Privacy Policy (GDPR)

Basic Provisions

  1. The controller of personal data according to Article 4, point 7 of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter GDPR) is STEAKGRILL s.r.o., ID No. 08311901, located at Račiněves 189, 413 01 Račiněves (hereinafter the Controller).
  2. The contact information of the Controller is restaurace@steakgrill.cz.
  3. Personal data means any information about an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
  4. The Controller has not appointed a data protection officer.

Legal Reason for Processing Personal Data

  1. The legal reason for processing personal data is your consent to processing for the purpose of sending newsletters pursuant to Article 6(1)(a) GDPR in conjunction with Section 7(2) of Act No. 480/2004 Coll., on certain information society services, if no goods or services have been ordered (hereinafter Consent).
  2. The Controller does not engage in automated individual decision-making within the meaning of Article 22 GDPR. You have given your explicit consent to such processing.

Purpose of Processing, Categories, Sources, and Recipients of Personal Data

Legal Reason
Legitimate Interest
Purpose
Regular traffic analysis, error detection, fraud prevention, and server attack prevention
Data
Third-party cookies and IP addresses and browsing data, viewed pages, and page actions for 50 months
Data Source
User activity on the website, page view with error
Recipients of Personal Data (Processors)
Google Analytics, web hosting services, and potentially other analytical services
Legal Reason
Consent
Purpose
Marketing and website promotion
Data
Emails
Data Source
Newsletter form
Recipients of Personal Data (Processors)
Email distribution service

Data Retention Period

  1. Unless otherwise stated above, the Controller retains personal data for the duration of the consent to the processing of personal data for the specified purposes if the personal data is processed on the basis of consent.
  2. Upon revocation of consent or the expiry of the personal data retention period, the Controller will delete the personal data.

Processing Rules for Cookies and Personal Data

  1. If cookies are mentioned among the personal data in the Purpose section, the following rules apply to their processing.
    • Each user can set the rules for using or blocking cookies in their internet browser, thereby expressing their consent to their processing.
    • The user can set permissions or rejection of all or only some cookies (e.g., third-party cookies). Blocking cookies may negatively affect the usability of the website and services.
    • Information from Google (about cookies) is placed on this website for visitors who agree to place cookies in their browser through the appropriate cookie behavior settings of each browser.
  2. If you object to the processing of technical cookies necessary for the functioning of the website, full functionality and compatibility of the website cannot be guaranteed.

Recipients of Personal Data (Controller's Subcontractors)

  1. The Controller intends to transfer personal data to a third country (a country outside the EU) or an international organization. Recipients of personal data in third countries are providers of mailing services, data and file storage, analytical tools, and direct marketing services.

Your Rights

  1. Under the conditions set out in the GDPR, you have the right
    • to access your personal data under Article 15 GDPR,
    • to rectify personal data under Article 16 GDPR, or to restrict processing under Article 18 GDPR,
    • to erase personal data under Article 17 GDPR,
    • to object to processing under Article 21 GDPR,
    • to data portability under Article 20 GDPR,
    • to withdraw consent to processing in writing or electronically to the address or email of the Controller specified in Article III of these terms.
  2. You also have the right to file a complaint with the Office for Personal Data Protection if you believe that your right to personal data protection has been violated.

Conditions for Securing Personal Data

  1. The Controller declares that it has taken all appropriate technical and organizational measures to secure personal data.
  2. The Controller has taken technical measures to secure data storage and personal data storage in paper form.
  3. The Controller declares that only authorized persons have access to personal data.

Final Provisions

  1. By submitting the internet registration form, you confirm that you are familiar with the privacy policy and that you accept it in its entirety.
  2. The Controller is entitled to change these terms. The new version of the privacy policy will be published on its website and will be sent to your email address provided to the Controller.