Legal documents

Personal Data Protection Policy

Effective from 1 January 2022

This is a translation of the Czech original for information only. In the event of any discrepancy, the Czech version prevails.

High-Tech Digital Modules s.r.o., Company ID: 09368124, with its registered office at Zámecká 1936/18, Moravská Ostrava, 702 00 Ostrava, registered in the Commercial Register kept by the Regional Court in Ostrava under file no. C 82883, as the controller of personal data (hereinafter the "Controller"), hereby informs you as customers and users of the website: IN Laser World: https://dev.inlaserworld.cz/ and as a data subject (hereinafter the "Data Subject") about the collection of personal data and the privacy principles described below.

1. Introduction

1.1.

This policy is drawn up in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "GDPR") and in accordance with Act No. 110/2019 Coll., on personal data processing.

1.2.

Personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

1.3.

Other terms such as "special categories of personal data", "data subject", "processing of personal data", "controller", "processor", "risk processing", "automated individual decision-making including profiling" and "appropriate technical and organisational measures" have the meaning of, and are to be interpreted in accordance and in context with, the GDPR.

2. What personal data the Controller processes

2.1.

The Controller processes the following data about the Data Subject:

  1. address and identification data: name, e-mail, telephone
  2. descriptive data: optionally (if provided by the Data Subject): height, weight, age
  3. game data (upon registration): data on activity and movement in the game
2.2.

In order to improve the quality of its services, personalise its offering, collect anonymous data and for analytical purposes, the Controller uses so-called cookies in the application. By using the website, the Data Subject consents to the use of that technology.

2.3.

Personal data may be stored for a period longer than stated in the table below if such data is processed solely for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes.

3. Purpose and legal basis of processing – processing period

Personal data processed Purpose of processing Legal basis for processing Processing period
name, e-mail, telephone
descriptive data
game data
handling pre-orders and communication with the client regarding the conclusion of a contract taking steps prior to entering into a contract (pre-contractual negotiations) for the period strictly necessary for pre-contractual negotiations
your name and e-mail provided outside the performance of a contractual relationship, solely for newsletter subscribers regular sending of commercial communications containing offers, information and news in accordance with Act No. 480/2004 Coll. consent granted upon subscription to the newsletter until consent is withdrawn; alternatively until the recipient unsubscribes

4. Principles of personal data processing

4.1.

The Controller processes personal data fairly, lawfully and transparently. This Policy informs the Data Subject of the scope, content and manner in which the Controller processes personal data.

4.2.

The personal data processed by the Controller is adequate, relevant and limited to what is necessary in relation to the contractual relationship and the stated purpose.

4.3.

The Controller needs the Data Subject's personal data to be accurate and up to date. If any of the data provided becomes out of date, the Data Subject is obliged to update it in their user account after registration.

4.4.

The Controller processes personal data in a manner that ensures its appropriate security, including protection by suitable technical or organisational measures against unauthorised or unlawful processing and against accidental loss, destruction or damage.

5. Recipients of personal data and intention to transfer information

5.1.

The Controller may also pass the Data Subject's personal data to a third party as a recipient. However, the Controller always proceeds in this way only in justified cases. The Controller may pass personal data to the following recipients:

  1. processors who process the Data Subject's personal data according to the Controller's instructions and whose relationships are governed in line with the requirements of Article 28 of the GDPR; for example providers of software used by the Controller to better secure and run its services; these will have access only to the extent necessary and for the purpose of administration and technical support of the software used;
  2. public authorities and other entities where required by applicable law;
  3. other entities in the event of an unexpected occurrence in which disclosure of the data is necessary to protect life, health, property or another public interest, or where it is necessary to protect our rights, property or safety.
5.2.

The Controller does not intend to transfer personal data to a third country or an international organisation.

6. Rights of the Data Subject

6.1.

The rights of the Data Subject are an important element of personal data protection. If the Data Subject invokes any of the rights listed below, the Controller will provide information on the measures taken without undue delay and in any event within one month of receiving the Data Subject's request. In exceptional cases the Controller may extend this period by up to two months. The Controller will inform the Data Subject of the extension and the reason for it.

6.2.

Personal data is processed by automated means in electronic form.

6.3.

The Data Subject has the right:

