Privacy policy

Privacy policy
Cookies and website processing policy
INFORMATION FOR CUSTOMERS ON THE USE OF FINGERPRINT READERS

Form Factory s. r. o.
ID: 05785880
with the registered office at Vinohradská 2405/190, Vinohrady, 130 00  Praha 3

PERSONAL DATA PROCESSING PRINCIPLES
INFORMATION FOR CLIENTS AND BUSINESS PARTNERS

INTRODUCTORY INFORMATION

Dear clients, business partners and visitors,

these principles inform you on how Form Factory s. r. o. (hereinafter „Company“) collects, processes, uses and transmits your personal data (hereinafter “personal data processing”).

Personal data mean information relating to a certain person who can be identified based on this information or in connection with other information.

The most common examples of personal data processed by the Company within its everyday business activity are identification data of clients and business partners (natural persons), or representatives, employees, coworkers or members of statutory bodies of business partners (natural persons), information on your membership or a concluded contract, contact details (in particular residence address, email address and phone number) and also records of visitors of Company premises.

Content

Who is the controller of your personal data?

The controller of your personal data is Form Factory s. r. o., with the registered office at Vinohradská 2405/190, Praha 3, ID: 05785880, incorporated in the companies register kept by Municipal Court in Prague under file No. C 270769.

The Company defines in what manner and for what purpose your personal data will be processed. You can find the Company´s contact details in the chapter “Inquiries and Contacts” below.

The Company and other connected companies from the Form Factory group are collectively designated herein as “Form Factory Group”.

What personal data about you and for what purpose does the Company process?

In the below table you will find what personal data, for what reason and for what purpose the Company processes in relation to clients, business partners and visitors.

a) Clients

Personal data
(Categories and examples)
Purpose of processing Legal ground for processing
Basic identification and contact data:

  • name and surname,
  • date of birth,
  • e-mail, phone number,
  • address.
  • Conclusion and performance of contract and related communication,
  • fulfillment of legal obligations,
  • records and enforcement of eventual claims.
  • Conclusion and performance of contract,
  • justified interest of Company in enforcing claims.
Data relating to contract with client:

  • membership type,
  • membership duration,
  • financial and invoicing terms.
  • Performance of relevant contract,
  • fulfillment of legal obligations.
  • Conclusion and performance of contract.
Data relating to personal training:

  • name,
  • profession,
  • age,
  • e-mail, telephone,
  • experience in personal training,
  • personal training goals,
  • health problems affecting configuration of personal training.
  • Performance of relevant training contract, personal training management.
  • Conclusion and performance of contract,
  • client´s consent.
Photography
  • Using photography for entry card
  • Relevant person´s consent.
Security data:

  • camera system records,
  • access system records.
  • Protection of Company property, clients and other persons,
  • protection against thefts and other criminal activity,
  • escape route check.
  • Justified interest of Company in providing entry check and protection of Company property, clients and other persons.
Data for marketing purposes

  • name and surname,
  • e-mail, telephone number, address,
  • information on current membership,
  • entitlements to discounts and benefits.
  • Promotion and support for sale and Company services,
  • Sending information on new services and products or other marketing/commercial messages.
  • relevant person´s consent with receiving commercial messages and with processing for marketing purposes,
  • justified interest in addressing clients via direct marketing and sending commercial messages.
Data about visits on our website:

  • IP addresses or cookies.
  • Records of visitors and improvements to our services and for statistical and analytical purposes. More information in „What are cookies?“ chapter below.
  • Justified interest of Company concerning information on visits on our website,
  • consent with such processing if required.

b). Business partners

Personal data
(Categories and examples)
Purpose of processing Legal ground for processing
Basic identification and contact data:

  • name and surname,
  • position, company,
  • e-mail, telephone number,
  • address,
  • payment and delivery data.
  • Conclusion and performance of contract and related communication,
  • records and enforcement of eventual claims.
  • Conclusion and performance of contract,
  • justified interest of Company in enforcing claims
Data for marketing purposes

