PRIVACY POLICY
Information under Articles 13 and 14 GDPR for shop.codecron.cz
|
Data Controller |
Jitka Hořavová, Company ID (IČO) 88201856 |
|
Registered Address |
Jiráskova 436/8, 789 85 Mohelnice |
|
Contact |
shop@codecron.cz | +420 602 883 450 |
|
Online Store |
https://shop.codecron.cz |
|
Version |
1.0 | effective from 16 Aug 2026 |
1. Controller and Contact
1.1 The controller is Jitka Hořavová, Company ID (IČO) 88201856, Jiráskova 436/8, 789 85 Mohelnice, Czech Republic, email shop@codecron.cz, phone +420 602 883 450.
1.2 No Data Protection Officer has been appointed. Questions and requests can be sent to the email address above.
2. Overview of Processing
|
Purpose |
Data and Legal Basis |
Retention Period |
|
Order and License |
name, contact details, address, order, license, payment; performance of contract |
for the duration of the contract and legal claims, typically 3 years |
|
Account and Downloads |
email, password hash, history, downloads, IP/logs; contract and legitimate interest |
for the duration of the account; inactive account 3 years from last activity |
|
Accounting and Taxes |
billing details, orders, payments, country/VAT ID; legal obligation |
typically 10 years under applicable regulations |
|
Payment and Fraud Prevention |
payment identifiers, amount, status, IP; contract and legitimate interest |
depending on the provider and legal claims |
|
Support and Complaints |
communication, files, technical data; contract, law, legitimate interest |
for the duration of resolution and typically 3 years thereafter |
|
Newsletter |
email, consent record, interactions; consent or statutory exception |
until withdrawal/objection; proof of consent retained for the duration of claims |
|
Analytics and Marketing |
online identifiers, device, visits; consent |
until withdrawal; specific cookies per the Cookie Policy |
|
Security and Logs |
IP, time, event, account; legitimate interest |
12 months |
|
Legal Claims |
contractual and communication data; legitimate interest |
for the duration of limitation periods and proceedings |
3. Recipients and Transfers
3.1 Data may be processed by providers of hosting, PrestaShop and its modules, email, accounting, support, security, analytics, marketing, and payments. Current list: DigitalOcean (hosting), own SMTP server (email), Fakturoid (accounting), Stripe (payments), Google Analytics (analytics), custom PrestaShop module (cookie platform).
3.2 Data is not transferred outside the EEA unless necessary for the selected supplier and a legal mechanism is in place, in particular an adequacy decision or standard contractual clauses and supplementary measures. Specific cases: Stripe (payments) and Google Analytics (analytics) are US-based companies processing data outside the EEA; the transfer is secured through standard contractual clauses. DigitalOcean operates on servers within the EU, so no transfer outside the EEA occurs in this case.
3.3 Data will be provided to public authorities only where there is a legal obligation or statutory request.
4. Rights of Data Subjects
4.1 Under the conditions set by the GDPR, you may request access, rectification, erasure, restriction, or data portability, object to processing based on legitimate interest, and withdraw consent at any time without affecting the lawfulness of processing carried out before its withdrawal.
4.2 Requests can be sent to shop@codecron.cz. The controller may reasonably verify identity and will respond without undue delay, typically within one month.
4.3 A complaint may be filed with the Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, https://uoou.gov.cz.
5. Automated Decision-Making, Data Provision Requirements and Security
5.1 Providing contractual and billing information is required to make a purchase. The newsletter and non-essential cookies are voluntary.
5.2 The online store does not carry out decision-making with legal or similarly significant effects solely through automated means. Fraud-prevention tools may flag a risky transaction for further review.
5.3 The controller uses appropriate measures, in particular encrypted transmission, access control, updates, backups, logging, and restricted administrator accounts. However, no system is completely secure.
5.4 This policy may be updated to reflect changes in processing or the law. The current version will be available at https://shop.codecron.cz/gdpr.