🔥 Up to 30% OFF? YES! Summer is in full swing, but we're already making room for our autumn arrivals, and you will help us out! Shop orthopedic mats, active tools or storage boxes with our summer discounts until July 19 🛒

Privacy policy

Privacy Policy
MUFFIK s.r.o.

 

  1. Preamble

 

  1. These Personal Data Protection and Processing Rules (hereinafter referred to as the “Rules”) describe which personal data of clients who are natural persons, as well as other clients in relation to the natural persons acting on their behalf (hereinafter referred to as the “Data Subject”), are processed in the course of the activities of MUFFIK s.r.o., Company ID No.: 08849102, VAT ID No.: CZ08849102, having its registered office at Podolská 50, 147 00 Prague 4, place of business at Petrov nad Desnou 150, 788 16 Petrov nad Desnou, Czech Republic, registered in the Commercial Register maintained by the Municipal Court in Prague, File No. C 326367 (hereinafter referred to as the “Controller”).

 

  1. These Rules set out the types of personal data we collect and process when you use our services, as well as the manner in which your personal data are used, shared, and protected. You will also find here an explanation of the options available to you in relation to your personal data and how you can contact us. By means of this document, we hereby inform you about the processing of your personal data and about your rights in accordance with Article 12 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the “GDPR”).

 

  1. Personal data means any information relating to an identified or identifiable natural person. An identifiable natural person is a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

 

 

  1. Processors and Recipients of Personal Data

 

  1. The Controller is entitled to transfer personal data to entities with which it has concluded a data processing agreement and which process personal data on behalf of the Controller as its Processors.

 

  1. The personal data of the Data Subject may also be disclosed or made available to the following recipients or categories of recipients:
  • suppliers and contractors of the Controller,
  • employees of the Controller,
  • persons in another contractual relationship with the Controller (for example, providers of marketing and advertising services, law firms, cooperating tax advisors),
  • financial institutions and insurance companies,
  • public authorities, for the purpose of fulfilling statutory obligations imposed by applicable legal regulations.

 

  • Categories of Processed Personal Data

 

  1. The Controller is entitled to process, in particular, the following personal data of the Data Subject:
  • address and identification data used for the clear and unambiguous identification of the Data Subject (e.g., first name, surname, academic title, date of birth, personal identification number if applicable, permanent residence address, business address, mailing address, company identification number, VAT identification number) and contact details enabling communication with the Data Subject (e.g., correspondence address, telephone number, fax number, e-mail address, and other similar information),
  • identity card or passport number, the authority that issued the identification document, its validity period, and, where applicable, a copy of the identification document,
  • descriptive data (e.g., bank account details, payment information, or credit card information),
  • data provided beyond the scope of the relevant laws, processed on the basis of the Data Subject’s consent (e.g., the use of personal data for recruitment purposes, for marketing or promotional purposes, etc.),
  • personal preferences, including marketing preferences and cookie settings of the Data Subject,
  • other data necessary for the performance of a contract,
  • any other personal data provided by the Data Subject to the Controller.

 

  1. Purposes and Legal Basis for the Processing of Personal Data

 

  1. The Controller processes the personal data of the Data Subject for the following purposes:
  2. a) performance of a contract, based on Article 6(1)(b) GDPR,
  3. b) compliance with the Controller’s legal obligations established by generally binding legal regulations, based on Article 6(1)(c) GDPR (for example, the Controller’s obligation to retain accounting and tax documents),
  4. c) establishment, exercise, or defence of the Controller’s legal claims, based on Article 6(1)(f) GDPR,
  5. d) sending of commercial communications, based on Article 6(1)(f) GDPR, due to the existence of the Controller’s legitimate interest consisting in direct marketing,
  6. e) other marketing purposes of the Controller related to the offer of products and services, including the sending of information about organised events, products, services, and other activities (e.g., through newsletters or telemarketing); contacting for market research and marketing survey purposes; contacting for the purpose of sending Christmas, Easter, or other holiday greetings, and for sending discount vouchers, gifts, or similar materials — based on Article 6(1)(a) GDPR.

