GDPR

Manage GDPR

Privacy Policy
GEMORA
This Privacy Policy describes how personal data of customers of the GEMORA online store are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and applicable legal regulations.

1. Data Controller
Brand name: GEMORA
Operator: Jan Kruliš
Registered address: Jaurisova 515/4, 140 00 Prague, Czech Republic
Company ID (IČO): 72578688
E-mail: info@gemora.cz
Phone: +420 777 197 552
The controller processes personal data in compliance with applicable legal regulations.

2. Personal Data We Process
We process only personal data necessary for operating the e-shop and fulfilling contractual obligations, in particular:
first and last name
billing and delivery address
e-mail address
phone number
order and purchase details
payment details (to the extent necessary to process payment)

3. Purpose of Processing
Personal data are processed primarily for the following purposes:
processing and fulfilling orders
delivery of goods
communication with customers
accounting and compliance with legal obligations
handling complaints, returns, and withdrawals from contracts

4. Legal Basis for Processing
Personal data are processed on the basis of:
performance of a contract between the controller and the customer
compliance with legal obligations
legitimate interest of the controller (e.g. protection of legal claims)
Consent is required only where explicitly stipulated by law (e.g. marketing communications).

5. Data Retention Period
Personal data are retained for:
the duration of the contractual relationship
the period required by accounting and tax regulations
the time necessary to protect legal claims of the controller
After this period, personal data are securely deleted or anonymized.

6. Disclosure of Personal Data to Third Parties
Personal data may be disclosed only to the necessary extent to the following categories of recipients:
shipping and delivery service providers
payment service providers
accounting and tax advisors
IT and hosting service providers
Personal data are not transferred to third countries outside the EU.

7. Security of Personal Data
The controller has implemented appropriate technical and organizational measures to protect personal data, including:
secured access to systems
protection of access credentials
secure electronic communication
Personal data are protected against unauthorized access, loss, misuse, or damage.

8. Rights of Data Subjects
Customers have the right to:
access their personal data
rectification of inaccurate or outdated data
erasure of personal data (where legally permissible)
restriction of processing
data portability
object to processing
lodge a complaint with a supervisory authority

9. Supervisory Authority
The supervisory authority is:
Office for Personal Data Protection
Pplk. Sochora 27
170 00 Prague 7
Czech Republic
www.uoou.cz

10. Final Provisions
This Privacy Policy is valid and effective as of 30 December 2025.
The controller reserves the right to amend this Privacy Policy at any time.