I. Personal Data Protection
1.1 By entering personal data, the user confirms that they understand the terms of personal data protection, that they express their consent to their wording, and that they accept them in full. 1.2 The Provider is the controller of users’ personal data pursuant to Art. 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to as: “GDPR”). The Provider undertakes to process personal data in accordance with legal regulations, in particular the GDPR. 1.3 Personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person. 1.4 When placing an order, personal data required for the successful processing of the order (name and address, contact details) are requested. The purpose of processing personal data is to process the user’s order and to exercise the rights and obligations arising from the contractual relationship between the Provider and the User. The purpose of processing personal data is also to send business communications and carry out other marketing activities. The legal basis for processing personal data is the performance of the contract pursuant to Art. 6(1)(b) GDPR, the performance of a legal obligation of the controller pursuant to Art. 6(1)(c) GDPR, and the legitimate interest of the Provider pursuant to Art. 6(1)(f) GDPR. The legitimate interest of the Provider is the processing of personal data for the purposes of direct marketing. 1.5 To fulfil the licence agreement, the Provider uses the services of subcontractors, in particular providers of mailing services (personal data is stored in third countries) and web hosting providers. Subcontractors are vetted with regard to the secure processing of personal data. The Provider and the web hosting subcontractor have entered into a personal data processing agreement, under which the subcontractor is responsible for properly securing the physical, hardware, and software perimeter, and therefore bears direct liability to the user for any leak or breach of personal data. 1.6 The Provider stores the user’s personal data for the period necessary to exercise the rights and obligations arising from the contractual relationship between the provider and the user and to assert claims arising from these contractual relationships (for a period of 15 years from the termination of the contractual relationship). After this period has elapsed, the data will be deleted. 1.7 The user has the right to request access to their personal data from the provider pursuant to Art. 15 GDPR, rectification of personal data pursuant to Art. 16 GDPR, or restriction of processing pursuant to Art. 18 GDPR. The user has the right to erasure of personal data pursuant to Art. 17(1)(a) and (c) to (f) GDPR. Furthermore, the user has the right to object to processing pursuant to Art. 21 GDPR and the right to data portability pursuant to Art. 20 GDPR. 1.8 The user has the right to file a complaint with the Office for Personal Data Protection if they believe that their right to personal data protection has been violated. 1.9 The user is not obliged to provide personal data. However, the provision of personal data is a necessary requirement for concluding and performing the contract, and without providing personal data it is not possible to conclude the contract or for the provider to perform it. 1.10 The Provider does not carry out automated individual decision-making within the meaning of Art. 22 GDPR. 1.11 A person interested in using the Provider’s services by completing the contact form:
- agrees to the use of their personal data for the purposes of electronically sending business communications, advertising materials, direct sales, market research, and direct product offers by the Provider and third parties, but no more often than once a week, and at the same time
- declares that they do not consider the sending of information under point 1.11.1 to be unsolicited advertising within the meaning of Act No. 40/1995 Coll., as amended, as the user expressly consents to the sending of information under point 1.11.1 in conjunction with Section 7 of Act No. 480/2004 Coll.
- The user may withdraw their consent under this paragraph in writing at any time at info@mavis.cz
1.12 The Provider uses so-called cookies on its website to improve the quality of services, personalise offers, collect anonymous data, and for analytical purposes. By using the website, the user agrees to the use of this technology.
