Privacy policy

1. Personal Data Controller
1.1 Anežka Juhová
Registered office:​​Prague 5, Smíchov, Pod Hybšmankou 2818/3
Identification No. (IČO)09667946
Phone number:​​ +420 731 903 601
Email:​​​​ studio@anezkajuhova.cz
Contact address:​​ Malířská 9, Prague 7, 170 00
(hereinafter referred to as the "Controller")
1.2 The Controller declares that all personal data processed by the Controller is strictly confidential. The Controller handles them in accordance with national and European Union legislation applicable to the protection of personal data.
1.3 The Controller collects, stores and uses your personal data within the meaning of Act No. 110/2019 Coll. on the processing of personal data (hereinafter referred to as the Personal Data Processing Act) and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the "GDPR"). The individual purposes for which the Controller processes personal data are further defined as follows:
1.4 The Controller also collects this personal data through its online shop at anezkajuhova.com (hereinafter referred to as the "Website").
1.5 This Privacy Policy is issued by the Controller so that you are sufficiently informed about what personal data the Controller processes about you, for what purpose, for how long, who will have access to your personal data and what your rights are. This Privacy Policy applies to all personal data collected by the Controller, whether collected for the performance of a contractual relationship, legal obligation, legitimate interest or consent.
2. Data processed
2.1. From the moment you visit the Website, the Controller  may process your personal data. This includes necessary cookies, and data that the Controller uses to provide the smart features of the Website.
2.2. The Controller primarily processes the aforementioned data to ensure the functionality of the Website. The IP address and, where applicable, other data on network communications are processed by the Controller  for the purpose of preventing and resolving incidents that could result in the non-functionality or limitation of the Website or could lead to its misuse (e.g. malware, cyber-attacks, batch downloading of data from services, access from anonymous web browsers, etc.), on the basis of theController's legitimate interest.
2.3. Once received, purely statistical data is anonymised by the Controller, aggregated and used as global indicators of Websiteusage.
2.4. The IP address and unique identifier are then processed by the Controller together with the Website usage data in order to provide you with personalised recommendations on how to use the Website more effectively on repeat visits. However, in this case, the Controller will only process this data if you have given your voluntary and informed consent within the meaning of Article 6(1)(a) GDPR to the storage of cookies on your device or to the processing of the associated data.
2.5. Furthermore, the Controller processes your personal data as a visitor if you contact her via the contact form, by email, telephone or via the social networks Facebook, Instagram or Twitter; within the meaning of Article 4(1) of the GDPR, this will normally be:
electronic mail address (e-mail);
telephone number;
name and surname;
The IP addresses of the devices from which the request form was made;
network identifiers assigned by the Controller or by Facebook, Instagram or Twitter;
your Facebook, Instagram or Twitter usernames.
2.6. This personal data is then processed by the Controller on the basis of:
a. your consent pursuant to Article 6(1)(a) of the GDPR, which in this case means the storage of cookies and the processing of the data thus obtained by linking it to data about your use of the service so that you can be shown personalised recommendations,
b. communication with customer support (before creating a user account or when logging out of a user account), which is both the Controller's and your legitimate interest within the meaning of Article 6(1)(f) of the GDPR.
