PRIVACY POLICY
We recognize that our customers, visitors, users and others who visit our website (collectively, “Users”) value their privacy. This document therefore contains important information regarding the rules we follow when processing personal data.
All processing of personal data by us is always carried out in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“GDPR”).
These privacy policies follow the General Terms and Conditions, which are available here: https://eshop.imps.cz/en/terms-and-conditions/
Note: In case of any differences between the Czech and foreign language versions of this Privacy Policy, the Czech version shall prevail.
BASIC INFORMATION
Identification and contact details of the Provider:
| name: | IMPS a.s. |
| ID: | 46345931 |
| punch: | Zaoralova 3090/ 17d |
| contact email: | tomas.slovak@imps.cz |
| contact phone: | +420 702 245 416 |
(hereinafter also referred to as the “Provider”)
Data Protection Officer:
The Provider has appointed a Data Protection Officer who assists in resolving personal data protection issues. If necessary, the User may contact him/her directly. The Data Protection Officer is available to answer questions regarding the handling of personal data or to provide further information on personal data protection:
| name: | Ing. Tomas Slovák |
| contact email: | tomas.slovak@imps.cz |
| contact phone: | +420 607 210 806 |
Transfer of personal data to a third country or international organization:
The provider does not transfer personal data to third countries or international organizations within the meaning of Art. 44 et seq. GDPR.
Automated individual decision-making and profiling:
The provider does not perform profiling or automated individual decision-making.
Supervisory authority:
The supervisory authority at the location of the Provider’s registered office is the Office for Personal Data Protection with its registered office at Pplk. Sochora 27, 170 00 Prague 7, e-mail: posta@uoou.cz , phone: 234 665 125.
Provider’s position:
The provider acts both as a personal data controller and as a personal data processor.
PERSONAL DATA CONTROLLER PROVIDER
The Provider acts as a personal data controller in relation to the personal data of the following persons: customers, contractual partners, website visitors.
What personal data does the Provider process, for what purpose and on what legal basis?
Visiting the website. The Provider processes data that it obtains from individuals by visiting the Provider’s website. When visiting the website, the Provider collects and processes the following types of personal data that are stored: IP address. The Provider also processes the following data: We do not process any such data. This data is necessary to enable the website to be displayed correctly. In addition, it may be used as necessary to maintain the secure operation of the website and for other purposes described in this Privacy Policy. The Provider processes this personal data based on its legitimate interest or the User’s consent. Information about cookies is provided below.
For the purpose of performing the contract (in particular, concluding the contract, communicating with the customer), implementing measures taken before concluding the contract (negotiations before concluding the contract) or fulfilling legal obligations (in particular, keeping accounts, issuing and recording tax documents), the Provider processes in particular the following personal data: name, surname, date of birth, name of employer, ID number, VAT number, bank account number, address, e-mail address, telephone number, mutual communication between IMPS as and the data subject, information provided by the data subject.
The Provider obtains personal data directly from the User when concluding the contract, therefore it always informs which personal data must be provided for the purposes of fulfilling the contract.
The principle of data minimization is respected by requiring only information that the Provider absolutely needs to conclude a contract or fulfill its contractual obligations or that the Provider has a legal obligation to handle. Providing other personal data is voluntary.
If the User is a customer of the Provider, the Provider may, for reasons of legitimate interest, send commercial communications – newsletters to the User’s e-mail address. In other cases, sending newsletters is possible only upon consent. Sending newsletters can be canceled at any time.
Registration / customer account: On the Provider’s website, Users are allowed to register by entering personal data.
During registration, the following personal data is communicated to the Provider: Name, surname, company name, ID number, VAT number, billing address, delivery address, telephone number, e-mail. The Provider adheres to the principle of data minimization, and therefore only necessary fields are marked as mandatory during registration.
Registration allows you to order goods.
If the Provider intends to process personal data other than that specified in this article, or for other purposes, it may do so only on the basis of a valid consent to the processing of personal data. Consent to the processing of personal data must be granted on a separate document.
The Provider declares that it does not process Users’ payment data. All payment data is processed by a third party, namely:
| name: | Comgate a.s. |
| ID: | 27924505 |
| punch: | Gočárová Street 1754/48b Hradec Kralove |
Information on the processing of personal data of the Provider’s employees is provided in a separate internal regulation.
Sensitive personal data
The Provider, as a personal data controller, does not process the personal data of Users that belong to special categories of personal data pursuant to Article 9 of the GDPR.
