foto foto foto foto

DECLARATION ON DATA PROTECTION

1. INTRODUCTION

This Declaration on data protection applies to the processing of all personal data of the consumers, customers, vendors and business partners (“business partners”) of Zátiší Catering Group a.s., registered office at Novotného lávka 200/5, 110 00 Prague 1, Company ID No. 15269574 (hereinafter referred to as “Our Company” or “we”). This Declaration on data protection does not apply to data related to business activity or to data about companies.

Our Company is the controller of the business partner’s personal data. This declaration states who we are and for what purposes we process your personal data and other information about you. If you have any questions, you can use the contact information at the end of this Declaration.

This Declaration on data protection is compiled in the scope required by legal regulations, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council, and is effective from 25 May 2018. The latest amendments were made on 15 May 2018. This Declaration may change over time and its current version is always published on our website. If any substantial changes are made, we will actively inform you of them.

2. FOR WHAT PURPOSES DO WE PROCESS YOUR PERSONAL DATA?

Our Company will process your personal data when conducting business transactions between you and Our Company, when you visit our website or application, or within other forms of contact with you.

A.    Answers to your questions

If you contact us, we will use your personal data in order to react and answer your questions.

For this purpose,

-        we process your personal data based on your consent, if you provide your personal data to us,

-        we process your name, contact details, your correspondence with us, your questions, and all other personal data which is required to answer your questions.

B.     Product and service development and improvement

We process your personal data in order to evaluate, analyse and improve our products and (customer) services. We use your personal data to analyse customer behaviour and make the corresponding changes to our products and services. When you use our website or application or enter or search for data via this website or application, we also process your personal data for the purpose of compiling analytic reports. We use your personal data to analyse customer behaviour and make the corresponding changes in our products and services in order to improve them. This means that we analyse how often you read our newsletters, how often you visit our website and application, which pages you click on and which products and services you purchase through our website and applications. In order to fill our database used for the aforementioned purposes, we may procure additional data from public sources.

For this purpose,

-        we process your personal data based on our legitimate interest, in order to improve our products and services

-        we process your contact data such as your address and e-mail address, personal data such as your name and date of birth, information about payments and credibility, and correspondence with Our Company. We also process the personal data which you entered on our website or which were generated when using our website, the technical data of your device such as its IP address, the pages you visited on our website, information about which pages you click on and browse, and the duration of your visit on our website.

-        If you decide to participate in our surveys, we may ask you to provide us with your personal data, such as your address, e-mail address, name and date of birth. For this purpose, we may also use the personal data which you gave us within one of the surveys.

C.    Evaluation and acceptance of the customer, vendor or business partners

If you contact us, we will process your personal data for the purpose of confirming and verifying your identity and also for evaluating and verifying the possibility of further cooperation. Our company will also process your personal data for administrative purposes, such as control and comparison with the records available in public registers of the state and supervisory authorities.

For this purpose,

-        we process personal data because it is necessary to conclude the agreement between you and Our Company. Our Company cannot concluded agreements without obtaining the required information,

-        we process your contact data such as your address and e-mail address, personal data such as your name and date of birth, information about payments and credibility, and details about your correspondence with Our Company.

D.    Concluding and performing agreements

If you have purchased a product or service from us as a customer or cooperate with us as a vendor or business partner, we process your personal data for administrative purposes, such as the sending of invoices and making payments. We also use your personal data in order to deliver, accept and manage our or your products and services. Our Company will process your personal data for the purpose of further performance of our agreement, including the delivery of customer services. If you access Our Company’s premises, we will process your personal data for the purpose of control.

            For this purpose,

-        we process personal data because it is necessary to conclude the agreement between you and Our Company. Our Company cannot concluded agreements without obtaining the required information,

-        we process your contact data such as your address and e-mail address, personal data such as your name and date of birth, payment information and details about your correspondence with Our Company.

E.     Relationship and marketing management

We use the information stored in our customer database in order to send you suitable offers and newsletters, and for the purpose of providing customer services, managing accounts and sending news. We also use your personal data for the purpose of developing, conducting and analysing market surveys and marketing strategies.

            For this purpose,

-        when sending newsletters and/or marketing and other mutual communication, we process your personal data based on your consent. Additionally, we process personal data based on our legitimate interest for the purpose of improving our marketing strategy,

-        we process your contact data such as your address and e-mail address, personal data such as your name, contact preferences, payment information, order history and correspondence with Our Company.

