Privacy Policy
I. Basic Provisions
- The operator of this website and the Data Controller within the meaning of Article 4(7) of Regulation (EU) No. 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as GDPR) is Abukosolutions, Nové sady 988/2, 602 00 Brno-střed, Czech Republic, ID: 23169044.
- To exercise your rights in connection with the processing of your personal data, you can contact the Data Controller using the following contact details:
- Email: info@abukosolutions.com
- Mobile: +420 702 004 019 (CZ)
- Data Box: khdz6q8
- Address: Nové sady 988/2, 602 00 Brno-střed (CZ)
- Personal data means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”); an identifiable natural person is a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, network identifier, or one or more specific elements of the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
- The Controller does not have a designated Data Protection Officer.
II. Categories of Processed Personal Data
- The Controller processes personal data that:
- You have provided personally in connection with a concluded contractual relationship. This includes the following personal data: email address, first and last name, telephone number.
- The Controller obtains from your activity when using individual website services, during communication with the Controller via online chat, by posting comments under articles published on the Controller’s website, publishing articles, registration, subscribing to newsletters, or completing online forms, all with your explicit consent. This may include personal data such as email address, first and last name, IP address (see Article IV).
- The Controller may obtain based on mere visits to the Controller’s website and your behavior on it through cookies and other online browser identifiers. In this case, the following personal data is recorded: see Section V. Cookie files do not allow personal identification of website visitors.
III. Legal Basis and Purpose of Data Processing
- The legal basis for processing personal data under Article II.1 is the performance of a contract, of which you are a party (order of the Controller’s services), in accordance with Article 6(1)(b) GDPR, and the Controller’s legitimate interest in providing direct marketing to its customers (e.g., sending business communications and newsletters) in accordance with Article 6(1)(f) GDPR. This data is retained for 5 years from the conclusion of the last contract between the Controller and you.
- The legal basis for processing personal data under Article II.2, which you provided to the Controller, is your explicit consent as stated in Article IV.2.
- Personal data obtained through cookies and other online identifiers is processed by the Controller based on your explicit consent, as stated in Article V. This does not apply to functional cookies necessary for the operation of the website (for which your consent is given by simply visiting the site).
- The purpose of processing personal data is:
- To process your order and exercise the rights and obligations arising from the contractual relationship between you and the Controller; personal data necessary to successfully complete the order (name, address, contact) is required; without providing this data, it is not possible to conclude or perform the contract.
- To send business communications, offers, newsletters, and other marketing activities (including automated individual decision-making).
- The Controller may engage in automated individual decision-making within the meaning of Article 22 GDPR. You have provided explicit consent for such processing.
IV. Visitor Consent for Marketing Purposes
- Your consent to receive business communications/offers or newsletters, including profiling (consent for marketing purposes), as a visitor of the Controller’s website, is given by entering your email address into the designated field on the website and confirming your intent by clicking the link sent to the provided email address (double opt-in).
- Consent for processing personal data for marketing purposes can be withdrawn at any time. Withdrawal of consent does not affect the processing of your personal data on another legal basis (e.g., contract performance).
V. Cookies and Online Identifiers
- Cookies and other online identifiers enable the proper functioning of the website, remembering customer login information, evaluating website traffic, optimizing marketing activities, and profiling (to tailor the offer to visitors based on the pages and functions they use most, including targeted ads).
- The Controller mainly uses the following cookies:
- Functional cookies: automatically deleted when leaving the website and help ensure proper functioning during the visit.
- Permanent cookies: stored permanently and may contain an anonymous browser identifier. These do not identify you personally and are used for measurement, statistics, and content/advertisement customization.
- Marketing cookies: display ads and offers relevant to you based on your website behavior (profiling).
- You give consent for the use of cookies and online identifiers for service provision, ad personalization, and traffic analysis by checking an interactive window on the bottom of the page or on the Cookies Policy page.
- You can use the Controller’s services without permanent and marketing cookies.
- Cookie usage can be managed through your browser. If you do not consent, you can prevent cookie collection by changing your browser settings or on the Cookies Policy page.
- The Controller collects cookies listed on the Cookies Policy page, regularly updated.
VI. Recipients of Personal Data
- Recipients of personal data include:
- Persons involved in providing the Controller’s goods and services and in payment processing.
- Persons handling accounting and providing tax advice to the Controller.
- Persons ensuring the website’s operation, e.g., software and service providers, hosting providers, etc.
- Persons providing marketing services for the Controller.
- The Controller may transfer personal data to third countries (outside the EU) to mailing and cloud service providers or automated spam detection service providers.
The current list of processors is available on the “Consent to the Processing of Personal Data” page.
VII. Data Retention Period
- The Controller retains personal data:
- As long as necessary to exercise rights and obligations arising from the contractual relationship between you and the Controller and claims from these contracts (5 years after contract termination).
- Until consent for marketing purposes is withdrawn, up to a maximum of 5 years if processing is based on consent.
- For cookies, personal data is retained for a maximum of one year.
After the retention period, personal data is deleted by the Controller.
VIII. Protection of Personal Data
- The Controller declares that it fully respects all principles of GDPR and has adopted all appropriate technical and organizational measures to secure personal data.
- Technical measures also secure data storage and physical records, including encryption, passwords, access limitation, and physical locking.
- Only persons authorized and trained by the Controller have access to personal data.
IX. Your Rights Regarding Personal Data Protection
- Under Articles 15–21 GDPR, you have the right:
- To access personal data: obtain confirmation whether your personal data is processed and, if so, access the data and information defined in Article 15 GDPR.
- To rectify inaccurate personal data and complete incomplete data (Article 16 GDPR).
- To erase personal data (“right to be forgotten”) once it is no longer necessary for the contract unless another legal reason exists (Article 17 GDPR).
- To data portability (Article 20 GDPR).
- To object to personal data processing (Article 21 GDPR).
- To withdraw consent in writing or electronically to the Controller’s address or email (Article I.2).
- The Controller will provide information about the measures taken no later than one month after receiving a request.
- You also have the right to file a complaint with the Office for Personal Data Protection if you believe your rights have been violated.
X. Final Provisions
- You consent to these Terms by checking the consent box on the online form. By doing so, you confirm that you have read and accept the Privacy Policy in full.
- The Controller reserves the right to modify this Policy. The new version will be published on the website.
These Terms come into effect on April 20, 2025.