II. Rights and Obligations Between the Controller and the Processor (Data Processing Agreement)
2.1 The Provider acts as a processor of users’ clients’ personal data pursuant to Art. 28 GDPR. The user is the controller of this data. 2.2 These terms govern the mutual rights and obligations in the processing of personal data to which the Provider has gained access in the course of performing the licence agreement concluded by accepting the general terms and conditions at www.mavis.cz (hereinafter referred to as the „licence agreement”) concluded with the User on the date the user account was established. 2.3 The Provider undertakes to process personal data for the User to the extent and for the purposes set out in Articles 2.4 – 2.7 of these terms. The means of processing will be automated. As part of the processing, the Provider will collect, store on data carriers, retain, block, and destroy personal data. The Provider is not authorised to process personal data in conflict with or beyond the scope set out in these terms. 2.4 The Provider undertakes to process personal data for the user to the following extent: ordinary personal data, special categories of data pursuant to Art. 9 GDPR, which the User obtained in connection with its own business activities. 2.5 The Provider undertakes to process personal data for the user for the purpose of processing client inquiries and requests obtained from the contact form. 2.6 Personal data may only be processed at the premises of the Provider or its subcontractors pursuant to Article 2.8 of these terms, within the territory of the European Union. 2.7 The Provider undertakes to process the personal data of the User’s clients for the User, all for the period necessary to exercise the rights and obligations arising from the contractual relationship between the Provider and the User and to assert claims arising from these contractual relationships (for a period of 15 years from the termination of the contractual relationship). 2.8 The User grants permission for the involvement of a subcontractor as a further processor pursuant to Art. 28(2) GDPR, namely the application hosting provider. The User further grants the Provider general permission to involve another personal data processor in the processing; however, the Provider must inform the user in writing of any intended changes concerning the addition or replacement of other processors and give the user the opportunity to object to such changes. The Provider must impose on its subcontractors, acting as personal data processors, the same obligations regarding the protection of personal data as are set out in these terms. 2.9 The Provider undertakes that the processing of personal data will be secured in particular in the following manner:
- Personal data is processed in accordance with legal regulations and on the basis of the User’s instructions, i.e. for the performance of all activities necessary for the provision of the web platform.
- The Provider undertakes to technically and organisationally secure the protection of processed personal data so as to prevent unauthorised or accidental access to the data, its alteration, destruction or loss, unauthorised transfers, its other unauthorised processing, as well as other misuse, and to ensure that all obligations of the personal data processor arising from legal regulations are continuously secured, both in terms of personnel and organisation, throughout the period of data processing.
- The technical and organisational measures adopted correspond to the level of risk. The Provider uses them to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services, and to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident.
- The Provider hereby declares that the protection of personal data is subject to the Provider’s internal security regulations.
- Only authorised persons of the Provider and subcontractors pursuant to Article 2.8 of these terms will have access to personal data; such persons will have the conditions and scope of data processing determined by the Provider, and each such person will access personal data under their own unique identifier.
- Authorised persons of the Provider who process personal data under these terms are obliged to maintain confidentiality regarding personal data and security measures, the disclosure of which would jeopardise their security. The Provider will ensure their demonstrable commitment to this obligation. The Provider will ensure that this obligation continues to apply to both the Provider and authorised persons even after the termination of their employment or other relationship with the Provider.
- The Provider will assist the user, through appropriate technical and organisational measures, insofar as this is possible, in fulfilling the user’s obligation to respond to requests for the exercise of the rights of data subjects set out in the GDPR, and likewise in ensuring compliance with the obligations under Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to the Provider.
- After the termination of the provision of services connected with the processing under Article 2.7 of these terms, the Provider is obliged to delete all personal data or return it to the User, unless it is obliged to retain the personal data under a specific law.
- The Provider will provide the User with all information necessary to demonstrate that the obligations under this agreement and the GDPR have been fulfilled, and will allow audits, including inspections, conducted by the User or another auditor authorised by the user.
2.10 The User undertakes to promptly report all facts known to it that could adversely affect the proper and timely performance of obligations arising from these terms, and to provide the Provider with the cooperation necessary to fulfil these terms.
III. Final Provisions
3.1 These terms cease to be valid upon expiry of the period specified in Articles 1.6 and 2.7 of these terms. 3.2 The user agrees to these terms by ticking the consent box via the online form. By ticking the consent box, the user declares that they have read these terms, that they express their consent to them, and that they accept them in full. 3.3 The Provider is entitled to change these terms. The Provider is obliged to publish the new version of the terms on its website without undue delay, or to send the new version to the User by e-mail. 3.4 The Provider’s contact details for matters relating to these terms: +420 487 425 913, info@mavis.cz. 3.5 Relationships not expressly governed by these terms are governed by the GDPR and the laws of the Czech Republic, in particular Act No. 89/2012 Coll., the Civil Code, as amended. These terms take effect on 1.1.2022