  • name and surname,
  • position, company
  • e-mail, phone number,
  • information current membership business cooperation and communication
  • entitlements to discounts and benefits.
  • Promotion and support for sale and Company services,
  • sending information on new services and products or other marketing/commercial messages.
  • relevant person´s consent (even with giving business card) or granted consent with receiving commercial messages and processing for marketing purposes,
  • justified interest in addressing clients via direct marketing and sending commercial messages.

c) Company visitors

 

Personal data

 

Purpose of processing Legal ground for processing
Security data:

  • camera system records,
  • records of visitors.
  • Protection of Company property, employees and other persons,
  • protection against thefts and other criminal activity,
  • checking persons staying in Company premises.
  • Justified interest of Company in providing entry check and protection of Company property, employees and other persons.

What sources does the Company use to obtain your personal data?

The Company obtains personal data which are subsequently processed directly from its clients or from business partners, eventually from publicly available sources (such as OR or ARES) or from

visitors staying in Company premises.

Does the Company share your personal data with other persons?

a) External service providers

The Company uses external service providers which ensure in particular bookkeeping, accounting, claims administration, marketing and promotion and IT. In order to be able to fulfill their duties the Company must give them certain personal data of clients, business partners and/or visitors to the external service providers.

External service providers are cleared by the Company and they provide sufficient guarantees regarding privacy and protection of personal data of clients, business partners and/or visitors. The Company concluded written contracts for processing personal data processing with all these providers which undertook (within these contracts) to protect personal data and maintain Company standards for protecting personal data.

b) Form Factory Group companies

The Company may share personal data within the Form Factory Group (more information on Form Factory Group members is available at www.formfactory.cz website). Each time the Company needs to share your personal data, it will do so only when it is necessary and it will share them only with selected employees from the Form Factory Group for fulfilling their work duties.

The Form Factory Group adopts suitable measures to ensure that these selected employees shall be bound by the obligation to maintain these personal data in confidentiality

c) Disclosure of personal data to third parties

in accordance with legal regulations concerning personal data protection, under certain circumstances the Company is obliged to share personal data of clients, business partners and/or visitors with third parties which are not the mentioned service providers or members of the Form Factory Group.

These third parties include in particular:

  • administrative and similar bodies (financial authorities),
  • financial institutions (banks, insurance companies),
  • police, prosecution office,
  • external advisors.

Does the Company transmit personal data to countries outside EEA?

The Company does not transmit your personal data outside the European Economic Area.

How are your personal data secured?

In order to ensure confidentiality, integrity and availability of your personal data, the Company uses modern IT security systems. The Company maintains suitable technical and organizational security measures against illegal or unauthorized personal data processing and against accidental loss or damage of personal data.

The access to your personal data is provided only to persons who need them to fulfill their work duties and they are bound by legal or contractual confidentiality obligation.

How long will the Company store your personal data?

The Company stores your personal data only for the period for which it needs them for the purpose for which they have been collected, eventually for the protection of Company´s justified interests or for the period for which consent with processing has been granted.

If the Company processes data based on your consent, it will do so for the period of 10 years after the consent with processing has been granted or until it is recalled.

What are your rights connected to personal data processing?

You can asserts any of the below listed rights under the set conditions. These rights are given to you by legal regulations concerning personal data protection, in particular by the General Data Protection Regulation (GDPR):

  • the right to clear, transparent and comprehensible information on how your personal data are used and what your rights are;
  • the right to recall the granted consent with personal data processing at any time and free of charge, either by mail, email or in person at our address listed below;
  • the right to access to personal data and provision of additional information related to their processing by the Company, or processors;
  • the right to rectification of incorrect or incomplete personal data;
  • the right to deletion of personal data, in particular if (i) they are no longer necessary for further processing; (ii) the consent with their processing has been recalled; (iii) the data subject justifiably objected against the processing, (iv) they were processed illegally; or (v) they must be deleted under legal regulations;
  • the right to limitation of personal data processing, if (i) the data subject contests the integrity of personal data, for the period until the Company verifies their integrity; (ii) the processing is illegal; (iii) the Company no longer needs them but the personal data are needed by the data subject for the purposes of asserting his legal claims and (iv) the data subject objects against personal data processing, until the Company verifies whether its justified interests prevail over data subject´s interests;
  • the right to lodge objections against personal data processing if the data are processed for the purposes of Company´s justified interests. If you lodge an objection against further processing for direct marketing purposes, your personal data will no longer be processed for these purposes;
  • the right to obtain his personal data and transfer them to other controller while adhering to legal conditions;
  • the right to file a complaint with the Office for Personal Data Protection with the registered office at Pplk. Sochora 27, 170 00 Praha 7; uoou.cz, if you believe the Company is violating the obligations resulting from legal regulations for personal data protection.

