Privacy Policy
I. Basic Provisions
1. The personal data controller within the meaning of Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the General Data Protection Regulation – GDPR) is New Climbing, s.r.o., ID No. 27 42 53 63, with its registered office at Táborská 979/5, 140 00 Prague 4, Czech Republic (hereinafter referred to as the “Controller”).
2. The Controller’s contact details are:
- Address: Táborská 979/5, 140 00 Prague 4
- E-mail: info@lezeckecentrum.cz
- Telephone: 604 273 621
3. Personal data are any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
II. Sources and Categories of Personal Data Processed
1. The Controller processes the personal data that you provide during electronic registration at the reception kiosk (your first name, last name, date of birth, and email address), as well as any personal data obtained in connection with the performance of an order placed by you.
2. The Controller processes your identification and contact details, together with any other personal data necessary for the performance of the contract.
III. Legal Basis and Purpose of Personal Data Processing
1. The Controller processes personal data on the following legal bases:
- the performance of a contract between you and the Controller pursuant to Article 6(1)(b) of the GDPR;
- the Controller’s legitimate interest in providing direct marketing (in particular for sending commercial communications and newsletters) pursuant to Article 6(1)(f) of the GDPR;
- your consent to processing for direct marketing purposes (in particular for sending commercial communications and newsletters) pursuant to Article 6(1)(a) of the GDPR in conjunction with Section 7(2) of Act No. 480/2004 Sb., on certain information society services, where no order for goods or services has been placed.
2. The Controller processes personal data for the following purposes:
- protection of the Controller’s legitimate interests, in particular to uniquely identify each visitor, ensure the safe operation of the Climbing Centre, and enforce compliance with the SmíchOFF Climbing Centre Visitor Rules. For these purposes, the Controller processes your first name, last name, date of birth, and email address;
- registration and administration of memberships, multi-entry passes, reservations, services, training sessions, courses, and purchases of goods and services made through the online store. For these purposes, the Controller processes your first name, last name, residential address, postcode, email address, and telephone number;
- protection of the health, safety, and property of the Controller, its visitors, and other persons through the use of CCTV. CCTV recordings are processed on the basis of the Controller’s legitimate interests and are retained for a maximum period of 15 days;
- performance of an order placed by you and the exercise of the rights and obligations arising from the contractual relationship between you and the Controller. When placing an order, you are required to provide the personal data necessary to process the order (in particular your name, address, and contact details). The provision of this personal data is a prerequisite for entering into and performing the contract. Unless such personal data is provided, the contract cannot be concluded and the Controller cannot perform the contract;
- sending commercial communications and carrying out other marketing activities.
3. The Controller engages in automated individual decision-making within the meaning of Article 22 of the GDPR. You have provided your explicit consent to such processing.
IV. Data Retention Period
1. The Controller retains personal data:
- for the period necessary to exercise the rights and fulfil the obligations arising from the contractual relationship between you and the Controller, and to exercise claims arising from such relationships (for a period of 15 years following the termination of the contractual relationship);
- where the processing of personal data for marketing purposes is based on your consent, until you withdraw your consent, but for no longer than 10 years.
2. Upon expiry of the personal data retention period, the Controller will delete the personal data.
V. Recipients of Personal Data (Subcontractors of the Controller)
1. The recipients of personal data are:
- persons involved in the provision of goods and services, and the processing of payments under a contract, including HO SmíchOFF, z.s., as the provider of climbing courses, camps, and clubs;
- the provider of the customer management system;
- providers of e-shop, website hosting, maintenance, and related IT services;
- persons providing marketing services.
2. The Controller does not intend to transfer personal data to a third country (a country outside the EU) or to an international organisation.
VI. Your Rights
1. Subject to the conditions set out in the GDPR, you have the following rights:
- right of access to personal data under Article 15 of the GDPR;
- right to rectification of personal data under Article 16 of the GDPR and, where applicable, right to restriction of processing under Article 18 of the GDPR;
- right of erasure of personal data under Article 17 of the GDPR;
- right to object to processing under Article 21 of the GDPR;
- right to data portability under Article 20 of the GDPR;
- right to withdraw consent to processing, in writing or electronically, using the postal or email address of the Controller specified in Article III of this Privacy Policy.
2. You also have the right to lodge a complaint with the Office for Personal Data Protection if you believe that your right to the protection of personal data has been infringed.
VII. Personal Data Security
1. The Controller declares that it has taken appropriate technical and organisational measures to ensure the security of personal data.
2. The Controller has taken technical measures to secure its data storage systems and personal data held in paper records.
