PERSONAL DATA PROCESSING AND PROTECTION POLICY

I. General

This Personal Data Processing and Protection Policy (the “Policy”) describes the methods of collection, use and sharing of the personal data of you, our customers, who have visited or purchased on the website www.gcapoker.com<http://www.gcapoker.com. It is an e-shop in clothing and other goods, which is operated by the trading company ROLAM s.r.o., ID No.: 26342324, having its registered office at Janáčkovo nábřeží 1153/13, Smíchov, 150 00 Praha 5, which thus acts as a controller of your personal data pursuant to this Policy.

Contact data of the personal data controller:

Address: Selbská 2721, 352 01 Aš 1, Czech Republic

E-mail: eshop@grandcasinoas.eu

  

II. Categories of the Personal Data Being Processed

Some of the personal data we process is provided by you to us when you use our services or communicate with us, for example, when you register and provide your name, e-mail address or home address. However, we also collect technical device and access data that is recorded automatically when you interact with our services. This may include, for example, information about what device you use. We collect other data on the basis of our own data analyses (e.g., as part of market research studies or customer evaluations). If necessary, we also receive data about you from third parties, such as information agencies, affiliates or payment service providers.

Where personal data is referred to, it concerns any information about an identified or identifiable natural person; an identifiable natural person is a natural person who can be identified, directly or indirectly, in particular by reference to a certain identifier, such as a name, an identification number, location data, a network identifier or to one or more specific elements of the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Any information by which we cannot identify you (even in combination with other information) is considered non-personal information. Non-personal information is also referred to as anonymous. When we combine your personal data with anonymous data, all data in this data file is considered personal. When we ask you to provide us with certain personal information, you can of course refuse to do so. You decide what information you provide to us. However, it is possible that we may then be unable to provide you with the services you have requested. For example, we will not be able to deliver the goods you have ordered without your delivery address provided to us. If only certain information is required in connection with the service, we will draw your attention to this by marking it appropriately.

 

We process the following personal data categories in particular:

Contact details

If you contact us or place an order for goods using our e-shop, we record your contact details. As a rule, your contact details may include your name, postal addresses, telephone numbers, e-mail addresses or username and similar contact details.

Purchase data

Depending on the method of sale and the status of order processing, the purchase data may contain the following information:

Order number

Details of the items being purchased (identification, size, colour, purchase price, etc.)

Information on payment method

Delivery and billing address

Notices and communications in connection with purchases (e.g., cancelations, complaints and notices for the customer service)

Delivery and payment status

Information on the suppliers taking part in order execution, in particular the delivery service (such as shipment number)

Payment details

We record the payment details you provide to make the payment. We obtain additional payment data from external payment service providers and information agencies with whom we cooperate in the execution of payments and credit checks. We then only disclose such data to our payment service providers as is necessary for the processing of the payment.

The payment details are the following, for instance:

Preferred payment method

Billing addresses

IBAN and BIC and/or account number and bank code

Payment card details

Information on interests

Profile data

The profile data is the personal and demographic information about your person and your individual interests that you provide to us when you register for your customer account.

Your profile data include the following, for instance:

Your name and surname

Your contact details

Your preferences

Demographic data, such as gender, age and place of residence

 

III. Lawfulness and Purpose of Personal Data Processing

The personal data controller processes your personal data exclusively in accordance with the applicable legislation, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter referred to as “GDPR”).

The primary reason for processing personal data is to conduct business with you, while other reasons are to personalize and develop our services and to verify and improve data security. 

Processing pursuant to Article 6(1)(b) of the GDPR (i.e., processing is necessary for the performance of a contract to which the data subject is a party or for the implementation of measures taken prior to the conclusion of the contract at the request of the data subject) - execution of a purchase contract, processing of your purchase.

Processing pursuant to Article 6(1)(a) of the GDPR (i.e., the data subject has consented to the processing of their personal data for one or more specific purposes); e.g., personalization of purchases for the purposes of improving services and better meeting your needs and interests, marketing purposes, market research, data analysis, newsletter subscription, publication of product reviews.

Processing pursuant to Article 6(1)(f) of the GDPR (i.e., processing is necessary for the purposes of the legitimate interests of the relevant controller or third party, except where those interests are overridden by the interests or fundamental rights and freedoms of the data subject requiring the protection of personal data, in particular where the data subject is a child); e.g., personalization of purchases, advertising, market research, data analysis. 

 

IV. Data Retention Period

We will retain your personal data for as long as necessary for the purposes set out in this Policy, in particular for the performance of our contractual and legal obligations. Where necessary, we will also retain your personal data for other purposes where the law permits us to continue to retain it for certain purposes.

 

V. Personal Data Receivers (to whom we disclose your personal data)

We only disclose your personal data to other entities where permitted by law.

We work particularly closely together with certain service providers, for example in the area of customer service, with technical service providers (e.g., IT service provider) or with logistics companies (e.g., mail carriers). These service providers may only process your personal data essentially under specific conditions and at our request. If we use these providers as order processors, they will only have access to your personal data to the extent and for as long as strictly necessary to provide their respective performances. 

In accordance with the chosen method of payment of the purchase price of goods, we also provide your personal data to the extent as necessary to payment service providers.

If we are obliged to do so in order to comply with an administrative or judicial decision or in case of criminal prosecution, we disclose your personal data to law enforcement authorities or other third parties as necessary.

 

VI. Your Rights

You have the following rights under the terms of the GDPR:

Right to access your personal data under Article 15 GDPR

Right to rectification of personal data pursuant to Article 16 GDPR or restriction of processing pursuant to Article 18 GDPR

Right to erasure of personal data pursuant to Article 17 GDPR

Right to data portability pursuant to Article 20 GDPR

Right to object to processing pursuant to Article 21 GDPR

Right to withdraw consent under Article 7(3) GDPR

Right to lodge a complaint with a data protection supervisory authority pursuant to Article 77 GDPR

You can exercise your aforementioned rights by using the contact details of the controller, which are set out in Article I of this Policy.

  

VII. Personal Data Security Conditions

Your personal data is securely transmitted to us in an encrypted form and we also secure our website and other systems with technical and organizational measures against loss, destruction, access, alteration or dissemination of your personal data by unauthorized persons.

We also apply a risk management system, which includes regular review of the technical and organizational measures.

  

VIII. Final Provisions

We may amend this Policy in the future in order to improve our services, to develop our business or to follow possible changes in legislation, and we will always try to keep you informed of such changes as clearly as possible; however, we encourage you to take an active interest in whether this Policy has changed. 

By submitting an order via the online ordering form, you confirm that you are familiar with this Policy and that you accept it in its entirety.