Personal Data Administrator
GREATEBIKE.EU provider - ekolo.cz s.r.o., which has its registered office in Statenice, Keltská 348, 25262, postcode 252 62, Company Identification No. 27141659, incorporated in the Commercial Register maintained by the Municipal Court of Prague, Section C, File No. 99425, as the data administrator shall process your personal data.
Type of Data Processed
If you order goods or services from us, we need the information which is referred to as mandatory in the ordering process (in particular your first name, surname and delivery address). If we did not have this information we would not be able to deliver the goods. For the purposes of the sale of goods or services, we also need your e-mail address, to which we shall send the order confirmation which serves as confirmation of entering into the purchase agreement, as well as a copy of the Terms and Conditions and Complaints Policy.
You can also fill in optional information when ordering goods or services. This information helps us to perform the concluded purchase agreement more efficiently. For instance, if you fill in your telephone number, we can send you a notice of the delivery of the goods, etc. Providing optional information is voluntary.
If you contact us via the customer line or send us a message, we shall also process your personal data stated in such communication.
Personal Data Processed Automatically
When you visit our website (greatebike.eu, greatebike.com), we may collect certain information such as the IP address, date and time of the visit to our website, information about your internet browser, operation system or language settings. We may also process information about your conduct on our website, such as links opened or goods displayed. The details of your conduct on the web are anonymised for maximum protection of your privacy, therefore we are unable to match them with a particular person.
We process cookies automatically. This is done through Google Analytics, which anonymises your personal data. This means that the cookies cannot be matched with a particular person.
Therefore, we cannot (even if we wanted to) monitor the conduct of any specific user on our website. You are ensured maximum anonymity while making purchases on our websites.
Cookies are collected through a script from Google Inc., which is located in the source code of our website. Your cookies are transferred to Google Inc. for anonymisation. Then we work with the anonymised cookies, which by then have ceased to be personal data. The process of anonymisation, i.e. transfer for anonymisation, is the processing of personal data, made by us on the legal grounds of legitimate interest.
What is a cookie file? It is a small text file created upon a visit to a website. It is used as a standard tool for the storage of information about visits to our website.
Thus we can distinguish between (but not identify) individual users and customise the content to individual preferences. Cookies are important and web browsing would be more difficult without them.
If you access our website from a phone, tablet or similar device, you access the version optimised for such devices. Your personal data is processed similarly to that of the computer access.
Why We Collect and Process Your Personal Data
Your personal data is processed for the following reasons:
Purchase of goods and services: the primary purpose of processing your data is the due dispatch and delivery of your order. If a problem occurs, we know whom to contact from the data you provided.
Customer care: if you address us with a question/issue, we have to process your personal data in order to answer/resolve it. The data may be transferred to third parties in certain cases (e.g. a delivery company).
User account: thanks to the personal data entered in your user profile, you will be able to use a number of functions (e.g. if you enter your telephone number, we can easily inform you about the time of the order delivery). You can change the entered details at any time, except for the e-mail address that serves for signing into your user account.
Electronic marketing: e-mail commercial communication is sent to you upon your consent. You can easily unsubscribe from commercial communication by adjusting your user profile settings, using our contact form or calling our infoline at +420 220 991 111. In the event that you create more user profiles in which you enter the same contact details (e.g. you have several accounts for different e-mail addresses, but the telephone number is the same in all the accounts), an automatic sign-off from commercial communication cannot be affected for all the user accounts due to technical reasons. You have to contact us by phone or through the contact form so that all your user accounts may be unsubscribed.
Customer reviews of goods and services: after you purchase products or services from us, you may be asked to evaluate them. You may also post a review on your own initiative.
Assertion of rights and legal claims and inspection by public authorities: we can also process your personal data in order to assert our rights and legal claims (e.g. in the event that we have an overdue invoice in your name). We may also process your data for inspections by public authorities and due to other serious reasons.
Legal Grounds for Processing Personal Data
Conclusion and Performance of an Agreement
A large part of your personal data is needed by us in order to conclude the purchase agreement or another contract for goods and services you intend to purchase. After the agreement has been concluded, we process your personal data in order to duly deliver the purchased goods, or to render the purchased services. We process in particular billing and delivery details on the above legal grounds.
We also use your personal data to provide you with relevant content, which may be of interest to you. On the grounds of legitimate interest, we process particular personal data, which is processed automatically, and cookies.
We may also send you e-mails and text messages on the same legal grounds. The processing of personal data related to monitoring via camera systems in our stores is based on the above legal grounds as well.
For the purposes of e-mail marketing and telemarketing, we process your personal data upon your consent. If you do not grant your consent and you are our customer, we can send you commercial communication even without your consent. In any case, you are entitled to ban such marketing communication simply by (a) adjusting your user profile settings or (b) using our contact form or calling us at our infoline at +420 220 991 111.
We also ask for your consent if we need to verify your ability to pay for the goods delivered to you without your paying the full purchase price in advance.
If you grant your consent to personal data processing, you are entitled to withdraw it at any time using our contact form (see Contact us > Other > Personal data > Other).
Transfer of Personal Data to Third Parties
Your personal data is transferred to third parties in the following cases:
Delivery of goods: the carrier chosen by you would not be able to deliver the goods ordered unless we transferred the information on where and to whom the goods should be delivered. This data is transferred to the carrier as entered in the order. Such data includes in particular your first name and surname, delivery address, telephone number where the carrier may contact you, and the amount to be paid on delivery, as the case may be. The carrier is only entitled to process the personal data we transfer for the purposes of delivery; the carrier must delete the personal data promptly afterwards.
Payment Cards: Our company does not possess the details of payment cards used by you. The details of your payment cards are only available to the secure payment gateway and the relevant bank.