For how long does the Provider process personal data?
Personal data is processed only for as long as there is a legal reason for its retention, after which the data is deleted immediately.
Personal data processed for the fulfillment of obligations arising from special legal regulations is processed by the Provider for the period specified in the relevant legal regulations. This includes, for example, statutory data retention or documentation obligations. This includes in particular data retention obligations arising from civil, commercial or tax regulations. If the data retention obligation expires, the personal data will be deleted without delay.
Other personal data is processed for the period: Personal data is processed for the duration of the contractual relationship with the customer and subsequently for a period of 1 year after the termination of the contractual relationship.
PERSONAL DATA PROCESSOR PROVIDER
The provider acts as a processor of personal data for other controllers.
The administrator of this personal data is obliged to comply with all personal data protection rules set out in the GDPR and other legal regulations governing this issue. The Provider bears no responsibility for any violation of personal data protection rules by the administrator of this personal data.
What personal data does the Provider process in the position of a personal data processor and what is the purpose of the processing?
The Provider provides the User with data space for the purpose of storing data, namely on the Provider’s servers. The User’s data may also include personal data of natural persons. This may include in particular: name, surname, date of birth, employer’s name, company ID, VAT number, bank account number, address, e-mail address, telephone number, mutual communication between IMPS as and the data subject, information provided by the data subject. In relation to the personal data that the User stores on the Provider’s servers, the Provider acts as a personal data processor. The administrator of this personal data is the User himself.
The Provider does not perform any operations with the User’s data, including personal data, except for storing them on servers. The sole purpose of handling this personal data is to store them and make them available to the User.
The provider processes the following personal data: name, surname, date of birth, employer’s name, ID number, VAT number, bank account number, address, e-mail address, telephone number, mutual communication between IMPS as and the data subject, information provided by the data subject.
The purpose of processing is: Contact purposes.
In the event that the Provider becomes a processor of personal data belonging to special categories of data, the User is responsible for the legality of obtaining such data and handling them in accordance with the GDPR and national legislation. The Provider reserves the right to remove such personal data from its servers if it detects non-compliance with the conditions for processing special categories of personal data. Before deleting personal data, the Provider contacts the User with a request for correction.
For how long does the Provider process personal data?
The Provider processes personal data for the duration of the contractual relationship with the User. After the termination of the contractual relationship, all data are deleted without undue delay after the termination of the contractual relationship. Users are entitled to request deletion of data at any time during the duration of the contractual relationship. In the event of receiving a request from the User to delete data, the Provider will delete all data without undue delay.
RECIPIENTS OF PERSONAL DATA
The provider does not transfer personal data to any other administrators.
The provider does not transfer personal data to any personal data processors.
DATA SECURITY METHODS
In order to secure the User’s data against unauthorized or accidental disclosure, the Provider uses reasonable and appropriate technical and organizational measures.
The Provider ensures that in the case of servers being located in a data center operated by a third party, similar technical and organizational measures are also implemented by this third party.
All data is located only on servers located in the European Union or in countries that ensure the protection of personal data in a manner equivalent to the protection provided by the legal regulations of the Czech Republic.
The Provider uses the following data security procedures: Technical measures consist of the application of technologies that prevent unauthorized access by third parties to the User’s data, in particular the use of firewalls, updated antivirus programs, etc. For the purpose of maximum protection, the Provider uses data encryption. Access to areas with a high concentration of personal data processing is protected by electronic security systems. Organizational measures constitute a set of rules of conduct for employees and are incorporated into the Provider’s internal regulations, which are considered confidential for security reasons. The procedures are based solely on minimizing the number of persons who have access to personal data and the ability to handle personal data. All employee access to personal data, as well as the methods of handling it, are monitored.
USER RIGHTS
Each User has:
- right to access personal data: The User has the right to obtain from the Provider confirmation as to whether or not personal data concerning him or her are being processed, and if so, the right to access such personal data and the following information: a) the purpose of the processing; b) the categories of personal data concerned; c) the recipients to whom the personal data have been or will be disclosed; d) the planned period for which the personal data will be stored; e) the existence of the right to request the controller to correct or delete personal data or to restrict their processing, or to object to such processing; f) the right to lodge a complaint with a supervisory authority; g) all available information about the source of personal data, unless it is obtained from the Users; h) the fact that automated decision-making, including profiling, is taking place. The User also has the right to obtain a copy of the processed personal data.
