Terms of personal data protection + GDPR
Processing of personal data
I.
Basic provisions
1. The controller of personal data pursuant to Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as “GDPR”) is THEFINALSECTION s.r.o. Company ID: 19220774 with its registered office at Lidická 700/19, Veveří, 60200 Brno (hereinafter referred to as “Controller”).
2. The contact details of the Controller are
Address: Lidická 700/19, 602 00 Brno, Czech Republic
email: diox@dioxproducts.com
telephone: +420 778 554 339
3. Personal data means all information about an identified or identifiable natural person; an identifiable natural person is a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
4. The controller has not appointed a data protection officer.
II.
Sources and categories of personal data processed
1. The Administrator processes the personal data that you have provided to him or the personal data that the Administrator has obtained based on the fulfillment of your order.
2. The Administrator processes your identification and contact data and data necessary for the fulfillment of the contract.
3. The Administrator processes the personal data that you have provided to him or the personal data that the Administrator has obtained based on the registration on the e-shop.
4. The Administrator processes the personal data that you have provided to him or the personal data that the Administrator has obtained based on the registration to receive news and marketing communications.
III.
Legal basis and purpose of processing personal data
1. The legal basis for processing personal data is:
the legitimate interest of the controller in providing direct marketing (in particular for sending commercial communications and newsletters) pursuant to Article 6(1)(f) of the GDPR,
Your consent to processing for the purposes of providing direct marketing (in particular for sending commercial communications and newsletters) pursuant to Article 6(1)(a) of the GDPR in conjunction with Section 7(2) of Act No. 480/2004 Coll., on certain information society services, in the event that no order for goods or services has been placed.
2. The purpose of processing personal data is
to process your order and exercise the rights and obligations arising from the contractual relationship between you and the controller; When placing an order, personal data is required that is necessary for the successful processing of the order (name and address, contact), the provision of personal data is a necessary requirement for the conclusion and performance of the contract, without the provision of personal data it is not possible to conclude the contract or to perform it by the controller,
sending commercial communications and carrying out other marketing activities.
3. The controller does not make automatic individual decisions within the meaning of Article 22 of the GDPR.
IV.
Data retention period
1. The administrator stores personal data
for the period necessary to exercise the rights and obligations arising from the contractual relationship between you and the administrator and to assert claims from these contractual relationships (for a period of 10 years from the termination of the contractual relationship).
for the period until the consent to the processing of personal data for marketing purposes is revoked, for a maximum of 10 years if the personal data is processed on the basis of consent.
2. After the expiry of the personal data storage period, the administrator deletes the personal data.
V.
Recipients of personal data (subcontractors of the controller)
1. Recipients of personal data are persons
1. Recipients of personal data are persons involved in the delivery of goods / services / payment under the contract, providing e-shop operation services (and other services in connection with the operation of the e-shop, providing marketing services.
Namely, these are the services:
Shoptetpay / shoptet.eu - Dvořeckého 628/8 169 00 Prague 6 Czech Republic IČ: 28935675 - processing of online payments and operator of the e-shop platform for the website www.dioxproducts.com.
Google LLC - Processing of services for searching for content on google.com, advertising services (cookies) Google Ads, Google Analytics and other systems for optimizing website data
Heureka Group a.s. - Karolinská 706/3 186 00 Prague 8 – Karlín Czech Republic B 24131 registered with the Municipal Court in Prague IČO: 07822774 DIČ: CZ07822774 - The service is not a recipient of personal data from the website www.dioxproducts.com. It only provides products for sales activities and also provides reviews from the website Heureka.sk / Heureka.cz to the website www.dioxproducts.com
Meta Platforms Inc 1 Meta Way, Menlo Park, California, 94025, USA - operator of social networks Facebook, Instagram, Whatsapp, Messenger. The service is not a recipient of personal data from the website www.dioxproducts.com.
Carriers: - Slovak Post, a.s. Partizánska cesta 9 975 99 Banská Bystrica, Slovak Republic
- Czech Post, s. p. Prague 1, Politických vězňů 909/4, 225 99, Czech Republic
- Zásilkovna s.r.o. Českomoravská 2408/1a 190 00 Prague 9, Czech Republic IČ: 28408306 DIČ: CZ28408306 and their suppliers and subcontractors of courier services
- Packeta Slovakia s. r. o. Sliačska 1E 831 02 Bratislava – mestská časť Nové Mesto, Slovak Republic IČO: 48136999 DIČ: 2120099014 and their suppliers and subcontractors of courier services
are recipients of personal data, only those that are strictly necessary for the delivery of the customer's order based on the created order. Namely: Name, Surname, Address, Telephone contact, e-mail in the case of cash on delivery or cash payment and method of payment.
2. The Administrator does not intend to transfer personal data to a third country (to a country outside the EU) or an international organization.
VI.
Your rights
1. Under the conditions set out in the GDPR, you have
the right to access your personal data pursuant to Article 15 GDPR,
the right to rectify personal data pursuant to Article 16 GDPR, or to restrict processing pursuant to Article 18 GDPR.
the right to erase personal data pursuant to Article 17 GDPR.
the right to object to processing pursuant to Article 21 GDPR
the right to data portability pursuant to Article 20 GDPR.
the right to withdraw consent to processing in writing or electronically to the address or email of the controller specified in Article III of these terms and conditions.
2. You also have the right to file a complaint with the Office for Personal Data Protection if you believe that your right to personal data protection has been violated.
VII.
Personal data security conditions
1. The Administrator declares that it has taken all appropriate technical and organizational measures to secure personal data.
2. The Administrator has taken technical measures to secure data storage and personal data storage in paper form, in particular locks, passwords, data encryption and data backup.
3. The Administrator declares that only persons authorized by him have access to personal data.
VIII.
Purchase evaluation on third-party portals
We determine your satisfaction with your purchase through e-mail questionnaires within the Heureka - Verified by Customers program, Zbozi.cz satisfaction questionnaires and Google satisfaction questionnaire, in which our e-shop is involved. We send these to you every time you make a purchase from us, unless you refuse to receive them pursuant to Section 7(3) of Act No. 480/2004 Coll. on certain information society services. We process personal data for the purposes of sending questionnaires within these programs on the basis of our legitimate interest, which consists in determining your satisfaction with your purchase from us. To send questionnaires, evaluate your feedback and analyze our market position, we use a processor, which is the operator of the heureka.cz, heureka.sk zbozi.cz, google.com portal; for these purposes, we may provide information about the purchased goods and your e-mail address to it. When sending e-mail questionnaires, your personal data is not provided to any third party for its own purposes. You can object to the sending of e-mail questionnaires within these programs at any time by rejecting further questionnaires using the link in the questionnaire e-mail. In case of your objection, we will not send you the questionnaire again.
IX.
Final provisions
1. By submitting an order via the online order form, you confirm that you are familiar with the terms and conditions of personal data protection and that you accept them in full.
2. You agree to these terms and conditions by checking the consent via the online form. By checking the consent, you confirm that you are familiar with the terms and conditions of personal data protection and that you accept them in full.
3. The Administrator is entitled to change these terms and conditions. The Administrator will publish a new version of the terms and conditions of personal data protection on its website and will also send you a new version of these terms and conditions to your e-mail address that you have provided to the Administrator.
The terms and conditions are valid from 20.3.2025