Privacy Policy
1. General provisions
1.1 This privacy policy (the ‘Policy’) explains how Knihobot s.r.o. (english website: Bookbot), Company ID No.: 054 00 651, with its registered office at Dukelských hrdinů 359/21, Holešovice, 170 00 Prague 7, registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, Entry 289573 (‘Bookbot’ or ‘We’) collects and treats the personal data of users of the portal available at www.bookbot.com (the ‘e-shop’) and/or of individuals interested in the mediation of sale by Bookbot via the e-shop.
1.2 This Policy describes what personal data Bookbot processes, how and what it uses it for, and how it keeps your personal data secure. This Policy constitutes information within the meaning of Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the ‘GDPR’).
1.3 Under this Policy, personal data is processed in the form of any information that can identify a specific natural person or information that directly relates to such an identified person. The data processed by Bookbot under this Policy may include other information (e.g. anonymised) that is not personal data.
2. Who is the controller of your personal data?
2.1 The controller of your personal data is Knihobot s.r.o. (Bookbot) If you have any comments regarding the processing of your personal data or if you wish to exercise your rights, you can contact us by email at info@bookbot.com.
2.2 Bookbot has not appointed a data protection officer.
3. Why do we process your personal data?
3.1 We mainly process your personal data because the processing of your personal data is necessary for the performance of a contract concluded between us (in particular a purchase contract or a commissioning contract under which we arrange the sale of your goods). Without the provision of the necessary data, the contract cannot be concluded and properly performed.
3.2 In other cases, we only process your personal data for the purposes for which you have given us consent, typically in a web form or within communication with us. The provision of personal data is voluntary, however, without the provision of personal data we cannot deal with requirements and inform you of the measures taken.
4. What personal data do we process?
4.1 We process personal data that you provide to us by filling in order forms or requests for mediation of sale. We process your email, name, surname, telephone number, bank account, information about the condition of books and other goods you give to use for resale, or your company name, VAT number, registered office address or other information you provide to us.
4.2 When you visit the e-shop, we also passively process technical information such as IP address, type of internet browser, operating system or other technical metadata such as time zone settings. Information about your behaviour in the e-shop may be stored in an anonymised form for analysis in order to improve the functionality of the e-shop.
4.3 We also use information about your activity in the e-shop and the offers you have viewed to ensure better e-shop operation and marketing. This data is collected automatically by means of tools using so-called cookies. If you have cookies enabled on your device, this data is also collected via these files. If you do not agree with the processing of cookies, please disable them in your browser settings. Please note that disabling cookies will deactivate some basic functions, such as adding items to your basket.
4.4 Aggregated data and passively collected information can be used to produce general statistical summaries. These summaries are anonymised and do not contain your personal data within the meaning of the GDPR.
5. For what purposes do we process personal data?
5.1 The processing of your personal data is necessary for the performance of a contractual relationship based on a purchase, commissioning or other contract and the exercise of the rights and obligations arising from them; without the provision of this data, the contract cannot be concluded and performed by us.
5.2 We also process your personal data for the purpose of keeping records of e-shop customers and records of goods sold, administration of the user account of a registered e-shop customer, customer care (handling complaints or claims, handling queries regarding the e-shop, etc.), customer evaluation of the e-shop (if you provide it), the performance of marketing activities (e.g. displaying advertisements, remarketing, conducting analyses, etc.) and, in specified cases, direct marketing. We also use information about your activity in the e-shop to ensure better functionality of the e-shop.
5.3 We may also process your personal data for the purpose of check by public authorities.
6. What about automated decision-making and profiling?
6.1 Your personal data is not subject to automated decision-making, including profiling within the meaning of Article 22(1) and (4) of the GDPR.
7. Who do we pass your personal data to?
7.1 We mainly use your personal data for our internal purposes.
7.2 However, we are unable to provide all the necessary services ourselves, so we also use the services of specialised companies (e.g. carriage of goods, analytics, accounting, etc.). We only provide these companies with the information they need to perform their specific duties, which may include, but in most situations does not include, your personal information. These service providers are only entitled to use this information as necessary to provide their services to us and they do so on the basis of a duly concluded contract for the processing of personal data.