We will react to your requests for assertion of rights within the statutory period, usually at the latest within 1 month following delivery of your request. If our reaction requires longer time in exceptional cases, we will inform you.

What are cookies?

Cookies are small data files necessary for correct functioning of pages and we therefore place them in your computer just as the majority of websites. Cookies are text files that websites place in your computer or mobile device when you start using a website. For a certain period, the websites can remember actions and settings you made on those websites. Thanks to this you do not need to enter these data again when you re-visit the website and go through individual sections of the web.

We use cookies mainly for marketing purposes, collection of statistical data and web traffic analysis so we can continue to improve our website and perfect our services we offer. The information on how you use our web is thus shared with our partners in the field of advertising and analysis, namely Google. To see how Google hands cookies, read the following document at https://www.google.com/policies/technologies/cookies/.

Inquiries and contacts

If you want to use any of your rights in relation to processing of your personal data or if you have other inquiry or complaint regarding their processing, contact us, please, by mail, phone or email using the below listed contact details.

Form Factory s.r.o.

Vinohradská 2405/190, 130 00  Praha 3

e-mail: osobniudaje@formfactory.cz

Amendments to these principles

It is possible that the Company decides to amend or update these principles. The current version of the principles will always be available at Company´s website (www.formfactory.cz), in the Personal Data Protection section.

Please, keep in mind that we will never make any amendments with retroactive effects and we will never amend our principles that affect handling of data that were collected before the amendments.

 

TOP

COOKIES AND WEBSITE PROCESSING POLICY

Form Factory s. r. o. with registered office at Vinohradská 2405/190, Prague 3, IČO 05785880, registered in the commercial register maintained by the Municipal Court in Prague, section C, insert 270769, issues this Cookie and Website Processing Policy.

If you visit our website that stores cookies, a small text file, i.e. a cookie, is created on your computer. Cookies are also stored in the web browser of mobile phones, tablets and other electronic devices.

On the basis of cookies, the given website “recognizes” you and can thus offer you the information you prefer and also ensure that we do not show you an advertisement that has already been displayed, or, for example, offer you to complete the information you filled in during previous visits to the website.

We use cookies to analyze website traffic through Google Analytics, Google Adwords, Facebook, Active Campaign, and HotJar services. These are analytics tools that help websites and apps understand how their visitors use them. Cookies can also be used to process statistical data on the use of websites without identifying a specific user.

In the event that you decide that you do not want cookies to be stored, it may happen that some parts of our website do not work as they should or they become slower.

What cookies we process

Functional (necessary): these cookies are necessary for the functioning of our website and the correct display of its content. They allow you to use basic functions such as logging in as a registered user or pre-filling forms and remembering your preferences. Without these cookies, we cannot guarantee the full functionality of our website. These cookies do not store any personal data.

Static: these cookies are used to record and analyze visitor behavior on our website. Used to aggregate general information about website movement, browser type, or time spent on the website. Subsequently, the analysis allows us to improve the functions of our website and its overall appearance.

Information in aggregated form that we obtain using these cookies can then be combined with other personal data. This is, for example, information related to the service you purchased from us. We process this information in the form of aggregated analyzes that allow us to improve our services. In this way, you are not individualized as a user.

These cookies are paired with the device you use to connect to our website. In cases where you use multiple devices, it may therefore happen that the cookie bar requiring consent will be displayed multiple times.

