This is a translation of the Czech original for information only. In the event of any discrepancy, the Czech version prevails.
High-Tech Digital Modules s.r.o., Company ID: 09368124, with its registered office at Zámecká 1936/18, Moravská Ostrava, 702 00 Ostrava, registered in the Commercial Register kept by the Regional Court in Ostrava under file no. C 82883, as the controller of personal data (hereinafter the "Controller"), hereby informs you as customers and users of the website: IN Laser World: https://dev.inlaserworld.cz/ and as a data subject (hereinafter the "Data Subject") about the collection of personal data and the privacy principles described below.
1. Introduction
This policy is drawn up in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "GDPR") and in accordance with Act No. 110/2019 Coll., on personal data processing.
Personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Other terms such as "special categories of personal data", "data subject", "processing of personal data", "controller", "processor", "risk processing", "automated individual decision-making including profiling" and "appropriate technical and organisational measures" have the meaning of, and are to be interpreted in accordance and in context with, the GDPR.
2. What personal data the Controller processes
The Controller processes the following data about the Data Subject:
- address and identification data: name, e-mail, telephone
- descriptive data: optionally (if provided by the Data Subject): height, weight, age
- game data (upon registration): data on activity and movement in the game
In order to improve the quality of its services, personalise its offering, collect anonymous data and for analytical purposes, the Controller uses so-called cookies in the application. By using the website, the Data Subject consents to the use of that technology.
Personal data may be stored for a period longer than stated in the table below if such data is processed solely for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes.
3. Purpose and legal basis of processing – processing period
| Personal data processed | Purpose of processing | Legal basis for processing | Processing period |
|---|---|---|---|
| name, e-mail, telephone descriptive data game data |
handling pre-orders and communication with the client regarding the conclusion of a contract | taking steps prior to entering into a contract (pre-contractual negotiations) | for the period strictly necessary for pre-contractual negotiations |
| your name and e-mail provided outside the performance of a contractual relationship, solely for newsletter subscribers | regular sending of commercial communications containing offers, information and news in accordance with Act No. 480/2004 Coll. | consent granted upon subscription to the newsletter | until consent is withdrawn; alternatively until the recipient unsubscribes |
4. Principles of personal data processing
The Controller processes personal data fairly, lawfully and transparently. This Policy informs the Data Subject of the scope, content and manner in which the Controller processes personal data.
The personal data processed by the Controller is adequate, relevant and limited to what is necessary in relation to the contractual relationship and the stated purpose.
The Controller needs the Data Subject's personal data to be accurate and up to date. If any of the data provided becomes out of date, the Data Subject is obliged to update it in their user account after registration.
The Controller processes personal data in a manner that ensures its appropriate security, including protection by suitable technical or organisational measures against unauthorised or unlawful processing and against accidental loss, destruction or damage.
5. Recipients of personal data and intention to transfer information
The Controller may also pass the Data Subject's personal data to a third party as a recipient. However, the Controller always proceeds in this way only in justified cases. The Controller may pass personal data to the following recipients:
- processors who process the Data Subject's personal data according to the Controller's instructions and whose relationships are governed in line with the requirements of Article 28 of the GDPR; for example providers of software used by the Controller to better secure and run its services; these will have access only to the extent necessary and for the purpose of administration and technical support of the software used;
- public authorities and other entities where required by applicable law;
- other entities in the event of an unexpected occurrence in which disclosure of the data is necessary to protect life, health, property or another public interest, or where it is necessary to protect our rights, property or safety.
The Controller does not intend to transfer personal data to a third country or an international organisation.
6. Rights of the Data Subject
The rights of the Data Subject are an important element of personal data protection. If the Data Subject invokes any of the rights listed below, the Controller will provide information on the measures taken without undue delay and in any event within one month of receiving the Data Subject's request. In exceptional cases the Controller may extend this period by up to two months. The Controller will inform the Data Subject of the extension and the reason for it.
Personal data is processed by automated means in electronic form.