2.7. The information about your use of the Controller's services as well as the information obtained from cookies, or their usability for the above purposes, is limited to the duration of the contract, i.e. usually for the duration of one visit to the Website, but no longer than 2 years or until the consent is withdrawn in accordance with Article 5 of this Privacy Policy.
2.8. By registering your user account and logging into the service, the Controller starts processing your personal data.
2.9. Within the meaning of Article 4(1) of the GDPR, the Controller processes the following personal data about you in accordance with the above:
name and surname;
electronic mail address (e-mail);
username;
residential address;
telephone number;
IP addresses of the devices from which the service was logged in or, where applicable, from which the request was made via the contact form; and other selected data from the system logs (browser data, browser language, date/time, etc.);
data about your preferences when using the Website;
information about your use of the Website and information about where you visited the Website, when you visited and left the Website, or how many times you have visited the Website;
network identifiers assigned by the Controller or by Facebook, Instagram or Twitter, your usernames on these networks and any associated e-mails;
other billing data (bank account number, ID number and VAT number);
other data that may lead to your identification (e.g. comments, remarks);
payment information.
2.10. This personal data is then processed by the Controller for the purpose of:
 a. performance of the contract and fulfilment of the legal obligations of the Controller according to Articles 6(1)(b) and 6(1)(c) of the GDPR and the Controller's Terms and Conditions, which means the performance of the concluded purchase contract for the Controller 's goods;
b. protecting servers from attacks and user accounts from misuse by third parties or misuse by certain users, informing you about planned downtimes and technical maintenance of software and hardware, which is the Controller's and your legitimate interest within the meaning of Article 6(1)(f) of theGDPR;
c. the prevention of damage caused by loss, degradation or corruption of data by regularly backing up the Website, as part of the performance of the contract and the legitimate interest in the proper provision of the service;
d. to enable the Controller  to inform you, as part of its legitimate interest, what improvements and innovations she plans to make, so that you always have an up-to-date and accurate overview, within the meaning of recital 47 of the GDPR.
2.11. The Controller  processes the personal data pursuant to article 2.10 a. for the period of performance of the purchase contract and thereafter for 10 years from the last date of delivery of the goods.
 2.12. Other personal data pursuant to this Article shall be processed by the Controller for the duration of the user account. The e-mail address is kept by the Controller  both for the time necessary to send you newsletters and for legitimate interest, whereby the Controller may contact you with an offer of its services for 12 months after the termination of the user account. Selected personal data may be retained by the Controller for a maximum of 15 years after termination in case of any dispute relating to the relationship between the Controller and you. In addition, the Controller may keep documents containing your personal data for archiving purposes, in particular tax documents containing your personal data may be kept by the Controller  for a period of 10 years from the end of the relevant tax year. After this period, the Controller  will destroy your personal data, unless she is entitled to process these data on the basis of another legal title.
 