F.     Business activities and internal management

We process your personal data when conducting and organising our business activity. This includes general governance, order management and our asset management. Our company also processes your personal data for the purpose of internal management. We conduct audits, investigations, business inspections and manage and use the directories of customers, vendors and business partners. We also process your personal data for the purpose of financial management and accounting, archiving and insurance, legal and business consultancy and for resolving disputes.

For this purpose,

-        we process personal data based on our legitimate interest, in order to maintain and develop business activities,

-        we process your contact data such as your address and e-mail address, personal data such as your name, payment information, order and payment history and correspondence with Our Company, and data generated in the course of performing the agreement concluded between you and Our Company.

G.    Organisational analyses and development, management reports, acquisitions and sales

At our company, we process your personal data in order to be able to prepare and submit reports and analyses. We use aggregated/anonymised personal data for the purpose of processing reports for Our Company’s management and for analysing our business activities. We conduct surveys among customers, suppliers and business partners, in order to obtain more information about your opinions within the preparation of our reports for Our Company’s management. We also process your personal data for the purpose of submitting reports to our management concerning mergers, acquisitions and sales, for the purpose of implementing these transactions.

For this purpose,

-        we process personal data based on our legitimate interest, in order to maintain and develop business activities,

-        we process your contact data such as your address and e-mail address, personal data such as your name and date of birth, order and payment history, correspondence with Our Company and information which you provided to us within the surveys.

H.    Use of our website or applications

If you use our website, we process technical data so that you can use the functions of our website and in order to allow our website administrators to manage and improve its functioning. If you enter data into our website, such as your product preferences or your location to accept information or functions, Our Company will process these data for the purpose of providing the requested information or functions. We also process your personal data in order to enable you to store your data (such as products and preferences) into your saved items and allow you to share them with others in the scope of the sharing option, which you set in your device.

For this purpose,

-        we process personal data based on our legitimate interest to create and make accessible a technically suitable, functional website and to improve the functions of our website,

-        we process the personal data which you entered via the website or which were generated when using Our Company’s website, the technical data of your device such as its IP address, the internet browser you use, the pages you visited on our website, information about which pages you click on and browse, and the duration of your visit on our website.

I.      Enabling your contact with us

Our Company is active on social media platforms such as Facebook, Twitter, LinkedIn and YouTube. If you contact Our Company via social media, we will process your personal data for the purpose of answering your questions and responding to your messages.

Moreover, if you use the “Contact” tab on our website or applications, you may contact us via various communication channels, for instance via the e-mail address, in order to send us your feedback and suggestions for improvement, as well as links to our website or data about the Facebook network.

For this purpose,

-        we process personal data based on our legitimate interest, in order to react adequately to your questions and refer you to our social media pages,

-        we process the communication channels which you chose to use to communicate with us, and the personal data which you provided to Our Company. This includes your (user) name, address, e-mail address and the personal data you provided in the messages. Moreover, if you use the links to the websites or applications of third parties, the respective third party may also insert cookies into your device.

 J.      Monitoring and control

We monitor our processes in order to verify the fulfilment of our guidelines and regulations. In the course of monitoring activity, we may gain access to your personal data and become familiar with them.    

For this purpose,

-        we may process your personal data based on our legitimate interest in monitoring our internal processes and complying with the law,

-        we may gain access to your personal data, which are stored in our systems and may be reviewed in order to control compliance with legal regulations. The personal data which we will have access to and which will be controlled will not be stored for reasons of complying with regulations, except for cases when we need them for the further investigation of potential non-compliance with regulations,

-        we will not store your personal data for this purpose if they are unrelated to potential non-compliance. In this case, we will store your personal data until the respective investigations or proceedings have been concluded.

K.    Protection of health, safety and ensuring integrity 

At Our Company, we greatly value your health, protection, safety and integrity. We process your personal data for the purpose of ensuring the safety of our employees, customers, vendors and business partners. For this reason, we verify your authorisation to access our premises and may check your personal data against the records available in the public registers of state and supervisory authorities. We also process your personal data to ensure the protection of Our Company and our employees and customers.

 

For this purpose,

-        we may process your personal data based on our legitimate interest in monitoring our internal processes and complying with the law,

-        we process your contact data such as your address and e-mail address, personal data such as your name and date of birth, order and payment history and the history of your visits to our premises.

