Privacy Policy - Archive (1.5. 23 - 27.8. 23)

GBPR - štít

We are the company Útěkáři s.r.o. and we operate an e-shop on the website Utekari.cz.

To provide our services, sell goods, and operate our website, or e-shop, we process certain personal data. Our company becomes the "Controller" of your personal data when you provide it.

The protection of our customers' personal data is a priority for us. Therefore, we have prepared these Personal Data Processing Principles to inform you, our customers, how our company obtains, stores, and further processes your personal data in connection with the sale of our products and related services.

The processing of personal data is primarily governed by Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) ("GDPR").

I. Processing of Personal Data

A) Processing of personal data when using the contact form

If you inquire about our products and services, we will work with your contact details that you provide to us, mainly through the inquiry form. These are: your name, e-mail, and phone number.

For what reason?

We will contact you through them for further arrangements regarding the services.

On what legal basis?

This processing is based on Article 6(1)(b) of the GDPR – negotiating a contract, or taking steps at your request prior to entering into a contract.

How long will we process personal data?

If we do not establish further cooperation, we will process your data for a maximum of 1 year from our last communication.

B) Processing of personal data in case of purchase

If you make a purchase with us, we will work with the data you fill in. These are mainly billing details: first name, last name, address, phone number, and e-mail.

For what reason?

We need to process personal data to fulfill our contract – to provide you with our services. We will also use your contact details to communicate with you regarding the status of your order, or regarding complaints or your inquiries.

We will further process personal data to fulfill our legal obligations (mainly for accounting and tax purposes, or for handling complaints, debt collection during statutory limitation periods, and others).

On what legal basis do we process personal data?

This processing is based on Article 6(1)(b) of the GDPR – performance of a contract, and Article 6(1)(c) of the GDPR – fulfillment of our legal obligation.

Who all are the recipients of your personal data?

In addition to us (the Personal Data Controller), these are banks in case of order payment by transfer or online payment, and contractual shipping companies in case of ordering a voucher by mail.

How long will we process personal data?

For personal data processed for legal reasons, we adhere to the duration of this obligation. We process other information for the duration of our service provision and then for 3 years from the last provision of such service or delivery of goods.

C) Newsletters (commercial communications)

If you are a purchasing customer and have allowed us to do so during the purchase, we will use your e-mail address to send you our news.

You can unsubscribe from the newsletter at any time via your e-mail. You can unsubscribe from the subscription (sending news) at any time by clicking the link in each e-mail with which we have sent you a commercial communication. The unsubscribe link can always be found in the footer of this e-mail. You can also explicitly unsubscribe by sending an e-mail to info@utekari.cz. In the subject of the e-mail, please state, for example, "Unsubscribe" etc.

On what legal basis do we process your data?

This is permitted by Section 7(3) of Act No. 480/2004 Coll., on certain information society services, unless you have prohibited us from doing so during the purchase.

How long will we process personal data?

We retain information about newsletter subscribers until consent is withdrawn or an objection to processing is raised.

D) Processing of personal data when playing games

If you use our Services in the form of playing Games, we will collect some information about you, which in certain situations may be considered personal data.

At the beginning of each game, Players for each Team fill in the team name. If this information is associated with a specific person and allows the team or specific person to be identified, it can be considered personal data. For this reason, we recommend that Players choose a team name that does not fulfill the characteristics of personal data.

We further collect data about individual teams that are used to evaluate the performance of players, or teams, when playing individual escape games. This includes, for example, the speed of task completion, the number of correct/incorrect answers, the number of hints, and the number of points collected. Based on the monitoring of this data, we evaluate the success of individual teams.

For what reason do we process them?

The purpose of processing data when teams play games is their identification and subsequent mutual evaluation in the leaderboard.

How long will we process personal data?

We retain information about teams and players until it is necessary for its purpose or until the Players themselves submit a request for its deletion.

E) Processing of personal data in reviews

After Players, or individual teams, complete a Game, they are asked to send a review, or provide feedback to the Provider, on the Game played.