- the right to correct personal data: The user has the right to have the Provider correct inaccurate personal data concerning him or her without undue delay, or to complete incomplete personal data.
- right to erasure of personal data: The User has the right to obtain from the Provider the erasure of personal data concerning him or her without undue delay if: a) the personal data are no longer necessary for the purposes for which they were collected or otherwise processed; b) the User withdraws the consent on the basis of which the data were processed and there is no other legal ground for the processing; c) the User objects to the processing and there are no overriding legitimate grounds for the processing; d) the personal data have been processed unlawfully; e) the personal data must be erased for compliance with a legal obligation laid down in Union or Member State law; f) the personal data have been collected in connection with the offer of information society services. However, the right to erasure shall not apply if the processing is necessary for compliance with legal obligations, for the establishment, exercise or defense of legal claims and in other cases provided for in the GDPR.
- right to restriction of processing: The User has the right to obtain from the Provider restriction of processing in any of the following cases: a) The User disputes the accuracy of the personal data, for a period of time necessary for the Provider to verify the accuracy of the personal data; b) the processing of the data is unlawful and the User refuses the erasure of the personal data and requests the restriction of their use instead; c) The Provider no longer needs the personal data for the purposes of the processing, but the User requires them for the establishment, exercise or defense of legal claims; d) The User has objected to the processing, until it is verified whether the legitimate grounds of the Provider override those of the data subject.
- the right to object to processing: The User has the right, on grounds relating to his or her particular situation, to object at any time to the processing of personal data concerning him or her which is processed on the basis of a legitimate interest. In such a case, the Provider shall not further process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests or rights of the Users, or for the establishment, exercise or defense of legal claims.
- right to data portability: The User has the right to obtain personal data concerning him or her, which have been provided to the Provider, in a structured, commonly used and machine-readable format, and the right to transmit such data to another controller, where: a) the processing is based on consent and b) the processing is carried out by automated means. When exercising his or her right to data portability, the User has the right to have personal data transmitted directly from one controller to another, if technically feasible.
- the right to file a complaint with a supervisory authority: If the User believes that the Provider is not processing his/her personal data lawfully, he/she has the right to file a complaint with a supervisory authority. The contact details of the supervisory authority are listed above.
- the right to information regarding the correction or deletion of personal data or the restriction of processing: The Provider is obliged to notify the individual recipients to whom the personal data have been made available of any correction or deletion of personal data or restriction of processing, except where this proves impossible or involves disproportionate effort. If the User so requests, the Provider shall inform him/her of these recipients.
- the right to be informed in the event of a personal data breach: If it is likely that a certain personal data breach will result in a high risk to the rights and freedoms of natural persons, the Provider is obliged to notify the User of this breach without undue delay.
- the right to withdraw consent to the processing of personal data: If the processing of some of the personal data is based on consent, the User has the right to withdraw his consent to the processing of personal data at any time in writing, by sending a statement of disagreement with the processing of personal data to the e-mail address: wabco@imps.cz.
COOKIES
The Provider uses cookies, which are small text files that identify users of the Provider’s website and record their user activities.
The text in a cookie file is often a series of numbers and letters that uniquely identify the User’s computer, but do not provide any specific personal information about the User. A cookie file usually contains the name of the domain from which it was sent, age information, and an alphanumeric identifier.
The Provider’s website automatically identifies the User’s IP address. All this information is recorded in an activity file by the server, which enables subsequent data processing. The Provider also records the request from the browser and the time of the request, the status and amount of data transferred within the framework of this request. It also collects information about the browser used and the computer’s operating system and their versions. It also records the websites from which you accessed the Provider’s website. The IP address of your computer is stored only for the period during which the website was used and then for the necessary period. After this period, the IP address is deleted or anonymized by shortening.
Types of cookies and similar technologies
Technical cookies and similar technologies: Due to its legitimate interest, the Provider uses technically necessary cookies that are necessary for the operation of the website and to ensure its functionality. These may be permanent or one-time cookies. A permanent cookie file remains on the hard drive even after the browser is closed. Permanent cookies can be used by the browser during subsequent visits to the Provider’s website. Permanent cookies can be deleted. One-time cookies are temporary and are deleted as soon as the browser is closed. The Provider uses this data to operate the website, in particular to identify and resolve errors, to determine the use of the website and to make adjustments or improvements. These are purposes for which the Provider has a legitimate interest in processing data pursuant to Article 6(1)(f) of the GDPR.
