Privacy Policy

 

Basic Provisions

The controller of personal data, according to § 5 letter o) of Act No. 18/2018 Coll. on the protection of personal data, as amended (hereinafter referred to as "the Act"), is Protutorly s.r.o., ID:56393644, located at Gelnická 111, 040 11 Košice (hereinafter referred to as "the controller").

For any questions, you can contact us:

  • Via email at help@protutorly.com
  • By phone at +421 907 077 239
  • By regular mail at our address: Protutorly s.r.o., Gelnická 111, 040 11 Košice, Košice, Slovakia.

Personal data refers to any information relating to an identified or identifiable natural person who can be identified directly or indirectly by reference to an identifier such as a name, an identification number, location data, or an online identifier.

You are a data subject because it is your personal data that the controller processes. The controller has not appointed a data protection officer.

Sources and Categories of Processed Personal Data

The controller processes personal data that you have provided, or personal data obtained based on fulfilling your order, primarily specified in:

  • Contracts we have concluded with you
  • Forms you have filled out on the website
  • Data sent or provided during mutual correspondence or communication
  • Data derived from other data you have provided

The controller processes your identification and contact data and data necessary for the fulfillment of the contract or processing the customer's order. We do not process special categories of personal data that are particularly sensitive.

Legal Basis and Purpose of Processing Personal Data

The legal basis for processing personal data is:

  • The fulfillment of the contract between you and the controller according to § 13 para. 1 letter b) of the Act
  • The legitimate interest of the controller in providing direct marketing according to § 13 para. 1 letter f) of the Act
  • Your consent to processing for direct marketing purposes according to § 13 para. 1 letter a) of the Act if no order of goods or services has been placed

The purpose of processing personal data is:

  • Handling your order and performing rights and obligations arising from the contractual relationship between you and the controller. Personal data required for the successful handling of the order (name and address, or other contact) is necessary for the conclusion and fulfillment of the contract. Without providing personal data, it is not possible to conclude the contract or fulfill it.
  • Sending commercial announcements and conducting other marketing activities, especially contacting by mail, email, telephone, and via SMS messages.

The controller engages in automated individual decision-making, including profiling, according to § 28 of the Act. You have given your explicit consent to such processing by using the controller's website (www.protutorly.com) or by clicking on consent on the website.

If the legal basis for processing your personal data is consent, you may revoke it at any time:

  • By email at help@protutorly.com
  • In writing at the address Protutorly s.r.o., Moyzesova 24, 04001 Košice
  • In person
  • Via a link in the message
  • Through the interface of the online contact form you use that allows this functionality

The revocation of consent does not affect the legality of the processing of personal data based on consent before its revocation. In case of revocation of consent, we will stop processing your personal data immediately and delete them.

If the controller processes your personal data on a legal basis other than your consent, the revocation of consent does not terminate their right to process your personal data on other legal grounds.

Duration of Personal Data Retention

The controller retains personal data:

  • For the period necessary to exercise the rights and obligations arising from the contractual relationship between you and the controller and to assert claims from these contractual relationships (for a period of 10 years after the end of the contractual relationship).
  • For the period until consent to the processing of personal data for marketing purposes is revoked, no longer than 10 years if personal data are processed based on consent.

After the retention period expires, the controller will delete the personal data.

Recipients of Personal Data (Subcontractors of the Controller)

Recipients of personal data are persons:

  • Involved in the delivery of goods/services/execution of payments based on the contract
  • Ensuring the operation of the e-shop and other services related to the operation of the e-shop, auditing, accounting, and legal services
  • Ensuring marketing services

The controller intends to transfer personal data to a third country (to a country outside the EU) or to an international organization. Recipients of personal data in third countries are providers of mailing services/cloud services.

Your personal data, which you have provided for marketing purposes, are processed through the MailChimp service operated by The Rocket Science Group, LLC. Additionally, your personal data may be processed through cloud services provided as part of the Office 365 application operated by Microsoft Corporation. All data concerning the fulfillment of the contract and invoicing between the controller and the data subject are processed through the online accounting encrypted cloud solution iKros operated by KROS, a.s.

In addition to the above, recipients of your personal data are our employees who process personal data for the purpose of fulfilling the contract, invoicing, or for marketing purposes.

Your Rights

Under the conditions set forth in the Act, you have:

  • The right to information
  • The right to access your personal data according to § 21 of the Act
  • The right to rectification of personal data according to § 22 of the Act, or restriction of processing according to § 24 of the Act
  • The right to object to automated individual decision-making and profiling
  • The right to erasure of personal data according to § 23 of the Act
  • The right to object to processing according to § 27 of the Act
  • The right to data portability according to § 26 of the Act
  • The right to revoke consent to processing in writing or electronically at the address or email of the controller specified in Article III of these conditions

Furthermore, you have the right to lodge a complaint with the Office for Personal Data Protection if you believe that your right to personal data protection has been violated.

Personal Data Security Conditions

The controller declares that all appropriate technical and organizational measures to secure personal data have been taken. Technical measures include password protection, encryption of data on cloud storage, and protection by antivirus, anti-phishing, and anti-malware programs. Only authorized persons have access to personal data.

Processing of Children's Personal Data

Personal data of children under the age of 16 can be processed only in special and justified cases. If you are under 16 years old and have provided us with consent to process your personal data, it is necessary that this consent be granted and confirmed by your legal representative. We may require your date of birth to verify your age. If we process your personal data on a legal basis other than your consent, we may require confirmation and consent of your legal representative.

Final Provisions

By submitting an order from the internet order form, you confirm that you are familiar with the conditions of personal data protection and that you accept them in their entirety.

You agree to these conditions by ticking consent through the internet form or by signing consent to process personal data. By ticking consent, you confirm that you are familiar with the conditions of personal data protection and that you accept them in their entirety.

The controller is entitled to change these conditions. The new version of the personal data protection conditions will be published on its website (www.protutorly.com) and will also send you the new version of these conditions to your email address that you have provided to the controller.

These conditions take effect on January 1, 2024.