PRINCIPLES OF PERSONAL DATA PROTECTION
1. Introductory Provisions
1.1 These Principles of Personal Data Protection (hereinafter referred to as the "Principles") of Biomed CZ spol. s r.o., with its registered office at Štolbova 2886, Pardubice 53002, registered with the Regional Court in Hradec Králové, section C 23480, ID No.: 27513394 (hereinafter referred to as the "controller") are drawn up in accordance with valid and effective legislation, which is represented in particular by Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as the "GDPR"), which is supplemented in the Czech Republic by the accompanying Act No. 110/2019 Coll., on the processing of personal data, as amended.
1.2 The controller's contact details are - email: biomedczseznam.cz, telephone: +420 776 057 680.
1.3 Personal data means any information about an identified or identifiable natural person; an identifiable natural person is a natural person who can be identified, directly or indirectly, in particular by reference to a specific identifier, such as a name, identification number, location data, network identifier or to one or more specific elements of the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
1.4 The controller always processes all personal data lawfully, correctly, fairly, transparently and responsibly.
1.5 The controller has not appointed a data protection officer.
2. Sources and categories of personal data processed
2.1 The controller processes personal data that you have provided to it or personal data that the controller has obtained on the basis of the performance of a contract.
2.2 The controller processes your identification and contact data and data necessary for the performance of the contract.
2.3 If you enter the controller's website located at the internet address https://www.bicomshop.cz/ (hereinafter referred to as the "website"), the IP address is recorded; if you have enabled the storage of cookies in your browser, data about the pages you have visited is recorded with their help. For the offer of services, the controller also uses advertising on social networks, but this is not directly the processing of your personal data; advertising may only be displayed to you if you have previously, for example, visited the controller's website.
2.4 Further information regarding the cookies used by the controller, for what purpose and other settings concerning the configuration or deletion of cookies can also be found on the website here.
2.5 The controller does not process a special category of personal data (so-called sensitive data).
3. Legal basis and purpose of personal data processing
3.1 The legal basis for the processing of personal data is:
● performance of the contract between you and the controller pursuant to Art. 6(1)(b) GDPR,
● the controller's legitimate interest in providing direct marketing (in particular for sending commercial communications and newsletters) pursuant to Art. 6(1)(f) GDPR,
● your consent to processing for the purposes of providing direct marketing (in particular for sending commercial communications and newsletters) pursuant to Art. 6(1)(a) GDPR in conjunction with Section 7(2) of Act No. 480/2004 Coll., on certain services of the information society, in the event that no contract has been concluded.
3.2 The purpose of the processing of personal data is:
● handling your request via the internet form and the exercise of rights and obligations arising from the contractual relationship between you and the controller; when filling in the internet form, personal data are required that are necessary for the successful handling of the request (first name, surname, residential address, or contact address, e-mail and telephone number), the provision of personal data is a necessary requirement for the conclusion and performance of the contract; without the provision of personal data it is not possible to conclude the contract or perform it on the part of the controller,
● sending commercial communications and carrying out other marketing activities.
3.3 The controller does not carry out automated processing or profiling of personal data.
3.4 The processing of personal data is purpose-limited, i.e. personal data is processed only for specific, explicitly stated and legitimate purposes, and the personal data is not further processed in a manner incompatible with those purposes.
3.5 As part of the minimisation of personal data, the controller processes adequate, relevant and limited personal data, to the extent necessary in relation to the purpose for which the personal data is processed.
4. Data retention period
4.1 The controller retains personal data:
● for the period necessary for the exercise of rights and obligations arising from the contractual relationship between you and the controller and for the assertion of claims from these contractual relationships, but no longer than 15 years from the termination of the contractual relationship,
● for the period until consent to the processing of personal data for marketing purposes is withdrawn, but no longer than 5 years.
4.2 After the personal data retention period has expired, the controller shall delete the personal data.
5. Recipients of personal data (controller's subcontractors)
5.1 The recipients of personal data are persons:
● involved in the provision of services or the execution of payments under the contract,
● providing accounting, legal and tax services,
● providing marketing services.
5.2 The controller shall also make personal data available to the relevant administrative authorities if such an obligation is imposed by law (i.e. in particular in the case of an inspection in which the given authority is entitled to require the submission of personal data).
6. Your rights
6.1 Under the conditions set out in the GDPR, you have the following rights in relation to the processing of personal data carried out by the controller:
● the right to be informed,
● the right of access to personal data,
● the right to rectification of personal data,
● the right to erasure of personal data,
● the right to restriction of processing of personal data,
● the right to withdraw consent to the processing of personal data for marketing purposes,
● the right to object to the processing of personal data,
● the right to lodge a complaint regarding the processing of personal data.
6.2 The right to be informed means that you have the right to be provided with clear, transparent and easily understandable information about your rights and about how the controller uses personal data. This right is fulfilled by these Principles.
6.3 The right of access to personal data means that you have the right to access your personal data. You have this right for the sake of certainty and possible verification that the controller uses your personal data in accordance with legal regulations on the protection of personal data.
6.4 The right to rectification of personal data means that you have the right to have the processed data corrected if it is inaccurate or incomplete.
6.5 The right to erasure of personal data means that you can request the deletion or removal of your personal data where there is no reason for their further processing. However, this is not an absolute right; the controller may still have the right or obligation to retain your personal data (e.g. when fulfilling legal obligations).
6.6 The right to restriction of processing of personal data means that in certain situations you have the right to restrict the further use of personal data by the controller. If processing is restricted, the controller may still store the personal data, but may not further use it.
6.7 The right to withdraw consent to the processing of personal data for marketing purposes may be exercised in writing or electronically at the address or email of the controller stated in Art. 1 para. 1.2 of these Principles.
6.8 The right to object means that you have the right to object to certain types of processing of personal data, including processing for the purposes of sending commercial communications.
6.9 A complaint may be lodged with the supervisory authority, which is the Office for Personal Data Protection, seated at Pplk. Sochora 27, 170 00 Prague 7. The necessary details on the procedure for lodging a complaint are provided on the website of the Office for Personal Data Protection uoou.cz .
7. Conditions for the security of personal data
7.1 The controller declares that it has adopted all appropriate technical and organisational measures to secure personal data.
7.2 The controller has adopted technical measures to secure data repositories and repositories of personal data in paper form.
7.3 The controller declares that only persons authorised by it have access to personal data.
8. Final provisions
8.1 All legal relationships arising in connection with the processing of personal data are governed by the law of the Czech Republic, regardless of where access to them was made.
8.2 The Czech general courts have jurisdiction to resolve any disputes arising in connection with the protection of privacy between you and the controller.
8.3 The Controller is entitled to amend or supplement these Principles. The Controller shall publish a new version of the personal data protection principles on the website and shall also inform you of this change by email.
8.4 These Principles take effect on 1.1.2026.