Consent to the processing of personal data
Dear customers and visitors of our online store,
A number of obligations relating to the protection of personal data arise from the applicable legislation, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation – GDPR). The company initMAX s.r.o., with its registered office at Plynární 1617/10, Holešovice, 170 00 Prague 7, ID No.: 11923652, registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, File 356164 (hereinafter referred to as the “Provider” or “we“) in all cases where we are the controller of your personal data, protect such personal data and handle them in accordance with applicable legal regulations.
WHAT PERSONAL DATA DO WE PROCESS?
Customer personal data
When you purchase a subscription to products on our online store, we process the following personal data:
- identification data (academic titles, name, surname, date of birth, permanent address, delivery address, in the case of entrepreneurs, ID and VAT numbers);
- contact details (telephone and e-mail contact);
- payment details (information about the product charged and paid for);
- Product details purchased.
Personal data of potential customers
When you express interest in the products we offer or subscribe to our marketing materials, we generally process the following personal data:
- identification data (academic titles, name, surname);
- Contact details (telephone and e-mail contact).
Personal data of visitors to the online store
When you visit our online store, we process the following personal data:
- user settings (user account settings – delivery address, data on monitored products);
- about your behaviour on the online store (individual product ratings, satisfaction questionnaires, products viewed, device data and IP address, browser).
Cookies are used to process this data – detailed information on their processing is available on this page below.
Personal data of suppliers
For suppliers of goods and services, including potential suppliers, we record the following personal data:
- identification data (academic titles, name, surname, date of birth, permanent address, delivery address, ID and VAT number);
- contact details (telephone and e-mail contact of the contact person);
- payment details (bank details, agreed amount and form of remuneration and its payment);
- Data on the relevant contractual relationship and other data that we are legally obliged to process.
SOURCE OF PERSONAL DATA
We obtain the personal data we process directly from the data subject and also from Bright Market, LLC dba FastSpring (a company with its registered office at 801 Garden St. #201, Santa Barbara, CA 93101, United States of America[AL2] ), which mediates the transaction, ensures the payment of the purchase price (the controller is provided with information about whether the product has been paid for, and subsequently manages the customer’s products (customers have the option to cancel subscriptions to purchased products on its website, and such information is subsequently handed over to the controller).
PURPOSE AND LEGAL BASIS OF PERSONAL DATA PROCESSING
We process personal data on the basis of the necessity of their processing for:
- performance of a contract – this particularly involves fulfilling contractual obligations towards customers or suppliers;
- Compliance with legal obligations – for customers and suppliers, this includes in particular:
- Act No. 89/2012 Coll., the Civil Code, as amended;
- Act No. 634/1992 Coll., on Consumer Protection, as amended;
- Act No. 235/2004 Coll., on Value Added Tax, as amended;
- Act No. 563/1991 Coll., on Accounting;
- our legitimate interests – for the purpose of sending marketing communications, for the prevention of potential disputes, or for their resolution;
- In some cases, we also process personal data on the basis of consent provided to us by the data subject for a specific purpose – e.g. sending marketing communications, data about your visit to our online store.
RECIPIENTS OF PERSONAL DATA
We will only pass on your personal data if such a transfer is necessary. We pass on your data to our payment partners and to our processors (accounting services).
Our processors have their registered office and place of personal data processing in the Czech Republic or in another EU country.
PROCESSING TIME
We process personal data for the period necessary to fulfil contractual obligations, to protect legitimate interests, or for the period for which we have a legal obligation to process the data (usually for a maximum of 10 years) or for the period for which you have given us consent to the processing of personal data.
We process personal data intended for direct marketing until the data subject expresses any disagreement with the sending of further communications.
We process personal data processed on the basis of consent for the period of validity of the consent, or until the data subject withdraws the consent.
YOUR RIGHTS
In accordance with applicable law, you have the following rights as a data subject:
- The right to access the personal data we process; this includes the right to obtain the following information from us:
- confirmation of whether we process your personal data,
- access to such personal data, unless the nature and purpose of their processing preclude it and such provision would not affect the rights and freedoms of other persons,
- the purposes of the processing,
- the categories of personal data concerned,
- about the recipients or categories of recipients to whom the personal data will be disclosed,
- the planned storage period or the criteria for its determination,
- the existence of the right to request rectification or erasure of personal data, or restriction of their processing, or the right to object to such processing,
- on the right to file a complaint with a supervisory authority,
- all available information about the source of personal data, unless it is obtained from the data subject – from you,
- whether automated decision-making, including profiling, takes place,
- appropriate safeguards for transfers of personal data outside the EU;
- if the rights and freedoms of other persons are not adversely affected, a copy of the personal data.
- The right to rectification or completion of data in the event that the data is processed incorrectly, inaccurately or incompletely.
