GDPR

This document provides a comprehensive summary of how personal data is processed within Boilen s.r.o. Specifically, this document informs about the extent of data processing; the duration for which personal data processing takes place; the purpose for which personal data is processed; and also which individuals’ data and types of personal data are processed by Boilen s.r.o. It also addresses the rights that can be exercised in connection with personal data processing.

The processing of personal data and all rights associated with it are governed by Regulation (EU) No. 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC, as well as national Act No. 110/2019 Sb., on the processing of personal data.

If there is any ambiguity in the principles described in this document below, or if you wish to inquire or have anything clarified, you may use the contact details provided in the specification of the data controller.

The data controller is generally the entity that, alone or jointly with others, determines the purpose, means, and methods of processing personal data, bearing the responsibility associated with it.

The data controller is Boilen s.r.o., identification number: 098 28 192, registered office at Chotěšovská 680/1, Letňany, 190 00 Prague 9, registered in the Commercial Register maintained by the Municipal Court in Prague, file number C 343114 (hereinafter referred to as the "Company").

You can contact the Company by email at info@boilen.cz or by phone at +420 777 500 669.

Data Protection Officer: Tomáš Kukrál

The Company processes the personal data of the following persons in the course of its business activities:

The nature of the personal data processed by the Company varies depending on the relationship with the individual whose data is processed. Generally, it includes the following information:

The Company adheres to the strictest data protection standards when processing personal data. It processes personal data in accordance with the following principles:

The Company primarily obtains personal data through the voluntary provision by individuals. This often occurs when a contract is concluded, an order is placed, etc. The Company also obtains data from third parties authorized to handle personal data, as well as through its own activities.

The Company retains personal data only for the necessary period required to fulfill the purpose for which the data is processed. Once that purpose is fulfilled or no other reason for retention exists, the Company deletes the data.

If you grant the Company consent to process personal data, the Company will retain this data until you withdraw consent, or for as long as the consent remains valid.

If the Company obtains your personal data during pre-contractual negotiations and the contract is not concluded, the Company will retain such data for no longer than one year from acquisition.

If the Company obtains your personal data based on a contract, it will retain the data for as long as the final limitation periods arising from the contract persist.

Accounting and tax records (containing personal billing information) are retained by the Company for the period specified by special legislation.

The Company uses personal data for purposes arising from its business activities. For most such data, the Company does not require consent because a specific legal regulation authorizes such processing.

If consent is required for processing, such consent may be withdrawn at any time. Withdrawal of consent does not affect the legality of data processing conducted before consent was withdrawn.

The main purposes of data processing by the Company are:

The Company processes personal data primarily within its internal operations. Such data is provided to employees and long-term partners who are bound by confidentiality regarding the personal data they encounter in their work.

If necessary to achieve the purposes for which personal data was obtained, the Company shares personal data with processors or independent or joint controllers. These third parties must meet the minimum level of data protection according to applicable legal regulations.

If a legal obligation exists, the Company shares processed personal data with public authorities.

The Company may also share processed personal data based on consent from the individual concerned.

We may share your personal data under certain conditions with the following entities:

Individuals whose data is processed by the Company have several rights, which they can exercise by contacting the Company using the details provided above.

These requests will be processed within one month of submission, with a possible extension to three months in justified cases. The Company is obliged to inform the applicant of any extension.

The Company will not charge any fees for handling requests, except in cases where the request is manifestly abusive, unfounded, or unreasonable (e.g., repeated requests from the same applicant within a short time). In such cases, the Company may charge a fee to cover the costs incurred.

You have the following rights:

Right to access personal data
Everyone has the right to request information about whether their personal data is processed by the Company. If so, they are entitled to information about:

Individuals whose data is processed have the right to request deletion without undue delay if:

The person whose personal data is processed by the Company has the right to request that the Company does not use their personal data but also does not delete it, under the following circumstances:

No personal data is processed automatically within the Company’s operations.

The Company does not transfer personal data outside the European Union or the European Economic Area, nor to international organizations unless required by law.

If third parties provide the Company with personal data, they must:

To tailor website settings, the Company uses data analysis services, including Google Analytics and cookies.

The Company has implemented measures to ensure the highest level of data security in accordance with applicable regulations. If you suspect that your personal data is not secure, please contact us immediately using the contact information provided above.

These policies are valid and effective as of December 1, 2021.