For orders over €50 you get free shipping throughout the Czech Republic!

Privacy Policy – Processing of Personal Data

Consent to the processing of personal data – user registration

When registering for a user account, as well as when placing an order, the buyer’s personal data is processed.
This processing serves to create and operate the account and to administer orders. Information about the personal data
processed for the purpose of order fulfillment is provided to the buyer before the order is submitted for review and confirmation.

Mlyn Marianna s.r.o., Palarikova 15, 921 01 Piestany, Slovak Republic, ID: 36337358 (hereinafter the “Controller”), in accordance with GDPR – Regulation (EU) 2016/679 of the European Parliament
and of the Council on the protection of natural persons with regard to the processing of personal data, processes the following
personal data of the buyer:

- first and last name
- phone number
- email address
- delivery address
- billing address
- company name
- company registered office
- Company ID, VAT number
- bank account number

The above personal data will be processed for the purpose of identifying contractual parties, communication between them,
and performance of the concluded contract, for the duration of the contractual relationship and for a further 10 years,
unless a longer period is required by law, or processing is necessary to protect the rights and legitimate interests of the Controller.

The email address may be used for sending accounting documents and for inclusion in a database for sending commercial communications.
This procedure is permitted under Section 7(3) of Act No. 480/2004 Coll., on Certain Information Society Services, based on a completed purchase,
unless refused by the buyer. Such messages may only concern similar goods and can be unsubscribed at any time – via a link in the email
or by sending a request to faktury@carun.cz.


Disclosure of personal data to third parties

The Controller declares that all personal data is confidential and will not be disclosed to third parties, except for:
- carriers (to the extent necessary for delivery)
- service providers of review platforms (e.g. customer satisfaction surveys)
- payment gateway providers
- IT and cloud service providers

Specifically:
- Web hosting provider: WEDOS Internet, a.s., ID No. 28115708, Masarykova 1230, Hluboká nad Vltavou, Czech Republic
- Cloud accounting provider: iPodnik Cloud s.r.o., Jiráskova 306, Jinočany, Czech Republic
- Payment gateway provider: Comgate Payments, a.s., Gočárova třída 1754/48b, 500 02 Hradec Králové, Czech Republic,
  a licensed payment institution supervised by the Czech National Bank. Comgate provides card payments (Visa, Mastercard, Apple Pay, Google Pay),
  instant bank transfers and other online payment methods. The system complies with PCI DSS Level 1 security standards.
- Collection points, if chosen by the customer for delivery.


Buyer’s rights under GDPR

The buyer has the right to:
- request information about what personal data is being processed
- obtain access to their data, update or correct it
- request restriction of processing
- request deletion of personal data (if not in conflict with the legitimate interests of the Controller)
- object to processing carried out on the basis of legitimate interest
- the right to data portability and to obtain a copy of the processed data
- lodge a complaint with the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27, www.dataprotection.gov.sk
- exercise the right to effective judicial protection if they believe their rights have been violated as a result of processing in contradiction with GDPR