Privacy Policy

GDPR

I. Basic Provisions

The data controller pursuant to Article 4, Paragraph 7 of Regulation (EU) 2016/679 of the European Parliament and Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data (hereinafter: “GDPR”) is BIGGEST s.r.o., ID No. 26080630, with its registered office at Borská 1232/40A, Skvrňany, 301 00 Plzeň (hereinafter: “controller”).

Controller Contact Details:

  • Address: Borská 1232/40A, Skvrňany, 301 00 Plzeň
  • Email: info@villafitz.cz
  • Phone: 377 555 028

Personal data refers to all information about an identified or identifiable natural person; an identifiable natural person is one who can be directly or indirectly identified, particularly by reference to an identifier, such as a name, identification number, location data, network identifier, or one or more specific elements of the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.

The controller has not appointed a Data Protection Officer.

II. Sources and Categories of Processed Personal Data

The controller processes personal data that you have provided or personal data obtained based on the fulfillment of your order.

The controller processes your identification and contact details and data necessary for contract fulfillment.

III. Legal Basis and Purpose of Data Processing

The legal basis for processing personal data is:

  • Fulfillment of a contract between you and the controller pursuant to Article 6(1)(b) GDPR,
  • The controller’s legitimate interest in providing direct marketing (including sending business communications and newsletters) pursuant to Article 6(1)(f) GDPR,
  • Your consent to process data for direct marketing purposes (including sending business communications and newsletters) pursuant to Article 6(1)(a) GDPR in conjunction with Section 7(2) of Act No. 480/2004 Coll., on certain services of the information society, if no goods or services have been ordered.

The purpose of processing personal data is:

  • Handling your order and performing rights and obligations arising from the contractual relationship between you and the controller; personal data required for the successful processing of orders (name, address, contact) must be provided as it is necessary for contract conclusion and performance. Without providing personal data, the contract cannot be concluded or performed by the controller,
  • Sending business communications and conducting other marketing activities.

The controller does not engage in automated individual decision-making within the meaning of Article 22 GDPR. Such processing is only performed with your explicit consent.

IV. Data Retention Period

The controller retains personal data:

  • For the period necessary to fulfill the rights and obligations arising from the contractual relationship between you and the controller and to assert claims from these contractual relationships (for 15 years from the end of the contractual relationship).
  • Until consent for processing personal data for marketing purposes is withdrawn, up to a maximum of 3 years if the personal data is processed based on consent.

After the retention period, the controller will delete personal data.

V. Recipients of Personal Data (Subcontractors of the Controller)

Recipients of personal data are:

  • Parties involved in delivering goods/services/processing payments based on the contract,
  • Parties involved in ensuring service operation,
  • Providers of marketing services.

The controller does not intend to transfer personal data to third countries (countries outside the EU) or international organizations. Recipients of personal data in third countries include providers of mailing and cloud services.

VI. Your Rights

Under GDPR, you have:

  • The right to access your personal data pursuant to Article 15 GDPR,
  • The right to correct personal data pursuant to Article 16 GDPR, or restrict processing pursuant to Article 18 GDPR,
  • The right to erasure of personal data pursuant to Article 17 GDPR,
  • The right to object to processing pursuant to Article 21 GDPR,
  • The right to data portability pursuant to Article 20 GDPR.

You have the right to withdraw consent for processing in writing or electronically to the address or email of the controller listed in Article III of these terms.

You also have the right to file a complaint with the Office for Personal Data Protection if you believe your data protection rights have been violated.

VII. Data Security Conditions

The controller declares that it has adopted all appropriate technical and organizational measures to secure personal data. Technical measures have been taken to secure data storage and physical storage of personal data. The controller declares that only authorized persons have access to personal data.

VIII. Final Provisions

By submitting an order via the online order form, you confirm that you are familiar with and accept the terms of personal data protection in full. You consent to these terms by checking the consent box on the online form. By checking the consent box, you confirm that you are familiar with and accept the terms of personal data protection in full.

The controller is entitled to change these terms. The new version of the personal data protection terms will be published on its website or sent to you via email.

These terms are effective as of August 14, 2024.