Principles relating to processing of personal and other data
On this website, you can find a summary on the ways how Bomma processes personal data, and the main principles of protection of your personal data and other processed data in accord to General Data Protection Regulation (GDPR).
What is GDPR
GDPR, or General Data Protection Regulation, came into force on 25 May 2018 and it presents a new legal framework for protection of personal data with the objective to protect as much as possible the rights of EU citizens against unauthorized use of their data, including their personal data. GDPR applies to every company, but also to individual (persons) and online services that process the data of their users.
Who processes your information
Administrator of your personal data is the company Bohemia Machine s.r.o., IČ: 45537011, Zámecká 1177, 582 91 Světlá nad Sázavou, registered in the commercial register that is administered by the Regional Court in Hradec Králové, file C1592. These data will be processed by the company (Administrator) in accordance with hereinafter defined conditions. Administrator can be contacted via e-mail at email@example.com.
What kind of personal data do we process
We process solely the personal information that you provide us in relation to the use of our services (e.g. subscription to our newsletter or purchase of our goods), and/or in case of concluding a purchase contract for a purchase of our goods.
The processed data are thus the data that you share with us in the process of registration to the following services:
- first name and surname (if you give us the information when ordering our goods),
- contact and/or delivery address (given to us for the purpose of shipping of ordered goods),
- telephone number (given to us for the purpose of shipping of ordered goods or in order to provide you with the information about the status of your order),
- payment data (number of your payment card) saved to your account (given to us only in the case of purchase on our e-shop),
- other data that you voluntarily provide us with, for example when completing a contact form,
as well as the data that we acquire by your usage of our website:
- IP address,
- cookie files (in the case of online services),
- or another online identifier.
Why do we process your personal data
Your personal data are processed mainly for the following reasons:
- to provide you with the services for which you have shown your interest (such as order or purchase of our goods on e-shop, or subscription to our newsletter),
- to enhance the quality of our services or, as the case may be, to extend the range of services provided by us, for which you have shown interest,
- to analyze and measure your interest in our services and products,
- to analyze your preferences and in accordance with the results of our analysis show you the content that you are really interested in,
- to gain advantages for the organization of our marketing campaigns,
- to send you commercial messages in the form of newsletters. In newsletters, you can find invitations to events that we organize, pieces of news and/or special offers. We don’t send them more often than once a month. However, if you wish to unsubscribe from receiving our newsletters you can do so by clicking on the ‘unsubscribe’ button in newsletter, or via e-mail at firstname.lastname@example.org.
- to provide you with answers to your questions that you have sent to us via our contact forms.
By giving us consent to process your personal data, we will be able to continue with providing you the aforementioned services.
Who can access your data
It is important to us that your personal data are safe. We cooperate exclusively with partners who are provably credible and who are able to guarantee the security of your personal data. None of our partners can use your personal data for other purposes then the aforementioned purposes, and they cannot disclose your personal data to another party.
Third parties that can have access to your personal data are:
- persons that perform an analysis of audience of our sites,
- persons that provide us with technical operations for certain services, and/or providers of technologies that we use for our services,
- persons that provide us with adequate security and integrity of our services and websites, and that test regularly this security and integrity of our services and websites,
- providers of payment gateways (providers of payment cards) in case of online payments,
- providers of transportation services that deliver you your goods,
- providers of technological solutions that help us to show you content and advertisements that are relevant to you.
There are some given legal conditions under which we are obliged to pass your personal data in accord to currently valid legislation to authorities such as the Police of Czech Republic, and/or to other authorities that are involved in criminal procedures, including specialized departments and other bodies of public administration.
What are cookies and what kinds of cookies do we use
Just as any other website, our website Bomma.cz uses as well cookie files. Cookie files are text files that contain small amount of information that are downloaded to your computer, mobile phone or another device upon visiting a website. Upon every following visit of the website the cookie files are sent back to the original website or any other website that recognizes them.
You, as an individual person, are not identifiable on the basis of these information and you are not identifiable even with the usage of other information we have about you. Cookie files store such a type of information as is the type of your device and browser, language preferences or the websites that you have visited. Thanks to the cookie files you see advertisements on products that are in accordance to you personal interests and preferences.