Marketing: these cookies help us to offer you marketing offers that may be of interest to you. This is to prevent us, for example, from showing you ads from an area you are not interested in. The information obtained on the basis of these cookies relates to the specific device from which you visit our website.

Third-party cookies are created and used by service providers such as Google Analytics, Google Adwords, Facebook, HotJar, Sklik and ActiveCampaign. We use these cookies to, for example, measure traffic to our website and the number of views.

How to check cookie settings

You can set cookies according to your choice. More information on how cookies work can be found here: https://www.allaboutcookies.org/.

You can delete all cookies stored on your device and you can also prevent their storage by changing the settings.

In exceptional cases, it may happen that the cookie is not saved correctly and then you may have problems logging into our web applications (e.g. andel.formfactory.cz). Instructions for deleting all incorrectly entered cookies can be found below:

Legal basis for processing cookies

This is the processing of personal data if we are able to tell based on your visit to our website that it is your device.

In the case of processing your personal data, we can only proceed with the processing if we have the corresponding legal title to do so according to the GDPR regulation. One of the legal titles is consent to the processing of personal data. As part of monitoring and evaluating activities, we are also entitled to process your personal data based on the administrator’s legitimate interest, i.e. for example offering you the best possible settings for specific services or support for your activities.

Automated decision making and profiling

If you have given your consent to the processing of personal data, we also combine it with information about your activities on our website. This connection of data occurs after you log in to our website: andel.formfactory.cz or fitness.formfactory.cz, by filling in and sending the order form or after accessing the website www.formfactory.cz or from the Moje Form Factory mobile application. The aim of this connection is to better recognize your preferences and interests and, based on this, to better adapt the offer of content that is shown to you.

You can object to the processing of personal data at any time against automated decision-making and profiling, or if the automated decision affects your rights and freedoms, you can ask us for an individual decision. See below for how you can withdraw your consent.

 

Third Party Analytics Tools

As part of our marketing services, our website uses third-party analytics tools primarily for the purpose of measuring website traffic, marketing campaigns, evaluating user behavior, tracking and logging mobile application errors.

  • eFitness: Form Factory’s operational information system.
  • Google Analytics: is an analytical tool for monitoring user behavior on our website and applications. The customer is evaluated within Google Analytics only on the basis of stored cookies. Form Factory does not provide any personal data of users to Google under any circumstances. Information on personal data processing and data security can be found here: www.google.com.
  • Facebook tools: we use the Customer Audience tool on our website for the purposes of Form Factory’s remarketing campaigns on Facebook, solely on the basis of your consent to the processing of personal data for marketing purposes, which you have given to Form Factory. You can revoke this consent at any time. We also use the Facebook pixel to optimize Form Factory’s marketing offers on Facebook if you have given Facebook the appropriate consent to the processing of cookies. Information on personal data processing and data security here: www.facebook.com.
  • Click: this is a tool we use as part of marketing promotion. Form Factory does not share any of your customer data.
  • Bing: Microsoft’s search engine, which is used for marketing promotion. Form Factory does not share any of your customer data.
  • HotJar: this is a tool for monitoring and evaluating user behavior on the web in the form of a heatmap. As a tool, HotJar evaluates information only on the basis of cookies. Form Factory does not share any personal information about customers. Information on personal data processing and data security here: www.hotjar.com.
  • Evaluating customer behavior: Through Survio, we evaluate the behavior of our website visitors based solely on their behavior on our website. The goal is to customize our website so that it is clearer and more user-friendly for you.
  • Personalization: it allows us to show the user the content that suits him as much as possible. As part of personalization, we identify the user, select a suitable offer for him and display it to him. Personalization takes place with the help of cookies. A non-personalized advertisement is displayed to a user who is not logged in to our website. A personalized ad will be displayed to a logged-in user (on the website or in the My Form Factory application) because cookies will be paired with the user profile.
  • Email campaigns (e.g. Ecomail, ActiveCampaign): we send two types of emails as part of campaigns. Emails with an offer to extend the contract (prolongation campaign) or with an offer to switch from a prepaid card to a flat-rate tariff (migration campaign) and random (ad-hoc) emails that are used for marketing promotion of Form Factory services.
  • Push campaigns: we send to the Moje Form Factory application according to the customer number of customers who have given us their consent/or have not objected to processing based on direct marketing.
  • Orders: as part of improving the quality of services, we evaluate the order process on our website. In practice, this means, for example, evaluating situations why it was not possible to complete an order on our website.

