The person responsible for data processing is:
Kalita Gold
Štěpánská 615/24, Nové Město, 110 00 Praha 1
Tel.: +442081579539
We appreciate your interest in our online shop. Protecting your privacy is very important to us. We therefore inform you in detail about the handling of your data below.
1. ACCESS DATA AND HOSTING
You can visit our websites without providing any information about yourself. Each time a web page is accessed, the web server only automatically stores a so-called server log file which contains, for example, the name of the requested file, your IP address, date and time of the retrieval, the amount of data transmitted and the requesting provider (access data) and documents the retrieval.
This access data is evaluated exclusively for the purpose of ensuring trouble-free operation of the site as well as the improvement of our offer. This serves pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR to safeguard our legitimate interests in the correct presentation of our offer, which predominate in the context of a balancing of interests. All access data will be deleted no later than seven days after the end of your page visit.
Hosting
The services for hosting and displaying the website are partly provided by our service providers in the context of processing on our behalf. Unless otherwise stated in this Privacy Policy, all access data as well as all data collected in forms provided for this purpose on this website will be processed on their servers. If you have any questions about our service providers and the basis of our cooperation with them, please contact the contact option described in this privacy policy.
2. DATA PROCESSING FOR CONTRACT PROCESSING, CONTACTING AND OPENING A CUSTOMER ACCOUNT
2.1 Data processing for contract processing
For the purpose of contract processing pursuant to Art. 6 para. 1 sentence 1 lit. b GDPR, we collect personal data if you voluntarily communicate them to us as part of your order. Mandatory fields are marked as such, since in these cases we require the data for contract processing and we cannot send the order without their indication. Which data are collected can be seen from the respective input forms.
Further information on the processing of your data, in particular on the transfer to our service providers for the purpose of ordering, payment and shipping, can be found in the following sections of this privacy policy. After complete processing of the contract, your data will be restricted for further processing and after expiry of the tax and commercial retention periods in accordance with Art. 6 para. 1 sentence 1 lit. c GDPR deleted, unless you expressly indicate further use of your data in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR or we reserve the right to use data that is permitted by law and about which we inform you in this declaration.
Legacy system
We use merchandise management systems from external service providers for order and contract processing. Our service providers are engaged in order processing for us. If you have any questions about our service providers and the basis of our cooperation with them, please contact the contact option described in this privacy policy.
2.2 Customer account
We collect personal data if you voluntarily provide it to us when you open a customer account. Mandatory fields are marked as such, since in these cases we require the data to open the customer account and you cannot complete the account opening without their indication. Which data are collected can be seen from the respective input forms. We use the data provided by you for the contract processing and processing of your inquiries in accordance with Art. 6 para. 1 sentence 1 lit. b GDPR.
The deletion of your customer account is possible at any time and can be done either by a message to the contact possibility described in this privacy policy or via a function provided for this purpose in the customer account. After deletion of your customer account, your data will be deleted unless you expressly refer to further use of your data in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR or we reserve the right to use data that is permitted by law and about which we inform you in this declaration.
2.3 Contacting
In the context of customer communication, we collect lit to process your inquiries in accordance with Art. 6 para. 1 sentence 1 lit. b GDPR if you voluntarily provide us with personal data when contacting us (e.g. via contact form, live chat tool or e-mail). Mandatory fields are marked as such, since in these cases we absolutely need the data to process your contact.
Which data are collected can be seen from the respective input forms. After complete processing of your request, your data will be deleted, unless you expressly enter into further use of your data in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR or we reserve the right to use data that is permitted by law and about which we inform you in this declaration.
3. DATA PROCESSING FOR THE PURPOSE OF DISPATCH PROCESSING
For the performance of the contract pursuant to Art. 6 para. 1 sentence 1 lit. b GDPR, we pass on your data to the shipping service provider commissioned with the delivery, insofar as this is necessary for the delivery of ordered goods.
3.1 Data processing for payment processing
When processing payments in our online shop, we cooperate with these partners: technical service providers, credit institutions, payment service providers.
