Legal Notice

Information is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (the “GDPR”).

INFORMATION ON PERSONAL DATA PROCESSING

Basic information, Controller of personal data

These Information are provided in accordance with the GDPR.

Controller: WILLGRADE CZECH REPUBLIC s.r.o., registered office: Husovo nám. 22, 269 01 Rakovník, Company ID No.: 27452280, entered in the Commercial Register kept by the Municipal Court in Prague, File No. C 112858 (hereinafter the “Company” or the “Controller”). The Controller processes your personal data.

Personal data means any information relating to an identified or identifiable natural person (the “data subject”).

Contact details of the Company:
Postal address: WILLGRADE CZECH REPUBLIC s.r.o.
E-mail: info@4katharsis.cz
Phone: +420 353 311 642
Web: www.4KATHARSIS.cz, www.willgrade.cz

Scope and purpose of personal data processing

The Company, as Controller, hereby informs you about the method and scope of processing personal data, including the scope of the data subject’s rights related to such processing. The Company provides services and sells/distributes natural cosmetics and, for this purpose, operates the website www.4KATHARSIS.cz.

Personal data are processed primarily for the following reasons:

  1. Purchase of goods and services

  2. Customer care and improvement of the Company’s services

  3. Marketing activities (sending commercial communications by e-mail)

Within the Company’s activities, personal data are processed:

  1. To the extent provided in connection with ordering the Company’s products and/or services, in the course of negotiating and performing a contract with the Company (including order processing, complaints), and exercising the right of withdrawal from the contract.

  2. For the purpose of offering the Company’s goods and services (sending commercial communications) and Company marketing campaigns.

Personal data are processed on the legal bases of contract performance/contract conclusion, the Controller’s legitimate interests, and the data subject’s consent. The Company processes personal data that you provide to it. If you provide third-party data for order/service processing, it is your responsibility to inform that person and obtain their consent to these privacy information.

Method of processing personal data

The Company stores partners’ and visitors’ personal data only for the period necessary for the purpose for which they were collected, or for protecting the Company’s legitimate interests. Personal data processed for marketing purposes are processed until you withdraw your consent or object to processing. You may withdraw consent at any time at: info@4katharsis.cz.

Personal data may be processed manually and automatically in electronic information systems while adhering to prescribed security and procedural measures.

When visiting the website, the Company may collect certain information such as IP address, date and time of access, and the browser used.

To improve evaluation of website performance and to set certain marketing activities, the Company uses cookies on its website—small text files stored locally by the browser. Cookies enable distinguishing website visitors, personalizing content, and performing statistical analyses related to website visits. You have full control and can manage cookies in your browser at any time.

Information about your behaviour on the website (e.g., which goods are shown, from which link you were redirected) may also be processed. Such information is anonymized to a degree that it cannot be attributed to a specific person.

With your consent, and in accordance with Article 22(2) GDPR, you may be subject to a decision based solely on automated processing, including profiling (as defined in Article 4(4) GDPR). The Company uses personal data in profiling to adapt the website and commercial communications to your preferences and needs based on your previous activities on the website.

Recipients / processors of personal data

Your personal data may be provided to entities that offer sufficient guarantees of personal data protection and have been vetted by the Controller under a data processing agreement.

Personal data may be shared with third parties:

  • Delivery of goods and payment processing: To deliver your order, your personal data (name, surname, delivery address, phone or e-mail contact, amount due) are provided to your chosen carrier. The processor may process the data only for delivery and payment purposes. Online payments are processed via payment gateways or bank transfer. The Company does not have access to your card details; these are held by the secure payment gateway (e.g., ComGate) and the relevant bank.
    Processors/Carriers: Zásilkovna s.r.o., Česká pošta s.p., PPL CZ s.r.o., GEIS CZ s.r.o.

  • Commercial communications: For sending commercial communications (e-mail, SMS), the Company may use a third party vetted for confidentiality and data protection under a data processing agreement.
    Processor: MAKE4YOU GROUP SE, Company ID 04920147

In certain circumstances, the Company is obliged to share personal data of business partners or participants with third parties in accordance with data protection laws—e.g., financial institutions (banks), administrative and similar authorities, police, public prosecutor’s office, external advisors.
Your personal data are not transferred outside the European Economic Area.

Security of personal data

To ensure confidentiality, integrity, and availability of personal data, the Company uses modern IT systems and maintains appropriate security, technical and organizational measures against unlawful or unauthorized processing and against accidental loss or damage. Access to personal data is permitted only to persons who need it to fulfil their work duties and who are bound by legal or contractual confidentiality obligations.

Your rights regarding personal data processing

Under the GDPR, you may exercise the following rights:

  • Right of access and to obtain information on the processing of your personal data

  • Right to complete or rectify inaccurate/incomplete personal data

  • Right to obtain your personal data and transfer them to another controller (data portability)

  • Right to object to processing of your personal data

  • Right to restriction of processing

  • Right to erasure (“right to be forgotten”)

  • Right to lodge a complaint with a supervisory authority (in the Czech Republic: Úřad pro ochranu osobních údajů, www.uoou.cz)

Questions and contact

To exercise any of your rights or for any questions or complaints regarding processing, please contact: info@4katharsis.cz

Changes to the privacy terms

The current version of the policy is available on the Company’s website.

Effective date: 1 July 2019