1. GENERAL PROVISION
2. WHAT INFORMATION DO WE COLLECT AND HOW DO WE COLLECT IT
Data that you provide to us:
We collect and further process the following types of personal data:
your first and last name, your telephone number and email address when you purchase the goods;
financial information regarding your payment method for goods (the final 4 digits from your valid credit card number, type, expiration date, and the information about the issuer of the credit card, e.g. name of the bank etc.);
NOTE FOR CALIFORNIA RESIDENTS: According to California law, the financial information regarding your payment method may be considered as sensitive personal information. Please note that we collect this information only for the purposes specified in Section 3 and that we do not sell this information to any third parties. If you think that we use your sensitive personal information for any other purpose, according to California law you have the right to request to limit its use to that use which is necessary to perform the services or provide the goods. For information about how you can request your rights according to California law, please see Section 13.
your shipping and billing address;
Data which we process automatically:
In order to make your future purchases faster and more convenient, you can make a request to save your personal information for future purchases by clicking on a button to save your personal information during the checkout. In such cases we will collect information about your purchases, payment methods and your shipping and billing addresses.
Information from Other Sources:
We can also process your data from other sources, such as updated delivery and address information from our carriers, which we use to process the modification of your order.
3. HOW POETIZER USES YOUR INFORMATION
We may use information that we receive for the following purposes and on the legal basis listed below:
Processing necessary for the performance of the contract to which you as the customer are a party or in order to take steps at your request prior to entering into a contract
On this legal basis, we use the information about you to:
fulfil your order of products;
deliver the products that you have requested;
provide you with customer support and communicate with you, as a customer (or even a potential customer) by email, postal mail, telephone and/or mobile devices about the products or services that may be of interest to you or about the matters relating to your order of goods or regarding your rights or claims provided in Poetizer Terms of Sale;
verify your eligibility to purchase our products.
Processing necessary for compliance with a legal obligation to which we are subject:
On this legal basis, we use the information about you to comply with the legal requirements.
Processing necessary for the purposes of the legitimate interests pursued by a third party:
On this legal basis, we use the information about you to:
detect, prevent and address fraud and other illegal activity; to protect ourselves, you and others, including as part of investigations
Processing to which you have given us your consent:
On this legal basis, we use the information about you to send you email notifications regarding our new products and offers only when you give us your opt-in consent (direct marketing purposes).
4. PERIOD OF PROCESSING
5. PROTECTING YOUR INFORMATION
Taking into account the state of the art, scope, context and purposes of processing of your personal information as well as the risk of varying likelihood and severity for your rights and freedoms, we take reasonable steps to protect and secure your personal information against unauthorized access or disclosure, accidental loss, destruction, misuse or damage. We use security software to protect the confidentiality of your personal information. We review our business practices periodically for compliance with policies and procedures governing the security of our information. However, please be aware that no information transmission over the Internet or storage technology can be guaranteed to be 100% secure.
6. YOUR RIGHTS AND CHOICES IN CONNECTION WITH OUR DIRECT MARKETING
We will send you email notifications regarding our new products and offers only when you give us your consent to do so by clicking on a button “email me with news and offers” during the checkout when you purchase our goods. You are entitled to unsubscribe from these email communications from us anytime by clicking on the "unsubscribe link" provided in such communications.
According to GDPR, you also have a right to submit objections to direct marketing
. If you no longer wish to receive marketing or promotional materials from us or you do not wish that your personal information is used for processing related to such marketing or promotional activities, you can request that we cease to use your personal information for these purposes. In such a case, you will no longer be able to benefit from some of the Poetizer Shop or specific features for which this category of processing is essential (i.e. the receipt of promotional materials). You can submit your objections to direct marketing by emailing us at email@example.com
or by clicking on a link available in the email notifications described above in Section 6.1.
7. SHARING OF YOUR INFORMATION
We may share your information with the following categories of third parties:
Service providers (or “data processors” according to GDPR) providing us the software used to run the Poetizer Shop
In order to perform your purchase, to fulfil orders, etc., these service providers, such as Shopify Inc. or its affiliates, may process certain information about you on our behalf such as your name, billing address, shipping address, email address, phone number, and payment information.
Service providers (or “data processors” according to GDPR) which we use for the fulfilment of your orders and their shipment
In order to fulfil and ship your order, these service providers may process certain information about you on our behalf such as your name, billing address, shipping address, email address and phone number.
Service providers (or “data processors” according to GDPR) which we use for processing of your payments
In order to process your payments, these service providers may process certain information about you on our behalf such as your name, billing address, shipping address, email address, phone number, and payment information.
Service providers (or “data processors” according to GDPR) providing us with the tax compliance tools
We use certain service providers that provide us with tax solutions ensuring our tax compliance. These service providers may process certain information about you on our behalf such as your name, billing address, shipping address, email address, phone number, and payment information.
Service providers which we use for email marketing
We use certain service providers who on our behalf send you email notifications regarding our new products and offers as described in Section 6. These service providers may process certain information about you on our behalf such as your name, address, telephone number, and email address.
We may also share your information with our legal, financial, insurance and other advisors.
Legal Disclosure / Law Enforcement
We may be required to disclose your personal information, if we believe doing so is required or appropriate to comply with law enforcement or national security requests and legal process, such as a court order or subpoena.
