Privacy policy

This Privacy Policy (the “Policy“) describes how we collect, use and otherwise handle personal information collected through the www.thedesign.cz web interface (the “Web Interface“).

Data Controller:

MEDON s.r.o., with registered office at Havelská 517/14, Staré Město, 110 00 Prague 1,
Company ID: 649 43 691
VAT ID: CZ64943691
registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, Insert 42547,

Contact details of the data controller:
Delivery address: Havelská 517/14, Staré Město, 110 00 Prague 1
phone number: +420 725 095 636
Contact e-mail: [email protected]

The protection of personal data is very important to us. Please read this Policy carefully, as it contains important information regarding the handling of your personal data and related rights and obligations.

1. INTRODUCTORY PROVISIONS

1.1. What guides our handling of personal data?

When handling personal data, we proceed in accordance with the legal order of the Czech Republic and directly applicable regulations of the European Union, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (hereinafter referred to as the “Regulation“), Act No. 110/2019 Coll, No. 480/2004 Coll., on certain information society services and on amending certain acts, as amended, and Act No. 127/2005 Coll., on electronic communications and on amending certain related acts (Electronic Communications Act), as amended.

1.2. What is personal data?

Personal data means any information that identifies or can identify a specific natural person. Personal data includes, but is not limited to:

  • identifying information, such as name, surname, identification number, tax identification number, date of birth, user account login;
  • contact details such as home address (or delivery address), telephone number, email address;
  • other data, such as information obtained through cookies, IP address (network identifier) including browser type, device and operating system, time and number of accesses to the web interface and other similar information.

2. COLLECTION AND USE OF PERSONAL DATA

2.1. How do we obtain your personal data?

You provide us with your personal data mainly when filling in an order (or in the contact form), or when setting up a user account or entering reviews. If there is any change to your personal data, please inform us.

When visiting and using the web interface, some personal data may also be collected and stored via cookies. You can read more about cookies in Article 5 of this Policy.

2.2. On what basis and for what purposes do we process your personal data?

  • We may process the personal data entered when making enquiries (in particular via the contact form) and ordering goods or services without your explicit consent on the basis of and for the purpose of concluding and performing a contract, i.e. for the purpose of supplying goods or services. Furthermore, we may process this data on the basis of and for the purpose of fulfilling our statutory obligations (in particular registration obligations, archiving of tax documents, etc.) and on the basis of our legitimate interest for the purpose of protecting our legal claims.
  • We may process the personal data entered when you set up your user account without your explicit consent for the performance of the contract and solely for the purpose of enabling access, administration and management of the user account.
  • We may process the personal data entered in the context of publishing reviews on the web interface without your explicit consent on the basis of a legal obligation, in particular for the purpose of verifying the authenticity of the reviews.
  • We may use your email address without your express consent on the basis of our legitimate interest to send you commercial communications relating to our goods or services similar to those you have ordered from us. You may refuse to receive commercial communications at any time (including when ordering goods or services).
  • If you give us your consent to do so by confirming this on the web interface, we may process your personal data entered on the web interface, in particular when you complete an order or create a user account, for the purpose of sending you commercial communications and direct marketing or for other purposes to which you have expressly agreed. If you are under 15 years of age, your legal representative must give consent. If in doubt, we may ask for confirmation of your age.
  • We determine your satisfaction with your purchase through e-mail questionnaires as part of the Verified by Customers program, in which our e-shop is involved. These are sent to you every time you make a purchase with us, unless you refuse to receive them. The processing of personal data for the purpose of sending questionnaires under the Customer Verified programme is based on our legitimate interest, in order to control and improve our services and our goods and to determine your satisfaction with your purchase with us. We use the processor Heureka.cz, the operator of the Heureka.cz portal, to send questionnaires, evaluate your feedback and analyse our market position; we may pass on information about the goods or services you have purchased and your email address to Heureka.cz for these purposes. Your personal data is not passed on to any third party for their own purposes when sending email questionnaires. You can object to the sending of email questionnaires under the Customer Verified program at any time by refusing further questionnaires using the link in the email with the questionnaire. If you object, we will not send you the questionnaire any further.
  • If you consent to the transfer of personal data for the purpose of evaluating your purchase, we will forward the order information together with your e-mail address to Seznam.cz. The latter may then use it to obtain an independent evaluation of our products and services. The personal data transmitted will only be held for as long as necessary for this use.
  • If personal data is processed via cookies, we process this personal data on the basis of and for the purposes of concluding and performing a contract (only necessary cookies are concerned) or on the basis of your consent (which you give in the relevant bar located on the web interface, without which it is not possible to collect these cookies), in particular for the purposes of carrying out user support, improving our services, including the analysis of user behaviour and marketing.

