Last Updated: 17.12.2024

Privacy Policy

1.1 Data Controller

The controller of your personal data within the meaning of Article 4(7) of Regulation (EU) 2016/679 (GDPR) is: Company: RINVID s.r.o. Registered office: Záhřebská 562/41, Vinohrady, Praha 2, 120 00, Czech Republic IČO (Company ID): 223 81 589 DIČ (Tax ID): CZ22381589 Registered in: Obchodní rejstřík vedený Městským soudem v Praze oddíl C, vložka 415352 Email: info@rinvid.com Phone: +420 292 332 381 Website: www.rinvid.com

1.2 Categories of Personal Data Collected

We may collect and process the following categories of personal data: • Identification data: name, surname, company name • Contact data: email address, telephone number, postal address • Technical data: IP address, browser type and version, operating system, device type, referring URL, pages visited, time and duration of visits • Communication data: content of messages submitted via the contact form (powered by Formspree or equivalent) • Cookie and analytics data: data collected through Google Analytics 4 • Newsletter data: email address (if you subscribe to our newsletter)

1.3 Purposes and Legal Bases for Processing

We process personal data for the following purposes, each supported by a legal basis under Article 6(1) GDPR: • Responding to contact form inquiries: Art. 6(1)(b) – performance of a contract or pre-contractual measures; Art. 6(1)(f) – legitimate interest (Retention: Duration of communication + 3 years) • Website analytics (Google Analytics 4): Art. 6(1)(a) – consent (Retention: 26 months) • Newsletter distribution: Art. 6(1)(a) – consent (Retention: Until withdrawal of consent) • Compliance with legal obligations (accounting, tax): Art. 6(1)(c) – legal obligation (Retention: As required by law, typically 5–10 years) • Protection of legitimate interests (IT security, fraud prevention): Art. 6(1)(f) – legitimate interest (Retention: As long as necessary for the purpose) • Website functionality and session management: Art. 6(1)(f) – legitimate interest (Retention: Session duration)

1.4 Data Recipients and Processors

Your personal data may be shared with the following categories of recipients (data processors) who process data on our behalf under a data processing agreement: • Google LLC (Google Analytics 4) – website analytics. Google processes data in the EU/EEA under Standard Contractual Clauses (SCCs). • Formspree, Inc. (or equivalent contact form provider) – processing of contact form submissions. Data may be transferred to the USA under SCCs. • GoDaddy Operating Company, LLC – website hosting. GoDaddy processes server logs and technical data necessary for hosting.

1.5 Transfers Outside the EEA

Some of our data processors are established in the United States. Where personal data is transferred outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place in accordance with Chapter V of GDPR, including Standard Contractual Clauses (SCCs) approved by the European Commission, or the EU-U.S. Data Privacy Framework where applicable.

1.6 Your Rights as a Data Subject

Under GDPR, you have the following rights regarding your personal data: • Right of access (Art. 15) • Right to rectification (Art. 16) • Right to erasure (Art. 17) • Right to restriction of processing (Art. 18) • Right to data portability (Art. 20) • Right to object (Art. 21) • Right to withdraw consent (Art. 7(3)) • Right to lodge a complaint To exercise any of these rights, contact us at: info@rinvid.com. We will respond to your request within 30 days.

1.7 Supervisory Authority

You have the right to lodge a complaint with the Czech Data Protection Authority: Úřad pro ochranu osobních údajů (ÚOOÚ) Pplk. Sochora 27, 170 00 Praha 7, Czech Republic Web: https://www.uoou.cz Email: posta@uoou.gov.cz

1.8 Automated Decision-Making and Profiling

We do not engage in automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.

1.9 Security Measures

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include SSL/TLS encryption for data in transit, access controls, and regular security assessments of our hosting infrastructure.