Privacy Policy
WAKEND s.r.o.
Effective from: May 10, 2024
WAKEND s.r.o., ID No.: 19879831, based at Kaprova 42/14, Staré Město, 110 00 Prague 1, registered with the Municipal Court in Prague, Section C, File 393150 (hereinafter the “Seller”), in its role as personal data controller, provides the following information regarding the processing of personal data in connection with the operation of the Wakend.store online store (the “E-shop”), purchase agreements made with E-shop customers (the “Buyers”), and the registration of Buyers on the E-shop.
This document also includes a description of the rights of data subjects related to the processing.
For any questions regarding privacy or to exercise your rights, please contact:
-
✉️ Email: info@wakend.co
1. WHAT PERSONAL DATA WE PROCESS, ON WHAT BASIS, AND FOR WHAT PURPOSE
1.1. Conclusion and Performance of the Purchase Contract
To conclude and fulfill a purchase contract for goods offered in the E-shop, we need the following personal data from Buyers (natural persons):
-
Identification details: name, surname, date of birth,
-
Contact details: email, phone number, delivery and billing address,
-
Depending on the payment method: bank account number and other payment-related information,
-
Details from your communication with us and information related to the conclusion and fulfillment of the purchase contract.
Without this data, it is not possible to conclude or fulfill the contract. The legal basis for this processing is the performance of a contract at the request of the Buyer.
1.2. Registration and Management of a User Account
The Seller allows Buyers to register and create a user account in the E-shop. When a Buyer registers, a contract for the creation and management of the user account is concluded.
For the performance of this contract, we process the same data listed in 1.1, plus:
-
Login credentials: username and encrypted password.
This data is necessary to create and manage the user account. Without it, registration and account operation is not possible. The legal basis is the performance of the contract at the Buyer’s request.
1.3. Fulfillment of Legal Obligations
We are legally required to process personal data in cases where applicable legislation obliges us to do so — e.g., for:
-
Handling customer complaints,
-
Maintaining accounting records,
-
Meeting tax obligations,
-
Complying with archiving laws.
The scope of data processed in these cases is determined by applicable legal requirements.
1.4. Legitimate Interests of the Seller
In justified cases, we may process personal data based on our legitimate interests. We always carefully assess and ensure that this processing does not unduly interfere with your privacy.
Example: Contact persons acting on behalf of Buyers (legal entities):
These are typically company representatives, employees, or authorized persons who communicate or contract with us on behalf of the Buyer. We process their personal data (name, surname, email, phone, job title, relationship to the Buyer, and communication records) for the purpose of:
-
Contract negotiation and fulfillment,
-
Maintaining communication,
-
Asserting or defending legal claims.
Example: Proof of consent to Terms and Conditions:
For contracts concluded electronically, we store data necessary to identify the Buyer as the contractual party, including timestamps as evidence of agreement and specific contract versions.
Example: Legal defense and enforcement:
We may process personal data to protect our rights in legal proceedings, audits, or inspections by public authorities (e.g., the Czech Trade Inspection Authority). This includes identification, contact, contract, and communication data.
1.5. Sending Commercial Communications
If you’ve:
-
Entered into a purchase contract with us,
-
Registered and created a user account, or
-
Voluntarily subscribed to our newsletter,
—we process your email and/or phone number to send you marketing messages and updates about our products and services.
Legal basis:
-
For existing customers: our legitimate interest in informing you about updates and new offers.
-
For newsletter subscribers without a contract: your explicit consent at the time of subscription.
Opt-out:
You can unsubscribe at any time, free of charge, by following the instructions in any marketing message, through your user account, or by emailing us directly.
2. WHERE WE GET YOUR PERSONAL DATA AND WHO WE SHARE IT WITH
2.1. Where the Data Comes From
We primarily collect your personal data directly from you. We do not gather any other data about you beyond what you provide or what arises from your activity on the E-shop.
You are obligated to provide only accurate and up-to-date information. If your personal data changes, you must update it accordingly.
2.2. Who We May Share Data With
We may share personal data in accordance with legal obligations:
-
To public authorities (e.g., tax offices, regulators) when required by law or upon official request.
We also work with data processors who assist with E-shop operations. These include:
-
Shopify Inc. (company ID: 549300HGQ43STJLLP808) – provider of the E-shop platform.