The Data Subject has the right:
-
to be informed about the processing of personal data
The Controller provides information about the processing of personal data primarily through this personal data protection policy. -
of access to personal data
Upon request, the Data Subject will obtain from the Controller information (confirmation) as to whether or not their personal data is being processed. If it is being processed, the Data Subject has the right to obtain the following information: the purposes of processing; the categories of personal data concerned; the recipients or categories of recipients to whom the personal data has been or will be disclosed; the envisaged period for which the personal data will be stored; the existence of the right to request rectification or erasure of personal data from the Controller; the right to object; the right to lodge a complaint with a supervisory authority; any available information as to the source of the personal data where it is not collected from the Data Subject; the existence of automated decision-making, including profiling. Most of this information can be found in this personal data protection policy, but if the Data Subject wishes, they may also ask about the above. -
to rectification and completion
If the Data Subject knows or believes that the Controller is processing inaccurate personal data about them, the Data Subject may point this out and the Controller is obliged to rectify the data. If the Data Subject wishes to have incomplete personal data completed with regard to the purpose of processing, they may notify the Controller and the Controller is obliged to complete the data. -
to erasure
This right imposes on the Controller the obligation to destroy personal data in accordance with Article 17(1) of the GDPR if at least one of the following conditions is met:- the personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
- the Data Subject withdraws consent and there is no other legal ground for the processing;
- the Data Subject objects to the processing and there are no overriding legitimate grounds for the processing;
- the personal data has been unlawfully processed;
- the personal data must be erased for compliance with a legal obligation;
- the personal data has been collected in relation to the offer of information society services referred to in Article 8(1) of the GDPR;
-
to restriction of processing
Under this right, the Data Subject may ask the Controller to restrict the processing of personal data. Where the conditions under Article 18(1) of the GDPR are met, the Controller must do so. -
to data portability
The Data Subject has the right to receive, in particular to download, their personal data from the Controller in a structured, commonly used and machine-readable format, and further has the right to have the personal data transmitted directly to another controller. -
to object
In some cases the Data Subject may raise a so-called objection to processing. This concerns in particular situations where the Data Subject had no opportunity to influence the fact that their data is processed and, at the same time, the processing is not the fulfilment of a legal obligation or a vital interest that would justify that impossibility. The Data Subject may raise three types of objection to processing. These are objections to:- processing based on the legal ground of legitimate interest and the performance of a task carried out in the public interest or in the exercise of official authority;
- processing for direct marketing purposes based on the legal ground of legitimate interest;
- processing for scientific or historical research purposes or for statistical purposes.
-
not to be subject to automated individual decision-making, including
profiling
Automated individual decision-making never takes place when the Data Subject's personal data is processed, not even on the basis of profiling. -
to withdraw consent to the processing of personal data where the processing
is based on consent
The Data Subject may at any time withdraw consent to the processing of their personal data that is processed on the basis of that consent. -
to obtain information about a breach of the security of your personal
data
If a personal data breach at the Controller is likely to result in a high risk to the rights and freedoms of the Data Subject, the Controller will notify the Data Subject without undue delay. -
to lodge a complaint with a supervisory authority
If the Data Subject were to gain the impression that the Controller is breaching its obligations when processing their personal data, the Data Subject has the right to lodge a complaint with the Office for Personal Data Protection, with its registered office at Pplk. Sochora 27, 170 00 Prague 7, Czech Republic; e-mail: [email protected]; www: https://www.uoou.cz; tel.: +420 234 665 111.
7. Changes to the policy
The personal data protection policy may change over time. All changes to the personal data protection policy will be published in the application. If the changes are significant, the Controller may inform the Data Subject about them by e-mail.
8. Our contact details
If the Data Subject wishes to contact the Controller in connection with the processing of their personal data, they may use the following contacts:
- in writing to the registered office address: Zámecká 1936/18, Moravská Ostrava, 702 00 Ostrava, Czech Republic
- by e-mail to the e-mail address: [email protected]
This personal data protection policy takes effect and becomes valid on: 1 January 2022