Privacy Policy

Personal Data Processing Policy
Direct sales contact: somek@stripschips.cz

adopted in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to as the “GDPR”)

1. Introduction

YES PRODUCTS s.r.o. , as the operator of the online store https://stripschips.com (hereinafter referred to as the “Controller”), processes personal data of so-called data subjects – natural persons who:
  • are interested in making a purchase in the online store (potential customers);
  • purchase or have purchased in the online store (customers).
The Controller ensures that the processing of personal data of data subjects is lawful, fair, transparent, accurate, confidential and that personal data is processed only to the necessary extent. The Controller also ensures that personal data is properly secured and that all rules laid down by the GDPR, as well as other legal regulations in the area of personal data handling, are complied with when processing personal data. These policies have been adopted, among other things, for the purpose of demonstrating the compliance of the Controller’s personal data processing with legal regulations. Explanations of the individual terms related to the processing of personal data under these policies are provided in Article 12 below.

2. Personal Data Controller

The personal data controller is YES PRODUCTS s.r.o., Company ID No.: 03103897, Husitská 107/3, 130 00 Prague – Žižkov, registered in the Commercial Register maintained by the Municipal Court in Prague, file no. C 227583/MSPH. The Controller may be contacted in any of the following ways:
  • in person at the Controller’s registered office at Husitská 107/3, 130 00 Prague – Žižkov,
  • electronically via [ sales@yesproducts.cz ];
  • by telephone at [+420 722 214 069].

3. Purposes of Processing for Which Personal Data Is Intended and the Legal Basis for Processing

3.1. Performance of a Purchase Agreement

The Controller processes personal data primarily for the purpose of concluding and performing a purchase agreement, i.e. at least so that the Controller can deliver the goods purchased in the online store to the customer. The legal basis for this processing is Article 6(1)(b) GDPR – performance of a contract to which the data subject is party.

3.2. Compliance with the Controller’s Legal Obligations

The Controller processes personal data for the purpose of complying with the Controller’s legal obligations arising, for example, from accounting and tax laws, consumer protection legislation, etc., including the Controller’s obligation to be able to demonstrate that it processes personal data in accordance with generally binding legal regulations, in particular in accordance with the GDPR. The legal basis for this processing is Article 6(1)(c) GDPR – compliance with a legal obligation to which the Controller is subject.

3.3. Legitimate Interests of the Controller

The Controller may process personal data for the purpose of:
  • direct marketing (see Article 5 below);
  • the establishment, exercise or defence of legal claims, in particular legal claims arising from a concluded purchase agreement.
The legal basis for this processing is Article 6(1)(f) GDPR – the legitimate interest of the Controller.

3.4. Consent of the Data Subject

Based on consent, the Controller may process personal data for the purpose of:
  • direct marketing (see Article 5 below);
  • creating and maintaining a customer account (see Article 10 below).
The legal basis for this processing is Article 6(1)(a) GDPR – the consent of the data subject.

4. Processing of Personal Data Based on Consent

4.1. Voluntary Nature

Granting consent to the processing of personal data is entirely voluntary. Failure to grant consent will have no adverse consequences for the data subject.

4.2. Withdrawal of Consent

Every data subject has the right to withdraw their consent to the processing of personal data at any time, in one of the following ways:
  • through the customer account;
  • by electronic notice sent to the Controller’s e-mail address (see Article 2 above);
  • by written notice sent to the address of the registered office or establishment / one of the establishments of the Controller (see Article 2 above).
Consent to the maintenance of a customer account may also be withdrawn by cancelling the customer account (see Section 10.2 below). Withdrawal of consent does not affect the lawfulness of personal data processing carried out before the withdrawal of consent on the basis of that consent.

5. Direct Marketing

5.1. General

Processing of personal data for direct marketing purposes means the processing of personal data for the purpose of sending commercial communications within the meaning of Act No. 480/2004 Coll., on Certain Information Society Services, as amended (hereinafter referred to as “Act No. 480/2004 Coll.”). Commercial communication means any form of communication, including advertising and invitations to visit the online store website, intended to directly or indirectly promote the goods or services or the image of the Controller, in particular so-called newsletters.

