Privacy policy
Privacy policy
The operator of the e-shop, Parsi s.r.o., on the website www.parsi.design, Company ID: 25448391, with registered office at Rohliny 39, 511 01 Mírová pod Kozákovem, Czech Republic (hereinafter referred to as the "Controller"), processes personal data provided by Customers for the purpose of fulfilling and confirming the Terms and Conditions, processing online orders, delivering goods, processing payments, and necessary communication between contractual parties for the period required by applicable law.
General Provisions
1. The Controller is responsible for processing personal data in accordance with Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 Coll., on the processing of personal data.
2. Contact information for the Controller: Email: info@parsi.design, Phone: +420 777 937 484.
3. Personal data refers to any information that identifies a natural person.
Sources of Personal Data
1. The Controller processes personal data provided voluntarily by the Customer or obtained through the fulfillment of the Purchase Agreement and processing of online orders on www.parsi.design.
2. Only the Customer's identification and contact data necessary to fulfill the Purchase Agreement are processed, together with the data described below in connection with the wishlist, product review, marketing and analytics features, where the Customer uses them.
3. Personal data are processed for delivery, payment processing, and necessary communication between the contractual parties. Personal data will not be publicly disclosed except where explicitly stated (for example, published product reviews).
Purpose of Processing Personal Data
The Controller processes personal data of Customers for the following purposes:
1. Registration on www.parsi.design and management of the Customer's account;
2. Processing online orders (name, address, email, phone number);
3. Fulfilling rights and obligations arising from the contractual relationship between the Customer and the Controller, including returns, complaints and withdrawal from the contract;
4. Sending marketing emails (product updates, offers and news) to Customers, on the legal basis described under “Legal Basis for Processing” and “Data Retention” below;
5. Providing the wishlist and product review features described below, where used by the Customer;
6. Analyzing website traffic and improving the E-shop.
7. Providing personal data is necessary to fulfill the Purchase Agreement. Without providing the necessary personal data, the agreement cannot be concluded. Consent given for other purposes (such as marketing) is voluntary and can be withdrawn at any time.
Legal Basis for Processing
1. Performance of a contract between the Controller and the Customer (Article 6(1)(b) GDPR) – for orders, delivery, payment and returns.
2. Consent of the Customer (Article 6(1)(a) GDPR) – for marketing emails sent to Registered Customers who have not made a purchase, where they separately ticked an (unticked-by-default) marketing consent box, and for non-essential cookies (analytics, wishlist and review cookies).
2a. The “customer exception” (Section 7(3) of Act No. 480/2004 Coll., on certain information society services) – for marketing emails about the Controller’s own similar products sent to Customers who have made a purchase, using the email address obtained in connection with that purchase, provided the Customer has a simple, free way to object at any time, including with every message. This is treated as a form of the Controller’s legitimate interest (Article 6(1)(f) GDPR).
3. Legitimate interest of the Controller (Article 6(1)(f) GDPR) – particularly for website security, fraud prevention, and providing product reviews and wishlist functionality that Customers have chosen to use.
4. Legal obligations of the Controller (Article 6(1)(c) GDPR) – for tax and accounting purposes.
Data Retention
1. Personal data are retained for the period necessary to perform rights and obligations arising from the contractual relationship and for 3 years after its termination. Data may be retained longer if required by accounting or tax obligations (generally 10 years for accounting and tax documents under Czech law).
2. GDPR does not set a fixed statutory retention period for marketing data; the general rule is that data must not be kept longer than necessary for its purpose (the storage limitation principle, Article 5(1)(e) GDPR), and the appropriate period depends on the legal basis for the marketing:
- For marketing sent under the customer exception (Section 7(3) of Act No. 480/2004 Coll.) to Customers who have made a purchase, it is common data-protection practice, though not a fixed legal deadline, to use the data for marketing for around 2 to 3 years from the Customer’s last purchase or last account activity, and to stop using it for marketing after that unless there is renewed activity or a further purchase.
- For marketing sent to Registered Customers who separately consented without having made a purchase, it is similarly common practice for the Controller to review the data and may ask the Customer to renew (resubmit) their consent after around 3 years of inactivity (no engagement with our marketing or store).
In either case, if the Customer unsubscribes or objects, their marketing data will be used for marketing no further, without delay. Cookie-based analytics data is retained for the period set in the relevant provider’s settings, generally in aggregated or pseudonymized form.
3. Account data for a Registered Customer who has not made a purchase and has not consented to marketing is kept only for as long as necessary to operate the account, and is not used for marketing purposes.
4. If a customer account remains inactive for an extended period (as a matter of the Controller’s practice, generally around 5 years, unless a longer period is required for legal, accounting or dispute-resolution reasons), the Controller may notify the Customer before deleting the account and its associated data.
5. If a Customer requests deletion of their account, the Controller will also remove them from the marketing database without delay. This does not affect invoice and accounting records, which must still be retained for the period described in point 1 above under Czech accounting and tax law.
3. After the applicable period, personal data will be deleted or anonymized.
Recipients and Processors
Third parties processing the Customer's personal data are subcontractors of the Controller. These services are used to fulfill the Purchase Agreement, operate the E-shop, and provide the features described in this Policy.
