Advice on Personal Data Processing

ATENTA s.r.o., ID No.: 08890757, with its registered office at Máchova 802, Mladá Boleslav II, 293 01 Mladá Boleslav, registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, Entry 337542 (hereinafter the “Controller”) would like to inform you pursuant to Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter the “Regulation” or “GDPR”) that the Controller will or may process your Personal Data (hereinafter “PD”) where it is necessary for the performance of a contract, compliance with a legal obligation and for the purposes of legitimate interests pursued by the Controller (hereinafter the “Legal Grounds for Processing”) in the following scope:

name, surname, address, email address, telephone, or commercial name, registered office, ID No., Tax ID No., provided that you provide the same. PD include address and identification data.

The Controller would like to inform you that PD shall be processed for the following purpose: conclusion and performance of a contract, accounting and tax transactions, compliance with statutory obligations, sending of marketing notifications if the Legal Grounds for Processing exists. The Controller would like to inform you that apart from the Controller, the other PD recipients shall include the following processors: HEUREUX s.r.o. and the carrier ALFASPED LOGISTIK s.r.o. (hereinafter the “Processors”).

The Controller would like to inform you that it shall store PD for a necessary period of time on the basis of the Legal Grounds for Processing, whereas this period can last up to 5 years from a purchase contract conclusion, while as regards accounting and tax documents, the required storage period shall be prescribed by the Act or other legal regulations. The email address shall be stored and used for the purposes of sending of marketing notifications until you turn off the notifications.

To turn off the notifications, use the email address gdpr@atenta.cz.

The Controller would like to inform you that you have the right to ask the Controller to access PD, rectify or erase PD, or restrict processing, or the right to object against processing and the right to PD transferability (i.e. obtain PD from the Controller in a commonly used and machine readable format and to transfer PD to another controller), that you may file a complaint with the Office for Personal Data Protection, that PD provision is not mandatory and that no automated decision-making or profiling is included. The Controller would like to further inform you that you have a right to obtain from the Controller a confirmation on whether PD is processed or not.

The Controller would like to inform you that you have the right to erasure of PD (i) if PD is no longer necessary for the Purpose; (ii) if you withdraw your consent and no further Legal Grounds for Processing exists; (iii) if you object against PD processing due to a legitimate interest pursued by the Controller or if you object against automated individual decision-making or profiling; (iv) if PD was processed illegally; (v) if PD has to be erased to comply with a statutory obligation; (vi) if PD was collected in connection with the offer of information society services.

The Controller expressly informs that you have the right to bring an objection at any time against the processing of PD that concerns you and that was obtained with the aim of performance of a task carried out in a public interest or is necessary for the legitimate interest pursued by the Controller, including profiling. You are further entitled to bring an objection at any time against the processing of PD, which concerns you, for marketing purposes. The Controller would like to advise you that you have the right not to be subject to a decision made based solely on automated processing, including profiling, which produce legal effects concerning you or significantly affects you, unless the same is necessary for the conclusion or performance of a contract or is based on express consent.

The Controller hereby informs that if a PD breach occurs, which is likely to result in high risk for the rights and freedoms of natural persons, the Controller shall report the breach to the relevant data subject without undue delay.