When you pay by payment card from a computer, you are redirected to a payment gateway server. Thus, your card details are not sent to our company but directly to the payment gateway provider via secure transmission. The payment gateway transfers the data to the relevant bank for the payment to be effected, again via secure transmission.
Our payment gateway provider is PayU SA, ul. Grunwaldzka 182, 60-166 Poznań, Poland, NIP 779-23-08-495.
Commercial Communication: in case we send commercial communication (e.g. via e-mail or text message), we may use a third party to distribute the messages. Such a third party is bound by the obligation of confidentiality and is not allowed to use your personal data for any other purpose.
Public Authorities: in the event that we enforce our rights, your personal data may be transferred to a third party (e.g. an attorney-at-law). If we are obliged to transfer your personal data by virtue of law or upon a request by a public authority (e.g. Czech Police), we have to do so.
What Is the Period for Processing Your Personal Data?
We shall process your personal data for the entire duration of the contractual relationship between you and our company.
In case your personal data processing is based on consent, your personal data shall, in general, be processed for 7 years or until such consent is withdrawn.
In case you subscribe to commercial communication, your personal data shall be processed for 7 years or until you express your disapproval with such communication. You can easily express your disapproval by adjusting your user profile settings, using our contact form or calling our infoline on +420 220 991 111.
Please note that the personal data necessary for the due rendering of services or for the fulfilment of all our duties, ensuing either from the contract between us or from generally binding legal regulations, has to be processed regardless of whether or not you granted your consent for the period set out in the relevant legal regulations and in compliance therewith (e.g. tax documents must be processed for at least 10 years).
The data obtained through the user account or in a similar way is processed for the period of using our services and then usually for 5 years after cancellation. Basic identification data and the information as to why the user account was cancelled or information which is a part of operational advance deposits are usually stored for the relevant period.
Personal Data Security
Your personal data is safe with us. We have adopted adequate technical and organisational measures in order to prevent unauthorised access and misuse of your personal data.
At ekolo.cz we are concerned about the protection of your personal data. Therefore, we regularly check and improve our security. All communication between your device and our web servers is encrypted. Logins are hashed and your data is only stored on servers in secure datacentres with limited, carefully controlled and audited access.
We try to use such safety measures that provide sufficient security based on state-of-the-art technology. The safety measures adopted are regularly updated.
Personal Data on Children Younger than 16 Years of Age
Our online shop is not intended for children under the age of 16. A person under the age of 16 is allowed to use our online shop only upon the consent of his or her parent or guardian.
What Are Your Rights Related to Personal Data Protection?
In relation to your personal data, you have in particular the right to withdraw your consent to the processing of your personal data at any time, the right to correct or supplement your personal data, the right to request restriction of processing, the right to raise an objection to or a complaint about the processing of your personal data, the right to access your personal data, the right to request the transfer of your personal data, the right to be informed of a breach of security of your personal data and, under certain conditions, the right to the deletion of certain personal data we process about you ('the right to be forgotten').
In case you believe that your personal data has been processed incorrectly, you can contact us at the e-mail address firstname.lastname@example.org. It will be faster and better for you to correct the personal data by yourself in your user profile.
You can ask us to send you the overview of the personal data by contacting us at the e-mail address email@example.com.
You also have the right to access the following information concerning your personal data:
- The purposes of processing your personal information
- The categories of the affected personal data
- The recipient of your personal data, besides you
- The planned period of storage of your personal data
Whether you have the right to claim the correction or deletion, restriction of personal data processing or to raise an objection to such processing
Information on the source of the personal data in case we did not obtain them from you
You may also claim the deletion of your personal data (this shall not apply to data in documents that are subject to the obligation of archiving under the law [e.g. invoices or credit notes]). In case we need your personal data to determine, execute or defend our legal claims, your request may be rejected (e.g. if we have an overdue invoice in your name or if a complaint procedure is in progress).
Please note that the essential details of your payment card are not stored by our company; they are stored at the payment gateway. Therefore, we are not able to delete such data; you have to address the payment gateway which mediated the payment.
You are entitled to the deletion of data in the following cases:
- The personal data is not needed for the purposes for which it was being processed
- You have withdrawn your consent under which the data was processed and there are no further legal grounds for it to be processed
- You have objected to the processing of personal data and you believe that after assessing your objection, it will become clear that your interest in the particular situation prevails over ours
- The personal data has been processed unlawfully
- The deletion obligation is stipulated by a special legal regulation
- The personal data concerns a person under the age 16
Raising an Objection
Certain personal data is processed on the grounds of our legitimate interest (see the section titled 'Legal grounds for processing personal data'). In case you have concrete reasons, you are entitled to raise an objection to the processing of this personal data. This objection can be raised by means of e-mail to firstname.lastname@example.org.
Restriction of Processing
In case (a) you deny the accuracy of your personal data; (b) your personal data is processed unlawfully; (c) we do not need your personal data for processing purposes, but it is needed to determine, execute or defend your legal claims; or (d) you raised an objection under the preceding paragraph, you shall be entitled to restriction of the processing of your personal data on our part.
In such cases, we may process your personal data only upon your consent (except for the storage or backup of the personal data concerned).
Lodging a Complaint
If you believe that your personal data has been processed unlawfully, you are entitled to lodge a complaint at the Office for Personal Data Protection. However, we would appreciate it if you would address us first so that we can try to resolve your concerns. You can always contact us easily by e-mail, email@example.com or on our infoline, +420 220 991 111.
This Personal Data Protection Policy, including its parts is valid and effective from 20 November 2018 and it is available in electronic form at www.greatebike.eu.