In certain cases, we share personal data with independent data controllers, such as:
-
Online payment providers used in the E-shop,
-
Shipping companies responsible for delivering your orders.
These parties process your personal data independently and are responsible for how they use it.
Unless specifically stated otherwise, we do not transfer your personal data outside the EU.
3. HOW WE PROCESS YOUR PERSONAL DATA
3.1. We primarily process your personal data electronically using automated means within our internal IT systems or those of our designated data processors.
3.2. In some cases, personal data may also be processed manually, particularly where manual processing is necessary or more suitable for a specific purpose.
3.3. Individuals who manage your data may include our employees or contractors. Their role includes correcting errors or ensuring accuracy. These individuals may only access personal data under the terms stated in this document and are bound by strict confidentiality obligations — especially regarding the security of personal data.
3.4. We always process personal data in accordance with applicable legal regulations and ensure it receives appropriate care and protection.
3.5. We take particular care to ensure that your rights are not infringed — especially your right to dignity, privacy, and personal integrity.
4. HOW LONG WE KEEP YOUR PERSONAL DATA
4.1. Purchase Contracts and User Account Agreements
We process personal data related to contract conclusion and fulfillment for as long as necessary to fulfill contractual obligations — that is, for the duration of the purchase contract or your E-shop registration.
4.2. Legal Obligations
We retain personal data required by law for the time periods defined by those laws.
-
For accounting and tax purposes, we keep billing and transaction data for 5 years from the end of the accounting period.
-
For VAT-related documents, we retain data for 10 years from the end of the taxable period in which the transaction occurred.
-
Data related to warranty claims or complaints is stored for the duration of the applicable warranty or claim period.
-
Archiving is carried out according to legal requirements under the Czech Act on Archives.
4.3. Legitimate Interests
Even after a contract ends, we may retain personal data for a period necessary to protect our legitimate interests — such as defending against legal claims by Buyers or third parties, including in court.
Unless a legal case is initiated, we keep this data for up to 5 years from the end of the contractual relationship.
4.4. Marketing Communications
We process personal data for sending commercial messages (as outlined in Section 1.5) until you unsubscribe. You can opt out at any time.
4.5. Extended Retention
We may retain personal data beyond the periods above if necessary — for example, if a court or administrative proceeding arises and the data is relevant to that case.
5. YOUR RIGHTS
You have the following rights regarding your personal data:
5.1. Right of Access
You have the right to request access to your personal data, including a copy of all personal data we hold about you.
To make a request, contact us via the email provided at the top of this document.
5.2. Withdrawal of Consent
If we process your data based on your consent, you may withdraw it at any time — freely and without charge — via:
-
Your user account,
-
The contact email provided, or
-
Any other method listed in this policy.
Once you withdraw consent, we will no longer process your data for that purpose.
If we process your data based on a legal obligation or other legal basis (not consent), you cannot withdraw consent, but you may still contact us and we will evaluate whether continued processing is necessary.
5.3. Additional Rights
You also have the right to:
-
Be informed about:
-
The purpose of data processing,
-
The personal data (or categories of data) we process, including its sources,
-
Any automated decision-making, including profiling, and the logic involved,
-
Recipients or categories of recipients of your data (including those in third countries),
-
How long your data will be stored, or the criteria used to determine this period.
-
-
Request an explanation from us,
-
Ask us to rectify, supplement, restrict, or delete your data (“right to be forgotten”),
-
Request a copy of your personal data or receive it in a structured, commonly used, machine-readable formatand transfer it to another controller,
-
Lodge a complaint with the Office for Personal Data Protection,
-
Object to the processing of your personal data.
6. HOW WE PROTECT YOUR PERSONAL DATA
We take the protection of your personal data seriously. To ensure your data is secure, we implement and enforce multiple layers of security, including:
-
Internal data protection and privacy policies,
-
Antivirus and anti-malware protection,
-
Firewalls,
-
Data encryption,
-
Access control and authorization management,
-
Regular backups,
-
Physical security measures.
All individuals who have access to your data (e.g. employees, contractors) are required to maintain confidentiality and follow strict data handling procedures. Disclosing security measures would compromise their effectiveness, so full technical details are not made public.
We always process your personal data in accordance with applicable legal regulations and strive to protect your rights — especially your right to dignity, privacy, and the integrity of your personal and private life.