Subcontractors of the Controller:
- Shopify – provides the e-commerce platform and technical infrastructure used to operate www.parsi.design, including product management, checkout, order processing, customer accounts, and related store functionality.
- Shopify Payments, PayPal, Shop Pay – payment providers; process payment and related order data to process and confirm payments. The Controller does not itself store full card details.
- Česká pošta, s.p., PPL CZ s.r.o., Zásilkovna s.r.o. and other carriers shown at checkout – delivery services; process personal data only for delivery and fulfillment of the contract.
- Shopify Email – marketing email service; processes the email address and, where relevant, order and browsing data of Customers who receive marketing emails, whether under the customer exception or based on consent (see “Legal Basis for Processing” above).
- Google Analytics – analytics service; personal data are processed to monitor website traffic and user behavior. Cookies may be stored on servers outside the European Union.
- Wishlist application – provides wishlist functionality and may process customer information, including name, email address, IP address, approximate geolocation, browser and operating system information, browsing activity, and information stored in a customer-identification cookie. The application may also access information relating to customers, products, orders, discounts, store analytics and the operation of the online store where necessary to provide its services.
- AG Product Reviews – provides product reviews and ratings and may process customer information, including name, email address, IP address, approximate geolocation, browser and operating system information, browsing activity, and information stored in a customer-identification cookie. Where necessary to provide its services, the application may also access information relating to customers, products, orders, discounts, store analytics and the operation of the online store. If a Customer submits a review, information provided with the review, such as the review content and any photographs or other media submitted by the Customer, may be processed and publicly displayed on the relevant product page.
⚠️ International Customers: Your data may be transferred outside the EU, including to the United States (for example by Shopify, Google, PayPal and Shopify Payments). Appropriate safeguards are in place, such as the EU-U.S. Data Privacy Framework or Standard Contractual Clauses approved by the European Commission, to ensure an adequate level of data protection.
Cookies
The E-shop uses cookies necessary for its basic operation (for example, to keep items in your cart and keep you logged in), which do not require consent. Non-essential cookies, including those used by Google Analytics and by the wishlist and product review applications, are only set with your consent, given through the cookie banner shown when you first visit the E-shop. The blog comment form may also set a cookie to remember your name and email address for future comments; this is considered a functional cookie set at your choice when you submit a comment. You can change or withdraw your consent at any time via the cookie settings link in the site footer or through your browser settings.
Product Reviews
Customers may voluntarily submit product reviews and ratings on our website.
When submitting a review, the Customer may provide information such as their name or chosen display name, email address, review content, photographs or other media. Information relating to an order may also be processed where necessary to verify or manage a review.
Reviews may be displayed publicly on the relevant product page. Customers should therefore avoid including personal information about themselves or other individuals in review content that they do not wish to make public.
We use AG Product Reviews as a third-party service to provide this functionality. The processing of personal data by the service is subject to applicable data-protection requirements and the service provider's own privacy policy.
Blog Comments
If a Customer submits a comment on our blog, we process the commenter's name, email address, IP address, comment content and, if provided, their website. The name and comment (but not the email address) may be displayed publicly under the blog post. Comments may be reviewed before publication and may be rejected, for example if they are spam or violate our Terms. We use this data to publish, moderate and protect the blog against spam. Legal basis: our legitimate interest in operating and moderating the blog (Article 6(1)(f) GDPR). A cookie may be used to remember the commenter's name and email for future comments; see "Cookies" above.
Customer Rights
Under GDPR and other applicable laws, Customers have the right to:
- Access their personal data;
- Correct their personal data;
- Delete their personal data;
- Restrict the processing of their personal data;
- Object to processing;
- Data portability;
- Withdraw consent to data processing at any time by email: info@parsi.design;
- File a complaint with a supervisory authority if they believe their personal data rights have been violated.
The competent supervisory authority in the Czech Republic is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic, www.uoou.cz. Customers residing in another EU country may also contact the supervisory authority of their own country of residence.
⚠️ For Customers outside the EU: You may also have rights under your local privacy laws (e.g., the California Consumer Privacy Act (CCPA) in the U.S., or PIPEDA in Canada). You can contact us at info@parsi.design for more information.
Data Security
1. The Controller has implemented appropriate technical and organizational measures to secure personal data.
2. The Controller applies measures in line with current technological standards to ensure data security.
3. Measures include access protection (passwords), antivirus software, and regular maintenance of computer systems.
Children
The E-shop is not directed at children, and the Controller does not knowingly collect personal data from children without the consent of a parent or legal guardian.
Final Provisions
1. By submitting an online order on www.parsi.design, the Customer confirms that they have read and accepted this Privacy Policy.
2. Where consent to marketing communications is required (see “Legal Basis for Processing” above), it is given by actively checking a marketing consent box, which is not pre-ticked, during account registration or newsletter sign-up.
3. The Controller may update this Privacy Policy at any time. Updated policies take effect on the date of publication on the website.
Effective date: 1 October 2026