3.2 Data processing for transaction processing
Depending on the selected payment method, we pass on the data necessary for the processing of the payment transaction to our technical service providers, who are working for us in the context of order processing, or to the commissioned credit institutions or to the selected payment service provider, insofar as this is necessary for the processing of the payment. This serves the performance of the contract pursuant to Art. 6 para. 1 sentence 1 lit. b GDPR.
In part, the payment service providers collect the data required for the processing of the payment themselves, e.g. on their own website or via a technical integration in the order process. The data protection declaration of the respective payment service provider applies in this respect.
If you have any questions about our partners for payment processing and the basis of our cooperation with them, please contact the contact option described in this privacy policy.
3.3 Data processing for the purpose of fraud prevention and optimisation of our payment processes
If necessary, we provide our service providers with further data that they use together with the data necessary for the processing of the payment as our processor for the purpose of fraud prevention and optimization of our payment processes (e.g. invoicing, processing of contested payments, support of accounting). This serves pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR to safeguard our legitimate interests in our protection against fraud or efficient payment management, which are predominant in the context of a balancing of interests.
4. ADVERTISING BY E-MAIL, POST
4.1 E-mail advertising with subscription to the newsletter
If you subscribe to our newsletter, we use the data required for this purpose or provided separately by you to regularly send you our e-mail newsletter based on your consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR. Unsubscribing from the newsletter is possible at any time and can be done either by a message to the contact option described below or via a link provided for this purpose in the newsletter.
After unsubscribing, we delete your e-mail address from the recipient list, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this declaration.
4.2 Newsletter dispatch
The newsletter may also be sent by our service providers as part of processing on our behalf. If you have any questions about our service providers and the basis of our cooperation with them, please contact the contact option described in this privacy policy.
4.3 Postal advertising and your right to object
In addition, we reserve the right to use your first and last name as well as your postal address for our own advertising purposes, e.g. to send interesting offers and information about our products by letter mail. This serves to safeguard our legitimate interests, which predominate in the context of a balancing of interests, in a promotional address to our customers pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR. You can object to the storage and use of your data for these purposes at any time by sending a message to the contact option described in this privacy policy.
5. COOKIES AND OTHER TECHNOLOGIES
5.1 General information
In order to make visiting our website attractive and to enable the use of certain functions, we use technologies on various pages including so-called cookies. Cookies are small text files that are automatically stored on your device. Some of the cookies we use are deleted after the end of the browser session, i.e. after closing your browser (so-called session cookies). Other cookies remain on your device and enable us to recognize your browser the next time you visit (persistent cookies).
We use such technologies for the use of certain functions of our website (e.g. shopping cart function) are mandatory. Through these technologies, IP address, time of visit, device and browser information as well as information about your use of our website (e.g. information about the contents of the shopping cart) collected and processed. This serves in the context of a balancing of interests predominantly legitimate interests in an optimized presentation of our offer in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR.
In addition, we use technologies to fulfil the legal obligations to which we are subject (e.g. to prove consent to the processing of your personal data) as well as web analysis and online marketing. Further information, including the respective legal basis for data processing, can be found in the following sections of this privacy policy.
We may also use technologies that are not individually listed in this Privacy Policy. Further information on these technologies, including the respective legal basis for data processing, can be found on the Usercentrics platform.
This can be achieved by clicking on the fingerprint button in the right or lower left corner of the page.
The cookie settings for your browser can be found under the following links:
Insofar as you are interested in using the technologies in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR, you can revoke your consent at any time by sending a message to the contact option described in the privacy policy or by clicking on the fingerprint button in the right or lower left corner of the page. If cookies are not accepted, the functionality of our website may be limited.
6. USE OF COOKIES AND OTHER TECHNOLOGIES FOR WEB ANALYSIS AND ADVERTISING PURPOSES
Insofar as you have given your consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR, we use the following cookies and other third-party technologies on our website. After the end of the use of the respective technology by us, the data collected in this context will be deleted. You can revoke your consent at any time with effect for the future. Further information on your withdrawal options can be found in the section "Cookies and other technologies."