L.     Compliance with regulations

In some cases, we process your personal data in order to comply with laws and other legal regulations, e.g. to fulfil our tax duties and legal obligations related to business activity. In the cases stipulated by the valid laws and other regulations, we may be obliged to disclose your personal data to the administrative or supervisory authorities.

For this purpose,

-        we process your personal data to ensure compliance with the valid legal regulations,

-        we process your contact data such as your address and e-mail address, personal data such as your name and date of birth, order and payment history, details about VAT and other taxes.

M.   Participation in promo and other events 

We send you information about promo events and invitations to participate in various activities. If you decide to participate in any of these activities, we will need your personal data in order to be able to organise them. Moreover, if you participate in any of these activities, we will need your personal data to evaluate the respective promo or other event.

For this purpose,

-        We process your personal data based on your consent. You may revoke your consent at any time without this impacting the legality of processing based on your consent before such revocation,

-        we process your name, address, e-mail address and records of the respective event.

 

3. HOW LONG DO WE STORE PERSONAL DATA?

Our Company will generally store data about business partners only for the period required for the respective business purpose, in the scope necessary to fulfil the requirements of the valid legal regulations.

Immediately after the respective period for storing data expires, the data will be:

(i)    securely deleted or destroyed,

(ii)   anonymised,

(iii) submitted to the archive (unless prohibited by law or the valid shredding plan).

4. WHO HAS ACESS TO YOUR PERSONAL DATA?

Access to your personal data within Our Company

Your personal data may be transferred among shareholders and among companies affiliated with our company. We provide your information for administrative purposes, so as to have a complete overview of your agreements with the affiliated companies to which Our Company belongs. We may also provide your data with the aim of offering you complete packages of services and products.

Our Company employees are authorised to access personal data exclusively in the scope required for the stipulated purposes and to fulfil their work duties.

Third-party access to your personal data

If necessary for the provision of products and services by Our Company, your personal data may also be accessed by the following third parties: banks, insurance companies, IT providers, accountants, consultants and other entities that may process your data in the scope necessary to ensure the activities of Our Company.

If a third party gains access to your personal data, Our Company will adopt contractual, technical and organisational measures to ensure that your personal data are processed only in the scope in which such processing is necessary. The third parties will process your personal data exclusively in accordance with the valid legislation.

If the personal data are provided to a third party in a country which does not ensure an adequate level of personal data protection, we will adopt measures to ensure the adequate protection of your personal data, e.g. by negotiating standard EU contractual conditions with these third parties.

In other cases, your personal data will be provided to third parties only if this is required by valid legal regulations.

5. HOW ARE YOUR PERSONAL DATA SECURED

We have introduced corresponding security measures to ensure the preservation of confidentiality and security of your personal data. We have introduced corresponding technical, physical and organisational measures to protect personal data from accidental and unlawful destruction or accidental loss, damage, modification, unauthorised publication or access, as well as all other forms of unlawful processing (including excessive gathering).

 

6.  HOW CAN YOU EXERCISE YOUR RIGHTS TO PROTECTION OF PRIVACY?

You have the right to request access to your personal data or a review thereof and under certain circumstances, also the right to the correction or deletion of personal data. You also have the right to request the restriction of processing of your personal data, the right to object to processing, and the right to data portability.

To exercise your rights to the protection of privacy, please contact us using the contact details provided in the final part of this declaration on data protection. Please take into account that for the purpose of further communication, we may ask you for additional information in order to verify your identity.

 

7.   CAN YOU REVOKE YOUR CONSENT?

You can always revoke your granted consent. Please take into account that such revocation will not have a retrospective impact. To revoke your consent, please contact us using the contact details provided in the final part of this declaration on data protection.

8.   HOW TO MAKE A COMPLAINT?

If you have a complaint regarding the use of your personal data by Our Company, you can make this complaint via the contact person, whose data is provided in the final part of this declaration. In addition to filing a complaint with Our Company, you may also address your complaint to the supervisory authority - Office for Personal Data Protection, Pplk. Sochora 727/27, 170 00 Prague 7 - Holešovice, https://www.uoou.cz/.

9.   HOW TO CONTACT US?

If you have any questions regarding the manner in which we process personal data, please read this declaration first. If you have any additional question, please contact us at: zatisiclub,zatisigroup,cz, marketing,zatisigroup,cz.

I confirm that I have become familiar with the content of this declaration and consent to the processing of my personal data for the purposes, in the scope and manner stipulated in this declaration.