How long we will keep browsing data

Browsing data stored according to your cookie settings is not stored in our internal systems. We store the information that we associate with cookie data in accordance with the consent you have given us or for the duration of the contractual relationship between us and you. We retain the combined data from cookies and our systems for as long as is necessary for the purpose for which it was collected, but no longer than 6 months.

Withdrawal of consent

If we process your data based on your consent, you can change this consent at any time in the cookie settings.

Contact information

In case of any questions or comments, you can contact us via the contact email osobniudaje@formfactory.cz

Detailed information on the processing of personal data and your rights under the GDPR can be found in the Personal Data Protection Policy here: www.formfactory.cz/en/privacy-policy

We may update this Policy from time to time and if we do, we will notify you here. This version of the Policy is effective from November 1, 2023.

You can change the cookie settings for this website in the “Cookie settings” item at the bottom of the page.

 

TOP

INFORMATION FOR CUSTOMERS ON THE USE OF FINGERPRINT READERS

Dear clients,

we know how the processing of your fingerprints is a sensitive topic for you, which is why we have decided to issue this separate information on the use of fingerprint readers containing the necessary information about the way and purposes of processing your fingerprints and related data, their protection, including the reasons that we led to the introduction of fingerprint readers.

As members of our fitness clubs, you have entered into a membership agreement with the company Form Factory s.r.o. , with registered office at Vinohradská 2405/190, Vinohrady, 130 00 Prague 3, IČO 05785880, registered in the commercial register maintained by the Municipal Court in Prague for sp. C 270769, is part of the Form Factory Group.

The administrator of your personal data is always the one of the above-mentioned companies that operates the given fitness club in which fingerprint readers are used (hereinafter referred to as the ” Administrator “).

Content

What led us to introduce fingerprint readers?

First of all, we would like to inform you why we decided to introduce fingerprint readers in our clubs.

Our clubs in the Czech Republic have approx. 20,000 members, to whom we issue the entrance cards necessary to enter the fitness club. Repeated checks have found that these access cards are being misused to a significant extent by both fitness club members and third parties.

Entry cards are further lent by members of fitness clubs to third parties, or are not returned by fitness club members, which leads to significant costs on our end.

As we are interested in our clubs being visited only by clients with whom we have properly concluded contracts, we have decided on a fingerprint entry control system.

Fingerprint identification and authentication of authorized fitness club members is the most effective measure to prevent fitness club member access cards from being misused by club members themselves or third parties.
The fingerprint scanning system also eliminates our cost losses on special one-time access cards issued to club members, which are not returned very often by fitness club members.

We also considered other possible ways to achieve the purpose of the processing. However, none of the possible solutions achieves the same effect or is not practically feasible, or financially viable with regard to additional personnel costs, which as a result would have negative effects on the price paid by members for enabling the use of fitness clubs.

Is the use of a fingerprint reader a condition of your membership?

No, the provision of your fingerprints for the creation and storage of a vector template on your entry card (or other personal RFID data carrier) is completely voluntary and subject to your prior written consent.

If, despite the obvious advantages of the new system, you decide not to give us such consent, or if you revoke it later, we will require you to present your photo ID to verify your identity every time you enter our fitness club.

What personal data do we process and for what purpose?

The table below shows what personal data we process, for what reason and for what purpose.

