Privacy Policy
CENTROFLOR, s.r.o.
Company ID 640 53 229 VAT CZ640 53 229
Registered office: Šluknovská 402, 407 78 Velký Šenov
File no.: C 10044, Regional Court in Ústí nad Labem
E-mail: info@centroflor.cz | Tel.: +420 773 001 763
Effective as of May 26, 2025
1. Introduction
These Privacy Principles explain what personal data we collect when you make a purchase, subscribe to our newsletter, or simply visit our online store www.centroflor.cz, why we process it, and what rights you have. We process personal data in accordance with Regulation (EU) 2016/679 (GDPR), Act No. 110/2019 Coll. on the Processing of Personal Data, and Act No. 480/2004 Coll. on Certain Information Society Services.
Data Protection Officer (DPO) has not been appointed, as the controller is not subject to the obligation under Article 37 GDPR.
2. What Data We Process and How We Obtain It
| Category | Examples | Source |
|---|---|---|
| Identification | First name, last name, Company ID (for businesses) | Provided by the customer during registration or ordering |
| Contact | E-mail, phone number, billing and delivery address | Provided by the customer |
| Order details | Purchased items, price, payment reference, purchase history | Internally generated during the order process |
| Payment data | Bank account number (for refunds), card payment information (token) | GoPay payment gateway |
| Technical / cookies | IP address, cookies, logs | Automatically collected when visiting the website |
If we obtain contact information from public registers (e.g., ARES) for B2B offers, the data subjects are informed at the latest upon first contact (Art. 14 GDPR).
3. Purposes and Legal Bases for Processing
| Purpose | Legal basis | Details |
|---|---|---|
| Contract performance (order processing, complaints) | Art. 6 (1)(b) GDPR | Without this data we cannot deliver goods or issue invoices. |
| Accounting and tax obligations | Art. 6 (1)(c) GDPR | Act No. 563/1991 Coll. – documents archived for 10 years. |
| Direct marketing to existing customers | Art. 6 (1)(f) GDPR | Legitimate interest under § 7 (3) of the IS Services Act; all e-mails include an unsubscribe link. |
| Newsletter | Art. 6 (1)(a) GDPR | Voluntary consent – you may withdraw it at any time. |
| Customer satisfaction surveys (Heureka “Verified by Customers”) and reviews | Art. 6 (1)(f) GDPR | Balancing test available upon request. |
| Personalization, analytics & remarketing (cookies) | Art. 6 (1)(a) GDPR | Only after consent is granted via the cookie banner. |
Right to Object
For processing based on legitimate interest (marketing, Heureka surveys), you may object at any time (Art. 21 GDPR) – just send an e-mail to info@centroflor.cz.
4. Recipients and Transfers to Third Countries
| Category / Name | Purpose | Location | Safeguard mechanism |
|---|---|---|---|
| GoPay s.r.o. | Payment processing | Czech Republic | Data processing agreement |
| PPL, Česká pošta, Zásilkovna | Parcel delivery | Czech Republic | Contract – address and phone only |
| Heureka.cz | Customer satisfaction survey | Czech Republic | Data processing agreement |
| Google LLC (Google Analytics / Ads) | Web analytics, remarketing | USA | Standard Contractual Clauses (SCC) + supplementary measures |
| META Platforms Ireland Limited | Facebook / Instagram Ads (remarketing) | EU / USA | SCC + Data Privacy Framework |
| Seznam.cz, a.s. (Sklik) | Advertising and retargeting platform | Czech Republic | Data processing agreement |
| Ecomail.cz, s.r.o. | E-mail marketing | Czech Republic | Data processing agreement |
| Smartsupp.com, s.r.o. | Live chat support | Czech Republic / EU servers | SCC + EU data centers |
For any data transfer outside the EEA, we apply Standard Contractual Clauses (SCC) and regularly perform transfer impact assessments.
5. Data Retention Periods
| Category | Retention period |
|---|---|
| Invoices & accounting records | 10 years after the end of the accounting period |
| Orders & complaint records | 5 years after contract completion |
| Marketing / mailing lists | Until unsubscribed / max. 3 years after last interaction |
| Cookies | Depending on type: essential – for session duration; analytical / marketing – max. 13 months |
After expiry of these periods, data is securely deleted or anonymized.
6. Your Rights
- Access to your personal data (Art. 15).
- Rectification of inaccurate data (Art. 16).
- Erasure (“right to be forgotten”) in cases provided by law (Art. 17).
- Restriction of processing (Art. 18).
- Data portability (Art. 20).
- Objection to processing based on legitimate interest (Art. 21).
- Withdrawal of consent at any time, if consent was the legal basis.
Send your request to info@centroflor.cz. We will respond within 30 days.
If you believe your data is being processed unlawfully, you have the right to lodge a complaint with the Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7 – Holešovice, https://www.uoou.cz.
7. Cookies and Online Technologies
Our website uses necessary cookies for functionality and analytical / marketing cookies only after your consent via the cookie banner.
8. Data Security
- Encrypted data transfer (HTTPS), firewall protection, and regular server updates.
- Restricted access – authorized personnel only, using two-factor authentication.
- Encrypted backups stored on geographically separate servers.
9. Automated Decision-Making
We do not use profiling or automated decision-making within the meaning of Art. 22 GDPR.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The latest version is always available at www.centroflor.cz/podminky-ochrany-osobnich-udaju/ and becomes effective upon publication.
Last update: May 26, 2025
