipients: contractually authorized processors such as technical solution providers, cloud services, IT services, shipping companies, auditors, legal services, accounting services. The survey provider is Typeform, Spain, with protection ensured through standard contractual clauses. 

 7.5. Retention period for personal data: indefinitely, until a request to stop receiving commercial communications is made. 

 7.6. Source of personal data: the subject.  

8. Processing of Personal Data When Using Contacts on the Website 

 8.1. Purposes for processing personal data: If you contact us through the contact form or published contact details (by phone, email, or post), we will process your personal data for the purpose of responding to your query/request. 

 8.2. Legal basis for processing: Consent expressed by sending the relevant request/letter or other message. Consent is voluntary and can be withdrawn at any time. 

 8.3. Categories of personal data concerned: identification data, contact details (email), subject and content of the query/request, date of submission, and, in the case of electronic communication, IP address and exact time. 

 8.4. Recipients/categories of recipients: contractually authorized processors such as technical solution providers, cloud services, IT services, shipping companies, auditors, legal services, accounting services. 

 8.5. Retention period for personal data: Data will be stored for the duration of the related communication and no longer than 1 year after, for any subsequent related communication. 

 8.6. Source of personal data: the subject. 

9. Processing of Personal Data for Compliance with Legal Obligations 

9.1. Purposes for processing personal data: If the Controller is required by law to retain specific documents, they do so for the purpose set by the law. Examples include the retention of accounting and tax documents. 

 9.2. Legal basis for processing: Compliance with legal obligations. 

 9.3. Categories of personal data concerned: Only the data or documents required by the relevant law. 

 9.4. Recipients/categories of recipients: contractually authorized processors such as technical solution providers, cloud services, IT services, shipping companies, auditors, legal services, accounting services. 

 9.5. Retention period for personal data: The Controller retains such data only for the period specified by the applicable law. 

 9.6. Source of personal data: the subject. 

 10. Processing of Personal Data for the Protection of the Controller's Rights and Defense Against Claims 

 10.1. Purposes for processing personal data: The Controller collects limited personal data and documents after processing to protect its rights, defend against claims, and in legal/administrative proceedings. 

10.2. Legal basis for processing: The Controller's legitimate interest in protecting its rights and demonstrating compliance. You have the right to object to this legitimate interest at any time. 

 10.3. Categories of personal data concerned: Documents proving legal actions, such as consents, logs, and requests for rights exercise. 

 10.4. Recipients/categories of recipients: contractually authorized processors such as technical solution providers, cloud services, IT services, shipping companies, auditors, legal services, accounting services. 

 10.5. Retention period for personal data:** The Controller retains such collected data for 3 years after the processing period determined by other purposes outlined in this Information. The retention period will not end sooner than the commencement of legal or other proceedings and related deadlines for legal remedies. 

 10.6. Source of personal data: the subject. 

11. Information on the rights of data subjects 

11.1. The Controller hereby informs the Data Subjects about the basic principles and guidelines in accordance with Article 13 and subsequent GDPR provisions, based on which the Company, as the Controller of personal data, handles the personal data of the Data Subject. 

11.2. The Data Subject has the right to obtain confirmation from the Controller as to whether or not personal data concerning them is being processed, and if so, has the right to access the personal data. 

 11.3. The Data Subject has the right to have the Controller promptly correct inaccurate personal data, or, taking into account the purposes of the processing, the Data Subject has the right to have incomplete personal data completed, including by providing a supplementary statement. 

 11.4. The Data Subject has the right to have the Controller erase personal data if the personal data is no longer necessary for the purpose of processing, the Data Subject has withdrawn their consent for its processing, has objected to the processing of personal data, and there are no overriding legitimate grounds for the processing. 

 11.5. The Data Subject has the right to have the Controller restrict the processing if the Data Subject contests the accuracy of the personal data, for a period necessary to verify the accuracy of the personal data; if the Controller no longer needs the personal data for processing purposes, but the Data Subject requires it for the establishment, exercise, or defense of legal claims; or if the Data Subject has objected to the processing of personal data. 

 11.6. The Data Subject has the right to withdraw consent to the processing of personal data at any time without penalty. The Data Subject may withdraw consent by any means listed above in the Controller's contact details. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal. 

 11.7. The Data Subject has the right to receive personal data relating to them that they have provided to the Controller in a structured, commonly used, and machine-readable format, and the right to transmit this data to another controller (right to data portability), without hindrance from the Controller to whom the personal data was provided, if: 

 11.7.1. the processing is based on consent or a contract; and 

 11.7.2. the processing is carried out by automated means. 

 11.8. The Data Subject has the right to lodge a complaint with the relevant supervisory authority if the Data Subject believes that the processing of personal data is in breach of the law. The relevant supervisory authority in the Czech Republic is the Office for Personal Data Protection – www.uoou.cz. 

 11.9. The Data Subject has the right to object to the processing of personal data concerning them if the Controller processes personal data for the following reasons: 

 11.9.1. processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, 

 11.9.2. processing is necessary for the purposes of the legitimate interests pursued by the Controller or a third party, 

 11.9.3. for direct marketing purposes, 

 11.9.4. for scientific or historical research purposes or for statistical purposes. 

 12. Security 

12.1. The Company hereby declares that the handling of personal data is fully compliant with applicable legal regulations. The personal data of the Data Subject is kept secure by the Company through established technical and organizational measures. 

12.2. The personal data of the Data Subject is processed manually or partially automatically by the Company's employees. 

12.3. All personal data in electronic form is stored in databases and systems that are accessible only to individuals who need to handle personal data directly for the purposes specified in these rules, and only to the extent necessary. Access to this personal data is protected by passwords and firewalls.    

13. Procedure for exercising rights, filing complaints 

13.1. You may exercise all rights by contacting the Controller. 

13.2. All your requests will be processed without undue delay, and in justified cases no later than within 30 days. 

 13.3. The contact details of the Controller, which can be used for requests, consent withdrawals, objections, or complaints to the Controller, are provided in Article 2. 

 13.4. You have the right to file a complaint with the Controller, without prejudice to the right to lodge a complaint with a supervisory authority according to Article 10. 

 14. Final Provisions 

 14.1. The processing of personal data of data subjects is governed by the legal framework of the Czech Republic. 

 14.2. The Controller reserves the right to amend the Information if necessary. The change becomes effective on the date of notification or on a later date specified in the notification of the change. Any change does not affect processing already initiated based on previous legal action unless otherwise stated in the notice. In such a case, the data subject has the right to reject the change and request the cessation of personal data processing. 

14.3. This Information is effective as of September 1, 2024. 

Search