We can only use your personal data for a purpose other than that for which it was collected with your consent.

2.3. For how long do we use the data?

We only use the personal data provided in the context of enquiring about and ordering goods or services or in the context of registration for the time necessary for the performance of the contract and the fulfilment of legal obligations or for the protection of our legal claims.

If you give us your explicit consent to the processing of your personal data or if we use your e-mail address to send you commercial communications and/or to control and improve our services and our goods in accordance with the previous article, the data will be used for the duration of the web interface on which we offer services or goods similar to those you have ordered from us, or for the period specified in the consent.

3. YOUR RIGHTS IN RELATION TO PERSONAL DATA

3.1. Right to withdraw consent to the processing of personal data

If we process your personal data only on the basis of your consent (i.e. without any other lawful reason), you can withdraw this consent at any time.

You can withdraw your consent to the processing of your personal data at any time by:

  • via email sent to our contact email address;
  • in writing in the form of a letter sent to our delivery address;
  • in the case of commercial communications, in the manner specified in each email containing commercial communications (by clicking on the unsubscribe link or otherwise).

Withdrawal of consent does not affect the lawfulness of data processing carried out until the withdrawal of consent to processing.

3.2. Right of access to personal data

You have the right to ask us whether we are processing your personal data. If we are processing your data, you have the right to access this personal data and in particular the following information:

  • the purpose of processing;
  • categories of personal data processed;
  • the recipients or categories of recipients to whom the personal data will be disclosed;
  • the period for which the personal data will be stored.

Upon your request, we will provide you with a copy of the processed data. We may charge you an administrative fee for additional copies, not exceeding the cost of making and transmitting those additional copies.

3.3. Right to repair

If your personal data is inaccurate or incomplete, you have the right to request immediate rectification, i.e. correction of inaccurate data and/or completion of incomplete data.

3.4. Right to object to processing

You have the right to object at any time to the processing of your personal data where we process it for direct marketing purposes, including any automated processing of personal data. Once you have objected, we will no longer process your personal data for these purposes.

3.5. Right to erasure (“right to be forgotten”)

You have the right to request that we delete your personal data if:

  • the personal data is no longer necessary for the purposes for which it was collected or processed;
  • you have withdrawn your consent to processing;
  • you have objected to the processing of personal data;
  • personal data have been unlawfully processed.

If there are no legal grounds for refusing erasure, we are obliged to comply with your request.

3.6. Right to restriction of processing

You have the right to request that we restrict the processing of your personal data if:

  • you deny the accuracy of your personal data;
  • the processing is unlawful and you request restriction of the processing of personal data instead of erasure;
  • We no longer need your personal data for processing purposes, but you require it for the establishment, exercise or defence of legal claims;
  • you object to the processing.

When restricting processing, we are only entitled to store your personal data; further processing is only possible with your consent or for legal reasons.

If the processing of personal data is restricted due to an objection to processing, the restriction lasts for the time necessary to determine whether we are obliged to comply with your objection.

If the processing of personal data is restricted due to a denial of the accuracy of the data, the restriction lasts for the period of verification of the accuracy of the data.

3.7. Right to data portability

You have the right to obtain the personal data you have provided to us in a structured, commonly used and machine-readable format and to have it transferred to another data controller.

3.8. How can you exercise your rights?

You can exercise your rights in relation to personal data by using our contact details. All information and actions will be provided to you without undue delay.
We will do our utmost to protect your personal data. However, if you are not satisfied with the handling, you have the right to contact the competent authorities, in particular the Office for Personal Data Protection (https://www.uoou.cz), which supervises the protection of personal data. This provision is without prejudice to your right to address your complaint directly to the Data Protection Authority.
In particular, if your residence, place of employment or place of alleged personal data breach is located outside the Czech Republic in another EU Member State, you may contact the competent supervisory authority in that Member State.

4. MANAGEMENT AND PROCESSING OF PERSONAL DATA

4.1. Who processes your personal data?

We are a data controller within the meaning of the Regulation.

To the extent necessary for the performance of the contract or other obligations, we may also transfer your personal data to other parties, such as carriers, cloud storage providers, email campaign managers, a “Customer Verified” certificate company, an external accountant or other parties involved in the performance of the contract or our obligations. Where appropriate, we may also entrust other processors and recipients of personal data. We will also tell you who specifically processes your personal data upon your request.