- The right to erasure of personal data in cases stipulated by the GDPR, e.g. in the case of withdrawal of consent to processing or objection to processing, in the case of unlawful processing of personal data, in the event that the personal data are no longer necessary for the purposes for which they were processed, etc. In these cases, you can request the deletion of your personal data, this option does not apply if the processing is necessary for compliance with a legal obligation, and in certain other cases provided for by the GDPR.
- The right to restriction of processing in cases foreseen by the GDPR, such as when you contest the accuracy of your personal data, object to processing, etc.
- The right to data portability that you have provided to us and that we process automatically, based on your consent, or on the basis of the necessity of their processing for the performance of a contract with you, or to take steps taken at your request prior to entering into a contract. In such cases, we will allow you to obtain your personal data in a structured, commonly used and machine-readable format or, if technically feasible, we will transmit it directly to another controller designated by you.
- The right to object to the processing of your personal data based on the necessity of processing for the purposes of legitimate interests, including processing for direct marketing purposes. Unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims, we will no longer process your personal data.
- The right to withdraw consent to the processing of personal data at any time by sending an explicit notice to our address Plynární 1617/10, Holešovice, 170 00 Prague 7, or to the e-mail address info@initmax.com. The withdrawal of consent is effective at the moment when the notification is delivered to us. According to the GDPR, the withdrawal of consent does not affect the lawfulness of processing based on consent granted before its withdrawal.
- The right not to be subject to automated individual decision-making with legal or similar effects, including profiling.
- The right to file a complaint with the supervisory authority, which is the Office for Personal Data Protection, with its registered office at Pplk. Sochora 27, 170 00 Prague 7.
If you have any questions or other requests regarding the processing of your personal data, you can contact us at any time in writing at Plynární 1617/10, Holešovice, 170 00 Prague 7 or by e-mail at info@initmax.com.
The provider uses the following cookies:
Processor | Cookies identification | Personal data | Processing purpose | Legal basis | Processing time |
---|---|---|---|---|---|
Technical cookies / similar technologies | |||||
initMAX s.r.o. | dcb_dsv | no | Version of consent to cookies processing. | legitimate interest | local storage/365 days |
initMAX s.r.o. | dcb_config | no | Configuration of consent to cookies processing. | legitimate interest | local storage/365 days |
Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | cookiePreferences | no | It registers the user's cookie preferences. | user consent | 2 years |
Analytical cookies / similar technologies | |||||
Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | _ga | no | ID used to identify users | user consent | 2 years |
Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | _ga_ | no | ID used to identify users | user consent | 2 years |
Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | _gid | no | ID used to identify users for 24 hours after last activity | user consent | 24 hours |
Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | _gat | no | It is used to track the number of Google Analytics server requests when using Google Tag Manager | user consent | 1 minute |
Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | _dc_gtm_ | no | It is used to track the number of Google Analytics server requests | user consent | 1 minuta |
Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | AMP_TOKEN | no | It contains a token code that is used to load the client ID from the AMP Client ID service. | user consent | 30 seconds to 1 year |
Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | _gat_gtag_ | no | It is used to set up and retrieve tracking data. | user consent | 1 hour |
Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | _gac_ | no | It contains information related to the user's marketing campaigns. These are shared with Google AdWords/Google Ads when Google Ads and Google Analytics accounts are linked. | user consent | 90 days |
Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | __utma | no | ID used to identify users a relací. | user consent | 2 years after last activity |
Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | __utmt | no | It is used to track the number of Google Analytics server requests. | user consent | 10 minut |
Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | __utmb | no | It is used to distinguish new sessions and visits. This cookie is set when the GA.js javascript library is loaded and there is no existing __utmb cookie. The cookie is updated every time data is sent to the Google Analytics server. | user consent | 30 minutes after last activity |
Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | __utmc | no | It is used only with old versions of Urchin Google Analytics, not with GA.js. It is used to distinguish between new sessions and visits at the end of a session. | user consent | End of session (browser) |
Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | __utmz | no | OIt contains information about the traffic source or the campaign that directed the user to the website. The cookie is set when the GA.js javascript is loaded and is updated when the data is sent to the Google Anaytics server. | user consent | 6 months after last activity |
Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | __utmv | no | Custom information for web developers is received via the _setCustomVar method in Google Analytics. The cookie contains new updates as well as news on the Google Analytics server. | user consent | 2 years after last activity |
Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | __utmx | no | It is used to determine whether the user is included in an A/B or multivariable test. | user consent | 18 months |
Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | __utmxx | no | It is used to determine when an A/B or multivariable test that the user is participating in ends. | user consent | 18 months |
Microsoft Corporation, Redmond, Washington, USA | _clck | no | website improvement | user consent | 24 hours |
Microsoft Corporation, Redmond, Washington, USA | _clsk | no | website improvement | user consent | 24 hours |