Privacy policy

I. BASICS

1.1. The controller of personal data pursuant to Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as "GDPR") is Kristýna Konieczná, ID number 10718796, with its registered office at Alžírská 1502, Ostrava 708 00 (hereinafter referred to as the "administrator").

1.2. The contact details of the administrator are:

1.3. Personal data means any information relating to an identifiable natural person, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

1.4. The administrator has not appointed a data protection officer.

II. SOURCES OF PERSONAL DATA

2.1. The administrator processes personal data provided to him with the consent of the buyer and which the administrator obtained based on the performance of the purchase contract and the processing of an electronic order in the online store www.tyiart.eu

2.2. The administrator only processes the buyer's identification and contact data necessary to fulfill the purchase contract.

2.3. The Administrator processes personal data for the purpose of delivery, payment settlement and necessary communication between the contracting parties for the period required by specific legal regulations. Personal data will not be published and will not be transferred to other countries.

III. LEGAL PURPOSE OF PROCESSING PERSONAL DATA

3.1. The legal basis for processing personal data is the fulfillment of the contract between the buyer and the controller pursuant to Article 6(1)(b) of the GDPR.

3.2. When placing an order, personal data is required that is necessary for the successful processing of the order, such as the name, delivery address, telephone contact and email address of the buyer. The administrator processes the buyer's personal data only for the purpose of processing the buyer's electronic order. A purchase contract cannot be concluded without providing personal data.

3.3. The controller does not make any automatic individual decision-making within the meaning of Article 22 of the GDPR.

IV. PERIOD OF PERSONAL DATA RETENTION

4.1. The administrator stores personal data for the period necessary to exercise the rights and obligations arising from the contractual relationship between the buyer and the administrator, and for a period of 3 years from the termination of the contractual relationship.

4.2. After the personal data retention period has expired, the administrator is obliged to delete the data.

V. RECIPIENTS AND PROCESSORS OF PERSONAL DATA  

5.1. The third party that receives the buyer's personal data is the administrator's subcontractors. The services of these subcontractors are unconditionally related to the successful fulfillment of the purchase contract and electronic order between the administrator and the buyer.

5.2. The recipients of personal data, or subcontractors of the administrator, are:
  • Webnode AG (e-shop system) and other services related to e-shop;
  • persons involved in the delivery of goods and the execution of payments under the purchase contract
  • Google Analytics;

5.3. The administrator does not intend to transfer personal data to a third country (a country outside the EU) or an international organization.

VI. BUYER'S RIGHTS

6.1. Under the conditions set out in the GDPR, the buyer has the right to:

  • 6.1.1. Access your personal data pursuant to Article 15 GDPR;
  • 6.1.2. Correct personal data pursuant to Article 16 of the GDPR, or to restrict processing pursuant to Article 18 of the GDPR;
  • 6.1.3. Delete personal data pursuant to Article 17 of the GDPR;
  • 6.1.4. Object to processing pursuant to Article 21 of the GDPR;
  • 6.1.5. Data portability according to Art. 20 GDPR
  • 6.1.6. Withdraw consent to processing in writing or electronically to the address or e-mail of the administrator specified in Article III of these terms and conditions.

6.2. The buyer has the right to file a complaint with the Office for Personal Data Protection if he believes that his right to personal data protection has been violated.

VII. PERSONAL DATA SECURITY

7.1. the administrator declares that it has taken all appropriate technical and organizational measures necessary to secure the Buyer's personal data.

7.2. The administrator has taken technical measures to secure personal data storage, in particular securing access to the computer with a password, using an antivirus program and regular maintenance of computers.

VIII. FINAL PROVISIONS

8.1. By sending an electronic order on the website www.tyiart.eu, the buyer confirms that he has been familiar with the terms and conditions of personal data protection and that he accepts them fully.

8.2. The buyer agrees to these rules by checking the box in the order.

8.3. The Administrator is entitled to change these Rules at any time. The Administrator is obliged to publish the new version of the Rules on its website.

These terms come into effect on January 1st, 2026.