Your personal data will not be transferred to countries outside the European Union unless it is necessary for the performance of a contract or for any other reason in accordance with the rules for such transfers set out in the regulation.

4.2. How do we process personal data?

Personal and other data collected are fully secured against misuse. Personal data will be processed in electronic form in an automated manner or in paper form in a non-automated manner.

5. COOKIES

5.1. What are cookies?

Cookies are text files stored on the computer or other electronic device of each visitor to a web interface that enable the web interface to function.

Not all cookies collect personal data; some only allow the web interface to function properly. You can refuse the use of cookies by selecting the appropriate settings in your browser.

Please note that if you refuse the use of cookies, you may not be able to use the full functionality of the web interface.

5.2. What cookies and for what purposes does the web interface use them?

The web interface uses session (temporary) cookies that are automatically deleted when you stop browsing the web interface. It also uses persistent cookies that remain on your device until they expire or you delete them.

The cookies used by the web interface are as follows:

  • first-party cookies – these cookies are assigned to the domain of our website; they are essential cookies and performance cookies that we use for the conclusion and performance of the contract (in particular essential cookies), where appropriate on the basis of the above-mentioned consent. These cookies may be temporary or permanent;
    • Necessary cookies – they allow you to navigate the web interface and use basic functions, they usually do not identify you in any way and are not personal data;
    • performance cookies – used to analyse how the web interface is used (number of visits, time spent on the web interface, etc.); the data collected by these cookies is usually anonymous, the collection of these cookies is based on your consent (which you give in the relevant bar located on the web interface, without which it is not possible to collect these cookies);
  • third-party cookies – these cookies are assigned to a different domain than the domain of our website, even when you are on our website; these cookies enable us, based on your consent (which you give in the relevant bar located on the web interface, without which these cookies cannot be collected), in particular to analyse our website and to display tailored advertising for you; these are functional cookies and targeted and advertising cookies;
    • Functional cookies – used to personalise content by remembering login details, geolocation, etc.; they may be used to collect and process personal data;
    • Targeting and advertising cookies – used to serve targeted advertisements on and off the web interface; they may collect and process personal data. We may also share information about your use of our website with our social media, advertising and analytics partners.

5.3. Services used that work with cookies

The web interface uses Google Analytics and, where applicable, other services provided by Google LLC (“Google“), Facebook Pixel provided by Facebook Inc. and Sklik provided by Seznam.cz, a.s. These services work with information obtained via cookies.

Google Analytics is used to obtain statistical information about your use of the web interface. The cookies collected by this service expire after a maximum of 2 years, depending on your browser settings, or until you manually delete them.

Google Ads is used to identify you within Google’s advertising network and to retarget your advertising (retargeting and remarketing). The cookies collected by this service expire after a maximum of 18 months, depending on your browser settings, or until you manually delete them.

The Facebook Pixel service is used to identify you within the Facebook Inc. advertising network and to retarget advertising (retargeting and remarketing). The cookies collected by this service expire after a maximum of 2 years, depending on your browser settings, or until they are manually deleted by you.

The Sklik.cz service is used to identify you within the Seznam.cz advertising network and to retarget advertising (retargeting and remarketing). The cookies obtained by this service expire depending on your browser settings after a maximum of 18 months, or until they are manually removed by you.

If you are interested in how Google uses the data it receives from us and how to modify or disable the processing, please click on the following link : How Google uses data when you use our partners’ websites or apps.

5.4. How to set and, if necessary, refuse the processing of cookies

For instructions on how to properly set and manage the processing of cookies in your internet browser, please click here:

Google Chrome – https://support.google.com/accounts/answer/61416?hl=cs
Internet Explorer – https://support.microsoft.com/cs-cz/help/17442/windows-internet-explorer-delete-manage-cookies
Microsoft Edge – https://support.microsoft.com/cs-cz/help/4468242/microsoft-edge-browsing-data-and-privacy-microsoft-privacy
Mozilla Firefox – https://support.mozilla.org/cs/kb/vymazani-cookies-dat-stranek?redirectlocale=cs&redirectslug=vymazani-cookies
Opera – https://help.opera.com/cs/latest/web-preferences/#cookies
Safari – https://support.apple.com/cs-cz/guide/safari/sfri11471/mac


This Policy is valid and effective as of October 30, 2023.