Privacy Policy

The principles of personal data protection in the internet shop and application thereof to processing of personal data

The principles of personal data protection are an executive summary of operator´s processing of personal data. The controller ensures that personal data are protected to the maximum extent possible to ensure that their processing is only to the extent and time necessary.

Definitions

Data subject – each person whose personal data are being processed.

E-shop – web application offering products and services which may be booked.

Shop – Seller´s business premises where products or services may be purchased.

Personal data – any information related to the natural person, which is thus identified or identifiable.

Controller – person which determined the means and defined the purpose of processing of personal data.

Information about the controller and its contacts

Personal data are being processed by the controller and its mediators. The controller is IDD Bratislava – Engineering and Supply Cooperative, registered seat Myjavská 16, 811 03 Bratislava.

ID-Number: 00585912, the controller determines the means and purpose for processing personal data of customers and is responsible for processing of collected personal data. For enquiries regarding personal data contact us please by:

  1. Phone: +421903653234
  2. E-mail: sabi@idd.sk
  3. Post at the above registered seat
  4. Personally in our business premises.

List of processed personal data including purposes and legal basis thereof

Name of processing operation Purpose for processing of personal data Category of personal data Legal basis for processing of personal data Data storage period Other recipients of personal data
Processing of personal data based on the Purchase Order Supply of goods or services Name, surname, shipping address, invoice address, e-mail, phone Contractual relation – contract performance Up to expiry of warranty period, i. e. two years Carriers providing transport of goods
Invoicing and archiving thereof Statutory records Name, surname, shipping address, invoice address, e-mail, phone Statutory obligation 10 years Inspection by Financial Administration of the Slovak Republic, Slovak Trade Inspection, Slovak Police Force in particular, as well as by other authorities
Customer Account Registration Record of customer´s personal data as basis for other POs that can be thus made faster Name, surname, shipping address, invoice address, e-mail, phone Consent to the registration by the data subject 5 years Non applicable
E-mailing of Newsletters E-mailing of business notification e-mail Consent by the data subject 5 years or until revocation Non applicable
News sent via DM Business notifications sent via DM Phone number Consent by the data subject 5 years or until revocation Non applicable
Business Partners Information about business partners Name, surname, car plate, e-mail, phone Consent by the data subject 5 years after the last business deal Non applicable
Job applicant Data from job applicants´ resumés Name, surname, academic title, education, e-mail, phone, professional experience Consent by the data subject 1 year Non applicable
Payroll and HR All information required by law about employee, including salary, vacation, health Name, surname, academic title, ID-card No., attendance, information for wage calculation information about family members Legal reason Maximum 50 years For inspection by the Social Insurance Agency, Financial Directorate of the Slovak Republic, health service insurance companies
File of complaints Information about complaints sent and handling thereof Academic title, name, surname, address, IBAN, phone, e-mail Statutory obligation of the controller 3 years For the inspection by Slovak Trade Inspection SOI
File of withdrawals from contracts Information about withdrawals from contracts and handling thereof Academic title, name, surname, address, IBAN, phone, e-mail Controller´s legitimate interest 3 years For the inspection by Slovak Trade Inspection SOI
Handling of customers´ enquiries Providing customers with information Title, name, surname, phone, e-mail Performance of precontractual relations 1 month Non applicable
Transfer of data about viewed websites Enhancement of the e-shop´s quality IP-address of the e-shop´s visitor Controller´s legitimate interest After lodging objection max. 3 years Google
Transfer of information for payment Transfer of data necessary for payment transaction e-mail, PO No, PO value For purposes of performance of the contract One-time data provisioning Bank Tatra Banka a.s.
Information about viewed websites and customer behavior thereon The service enhances the e-shop´s quality IP address and simulated visit to the website Controller´s legitimate interest After lodging objection and max. 2 years Smartlook
Customer loyalty program Discounts for frequent customers Name, surname, title, permanent residence, e-mail and phone Consent by the data subject 5 years long after the last purchase Non applicable

All data are exclusively collected and requested from you. We use no other resources for data collection.

What rights do you have in the field of personal data protection?

Your right Legal clarification
Right of information You have the right to get information about who, how, for what purpose, how long, etc. processes your personal data (the information is published in this document)
Right to access data You can request information about who can access your personal data. The extract from this right is in the format we have made. You can request the information in writing or via e-mail.
Right to rectification If your personal data are inaccurate, you can ask for rectification thereof. Personal data will be thus accurate and can be used for further processing.
Right to erasure If you don´t wish any further processing of your personal data by the controller, you can ask for erasure thereof and the controller shall erase them. This shall not apply if processing and archiving of personal data are statutory obligation.
Right to restriction shall only apply if data are processed due to legitimate interest of the controller. If you object, this right may apply during the time of assessment of your objection It means that personal data will not be processed at that time.
Right to revoke consent may be exerted if such consent has been given, but the data subject does not intend on having his/her data processed based on his/her consent. The data subject can revoke his/her consent and the controller shall not process his/her personal data anymore.
Right to data portability You may only request data portability based on the consent by data subject or in order to perform contractual or precontractual relations.
Right to lodge a complaint with supervisory authority if you assume that your personal data have been processed in violation of the law or the Directive, you have the right to lodge a complaint with the supervisory data protection authority: Úrad na ochranu osobných údajov Slovenskej republiky, https://dataprotection.gov.sk/

How can you exert your rights?

You can exert your right as follows:

  1. by e-mail,
  2. in person,
  3. by post.