The User can set their browser to block these cookies. The Provider warns that in such a case some parts of the website will not function.
the WebStorage listed in the table below in the same way and for the same reasons.
With the User’s permission, the Provider uses other cookies:
Analytical cookies and similar technologies: These cookies help the Provider analyze how Users use the website. They can be used, for example, to measure and improve the performance of the website. These cookies allow, for example, to determine how the User came to the website, whether directly, using a search engine or via a link on a social network. The Provider also learns how long Users stay on the page and what links they click on.
These cookies are set on the User’s device only if the User gives their consent during their first visit to the website (pursuant to Article 6(1)(a) GDPR). Analytical cookies can be rejected at any time by making a change in the Detailed Cookie Settings.
the WebStorage listed in the table below in the same way and for the same reasons.
Advertising cookies and similar technologies: Advertising cookies enable the display of advertising based on the User’s preferences. They can be used, for example, to allow the Operator to create a profile of the User’s interests and to display relevant advertisements to the User.
These cookies are set on the User’s device only if the User gives their consent when they first visit the website (pursuant to Article 6(1)(a) GDPR). Advertising cookies can be rejected at any time by making a change in the Detailed Cookie Settings. If the User does not consent, they will not receive content and advertisements tailored to their interests.
the WebStorage listed in the table below in the same way and for the same reasons.
or other cookies / similar technologies, if listed in the table below.
To obtain and manage the User’s consent, the Provider uses the CookiesLišta.cz platform from Cookies lišta, sro, IČ: 17418640, Příčná 1892/4, Prague 1, 110 00 Prague. The platform collects information about the device, browser information, anonymized IP address, date and time of visit, requested URLs, path to the website and geographical location. This makes it possible to inform the User about the Provider’s web environment and to obtain, manage and document his consent. The legal basis for data processing is Article 6(1)(c) GDPR, as the Provider is legally obliged to provide evidence of consent in accordance with Article 7(1)(c) GDPR. The data will be deleted as soon as they are no longer needed for logging and there are no legal retention requirements. Further information on the topic of personal data protection at the platform provider can be found at: https://www.cookieslista.cz.
The Provider’s website may also place third-party cookies. The Provider uses the following cookies:
Processor Cookies designation Personal data Purpose of processing Legal Reason Processing time Technical cookies / similar technologies IMPS a.s. dcb_dsv no Version of consent to the processing of cookies. legitimate reason local storage / 365 dní IMPS a.s. dcb_config no Configuration of consent to the processing of cookies. legitimate reason local storage / 365 dní Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States cookiePreferences no Registers the user's cookie preferences. user consent 2 years Smartsupp.com, s.r.o. - Šumavská 31, 602 00 Brno-střed, Česká republika Ssupp_chatid no The function is to store a unique session ID. legitimate reason end of session (browser) Smartsupp.com, s.r.o. - Šumavská 31, 602 00 Brno-střed, Česká republika Ssupp_vid no The function is to store a unique user ID. legitimate reason 6 months Smartsupp.com, s.r.o. - Šumavská 31, 602 00 Brno-střed, Česká republika Ssupp_visits no The function is to store the number of visits. legitimate reason 6 months Smartsupp.com, s.r.o. - Šumavská 31, 602 00 Brno-střed, Česká republika Ssupp.Visits no The function is to store the number of visits. legitimate reason 6 months Smartsupp.com, s.r.o. - Šumavská 31, 602 00 Brno-střed, Česká republika Ssupp.Position no The function is to save the configuration. legitimate reason end of session (browser) Smartsupp.com, s.r.o. - Šumavská 31, 602 00 Brno-střed, Česká republika Ssupp.Unreaded no The function is to save if the message has been displayed. legitimate reason end of session (browser) Smartsupp.com, s.r.o. - Šumavská 31, 602 00 Brno-střed, Česká republika Ssupp.Message no The function is to save the actions performed on the website. legitimate reason end of session (browser) Smartsupp.com, s.r.o. - Šumavská 31, 602 00 Brno-střed, Česká republika Ssupp.Barclicked no The feature is to save the chat status. legitimate reason end of session (browser) Smartsupp.com, s.r.o. - Šumavská 31, 602 00 Brno-střed, Česká republika Ssupp.Opened no The feature is to save the chat status. legitimate reason end of session (browser) Smartsupp.com, s.r.o. - Šumavská 31, 602 