Personal data  Purpose of processing Legal basis of processing
  • biometric data – fingerprints (stored in the form of a vector template on an entry card or other RFID carrier);
  • the number of the personal RFID data carrier of the fitness club member;
  • date and time of entry generated by the entry reader;
  • member identification data in the eFitness system.
  • asset protection Administrator:
    • allowing only authorized members to enter the Administrator’s fitness clubs;
    • prevention of misuse of the Administrator’s fitness club entry cards by unauthorized persons;
  • records of the use of fitness clubs by members.
  • the express consent of the member of the administrator’s fitness club (protection of the administrator’s property);
  • the Administrator’s legitimate interest in recording the use of fitness clubs by members.

How do we get your fingerprint and other personal data?

We get your fingerprints directly from you by placing your finger on the fingerprint reader. When scanning a fingerprint, the complete (biometric) fingerprint is not stored, but only a vector template is obtained, which is a reduction of the complete biometric data.

Before storing the template on your entry card (or other personal RFID data carrier), it is processed by a mathematical operation into a numerical expression, from which it is subsequently impossible to reconstruct the original biometric data, i.e. your fingerprint. The fingerprint reader does not read the fingerprint of a particular person as a whole, but only selects some features from the finger image specific to that person and compares them with the reference pattern stored on your entry card (or other RFID data carrier). The fingerprint reader does not store the fingerprint, it only uploads it to your entry card (or other personal RFID data carrier).

The other personal data we process is obtained when you place your entry card to the fingerprint reader, which reads your personal card number and the date and time of entry and sends it to the eFitness Manager system, which pairs the given data with your person and other data, which we process about you, as stated in the Principles of personal data processing – Information for clients and business partners https://www.formfactory.cz/ochrana-osobnich-udaju/ .

Do we share your personal data with other people?

Fingerprints

Fingerprints or the stored vector fingerprint template will only be stored on the entrance card or other personal RFID data carrier of the fitness club member, neither we nor third parties will have access to the template. Thus, fingerprints will not and cannot be shared with anyone.

Other personal data

The time and date of entry will be generated directly by the entry device and stored in the eFitness system and associated with the member’s identification data stored in this system.
Personal data – the unique number of the personal RFID data carrier is stored in the eFitness system, just like the member’s identification data.
This data may be shared with external service providers, companies from the Form Factory Group or third parties, as detailed in the Personal Data Processing Policy – Information for clients and business partners https://www.formfactory.cz/en/privacy-policy/ .

Do we transfer personal data to countries outside the EEA?

We do not transfer your personal data outside the European Economic Area.

How is your personal data secured?

Personal data – fingerprints will only be stored on the entrance card or other personal RFID data carrier of the fitness club member, i.e. without access by the Administrator or any other person. Saving in the form of a vector template does not allow for the retrospective reconstruction of fingerprints or any other use of them.

The time and date of entry will be generated directly by the entry device and stored in the eFitness system and associated with the member’s identification data stored in this system.

Personal data – the unique number of the entry card or other personal RFID data carrier is stored in the eFitness Manager system, just like the member’s identification data.

The eFitness Manager system is secure and protected against access by third parties. Only selected employees of the Administrator have access to the eFitness system, for which a unique password and login name is created by the administrator in cooperation with the HR department of the Administrator. The password is changed at regular intervals. In case of termination of employment of an employee with access to the eFitness system, his access to the eFitness system is blocked.

Assessment of the impact on the protection of personal data

Taking into account that it was likely that the type of processing we intended, especially when using new technologies, taking into account the nature, scope, context and purposes of the processing, would result in a high risk to the rights and freedoms of natural persons, we carried out even before the launch of the fingerprint scanning system, the so-called personal data protection impact assessment according to Article 35 of the General Regulation on Personal Data Protection ( GDPR ).

As part of the assessment, we assessed the necessity and adequacy of the given processing operations from the point of view of the purposes, we assessed the risks to the rights and freedoms of the data subjects and took measures to address these risks.

Based on the assessment of the impact on personal data protection, we have come to the conclusion that in the case of strict compliance with the set technical and organizational measures, the compliance of the fingerprint scanning system will be ensured, taking into account the nature, scope, context and purposes of processing and the identified risks for the rights and freedoms of data subjects fingerprints and related processing of personal data with the duties of the administrator determined, among other things, in Article 24 of the GDPR.