Sending a review and thus providing personal data related to it is voluntary.

However, to send a review by a Player to the Provider, it is necessary to fill in an identification/contact detail, which is an e-mail.

Reviews are not automatically published on our website. If the Provider decides that they would like to publish a selected review on their website, they will first contact its author using the provided e-mail address to obtain consent to publish their review.

For what reason do we process the data?

The purpose of collecting personal data associated with reviews is the ability to respond to authors' reviews.

How long will we process personal data?

If the review is not published based on the granted consent, we will process the data associated with the review for a maximum of 1 year from its submission.

II. Who will have access to the data?

Your data will remain with us (the Personal Data Controller). Nevertheless, some companies or other persons work for us who gain access to the data because they help us with the operation of our e-shop. These are:

  • the operator of the e-shop platform Shopify (Attn: Data Protection Officer
    c/o Intertrust Ireland, 2nd Floor 1-2 Victoria Buildings, Haddington Road
    Dublin 4, D04 XN32 Ireland)
  • Banks and companies involved in electronic payments
  • Shipping companies in case of ordering a printed voucher
  • E-shop administrators: Pavel Bureš and Martin Sedlář
  • Some of your personal data may also be accessible to suppliers of our IT systems and related services, who act as data processors, or providers of cloud solutions.

    We do not transfer your personal data outside the European Union (EU) and the European Economic Area (EEA).

    III. What else you should know

    We do not have a designated Data Protection Officer in our company.

    Our company does not make decisions based on automated processing or profiling.

    If you have any questions regarding personal data, please contact us at the e-mail address podpora@utekari.cz or info@utekari.cz.

    IV. Use of Cookies

    Cookies are text files containing small amounts of information that are downloaded to your device when you visit our website. Cookie files are then sent back to the website or another website that recognizes them each time you visit.

    Cookie files perform various tasks, for example, they enable efficient navigation between websites, remember your preferences, and generally improve the user experience. They can also ensure that advertisements displayed online are better tailored to you and your interests.

    We use the following cookies on our website:

    • Necessary cookies: are required for the operation of the website, for example, they allow you to log in to secure parts of the site and other basic functionalities of the site. This category of cookies cannot be disabled.
    • Analytical/statistical cookies: allow us, for example, to recognize and determine the number of visitors and to monitor how our visitors use the website. They help us improve the way the site works, for example by enabling users to easily find what they are looking for. We only launch these files with your prior consent.
    • Advertising cookies: are used to track preferences and enable the display of advertisements and other content that best matches your interest and online behavior. We only launch these files with your prior consent.

    Please note that third parties (including, for example, external service providers) may also use cookies and/or access data collected by cookies on the websites.

    Necessary cookies used:

    Cookie name Purpose Duration
    _secure_session_id Maintain user "session" during purchase, payment and delivery information. 24 hours
    _shopify_m Store user privacy settings. 1 year
    _shopify_tm Store user privacy settings. 30 minutes
    _shopify_tw Store user privacy settings. 2 weeks
    _storefront_u Supports updating data in the customer account. 1 minute
    _tracking_consent Store privacy rules 1 year
    c Store information necessary to complete the purchase. 1 year
    cart Used in connection with the shopping cart. 2 weeks
    cart_currency Set after completing a purchase to ensure that the new cart has the same currency as the last purchase. 2 weeks
    cart_sig "Hash" of the cart content. Used to ensure the integrity of the cart content and optimize some cart operations. 2 weeks
    cart_ts Used in connection with completing a purchase. 2 weeks
    cart_ver Used in connection with the shopping cart. 2 weeks
    checkout Used in connection with completing a purchase. 4 weeks
    checkout_token Used in connection with completing a purchase. 1 year
    dynamic_checkout_shown_on_cart Used in connection with completing a purchase. 30 minutes
    hide_shopify_pay_for_checkout Used in connection with completing a purchase. session
    keep_alive Used in connection with customer localization. 2 weeks
    master_device_id Used in connection with merchant login. 2 weeks
    previous_step Used in connection with completing a purchase. 1 year
    remember_me Used in connection with completing a purchase. 1 year
    secure_customer_sig Used to identify the user after logging into the e-shop so that they do not have to log in again. 20 years
    shopify_pay Used in connection with completing a purchase. 1 year
    shopify_pay_redirect Used in connection with completing a purchase. 1 hour, 3 weeks or 1 year, depending on value
    tracked_start_checkout Used in connection with completing a purchase. 1 year
    checkout_one_experiment Used in connection with completing a purchase. session
    checkout_session_lookup Used in connection with completing a purchase. 3 weeks
    checkout_session_token_<<id>> Used in connection with completing a purchase. 3 weeks
    identity_state Used in connection with customer authentication. 24 hours
    identity_state_<<id>> Used in connection with customer authentication. 24 hours
    identity_customer_account_number Used in connection with customer authentication. 12 weeks

