Privacy Policy
Privacy Policy:
Data controller: The controller of personal data is La Grace s.r.o., with its registered office at Dlouhá 730/35, Staré Město, 110 00 Praha 1, company ID: 28118987, registered in the Commercial Register under file number C 312576 kept by the Municipal Court in Prague.
Which personal data we collect and for which purposes
As part of the process of buying a gift in our gift shop, we collect and process the following personal data:
- First name and surname
- address
- telephone
As part of the reservation system (binding reservation of a voyage) we collect:
- First name and surname
- address
- telephone
- passport number
- date of birth and place of birth
On which legal grounds we collect and process personal data
In order to collect and process your data, we must always have at least one of the so-called legal grounds for doing so. In our case we work with the following three grounds.
- Performance of a contract
When you buy a gift or make a reservation for a voyage. In order to provide this service properly, we need some of your personal data. - Compliance with a legal obligation
The processing of certain personal data for a particular purpose is expressly required by certain legal regulations of the Czech Republic. In our case this concerns, for example, accounting or information required by the coastguard. - Legitimate interest
As a legal entity, we want to keep improving the services we provide and, where appropriate, to develop and offer new ones. Likewise, we want to defend ourselves where necessary against attempts to obstruct these activities. The individual activities that serve to fulfil the aims mentioned above can be understood as our legitimate interest. This area includes, for example, the use of web analytics for the purpose of improving and developing our services, or the retention of communications in case of possible complaints.
How long we collect your data
Where we are complying with a legal obligation, we process personal data for the period laid down by legislation. Within the reservation process, we process it for the strictly necessary period, up to a maximum of 10 years.
How we protect your personal data
We protect personal data to the greatest possible extent against unauthorised access or transfer and against its loss or destruction. The system protecting your data comprises the following parts.
- Physical security and electronic security
We use state-of-the-art IT systems and applications. All the applications we use are secured by encryption and access to them is protected by login credentials.
Our office is secured with security locks. - Procedural security
We have mapped in detail all the operations we carry out with your personal data. This allows us to collect only the personal data we really need and to minimise how we handle it, and thus to reduce the potential risks of misuse as much as possible. - Personnel security
All persons who come into contact with your personal data in the course of fulfilling their employment or contractual duties are bound by a statutory or contractual duty of confidentiality. This duty continues even after their employment or contractual relationship with us has ended.
Who processes your data
Your personal data is processed for us by several entities, so-called processors, which we list in the overview below. All processors meet strict conditions in the area of data security and process your personal data for us on the basis of a personal data processing agreement or contractual terms.
Processing covers systematic activities such as the collection, recording, organisation, structuring and retrieval of personal data, as well as the storage of data on information carriers or its destruction.
Processors providing technical and technological services for La Grace s.r.o.
- Webnode
Your rights
As a natural person you have the following rights, which you may exercise with us at any time.
- The right to information
- The right of access to personal data
- The right to rectification, or completion, of personal data
- The right to erasure, i.e. the right to be forgotten
- The right to restriction of processing
- The right to data portability
- The right to object and the right not to be subject to automated individual decision-making, including profiling