For your idea, we briefly summarize the measures that we have adopted and follow when processing personal data, and which we regularly evaluate and, where appropriate, modify:

  1. personal data will be processed only by authorized persons with individual user permission and access rights and in compliance with the established procedure for access to records;
  2. we will keep records of persons authorized to process personal data, including the form, scope and purpose of access;
  3. we will strictly comply with the accepted guidelines on technical and organizational security of personal data processing;
  4. we will regularly train and test persons authorized to process personal data on the obligations in the area of ​​personal data processing security and the obligations of the Administrator;
  5. persons authorized to process personal data will be instructed on the confidentiality of personal data and will be contractually obliged to maintain confidentiality about personal data and measures to secure it;
  6. premises in which personal data will be processed or stored (including documentation and material carriers containing personal data) will be secured against access by unauthorized persons;
  7. personal data will be stored on secure servers or technical data carriers to which only authorized persons have access based on access codes or passwords;
  8. we will document access to servers, technical data carriers and documents containing personal data, including any transfer of personal data to third parties;
  9. contracts with external suppliers who install and/or maintain the fingerprint scanning system will contain sufficient technical and organizational guarantees for the protection of personal data, in particular ensuring confidentiality, guaranteeing minimum technical and organizational measures to protect personal data and the obligation to cooperate;
  10. we will regularly test and update the measures taken to secure the processing and protect personal data, at least once a year or more often if there is a significant organizational change or a change in technology, environment, etc., or if there is a serious incident affecting the security of the processing personal data.

How long will we keep your personal data?

We will keep your personal data only for as long as we need it for the purpose for which it was collected, or to protect our legitimate interests or for the period for which consent to processing has been granted.

What are your rights regarding the processing of personal data?

Under the specified conditions, you can exercise all the rights listed below, which are granted to you by the legal regulations governing the protection of personal data, in particular the GDPR:

  • the right to clear, transparent and understandable information about how your personal data is used and what your rights are;
  • the right to revoke the granted consent to the processing of personal data at any time, free of charge, by post, e-mail or in person at our address listed below;
  • the right to access personal data and to provide other information related to their processing by the Administrator, or processors;
  • the right to correct incorrect and incomplete personal data;
  • the right to delete personal data, especially if (i) they are no longer needed for further processing; (ii) consent to their processing has been revoked; (iii) the data subject has legitimately objected to their processing; (iv) have been processed unlawfully; or (v) must be deleted as required by law;
  • the right to restrict the processing of personal data, if (i) the data subject challenged the correctness of the personal data until the Administrator verifies their correctness; (ii) the processing is unlawful; (iii) the Administrator no longer needs them, but the personal data is needed by the data subject for the purposes of exercising his legal claims or (iv) the data subject objects to their processing until the Administrator verifies whether the legitimate interests of the Administrator outweigh the interests of the data subject;
  • the right to object to the processing of personal data if they are processed for the purposes of the Administrator’s legitimate interests. If you object to further processing for direct marketing purposes, personal data will not be further processed for these purposes;
  • the right to obtain your personal data and transfer them to another administrator when legal conditions are met;
  • the right to file a complaint with the Office for Personal Data Protection, based in Plk. Sochora 27, 170 00 Prague 7; www.uoou.cz, if you believe that the Administrator is violating the obligations arising from legal regulations on the protection of personal data.

We will respond to your requests for the exercise of rights within the statutory period, usually no later than 1 month after receiving the request. If our response would require a longer time in exceptional cases, we will inform you about it.

Questions and contacts

If you wish to exercise any of your rights in connection with the processing of your personal data or have any other question or complaint regarding their processing, please contact us by mail, telephone or e-mail at the contacts listed below.

Form Factory s.r.o.

address: Vinohradská 2405/190, 130 00 Prague 3
e-mail: osobniudaje@formfactory.cz

Changes to this policy

We may decide to change or update this policy. You will always have the current wording of the policy available on the www.formfactory.cz website in the Privacy section.

However, we assure you that there will be no retroactive changes.

 

TOP