The controller has the right to request a reasonable cost refund from the data subject. The controller has the right to reject such request from the data subject provided that the reasons given should be proven as unsubstantiated, unreasonable or if requests are repetitive.

How do we secure protection and store data?

Personal data are protected against unauthorized persons, destruction, damages or loss both offline and online. We have taken complex electronic, organizational and physical measures.

Any use of profiling?

We do not use profiling.

What is your policy on the use of small text files, the so-called cookies?

While browsing the website, cookies are created and placed on your computer. Thanks to cookies we can identify you among other users and thus we can tailor more intuitive browsing and content of the website. We collect the following timely cookies:

  1. Temporary – they only contain information about the current browser relation. Temporary cookies are automatically deleted when you disable the browser.
  2. Permanent – they contain information about preferred settings (e.g. language) or they save your name and password for the website if you agree thereto. The cookies will not be automatically deleted. You can delete them manually.

With regard to their purpose, we divide cookies as follows:

  1. Technical or functional cookies – (belong to temporary cookies) contain inevitable information about the website like its security, etc.
  2. Preference cookies – are substantial for the correct functionality of the website. They contain information about the selected language or your login data (if you agreed thereto).
  3. Analytical / performance cookies – identify visitors and collect statistical and analytical data. Thanks to these cookies we are able to count the number of visitors or stock up with high demand products or reduce price thereof.
  4. Advertising cookies – keep track of your website visits, views or products for the purposes of showing more precisely targeted advertising. You provide data voluntarily. However, some files are permanent, i.e. they are not automatically deleted. It is upon you to delete them manually.

You can set cookies under settings of your browser and on our website.

Na správu súborov cookie a podobných technológií (sledovacie pixely, webové signály atď.) a súvisiacich súhlasov používame nástroj na udeľovanie súhlasov „Real Cookie Banner“. Podrobnosti o fungovaní nástroja „Real Cookie Banner“ nájdete na stránke <a href="“https://devowl.io/rcb/data-processing/“" rel="“noreferrer“" target="“_blank“">https://devowl.io/rcb/data-processing/</a>.

Právnym základom pre spracúvanie osobných údajov v tejto súvislosti je čl. 6 ods. 1 písm. c GDPR a čl. 6 ods. 1 písm. f GDPR. Naším oprávneným záujmom je správa používaných súborov cookie a podobných technológií a súvisiacich súhlasov.

Poskytnutie osobných údajov nie je zmluvne požadované ani nevyhnutné na uzavretie zmluvy. Nie ste povinní poskytnúť osobné údaje. Ak osobné údaje neposkytnete, nebudeme môcť spravovať vaše súhlasy.

Cookies storage period of the following entities:

Cookie Subgroup Life cycle Note
Website Relation Functional
Google Analytics 1,460 days Analytical tool

Who can access my personal data in general?

Your personal data can be accessed by employees, operators and their contractual mediators or recipients, as e.g. shipping companies. Our employees have been instructed by the company´s regulation and they are obliged to strictly follow the rules of your personal data protection. The same applies to our contracted mediators.

Which statutory rules apply to personal data protection?

It includes:

  • The Charter of Fundamental Rights of the European Union,
  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, GDPR),
  • Constitution of the Slovak Republic,
  • Personal Data Protection Act No. 18/2018 Coll. as amended

Who is your data protection officer?

Our company has not appointed any data protection officer as it is no statutory obligation in our case. If you require any information regarding personal data, feel free to contact our company, please.

Who is your service provider?

System administration (including website administration)

  1. IDD Bratislava - Inžiniersko dodávateľské družstvo, registered seat at Myjavská 16, 811 03 Bratislava, data localization: Slovak Republic.

Customer/User account administration (users´ registration, password generation, etc.)

  1. IDD Bratislava - Inžiniersko dodávateľské družstvo, registered seat at Myjavská 16, 811 03 Bratislava, data localization: Slovak Republic.

Complaint management, management of withdrawals from contracts, issuing of invoices, dispatching of goods

  1. IDD Bratislava - Inžiniersko dodávateľské družstvo, registered seat at Myjavská 16, 811 03 Bratislava, data localization: Slovak Republic.

E-mailing news (sending newsletters)

  1.  IDD Bratislava - Inžiniersko dodávateľské družstvo, registered seat at Myjavská 16, 811 03 Bratislava, data localization: Slovak Republic.
  2. The Rocket Science Group LLC d/b/a Mailchimp, 675 Ponce de Leon Ave NE, Suite 5000 Atlanta, data localization: USA (without access to personal data and without additional authorization of account administrator).

Sending news via DM (DM newsletter)

  1. IDD Bratislava - Inžiniersko dodávateľské družstvo, registered seat at Myjavská 16, 811 03 Bratislava, data localization: Slovak Republic.

Data storage (hosting services)

  1. Websupport, s.r.o., Staré Grunty 12, 841 04 Bratislava, data localization: Slovak Republic.
  2. Google Ireland Limited, Barrow Street, Dublin 4, Ireland, data localization: USA (without access to personal data and without additional authorization of account administrator).

In charge for accounting and payroll (statutory obligation of the controller/operator)

  1. IDD Bratislava - Inžiniersko dodávateľské družstvo, registered seat at Myjavská 16, 811 03 Bratislava, data localization: Slovak Republic.

May I purchase even if I am under the age of 16?

No. This e-shop can only be used by users over 16 years of age, however, if your parent allowed you to use our website and to purchase thereon, then you may purchase.

Nákupný košík
Návrat hore