5.2. How Does It Actually Work?

The processing of personal data for the purpose of sending commercial communications to potential customers, i.e. persons who have not yet made a purchase in the online store but have decided to subscribe to commercial communications, is possible only on the basis of their consent to the processing of personal data. Likewise, the sending of commercial communications to potential customers itself may be carried out only on the basis of consent in accordance with Section 7(2) of Act No. 480/2004 Coll. The processing of personal data for the purpose of sending commercial communications to customers, i.e. persons who have already made a purchase in the online store, is possible even without their consent, on the basis of the Controller’s legitimate interest (see Section 3.3 above or Recital 47 GDPR). Likewise, the sending of commercial communications to customers itself may be carried out without their consent in accordance with Section 7(3) of Act No. 480/2004 Coll., provided that the customer did not initially refuse this. [for more details, see https://www.uoou.cz/gdpr-a-nbsp-primy-elektronicky-marketing/d-30715]

5.3. Termination of Processing for Direct Marketing Purposes

The Controller shall terminate the processing of personal data for direct marketing purposes without undue delay after the customer or potential customer expresses their disagreement with such processing. Such disagreement may be expressed, for example, in one of the following ways:
  • by withdrawing consent to the processing of personal data (see Article 4 above);
  • by expressing disagreement with the processing of personal data, in the same manner as consent to the processing of personal data may be withdrawn (see Article 4 above);
  • by unsubscribing, which is possible in every commercial communication;
  • by objecting to such processing, subject to the conditions of Article 21 GDPR.
Regardless of the above, the Controller shall terminate the processing of personal data for direct marketing purposes no later than within 2 years from the last purchase in the online store (conclusion of a purchase agreement). Any further purchase therefore extends the processing period by another 2 years. If no purchase is ever made in the online store, the Controller shall terminate the processing at the same time as cancelling the customer account (see Section 10.2 below).

6. Categories of Recipients of Personal Data

A recipient of personal data is anyone to whom the Controller provides personal data. The Controller will transfer personal data in particular to the following recipients: entities providing accounting services, postal services, newsletter distribution services, legal services, IT services, payment gateway operators, payment system operators, domain administrators, technical support providers, etc. These recipients will process personal data either as independent controllers, i.e. entities that themselves determine the purposes and means of personal data processing independently of the Controller, or as processors, i.e. entities that process personal data for the Controller on the basis of the Controller’s instructions. In addition, the Controller will provide personal data to public authorities if such obligation is imposed on the Controller by generally binding legal regulations. These recipients will always process personal data as independent controllers. However, public authorities are not considered recipients when exercising their investigative powers.

7. Transfers to Third Countries or International Organisations

The Controller will not transfer personal data to third countries or international organisations within the meaning of Article 44 et seq. GDPR.

8. Personal Data Processing Period

Personal data will be processed only for the period necessary in relation to the purpose of its processing. The expiry of one legal basis for the processing of personal data does not affect the processing of personal data, to the necessary extent, on the basis of another legal basis.

8.1. Performance of a Purchase Agreement

For this purpose, the Controller will process personal data until 30 days after the expiry of the last of the obligations agreed in the purchase agreement. This does not affect the Controller’s ability to subsequently continue processing such personal data on the basis of other legal bases and for the purposes specified in these policies.

8.2. Compliance with the Controller’s Legal Obligations

For this purpose, the Controller will process personal data for the duration of the relevant legal obligation of the Controller laid down by generally binding legal regulations.

8.3. Legitimate Interests of the Controller

8.3.1. Direct Marketing

For this purpose, the Controller may process personal data until disagreement with such processing is expressed, but no longer than for a period of 2 years from the last purchase in the online store (see Section 5.3 above).

8.3.2. Legal Claims

For this purpose, the Controller may process personal data for the duration of the relevant legal claim, but no longer than 1 year after the expiry of the limitation period under generally binding legal regulations. In the event of the commencement and continuation of judicial, administrative or any other proceedings in which rights or obligations arising from the relevant legal claim are addressed, the personal data processing period for this purpose shall not end before such proceedings have been finally concluded.

