Information on the processing and protection of personal data in accordance with the General Data Protection Regulation (GDPR).
Brainstory s.r.o.
Company ID: 14049970
Registered office: Hybernská 1008/22, Nové Město, 110 00 Prague 1, Czech Republic
1.1. The controller of personal data pursuant to Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation – GDPR) is Brainstory s.r.o., the operator of www.chcinamedicinu.cz (hereinafter referred to as the "Controller").
1.2. The Controller's contact email is: info@chcinamedicinu.cz
1.3. Personal data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person.
1.4. The Controller has not appointed a Data Protection Officer (DPO).
2.1. The Controller processes personal data that you provide directly or that the Controller obtains in connection with the fulfilment of your registration or order.
2.2. The Controller processes your identification and contact details, as well as any personal data necessary for the performance of the contractual relationship.
3.1. The legal basis for processing personal data is:
- the performance of a contract between you and the Controller pursuant to Article 6(1)(b) GDPR;
- the legitimate interest of the Controller in direct marketing activities (in particular sending newsletters and promotional communications) pursuant to Article 6(1)(f) GDPR;
- your consent to the processing of personal data for direct marketing purposes pursuant to Article 6(1)(a) GDPR, in conjunction with Section 7(2) of Act No. 480/2004 Coll., where no purchase of goods or services has taken place.
3.2. The purposes of processing personal data are:
- processing your registration or order and exercising the rights and obligations arising from the contractual relationship between you and the Controller. Personal data required during registration are necessary for concluding and performing the contract. Without such data, the contract cannot be concluded or fulfilled;
- sending newsletters, promotional communications and carrying out other marketing activities.
3.3. For promotional purposes, the Controller may create and publish photographs and other visual recordings taken during the Course on its website and social media channels. These recordings may be retained for 10 years from the effective date of the Agreement.
3.4. The Controller does not carry out automated individual decision-making within the meaning of Article 22 GDPR.
4.1. The Controller retains personal data:
- for the duration of your consent to marketing communications, or until such consent is withdrawn, but for no longer than 10 years, where processing is based on consent.
4.2. Upon expiry of the applicable retention period, the Controller shall securely delete the personal data.
5.1. Recipients of personal data include entities involved in:
- providing courses and related services;
- processing payments;
- operating and maintaining the website;
- providing marketing services.
5.2. The Controller may transfer personal data to third countries (countries outside the European Union) or to international organisations. Such recipients may include providers of email marketing services and other service providers involved in the operation of the website.
6.1. Under the GDPR, you have the right to:
- access your personal data (Article 15 GDPR);
- request rectification of inaccurate or incomplete personal data (Article 16 GDPR);
- request restriction of processing (Article 18 GDPR);
- request erasure of your personal data (Article 17 GDPR);
- object to processing (Article 21 GDPR);
- receive your personal data in a portable format (Article 20 GDPR);
- withdraw your consent to processing at any time by contacting the Controller in writing or by email using the contact details provided in Section 1.
6.2. You also have the right to lodge a complaint with the competent supervisory authority if you believe that your rights relating to the protection of personal data have been violated.
7.1. The Controller declares that it has implemented appropriate technical and organisational measures to ensure the security of personal data.
7.2. The Controller has adopted appropriate technical measures to protect electronic data storage systems as well as physical records containing personal data.
7.3. Personal data are accessible only to persons authorised by the Controller.
7.4. By submitting the registration form and selecting the relevant consent checkbox, you confirm that you have read, understood and accepted this Privacy Policy in its entirety.
7.5. The Controller reserves the right to amend this Privacy Policy at any time. Any updated version shall be published on the Controller's website and shall become effective upon publication.