For more information, including the basis of our cooperation with the individual vendors, please refer to the individual technologies. If you have any questions about the providers and the basis of our cooperation with them, please contact the contact option described in this privacy policy.
6.1 Use of Google services
We use the following technologies of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). The information about your use of our website automatically collected by Google Technologies is usually transmitted to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA and stored there.
There is no adequacy decision by the European Commission for the US. Our cooperation is based on standard data protection clauses of the European Commission. If your IP address is collected via Google technologies, it will be shortened by activating IP anonymization before being stored on Google's servers. Only in exceptional cases will the full IP address be transmitted to a Google server and shortened there.
Unless otherwise specified in the individual technologies, data processing is carried out on the basis of an agreement concluded for the respective technology between persons jointly responsible in accordance with Art. 26 GDPR. Further information about data processing by Google can be found in Google's privacy policy. If cookies are not accepted, the functionality of our website may be limited.
Google Analytics
For the purpose of website analysis, Google Analytics automatically collects and stores data (IP address, time of visit, device and browser information as well as information about your use of our website) from which usage profiles are created using pseudonyms. Cookies can be used for this purpose. Your IP address will not be merged with other Google data. The data processing takes place on the basis of an agreement on the order processing by Google.
For the purpose of optimized marketing of our website, we have activated the data sharing settings for "Google products and services." For example, Google can access the data collected and processed by Google Analytics and then use it to improve Google's services. The data release to Google within the scope of these data release settings takes place on the basis of an additional agreement between responsible parties. We have no influence on the subsequent data processing by Google.
Google Ads
For advertising purposes in the Google search results as well as on the websites of third parties, when visiting our website, the so-called Google Remarketing Cookie is set, which is automatically used by the collection and processing of data. (IP address, time of visit, device and browser information as well as information about your use of our website) and enables interest-based advertising by means of a pseudonymous CookieID and based on the pages you visit.
Data processing beyond this takes place only if you have activated the setting "personalized advertising" in your Google account. If you are logged in to Google during your visit to our website, Google uses your data together with Google Analytics data to create and define target group lists for cross-device remarketing.
For website analysis and event tracking, we use Google Ads Conversion Tracking to measure your subsequent usage behavior if you have accessed our website via an advertisement from Google Ads. For this purpose, cookies can be used and data (IP address, time of visit, device and browser information as well as information about your use of our website based on events specified by us, such as visiting a website or subscribing to the newsletter) can be collected, from which usage profiles are created using pseudonyms.
Google Fonts
For the uniform presentation of the content on our website, data (IP address, time of visit, device and browser information) are collected by the script code "Google Fonts," transmitted to Google and subsequently processed by Google. We have no influence on this subsequent data processing.
YouTube Video Plugin
In order to integrate third-party content, data (IP address, time of visit, device and browser information) are collected via the YouTube video plugin in the extended data protection mode we use, transmitted to Google and subsequently processed by Google only if you play a video.
Insofar as information is transferred to Google servers in the USA and stored there, the American company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. Under this agreement between the US and the European Commission, the latter has established an appropriate level of data protection for companies certified under the Privacy Shield. You can prevent the collection of the data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available under the following link: https://tools.google.com/dlpage/gaoptout?hl=en
As an alternative to the browser plugin, you can click on the following link to prevent the collection by Google Analytics on this website in the future: Deactivate Google Analytics.
An opt-out cookie is stored on your device. If you delete your cookies, you must click the link again.
7. SOCIAL MEDIA
7.1 Use of social plugins from Facebook, Twitter, Instagram, Pinterest, using the Shariff solution
Social buttons from social networks are used on our website. These are only integrated into the page as HTML links, so that when you access our website, no connection is established with the servers of the respective provider. Click on one of the buttons, the website of the respective social network opens in a new window of your browser.
7.2 Our online presence on Facebook, Twitter, Instagram, Youtube, Pinterest
Insofar as you have given your consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR to the respective social media operator, when visiting our online presences on the social media mentioned above, your data are automatically collected and stored for market research and advertising purposes, from which usage profiles are created using pseudonyms.