8.4. Consent of Data Subjects

8.4.1. Direct Marketing

For this purpose, the Controller may process personal data until:
  • withdrawal of consent to the processing of personal data (see Article 4 above);
  • expression of disagreement with the processing of personal data, in the same manner as consent may be withdrawn (see Article 4 above);
but no longer than until the customer account is cancelled (see Section 10.2 below).

8.4.2. Maintenance of a Customer Account

For this purpose, the Controller may process personal data until the customer account is cancelled (see Section 10.2 below).

8.5. Erasure of Personal Data

Without undue delay after the expiry of the processing period under Sections 8.1, 8.2 or 8.3.2 above, the Controller shall anonymise or destroy the relevant personal data for which the purpose of processing has ceased to exist. In the cases under Sections 8.3.1 or 8.4 above, the Controller shall terminate the processing of personal data for the stated purposes without undue delay after consent is withdrawn, disagreement is expressed or the customer account is cancelled.

9. Rights of Data Subjects

Every data subject has, among other things, the following rights:
  • the right to request access to their personal data, subject to the conditions of Article 15 GDPR;
  • the right to rectification or erasure of personal data, subject to the conditions of Article 16 or Article 17 GDPR;
  • the right to restriction of personal data processing, subject to the conditions of Article 18 GDPR;
  • the right to object to processing, subject to the conditions of Article 21 GDPR;
  • the right to data portability, subject to the conditions of Article 20 GDPR;
  • the right to withdraw consent to the processing of personal data (see Article 4 above).
If the data subject believes that their right to personal data protection has been violated, they also have the right to lodge a complaint with the supervisory authority, which is the Office for Personal Data Protection, with its registered office at Pplk. Sochora 27, Holešovice, 170 00 Prague 7.

10. Customer Account

10.1. Creation of a Customer Account

Creating a customer account is entirely voluntary, as the Controller allows purchases to be made in the online store even without creating a customer account, i.e. without registration. In order for the Controller to store personal data entered into the form for creating and maintaining a customer account, or entered into the customer account at any later time, the Controller needs consent to do so. Until the potential customer concludes a purchase agreement with the Controller, i.e. becomes a customer, and subsequently after all obligations under the concluded purchase agreement have been fulfilled, the Controller will not handle the personal data otherwise than for the purposes of maintaining the customer account; however, this does not affect the Controller’s ability to process personal data on the basis of other legal bases, in particular on the basis of consent granted for the purposes of direct marketing, i.e. sending commercial communications.

10.2. Cancellation of a Customer Account

The customer account may be cancelled at any time through the customer account or on the basis of a request to cancel the customer account sent to one of the contact addresses listed in Section 2.2 above. Regardless of the above, the Controller shall cancel the customer account no later than within 3 years from the customer’s last purchase in the online store. If no purchase is ever made in the online store, the Controller shall cancel the customer account within 3 years from its creation.

11. Cookies and Other Technical Data

Further information on so-called cookies and other technical data processed when visiting the online store website is provided in a separate document available at Cookies.

12. BASIC Terms

Personal data means any information relating to an identified or identifiable natural person, the so-called data subject; an identifiable natural person is a natural person who can be identified directly or indirectly, in particular by reference to a certain identifier, such as first name, surname, date of birth, residence, e-mail, telephone number, identification number, location data, network identifier or to one or more specific elements of the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Processing of personal data means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or any other form of making available, alignment or combination, restriction, erasure or destruction. A customer is a natural person who has concluded a purchase agreement with the Controller through the online store, i.e. a person who has a so-called customer relationship with the Controller. A potential customer is a natural person who has not yet concluded a purchase agreement with the Controller through the online store, i.e. a person who does not have a so-called customer relationship with the Controller.

13. Further Information on Personal Data Processing

In the event of questions regarding the processing of personal data, the Controller may be contacted via one of the contact addresses listed in the introduction to these policies. General information on the processing of personal data can also be found on the website of the Office for Personal Data Protection available at www.uoou.cz. These policies become effective on 25 April 2026.