  1. to be informed about the processing of personal data
    The Controller provides information about the processing of personal data primarily through this personal data protection policy.
  2. of access to personal data
    Upon request, the Data Subject will obtain from the Controller information (confirmation) as to whether or not their personal data is being processed. If it is being processed, the Data Subject has the right to obtain the following information: the purposes of processing; the categories of personal data concerned; the recipients or categories of recipients to whom the personal data has been or will be disclosed; the envisaged period for which the personal data will be stored; the existence of the right to request rectification or erasure of personal data from the Controller; the right to object; the right to lodge a complaint with a supervisory authority; any available information as to the source of the personal data where it is not collected from the Data Subject; the existence of automated decision-making, including profiling. Most of this information can be found in this personal data protection policy, but if the Data Subject wishes, they may also ask about the above.
  3. to rectification and completion
    If the Data Subject knows or believes that the Controller is processing inaccurate personal data about them, the Data Subject may point this out and the Controller is obliged to rectify the data. If the Data Subject wishes to have incomplete personal data completed with regard to the purpose of processing, they may notify the Controller and the Controller is obliged to complete the data.
  4. to erasure
    This right imposes on the Controller the obligation to destroy personal data in accordance with Article 17(1) of the GDPR if at least one of the following conditions is met:
    • the personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
    • the Data Subject withdraws consent and there is no other legal ground for the processing;
    • the Data Subject objects to the processing and there are no overriding legitimate grounds for the processing;
    • the personal data has been unlawfully processed;
    • the personal data must be erased for compliance with a legal obligation;
    • the personal data has been collected in relation to the offer of information society services referred to in Article 8(1) of the GDPR;
    and at the same time none of the exceptions listed in Article 17(3) of the GDPR applies.
  5. to restriction of processing
    Under this right, the Data Subject may ask the Controller to restrict the processing of personal data. Where the conditions under Article 18(1) of the GDPR are met, the Controller must do so.
  6. to data portability
    The Data Subject has the right to receive, in particular to download, their personal data from the Controller in a structured, commonly used and machine-readable format, and further has the right to have the personal data transmitted directly to another controller.
  7. to object
    In some cases the Data Subject may raise a so-called objection to processing. This concerns in particular situations where the Data Subject had no opportunity to influence the fact that their data is processed and, at the same time, the processing is not the fulfilment of a legal obligation or a vital interest that would justify that impossibility. The Data Subject may raise three types of objection to processing. These are objections to:
    • processing based on the legal ground of legitimate interest and the performance of a task carried out in the public interest or in the exercise of official authority;
    • processing for direct marketing purposes based on the legal ground of legitimate interest;
    • processing for scientific or historical research purposes or for statistical purposes.
    Where an objection is raised, the Controller shall no longer process the data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the Data Subject, or for the establishment, exercise or defence of legal claims. Where an objection is raised to the processing of personal data for direct marketing purposes or profiling, the Controller must stop processing the personal data.
  8. not to be subject to automated individual decision-making, including profiling
    Automated individual decision-making never takes place when the Data Subject's personal data is processed, not even on the basis of profiling.
  9. to withdraw consent to the processing of personal data where the processing is based on consent
    The Data Subject may at any time withdraw consent to the processing of their personal data that is processed on the basis of that consent.
  10. to obtain information about a breach of the security of your personal data
    If a personal data breach at the Controller is likely to result in a high risk to the rights and freedoms of the Data Subject, the Controller will notify the Data Subject without undue delay.
  11. to lodge a complaint with a supervisory authority
    If the Data Subject were to gain the impression that the Controller is breaching its obligations when processing their personal data, the Data Subject has the right to lodge a complaint with the Office for Personal Data Protection, with its registered office at Pplk. Sochora 27, 170 00 Prague 7, Czech Republic; e-mail: [email protected]; www: https://www.uoou.cz; tel.: +420 234 665 111.

7. Changes to the policy

7.1.

The personal data protection policy may change over time. All changes to the personal data protection policy will be published in the application. If the changes are significant, the Controller may inform the Data Subject about them by e-mail.

8. Our contact details

8.1.

If the Data Subject wishes to contact the Controller in connection with the processing of their personal data, they may use the following contacts:

  1. in writing to the registered office address: Zámecká 1936/18, Moravská Ostrava, 702 00 Ostrava, Czech Republic
  2. by e-mail to the e-mail address: [email protected]

This personal data protection policy takes effect and becomes valid on: 1 January 2022

Appendix: cookies and website measurement on terrapix.eu

This appendix is not part of the document above. It describes the technical items that terrapix.eu stores in your browser.

Technical items keep the website working and remember your choices. Cloudflare Web Analytics also measures traffic without analytics cookies. Meta Pixel runs only with your marketing consent.

Marketing: Meta Pixel

Meta Pixel (ID 1448667413841562) shares page visit data (PageView), page URL, browser information, IP address and cookie identifiers with Meta Platforms Ireland Limited. It measures advertising effectiveness and helps personalise ads on Facebook and Instagram. Meta may link this information to your account and process it outside the EEA, including in the USA, under its policies.

The legal basis is your consent. The Pixel does not load without it. You may withdraw consent at any time using “Cookie settings” in the footer; we stop further tracking and delete Pixel cookies accessible on our domain. Withdrawal does not affect the lawfulness of earlier processing. For processing, retention, international transfers and your rights, see the Meta Privacy Policy and Meta Cookies Policy.

Name Type Purpose Duration
terrapix_lang cookie remembering the website language you selected manually 1 year
__cf_bm cookie (Cloudflare) protection against bots and attacks about 30 minutes
_cfuvid cookie (Cloudflare) technical distinction of visits during rate limiting for the duration of the visit
pf-roi-rl-v1 localStorage limiting how often the ROI calculator result can be sent rolling 24 hours
pf-roi-state-v1 localStorage remembering your ROI calculator settings until cleared in the browser
terrapix-consent-v1 localStorage your analytics and marketing cookie preferences; change them in the footer choice valid for 180 days
_fbp, _fbc Meta Pixel cookies Marketing — only after consent; _fbc when arriving from a Meta ad typically up to 90 days

Cloudflare technical cookies and the language cookie created by your explicit language selection are necessary for the requested website function and, under Section 89(3) of Act No. 127/2005 Coll., do not require consent. Data in localStorage stays in your browser only and is never sent anywhere.

Links from QR codes on printed materials (the /qr/ paths) only count anonymous aggregate loads. They store no IP address, cookies or other personal data.