7.3 We are currently cooperating with the following companies:
- Česká pošta, s.p., Politických vězňů 909/4, 225 99 Praha 1 Česká republika;
- Zásilkovna s.r.o., Lihovarská 1060/12, 190 00 Praha 9;
- General Logistics Systems Czech Republic, s.r.o., Průmyslová 5619/1, CZ-58601 Jihlava;
- Facebook Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour Dublin 2, Ireland;
- Google Ireland Limited, Gordon House, Barrow Street, Dublin, D04 E5W5, Dublin; https://business.safety.google/privacy/
- Mailgun Technologies, Inc., 535 Mission St., San Francisco, CA 94105;
- Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855 Luxembourg;
- Heureka Shopping s.r.o., Karolinská 650/1, 186 00 Praha 8 – Karlín;
- vpsFree.cz z.s., Nad Dalejským údolím 2699/9, 155 00 Praha-Stodůlky;
- Levné knihy a.s., Do Čertous 2660/16, 193 00 Praha 9.
- Trusted Shops AG – Cologne, Subbelrather Straße 15c, 50823 Cologne, Nemecko
- Pikito a.s., Výtvarná 1023/4, Ruzyně, 161 00 Praha 6, Czech Republic
- DoDo Group SE, Pernerova 702/39, Karlín, 186 00 Praha 8, Czech Republic
- Deutsche Post DHL Group, Charles-de-Gaulle-Straße 20, 53113 Bonn, Germany
- Österreichische Post AG, Rochusplatz 1, 1030 Vienna, Austria
- Pošta bez hranic, třída 3. května 910, 763 02 Zlín – Malenovice, Česká republika
- EM Autodoprava s. r. o., Ul. Jána Hajdóczyho 5835/22, Trnava 917 01, Slovakia
- Airway spol. s r.o., Švecova 2383/2, 149 00, Praha 4, Czech Republic
- Adyen International B.V., Simon Carmiggeltstraat 6-50, 1011 DJ, Netherlands
- ComGate Payments, a.s. Gočárova třída 1754/48b, Pražské Předměstí, 500 02 Hradec Králové
- BloomReach, Inc.82 Pioneer Way Mountain View, CA 94041
- Thalia Book & Media GmbH, Country Road 41, 4010 Linz
- Slovak Parcel Service s.r.o., Senecká cesta 1, 900 28 Ivanka pri Dunaji
7.4 We do not pass personal data to any third party for the purpose of further processing.
8. Where do we retain the data?
8.1 The data is retained on our backup servers and in the data centre of vpsFree.cz z.s. The data centre security is fully GDPR compliant. All communication between your device and our web servers is encrypted.
9. How long do we process your personal data?
9.1 We process your personal data subject to your consent until your consent is withdrawn, but for a maximum period of 3 years from the time of consent. We retain your personal data that we process on the basis of another legal reason for the entire duration of the contractual relationship and subsequently for a period of 3 years.
9.2 After the above periods, we only retain or otherwise process personal data if required to do so by applicable law.
9.3 We will anonymise or delete your personal data from our databases and systems once the period for which we are required to retain it by law has expired.
10. What are your rights?
10.1 We process your data transparently, fairly, in accordance with the GDPR and generally binding legal regulations. You have the right to access your data and the right to have it corrected or completed. In cases of processing of your data for which you have given consent, you have the right to withdraw this consent at any time. In addition, you have the right to request the transfer of your personal data, the right to be informed of a breach of security of your personal data and, under certain conditions, the right to have certain personal data that we process in relation to you erased.
10.2 You can exercise your right to access your data and your other rights by sending a request electronically to info@bookbot.com, as well as any other questions. If you believe that the processing of your data is not in order, you can file a complaint with the Office for Personal Data Protection.
This Privacy Policy takes effect on 1 October 2021.