These can be used, for example, to display advertisements inside and outside the platforms that are presumed to correspond to your interests. Cookies are usually used for this purpose. The detailed information on the processing and use of the data by the respective social media operator as well as a contact possibility and your rights in this regard and setting options for the protection of your privacy, can be found in the privacy policy of the providers linked below. If you still need help in this regard, you can contact us.
- Facebook is an offer of Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland ("Facebook Ireland") The information collected automatically by Facebook Ireland about your use of our online presence on Facebook is usually transferred to a server of Facebook, Inc., 1601 Willow Road, Menlo Park, California 94025, USA. There is no adequacy decision by the European Commission for the US. Our cooperation is based on standard data protection clauses of the European Commission. The data processing in the context of the visit of a Facebook fan page takes place on the basis of an agreement between jointly responsible persons in accordance with Art. 26 GDPR. For more information (about Insights data), see.
- Twitter is an offer of Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland ("Twitter"). The information that Twitter automatically collects about your use of our online presence on Twitter is usually transmitted to and stored on a Twitter, Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA server. There is no adequacy decision by the European Commission for the US. Our cooperation is based on standard data protection clauses of the European Commission.
- Instagram is an offer of Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland ("Facebook Ireland") The information collected automatically by Facebook Ireland about your use of our online presence on Instagram is usually transferred to a server of Facebook, Inc., 1601 Willow Road, Menlo Park, California 94025, USA. There is no adequacy decision by the European Commission for the US. Our cooperation is based on standard data protection clauses of the European Commission. The data processing in the context of the visit of an Instagram fan page takes place on the basis of an agreement between jointly responsible persons in accordance with Art. 26 GDPR. For more information (about Insights data), see.
- Pinterest is an offer of Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland ("Pinterest"). The information automatically collected by Pinterest about your use of our online presence on Pinterest is usually transferred to a server of Pinterest, Inc., 505 Brannan St., San Francisco, CA 94107, USA and stored there. There is no adequacy decision by the European Commission for the US. Our cooperation is based on standard data protection clauses of the European Commission.
- YouTube is an offer of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). The information automatically collected by Google about your use of our online presence on YouTube is usually transmitted to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA and stored there. There is no adequacy decision by the European Commission for the US. Our cooperation is based on standard data protection clauses of the European Commission.
8. CONTACT OPTIONS AND THEIR RIGHTS
As a data subject, you have the following rights:
- pursuant to Art. 15 GDPR, the right to request information about your personal data processed by us to the extent specified therein;
- pursuant to Art. 16 GDPR, the right to demand the immediate correction of incorrect or completion of your personal data stored by us;
- pursuant to Art. 17 GDPR, the right to request the erasure of your personal data stored by us, unless further processing
- exercising the right to freedom of expression and information;
- to fulfil a legal obligation;
- for reasons of public interest; or
- is necessary to assert, exercise or defend legal claims;
- pursuant to Art. 18 GDPR, the right to request the restriction of the processing of your personal data, insofar as
- the accuracy of the data is disputed by you;
- the processing is unlawful, but you refuse its deletion;
- we no longer need the data, but you need it to assert, exercise or defend legal claims; or
- You have objected to the processing pursuant to Art. 21 GDPR;
- pursuant to Art. 20 GDPR, the right to receive your personal data that you have provided to us in a structured, common and machine-readable format or to request the transfer to another controller;
- pursuant to Art. 77 GDPR, the right to complain to a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters.
Right to object
Insofar as we process personal data as explained above in order to safeguard our legitimate interests predominantly in the context of a balancing of interests, you can object to this processing with effect for the future. If the processing is for direct marketing purposes, you can exercise this right at any time as described above. Insofar as the processing is carried out for other purposes, you have the right to object only if there are reasons arising from your particular situation.
After exercising your right to object, we will no longer process your personal data for these purposes, unless we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, rights and freedoms, or if the processing of the assertion, exercise or defence of legal claims is for the purpose of marketing. This does not apply. We will then no longer process your personal data for this purpose.
For questions regarding the collection, processing or use of your personal data, for information, correction, restriction or deletion of data as well as revocation of granted consents or objection to a specific use of data, please contact us directly via the contact details in our imprint.