3. The Controller declares that only persons authorised by the Controller have access to personal data.
VIII. Final provisions
1. By registering upon entry to the SmíchOFF Climbing Centre and signing the registration form, you confirm that you have read and understood this Privacy Policy and accept it in its entirety.
2. By submitting an order through the online order form, you confirm that you have read and understood this Privacy Policy and accept it in its entirety.
3. The Controller reserves the right to amend this Privacy Policy. Any updated version will be published on the Controller’s website.
This Privacy Policy comes into effect on 19 June 2020.
HO SmíchOFF, zs.
I. Basic Provisions
1. The personal data controller within the meaning of Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the General Data Protection Regulation – GDPR) is HO SmíchOFF, ID No. 063 50 968, with its registered office at Táborská 979/5, 140 00 Prague 4, Czech Republic (hereinafter referred to as the “Controller”).
2. The Controller’s contact details are:
- Address: Táborská 979/5, 140 00 Prague 4
- E-mail: hosmichoff@gmail.com
- Telephone: 733 366 553
3. Personal data are any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
II. Sources and Categories of Personal Data Processed
1. The Controller processes personal data you have provided to it or personal data it has obtained in connection with fulfilling your order.
2. The Controller processes your identification and contact details, together with any other personal data necessary for the performance of the contract.
III. Legal Basis and Purpose of Personal Data Processing
1. The Controller processes personal data on the following legal bases:
- the performance of a contract between you and the Controller pursuant to Article 6(1)(b) of the GDPR;
- the Controller’s legitimate interest in providing direct marketing (in particular for sending commercial communications and newsletters) pursuant to Article 6(1)(f) of the GDPR;
- your consent to processing for direct marketing purposes (in particular for sending commercial communications and newsletters) pursuant to Article 6(1)(a) of the GDPR in conjunction with Section 7(2) of Act No. 480/2004 Sb., on certain information society services, where no order for goods or services has been placed.
2. The Controller processes personal data for the following purposes:
- performance of an order placed by you and the exercise of the rights and obligations arising from the contractual relationship between you and the Controller. When placing an order, you are required to provide the personal data necessary to process the order (in particular your name, address, and contact details). The provision of this personal data is a prerequisite for entering into and performing the contract. Unless such personal data is provided, the contract cannot be concluded and the Controller cannot perform the contract;
- maintaining membership records and related activities;
- sending commercial communications and carrying out other marketing activities.
3. The Controller engages in automated individual decision-making within the meaning of Article 22 of the GDPR. You have provided your explicit consent to such processing.
IV. Data Retention Period
1. The Controller retains personal data:
- for the period necessary to exercise the rights and fulfil the obligations arising from the contractual relationship between you and the Controller, and to exercise claims arising from such relationships (for a period of 15 years following the termination of the contractual relationship);
- where the processing of personal data for marketing purposes is based on your consent, until you withdraw your consent, but for no longer than 10 years.
2. Upon expiry of the personal data retention period, the Controller will delete the personal data.
V. Recipients of Personal Data (Subcontractors of the Controller)
1. The recipients of personal data are:
- persons involved in the provision of goods and services, and the processing of payments under a contract;
- providers of e-shop, website hosting, maintenance, and related IT services;
- persons providing marketing services.
2. The Controller does not intend to transfer personal data to a third country (a country outside the EU) or to an international organisation.
VI. Your Rights
1. Subject to the conditions set out in the GDPR, you have the following rights:
- right of access to personal data under Article 15 of the GDPR;
- right to rectification of personal data under Article 16 of the GDPR and, where applicable, right to restriction of processing under Article 18 of the GDPR;
- right of erasure of personal data under Article 17 of the GDPR;
- right to object to processing under Article 21 of the GDPR; and
- right to data portability under Article 20 of the GDPR.
- right to withdraw consent to processing, in writing or electronically, using the postal or email address of the Controller specified in Article III of this Privacy Policy.
2. You also have the right to lodge a complaint with the Office for Personal Data Protection if you believe that your right to the protection of personal data has been infringed.
VII. Personal Data Security
1. The Controller declares that it has taken appropriate technical and organisational measures to ensure the security of personal data.
2. The Controller has taken technical measures to secure its data storage systems and personal data held in paper records.
3. The Controller declares that only persons authorised by the Controller have access to personal data.
VIII. Final Provisions
1. By submitting an order through the online order form, you confirm that you have read and understood this Privacy Policy and accept it in its entirety.
2. The Controller reserves the right to amend this Privacy Policy. Any updated version will be published on the Controller’s website.
This Privacy Policy comes into effect on 19 June 2020.