We have entered into data processing agreements with the aforementioned processors ensuring, in particular, appropriate technical and organizational measures.
As we are a company located in the European Union, your information will be transferred from the European Union to the above-mentioned service providers who are located in the United States of America. These service providers may also transfer your information to us in the European Union. To ensure that your information is adequately protected, we have entered with our service providers located in the USA into the standard contractual clauses for the transfer of Personal Data to third countries set out in Commission Decision 2021/914 of 4 June 2021 which ensure an adequate level of data protection.
We may remove parts of data that can identify you and share anonymized data with other parties. We may also combine any anonymized information with other information in a way that it is no longer associated with you and share that aggregated information.
8. UPDATING YOUR PERSONAL INFORMATION
We prefer to keep your personal information accurate and up-to-date. If you discover that your personal data that you have provided to us are inaccurate or need an update, please contact us at firstname.lastname@example.org
as described in Section 14. We currently do not allow the option to update your account information directly on the Poetizer Shop platform, but we are working on it so that you will be able to use such a feature soon.
9. ''DO NOT TRACK'' TOOL
10. YOUR RIGHTS ACCORDING TO GDPR
We take reasonable measures to ensure that you are able to keep your personal information accurate and up-to-date. You can always ask us to confirm whether or not we process your personal information and if we do, to what extent, and require access to it.
In accordance with applicable laws and as further detailed below, you have the right to request access to, rectification, erasure or portability (e.g. to another service provider) of your personal information that we process, as well as to request restriction of such processing. If the processing of your personal information is based on your consent, you can also withdraw your consent that you have given to us at any time. Please note that withdrawal of your consent does not affect lawfulness of any processing based on the consent before its withdrawal.
Inaccurate information. If you find out that your personal information is inaccurate or incomplete, you may request us to update such personal information. We will rectify your information accordingly without undue delay
Erasure of your personal information. You can request that we erase your personal information at any time. If you approach us with such a request, we will delete (and ensure deletion by the processors that we engage) your personal information we have without undue delay. We will also delete all your personal information in case you withdraw your consent or under the circumstances that applicable laws require us to do so. Your personal information will be deleted accordingly, provided that it is no longer necessary for the fulfilment of your order or there is no other legal ground for the processing.
Restriction of processing. If you request to restrict the processing of your personal information, e.g. in circumstances when you contest the accuracy of your personal information, or lawfulness of our need to process your personal information, we will limit the processing of your personal information to the necessary minimum (storage). In such a case, if applicable, we will process your personal information only for the establishment, exercise or defence of legal claims or, where necessary, for protection of rights of another natural or legal person, or other limited reasons dictated by the applicable law. In case the restriction is lifted and we continue processing your personal information, we will inform you accordingly without undue delay.
Portability of your personal information. You have the right to receive personal data which relate to you and you have provided to us. If you approach us with such a request, we will provide you with your personal information in a commonly used and machine-readable format. If you request so, we may also send your personal information to a third party (another data controller) which you may identify in your request, unless such request would adversely affect rights or freedoms of others or would not be technically feasible.
If you exercise any of your rights according to this Section 10 or applicable laws, we will communicate any rectification or erasure of your personal data or restriction of processing in accordance with your request to each recipient to whom the personal information has been disclosed pursuant to Section 7, unless such communication proves impossible or involves disproportionate effort.
You have the right to lodge a complaint concerning our data processing activities to the competent supervisory authority, which is, for Poetizer being subject to Czech jurisdiction, the Czech Office for Protection of Personal Information, with registered seat at Pplk. Sochora 27, 170 00 Prague 7, Czech Republic (www.uoou.cz).
11. AUTOMATED DECISION-MAKING INCLUDING PROFILING
, when Shopify uses machine learning, it either: (1) still has a human being involved in the process (and so it is not fully automated); or (2) uses machine learning in ways that don’t have significant privacy implications.
12. CHILDREN'S PRIVACY RIGHTS
According to our Terms of Sale
, the purchase of goods on Poetizer Shop is primarily allowed to persons of legal age. We do not knowingly therefore collect personal information from children under the age of 13 (or under the age of 16 in certain jurisdictions, such as EU member countries). If you learn that your child has provided us with personal information without your consent, you may alert us at email@example.com
. If we learn that we have collected personal information of a child under the age of 13 (or under the age of 16 in certain jurisdictions, such as EU member countries) we will take steps to delete such information from our files as soon as possible unless we receive your verifiable parental consent.
13. YOUR PRIVACY RIGHTS IF YOU ARE A CALIFORNIA RESIDENT
Right to access your personal information. You have the right to request that we send you the categories and the specific pieces of your personal information we have collected in the 12 months preceding your request.
Deletion rights. You have the right to request that we delete any of your personal information collected from you, subject to certain exceptions set out in the California Consumer Privacy Act („CCPA”).
Non-discrimination. We will not discriminate against you in any way for exercising any of your rights related to the collection of your personal information.
“Shine the Light” right. You have the right to ask us one time per year for information about our disclosure, if any, of personal information to third parties for their direct marketing purposes in the preceding calendar year.
14. HOW TO CONTACT US
. We will respond within 1 month after receipt of your request, but we retain the right to extend this period by up to 1 month if necessary. We will in any event inform you within 1 month after receipt of your request whether it is necessary to extend the period to respond.