Privacy Policy
I.
General provisions
The controller of personal data under Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) is the limited liability company
NICH s.r.o., with its registered office at Zábřežská 596/40, 787 01 Šumperk,
Company ID: 22626999, VAT ID: CZ22626999,
registered in the Commercial Register maintained by the Regional Court in Ostrava, Section C, File 98784 (hereinafter the “Controller”).
Controller’s contact details:
email: truelights@email.cz telephone: +420 737 188 180 address: Zábřežská 596/40, 787 01 Šumperk
Personal data means any information relating to an identified or identifiable natural person within the meaning of Article 4 GDPR.
The Controller has not appointed a data protection officer.
II.
Sources and categories of personal data processed
The Controller processes personal data provided by the data subject or obtained in connection with the performance of a contract (in particular, an order for goods or services).
The data processed includes, in particular, identification and contact details (first name, surname, address, email and telephone number), order details, payment details and technical data relating to the use of the website.
III.
Legal basis and purpose of personal data processing
The legal bases for processing personal data are:
– performance of a contract under Article 6(1)(b) GDPR, – compliance with a legal obligation of the Controller under Article 6(1)(c) GDPR, – the Controller’s legitimate interests under Article 6(1)(f) GDPR, in particular the protection of legal claims and direct marketing, – the data subject’s consent under Article 6(1)(a) GDPR, in particular for sending commercial communications where no contract has been concluded.
Personal data is processed, in particular, for the following purposes:
– processing orders and fulfilling the contractual relationship, – complying with legal obligations (in particular accounting and tax obligations), – sending commercial communications and marketing information, – protecting the Controller’s legitimate interests.
The Controller does not carry out automated individual decision-making within the meaning of Article 22 GDPR.
IV.
Personal data retention period
The Controller retains personal data:
– for the duration of the contractual relationship and subsequently for 15 years after its termination, to protect legal claims and comply with legal obligations, – for the duration of consent to processing personal data for marketing purposes, but for no longer than 20 years, unless consent is withdrawn earlier.
Once the retention period has expired, personal data is securely deleted or anonymised.
V.
Recipients of personal data
Recipients of personal data include, in particular:
– persons involved in delivering goods or services and processing payments, – providers of services for operating the e-shop (e.g. Shoptet), – accounting, tax and legal advisers, – providers of marketing, mailing and cloud services.
Personal data may be transferred to third countries outside the EU only to entities providing appropriate safeguards for personal data protection under the GDPR.
VI.
Rights of the data subject
Subject to the conditions set out in the GDPR, the data subject has, in particular, the right:
– to access their personal data under Article 15 GDPR, – to have personal data rectified or completed under Article 16 GDPR, – to have personal data erased under Article 17 GDPR, – to restrict processing under Article 18 GDPR, – to object to processing under Article 21 GDPR, – to data portability under Article 20 GDPR.
The data subject also has the right to lodge a complaint with the Czech Office for Personal Data Protection.
VII.
Security of personal data
The Controller has adopted appropriate technical and organisational measures to protect personal data against unauthorised access, loss or misuse.
Only authorised persons have access to personal data.
VIII.
Final provisions
By submitting an order through the online shop, the data subject confirms that they have read and understood this Privacy Policy.
The Controller is entitled to amend this policy. The current version is always published on the Controller’s website.
This Privacy Policy takes effect on 19. 1. 2026.