00 Brno-střed, Česká republika Ssupp.Group no The feature is to save the chat status. legitimate reason end of session (browser) Smartsupp.com, s.r.o. - Šumavská 31, 602 00 Brno-střed, Česká republika Ssupp.Chatid no The function is to store a unique session ID. legitimate reason end of session (browser) Smartsupp.com, s.r.o. - Šumavská 31, 602 00 Brno-střed, Česká republika Ssupp.Vid no The function is to store a unique user ID. legitimate reason 6 months Analytical cookies / similar technologies Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States _ga no Hlavní cookie používaná k rozlišení unikátních uživatelů. user consent 2 years Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States _ga_* no Používá se k zachování stavu aktuální relace (namísto * je unikátní ID kontejneru). user consent 2 years Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States _gid no Používá se k rozlišení uživatelů pro potřeby denních statistik. user consent 24 hours Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States _gat no Používá se k omezení počtu požadavků na servery Googlu. user consent 1 minute Microsoft Corporation - 1 Microsoft Way, Redmond, WA 98052, USA _clck no Uchovává ID uživatele služby Clarity a předvolby, které jsou jedinečné pro daný web a jsou přiřazeny stejnému ID uživatele. user consent 365 days Microsoft Corporation - 1 Microsoft Way, Redmond, WA 98052, USA _clsk no Propojuje více zobrazení stránek uživatelem do jediného záznamu relace Clarity. user consent 1 day Microsoft Corporation - 1 Microsoft Way, Redmond, WA 98052, USA CLID no Identifikuje, kdy Clarity poprvé zaznamenalo tohoto uživatele na jakémkoli webu používajícím Clarity. user consent end of session (browser) Microsoft Corporation - 1 Microsoft Way, Redmond, WA 98052, USA ANONCHK no Označuje, zda je MUID přenesen do ANID, cookie používaného pro reklamu. Clarity nepoužívá ANID, a proto je vždy nastaven na 0. user consent end of session (browser) Microsoft Corporation - 1 Microsoft Way, Redmond, WA 98052, USA MR no Označuje, zda se má obnovit MUID. user consent 7 days Microsoft Corporation - 1 Microsoft Way, Redmond, WA 98052, USA MUID no Identifikuje jedinečné webové prohlížeče, které navštěvují weby společnosti Microsoft. Tyto soubory cookie se používají pro reklamu, analýzu stránek a další provozní účely. user consent 365 days Microsoft Corporation - 1 Microsoft Way, Redmond, WA 98052, USA SM no Používá se při synchronizaci MUID napříč doménami Microsoft. user consent end of session (browser) Advertising cookies / similar technologies Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States _gac_UA-* no The function is to store and count page views. user consent 90 days Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States goog_pem_mod no The function is to provide ad serving or redirects. user consent permanently Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States ads/ga-audiences no The function is to store information for remarketing purposes. user consent immediately Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States session_depth no The function consists of saving the frequency of display of advertisements. user consent 30 minutes Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States _gac_* no The function is to store and count page views. user consent 90 days Google LLC - 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States google_pem_mod no The function is to provide ad serving or redirects. user consent permanently Seznam.cz, a.s. - Radlická 3294/10, 150 00 Praha 5, Česká republika sid no Conversion tracking. user consent 30 days Seznam.cz, a.s. - Radlická 3294/10, 150 00 Praha 5, Česká republika Sklik-* no Retargeting. user consent 30 days
Setting cookies in your browser
Most web browsers automatically accept cookies, but you can use controls to block or delete them.
Instructions for blocking or deleting cookies in browsers can usually be found in the privacy policies or help documentation of individual browsers.
Social networks
The provider is present on social networks in order to communicate with customers, interested parties and users who are logged in there and to inform them about its offers.
The Provider points out that the User uses these platforms and their functions at their own risk. This applies in particular to the use of interactive functions (eg commenting, sharing, rating). The Provider bears no responsibility for the handling of this personal data and points out that personal data may also be processed outside the European Union.
FINAL PROVISIONS
The Provider will update this Privacy Policy in the event of any changes. The current version of the Privacy Policy will always be available on the Provider’s website. If there is a significant change in the methods of handling personal data in this Privacy Policy, the Provider will inform the User by visibly posting a relevant notice before implementing these changes.
Last edited 11. 3. 2024