Cookie files are used for recognition of repeated visits of our websites. Cookie file stores the preferential local and language settings of the user and a randomly assigned identifier of your visit. The information from the cookie file are stored on our website, so that we can better monitor the numbers of our new and returning visitors and so that we can perform internal analysis of the visited websites. These information are used to improve the navigation on our website and to improve the quality of the services that we provide you with.
Another group of these are third party cookie files (e.g. Google Analytics for the analysis of the volume of visitors of a specific website, and/or cookies of providers of advertisement systems that are used on our website). These cookies are operated by third parties and we do not have the access to read or store this information.
Most web browsers do accept cookie files automatically as it is accepted in initial setting of the browser, however by changing the settings of your web browser, it is possible to disable cookies entirely, or accept selectively only certain types of cookie files. If you decide to disable cookies entirely, some part of our website may not be accessible, and/or they may not be displayed correctly.
Detailed information about can be found here: aboutcookies.org.
If your web browser accepts cookies, we assume that you agree with use of standard cookies by our websites.
If you do not wish to store these cookies you can disable them on this website:
For how long do we process your data
Your data are going to be processed for the whole period of time that you use our services (i.e. for the duration of the contractual relations between you and us) and subsequently based on your consent for the period of the 3 additional years, unless you retract your consent with the processing of your personal data. We our obliged by law to store your invoice data for 5 years.
Can we process your personal data without your consent?
Yes, we can process your personal data without your consent, but solely for the following purposes
- provision of a service or of a product (fulfillment of contract that was concluded between you and us; take into consideration that by contract is understood also an actual usage of a certain service without the need of signing anything);
- fulfillment of legal obligations that arise for us from the validity of acts of general application (e.g. we are obliged to store traffic and location data under Law No 127/2005 on electronic communications); or
- processing that is indispensable to achieve our legitimate interests (e.g. for the purposes of direct marketing, ensuring security of our websites).
The possibility and legality of such processing of data is in accordance with the legislation in force and your consent is not required.
On what basis do we process your personal data
We can process your data:
- on the basis of your granted consent,
- on the basis of legitimate interest (especially processing of the data for the purposes of direct marketing),
- for the performance of the contract that we have concluded, the scope of the data that we may process is limited only to those personal data that are indispensable for performance of the contract,
- to fulfill the obligations that are imposed upon us by law.
Protection of your personal data
All of the personal data that you share with us are protected by standard means and technologies. Our system is controlled on a regular basis and we use such security measures so that, as much as possible, there is no unauthorized access to your personal data. Our security measures provide a sufficient protection in regard to the current state of technologies. For the purpose of even better protection of your personal data is the access to your data protected by a password and sensitive data are encrypted during the transfer from your web browser to our websites.
Withdrawal of consent regarding the processing of your personal data
Your voluntarily given consent regarding the processing of your personal data can be from at any time and at no cost. You can withdraw your consent via e-mail message sent to the address: email@example.com.
The withdrawal of your consent does not affect the possibility to continue to process your personal data that we are already processing on the basis of the consent given before the withdrawal. The withdrawal of your consent also does not affect the processing of the personal data that are being processed on other legal basis than is the declaration of consent (i.e. especially if the processing is indispensable for performance of the contract, legal duties or other reasons that are stated in the legislation in force).
Am I obliged to share my personal information? What if I decide not to share my personal information?
Your personal data are shared with us voluntarily. Their processing, often in in an anonymized form which disallows us to identify you as a specific user, allows us to provide you with our services and improve them all the time. If you do not give us your consent, or you withdraw from it, it is possible that we will not be able to provide you anymore with our services, and/or we will not be able to provide you with the services in their full scope and quality. However, it is not your duty to use our cost-free services.
Your rights in relation to protection of personal data
In relation to your personal data, you have the following rights:
- the right to withdraw you consent at any time;
- the right to correct and/or add your personal data;
- the right to ask for limited scope of processing of your data;
- the right to challenge or complain to the processing in certain cases;
- the right to ask for transmission of your data;
- the right to access your personal data;
- the right to be informed about the violation of protection of personal data in certain cases;
- the right for the deletion of your personal data (the right to be “forgotten”) in some cases;
- other rights the rights set out in the law on the protection of personal data and in the general regulation on privacy no. 2016/679 after its entry into force.
How you can contact us
In the case of any questions regarding the protection of personal data and/or withdrawal form your consent with the subsequent processing of your personal data, please contact us via e-mail at firstname.lastname@example.org.