 

  1. Retention Period of Personal Data

 

  1. Personal data shall be processed only for the period necessary in view of the purpose for which they are processed. With regard to the above:
  • for the purpose referred to in point (a) above, personal data shall be processed until the contractual obligations have expired (this does not affect the Controller’s right to further process such personal data — to the necessary extent — for the purposes referred to in points (b), (c), (d), and/or (e) above),
  • for the purpose referred to in point (b) above, personal data shall be processed for the duration of the relevant legal obligation of the Controller,
  • for the purpose referred to in point (c) above, personal data shall be processed until the end of the fourth calendar year following the expiry of the warranty period under the contract (if a quality warranty was agreed upon in the contract), but at least until the end of the fifth calendar year following the termination of contractual obligations,
  • in the event of the initiation and continuation of judicial, administrative, or other proceedings in which the rights or obligations of the Controller in relation to the respective Data Subject are being addressed, the period of processing for the purpose referred to in point (c) above shall not end before the conclusion of such proceedings,
  • for the purpose of sending commercial communications under point (d) above, personal data shall be processed until the Data Subject expresses an objection to such processing,
  • for the purposes referred to in point (e) above, personal data shall be processed for the period for which the Data Subject has granted consent to the Controller in accordance with a separately executed consent to personal data processing. In such a case, the Data Subject acknowledges that, prior to the expiry of this period, the Controller may contact them for the purpose of renewing their consent.
  1. No later than by the end of the calendar quarter following the expiry of the processing period referred to above, the respective personal data, for which the purpose of processing has ceased, shall be destroyed (by shredding or by another method ensuring that no unauthorised person can gain access to such personal data) or anonymised.

 

  1. Method of Personal Data Processing

 

  1. The processing of personal data is carried out by the Controller. The processing takes place at the Controller’s registered office by authorised employees of the Controller or, where applicable, by Processors. The Controller may collect or obtain personal data through its website at info@muffik.eu, via online forms, electronic or telephone communication, personal meetings, or by other means. The processing is performed using computer technology and, where personal data are in physical (paper) form, also manually — in compliance with all security principles applicable to the management and processing of personal data. For this purpose, the Controller has adopted technical and organisational measures to ensure the protection of personal data, in particular measures preventing unauthorised or accidental access to personal data, their alteration, destruction or loss, unauthorised transmission, unauthorised processing, or any other misuse of personal data. All entities to which personal data may be disclosed respect the Data Subjects’ right to privacy and are obliged to act in accordance with the applicable legal regulations on personal data protection.

 

  1. No automated individual decision-making or profiling based on the provided personal data shall be carried out. The personal data of Data Subjects shall not be transferred to third countries.

 

  • Processing of Personal Data

 

  1. The Controller, the Controller’s suppliers, employees, and persons in other contractual relationships with the Controller shall always adhere to the following principles when handling personal data:
  • personal data shall be processed fairly and in compliance with applicable legal regulations,
  • personal data shall be collected, processed, and used only to the extent necessary for the purposes consistent with the purpose of personal data processing,
  • personal data shall be accurate and up to date; any inaccuracy shall be corrected as soon as the Controller becomes aware of it,
  • personal data shall be processed only for as long as necessary in relation to the purpose of their processing,
  • due regard shall always be given to respecting the rights of the Data Subjects,
  • appropriate technical and organisational measures shall be taken to prevent unauthorised or unlawful access to personal data or their disclosure. All personal data stored on computers are and shall remain protected by password-secured systems accessible only to authorised persons. The offices are locked after working hours and may be entered only by authorised personnel.

 

  • Information Provided to Data Subjects under the GDPR

 

  1. In connection with the processing of their personal data, Data Subjects have a number of rights, including the right to request from the Controller:
  • access to their personal data (under the conditions set out in Article 15 GDPR),
  • rectification or erasure of personal data (under Articles 16 or 17 GDPR),
  • restriction of processing of personal data (under Article 18 GDPR),
  • to object to the processing of personal data (under Article 21 GDPR),
  • the right to data portability (under Article 20 GDPR),
  • the right to obtain from the Controller confirmation as to which personal data are being processed, for what purposes, and to whom they may be disclosed,
  • the right to object to the processing of personal data,
  • the right to request correction or supplementation of personal data,
  • the right to withdraw consent to the processing of personal data, either in writing or electronically, to the postal or e-mail address of the Controller specified in these Rules.

 

  1. If a Data Subject discovers or reasonably believes that their personal data are being processed in a manner contrary to the protection of the Data Subject’s private and personal life, or in breach of applicable legal regulations, the Data Subject has the right to contact the Controller with a request for an explanation and/or for remedial action. Such a request must be made in writing by sending a letter to the Controller’s address: Petrov nad Desnou 150, 788 16 Petrov nad Desnou, Czech Republic, or by e-mail to: info@muffik.eu.

 

  1. If the Data Subject’s request is found to be justified, the Controller shall, without undue delay, remedy the defective situation. This shall not affect the Data Subject’s right to lodge a complaint directly with the supervisory authority — the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, tel. +420 234 665 555, website: www.uoou.cz.

 

 

Privacy Policy dated 1 October 2025