    Performance, analytical and marketing cookies

    Cookie name Function Duration
    _landing_page Landing page tracking cookie 2 weeks
    _orig_referrer Landing page tracking cookie 2 weeks
    _s Shopify analytical cookie 30 minutes
    _shopify_d Shopify analytical cookie session
    _shopify_s Shopify analytical cookie 30 minutes
    _shopify_sa_p Shopify analytics regarding marketing and recommendations. 30 minutes
    _shopify_sa_t Shopify analytics regarding marketing and recommendations. 30 minutes
    _shopify_y Shopify analytical cookie 1 year
    _y Shopify analytical cookie 1 year
    _shopify_ga Shopify and Google analytical cookie session
    customer_auth_provider Shopify analytical cookie session
    customer_auth_session_created_at Shopify analytical cookie session

    Further information about cookies and their current list can be found through individual internet browsers, most often under "Developer Tools."

    Consent can be expressed through a checkbox in the so-called cookie bar. You can also subsequently refuse cookie files in your internet browser settings, or set to use only some of them.

    V. Data Security

    We have implemented and maintain necessary appropriate technical and organizational measures, internal controls and information security processes in accordance with best business practices corresponding to the possible impending risk for you as a data subject. At the same time, we take into account the state of technological development with the aim of protecting your personal data from accidental loss, destruction, alteration, unauthorized disclosure or access. These measures may include, among other things, measures ensuring physical security, taking appropriate steps to ensure the accountability of all persons who have access to your data, their training, regular backup, data recovery and incident management procedures, software protection of devices on which personal data is stored, and other measures.

    VI. Your rights in connection with the processing of personal data

    Among other things, the GDPR gives you the right to contact us and request information about what personal data we process, to request access to this data and to have it updated or corrected, or to request a restriction on processing. You can request a copy of the personal data processed, request us to delete personal data in certain situations, and in certain cases you have the right to data portability. You can object to processing based on legitimate interest.

    The controller is not obliged to fully or partially comply with the request in certain cases specified by the GDPR. This will especially be the case if the request is manifestly unfounded or unreasonable, especially due to repetition. In such cases, we may impose a reasonable fee reflecting the administrative costs associated with providing the requested information or taking the requested actions, or refuse to comply with the request.

    We will store information about the data subject exercising their rights with us and how we handled their request for a reasonable period (4 years) in order to document this fact, for statistical purposes, to improve our services and to protect our rights.

    If you believe that your data is not being handled correctly, you have the right to file a complaint with the Office for Personal Data Protection (ÚOOÚ), or to take your claims to court.

    VII. Updating the personal data processing policy

    We may modify or update these Personal Data Processing Principles on an ongoing basis. Any changes to these Personal Data Processing Principles will become effective upon their publication at the following link: https://utekari.cz/pages/zasady-ochrany-osobnich-udaju. We will inform our customers who have subscribed to the newsletter about significant changes via the email address they provided before the effective date.

    These terms are effective from May 1, 2023