Privacy Policy

Last updated: To be added

English version is a translation for convenience; the Czech version prevails. Informativní překlad, závazná je česká verze.

This page explains what personal data we process when you buy from us or write to us, why, how long we keep it, who receives it and what rights you have.

1. Who processes your data

The controller is:

  • Carpe Diem GANG s.r.o.
  • Company ID (IČO): 19307454
  • Registered office: Kačírkova 933/5, Jinonice, 158 00 Prague 5, Czech Republic
  • E-mail: info@carpediemgang.cz
  • Phone: +420 773 041 098

We have not appointed a data protection officer; we are not required to under Article 37 GDPR. Please use the e-mail address above for anything concerning your data.

2. What data we process

When you place an order:

CategoryDetails
Contact datae-mail address, phone number
Delivery datarecipient's name, street and number, city, postcode, country; for pick-up point delivery the name and address of the chosen point
Billing data (only if different)name or company name, address, company ID, VAT ID
Order dataorder number, items and variants, prices, delivery, currency, order language, order status and its changes, your note (if you add one)
Payment datapayment result, the payment identifier at the provider, card brand and last four digits. The card number, expiry date and CVC never reach us — you enter them directly in the payment provider's secure form
Communicatione-mails you send us and a record that we sent you the order confirmation

When you write to us: your e-mail address and the content of your message.

When you only browse: the contents of your basket (product codes and quantities only) in a cookie in your browser — see the Cookies page.

IP address. To limit the number of checkout and admin login attempts we work with a hash of the IP address held temporarily in the server's memory. We do not store readable IP addresses in our database. Hosting logs (see section 5) may contain IP addresses for a period set by the hosting provider.

We offer no registration and no customer account, so you have no password with us.

PurposeLegal basis (GDPR)Scope
Processing the order, delivery, communication about the orderArt. 6(1)(b) — performance of a contractcontact, delivery and billing data, order and payment data
Handling withdrawals, complaints and refundsArt. 6(1)(b) and (c) — contract and legal obligationorder data, communication, payment data as needed for the refund
Accounting and tax obligationsArt. 6(1)(c) — legal obligation (Act No. 563/1991 Coll. on Accounting)billing, order and payment data
Security of the shop (rate limiting, abuse prevention)Art. 6(1)(f) — legitimate interest in secure operationhashed IP address, technical data
Establishing, exercising or defending legal claimsArt. 6(1)(f) — legitimate interestorder data and communication
Answering your questionArt. 6(1)(f) — legitimate interest in customer communicatione-mail and message content

We send no marketing messages and run no newsletter. We process no data on the basis of consent; if that changes we will ask for your consent in advance and update this policy.

Providing the data marked as required in the checkout is necessary to conclude and perform the contract.

4. How long we keep data

DataRetention
Accounting documents and the data on them5 years from the end of the accounting period concerned (Act No. 563/1991 Coll.)
Order data and related communicationfor as long as rights from defective performance and claims arising from them can be exercised; no longer than 5 years from delivery
E-mail and message content (enquiry without an order)1 year from the last communication
Hashed IP address for rate limitingminutes; kept only in the running server's memory
Basket cookie30 days from the last change to the basket
Admin login session (shop owner only)12 hours

After these periods we delete the data or anonymise it so that you can no longer be identified.

5. Who receives the data

We do not sell your data and do not pass it to anyone for their own marketing. We share it only with those without whom the shop could not operate:

RecipientPurposeData
Stripe (Stripe Payments Europe, Ltd., Ireland, and its affiliates) — payment servicescard payment processing, fraud prevention, refundse-mail, amount and currency, order identifier, card data entered directly with them
Zásilkovna / Packeta (Packeta Czech s.r.o., ID 28408306) — carrierdelivery and delivery notificationsrecipient's name, delivery address or pick-up point, phone, e-mail, parcel number
Resend (Resend, Inc., USA) — e-mail deliverysending the order confirmation and other transactional e-mailse-mail address and message content
Vercel (Vercel Inc., USA) — application hostingrunning the website; operational logstechnical request data (including IP address) and data passing through the site
Neon — database (Frankfurt region, EU)storing orders and related dataall data listed in section 2
Accountant / tax adviserbookkeepingaccounting documents
Public authoritiesonly where required by lawas required by law

We have data processing agreements under Article 28 GDPR with our processors.

6. Transfers outside the EU

The application and the database run in data centres in the European Union (Frankfurt). Some of our providers are, however, companies established in the United States or have a US parent company, and a transfer outside the EU may occur. Such transfers are based on the Standard Contractual Clauses approved by the European Commission, or on an adequacy decision, together with the provider's contractual safeguards.

7. Cookies

We store a single cookie of our own in your browser — the one holding the contents of your basket. We use no analytics and no advertising cookies. The shop administration has technical cookies of its own (login, login-form security and the interface language); they are set only for the shop owner and are never stored in a customer's browser. The full list, including third-party cookies in the checkout, is on the Cookies page.

8. How we protect the data

  • The site is served only over an encrypted connection (HTTPS).
  • We hold no card data — you enter it directly with the payment provider.
  • Only the shop owner has access to the administration; the password is stored as a cryptographic hash and the session expires after 12 hours.
  • The order status link contains a one-off secret token. Anyone who has the link can see the order and the delivery address, so please do not share it.

9. Automated decision-making

We carry out no profiling and no automated decision-making producing legal effects concerning you or similarly significantly affecting you. The payment provider may use automated tools to assess transaction risk and may decline a payment.

10. Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), to object to processing based on legitimate interests (Art. 21), and to lodge a complaint with a supervisory authority.

Write to info@carpediemgang.cz. We reply within one month; in complex cases we may extend the period and will tell you if we do. To avoid disclosing data to the wrong person we may ask for additional information to verify your identity (for example an order number).

The right to erasure does not apply where we are required to keep the data (for example accounting documents).

Supervisory authority: Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, https://uoou.gov.cz.

11. Changes to this policy

We may update this policy, for example when we start using a new service. The current version is always on this page together with the date of the last update.

Legal name
Carpe Diem GANG s.r.o.
IČO
19307454
VAT
not VAT registered
Registered address
Kačírkova 933/5, Jinonice, 158 00 Praha 5, Czechia
Web
www.carpediemgang.cz

Commercial register details will be added once they are confirmed.

Any questions?

Send us a message and we will get back to you.

info@carpediemgang.cz