3. Processing of data on the basis of consent
3.1. The Controller may also process your personal data if you give your voluntary and informed consent within the meaning of Article 6(1)(a) GDPR. Your use of the Website is never conditional on your consent, but your consent may make it easier for the Controller to work with the Website and may help the Controller to improve the services she provides.
3.2. With the exception of the aforementioned consent, the Controller will process in particular your 
e-mail address, telephone number, name and surname and, where applicable, delivery address, within the limits of any further consent.
3.3. The consent will most often take the form of a tickbox, which you will find, for example, during registration, in any web surveys or questionnaires, or you will give it to the Controller by taking the active step required in the e-mail.
3.4. You can give your consent to the Controller for various purposes jointly or individually, e.g. to display any marketing communications from the Controller and to send them to your e-mail address, or so that the Controller can contact you by telephone or e-mail and offer you its services and products, i.e. to send you commercial communications, to inform you about loyalty promotions or events, or so that your personal data can be the subject of sociological research or market research carried out by third parties to improve the Controller's services in pseudonymised form.
3.5. The Controller may process personal data on the basis of consent for a period of 5 years, unless otherwise specified for the selected consent.
 
4. Rights of the data subject
4.1. As a data subject, you have the following rights under the law, which you can exercise at any time. These are:
a. the right of access to personal data, under which you have the right to obtain information from the Controller about whether the Controller is processing your personal data. The Controller is obliged to provide you with this information without undue delay. The content of the information is determined by the provisions of Article 15 of the GDPR. The Controller  has the right to charge a reasonable fee for providing the information, not exceeding the costs necessary to provide the information;
b. the right to rectification or erasure of personal data or restriction of processing, under which you have the right to have personal data that are inaccurate or incorrect rectified. If your personal data is no longer necessary for the purposes for which it was collected or is being processed unlawfully, you have the right to have it erased. If you do not want to request the erasure of your personal data, but only to temporarily restrict its processing, you can request the restriction of processing;
c. the right to request an explanation if you suspect that the processing of personal data by the Controller is in breach of the law;
d. the right to contact the Data Protection Authority if you have doubts about compliance with the obligations related to the processing of personal data;
e. the right to data portability, i.e. the right to obtain personal data concerning you that you have provided to the Controller in a structured, commonly used and machine-readable format, see Article 20 GDPR for more details;
f. the right to object to the processing of personal data which are processed for the performance of a task carried out in the public interest or in the exercise of official authority or for the protection of the legitimate interests of the Controller. The Controller shall terminate the processing without undue delay unless she demonstrates that there is a legitimate interest/reason for the processing which overrides your interests, rights or freedoms;
g. the right to withdraw consent to the processing of personal data at any time if you have given your consent to the Controller to process your personal data.
5. Cookies
5.1 Cookies are small files that are temporarily stored on your computer and help the Controller to improve the user experience on the Website. Cookies are used by the Controller to personalize Website content and advertisements, to provide social networking features and to analyze traffic. The Controller also shares information about your use of the Website with its social networking, advertising and analytics partners, who may combine it with other information that you have provided to them or that they have collected when you use their services.
5.2 By law, the Controller may only store cookies on your device that are strictly necessary for the operation of the Website. For all other types of cookies, the Controller needs your consent. The Controller will be very grateful if you provide this consent to help her improve the Website and services. You can, of course, change or withdraw your consent to the use of cookies on the Website at any time.
5.3 The Website may use the following types of cookies:
a. Required: These cookies are necessary for the site to function properly, including capabilities like logging in and adding items to the cart. These are so called “technical cookies” and tThis category of cookies cannot be disabled;
b. Personalization: These cookies store details about your actions to personalize your next visit to the website. These files are only stored and read by the Controller with your prior consent;
c. Marketing: These cookies are used to optimize marketing communications and show you ads on other sites. These files are only stored and read by the Controller with your prior consent;
d. Marketing cookies:These cookies help us understand how you interact with the site. We use this data to identify areas to improve. Thesr files are only stored and read by the Controller with your prior consent.
The Controller uses the following types of cookies on the Website:
Cookie:​​​anezkajuhova.cz    
Name:​​​​__ddg1_    
Features:​This cookie is used for analytics and tracking purposes and allows the Website to distinguish between different users and understand how users interact with the Website.    
Processing time:​1 year    
5.4 Consent can be expressed via a tickbox contained in the cookie bar. You can also subsequently refuse cookies in your browser settings or set to use only some of them.
5.5 You can also refuse cookies in general or set to activate only some cookies (depending on the type of browser) via your internet browser. You can find the settings for cookies in the most commonly used browsers at the following links:
Chrome;
Firefox;
Internet Explorer;
Opera;
Microsoft Edge.
5.6 If you give your consent, the Controller may share information about your use of the Website with its social media, advertising and analytics partners. By giving your consent, you agree to the linking of the following services:
Google
Facebook
Instagram
X (ex Twitter)
5.7 If you give your consent, in order to display targeted advertising within advertising and social networks on other Websites, the Controller transmits data about your behaviour on the Website to these advertising and social networks; however, it does not transmit your identification data to them.
 
6. Transfer of personal data
6.1 Depending on your location, data transfer may involve the transfer and storage of your information in a country other than your own. However, this will not include countries outside the European Union and the European Economic Area. If such a transfer occurs, you can contact us by e-mail: studio@anezkajuhova.cz.
 
7. Information and questions
7.1. For further information on data protection rights and obligations, the data subject may consult the Website anezkajuhova.com or the Controller via an e-mail to studio@anezkajuhova.cz.
7.2. If you believe that the data Controller is not handling your data properly, you have the right to file a complaint with the Office for Personal Data Protection, with its registered office at Pplk. Sochora 27, 170 00 Prague 7, mailbox ID: qkbaa2n, e-mail:posta@uoou.cz or take your claims to court.
7.3. This Privacy Policy is effective from 6.6.2024