Processing of personal data

PRINCIPLES OF PROCESSING PERSONAL DATA

USSPA s.r.o., Company ID 63218003, with its registered office at Dolní Dobrouč 384, ZIP 561 02, registered in the Commercial Register kept by the Regional Court in Hradec Králové, Section C, File 7850 (“USSPA”), declares that all processed personal data is considered strictly confidential and is handled in accordance with applicable legal regulations on personal data protection. The security of your personal data is a priority for USSPA. For this reason, on this page we will inform you about the data we store and at the same time explain to you why we need this data and how you can restrict its collection.


USSPA is, within the meaning of the General Data Protection Regulation (Regulation (EU) 2016/679 ("Regulation" or "GDPR"), the controller of your personal data, i.e. it collects, stores and uses (and otherwise processes) your personal data for the performance of its business activities (the individual purposes for which personal data is processed are further defined below for individual categories of data subjects).

LEGAL GROUNDS for processing personal data

This Privacy Policy applies to all personal data collected by USSPA (i) when you use the USSPA website (the “Website”) and to all personal data collected by USSPA (ii) in compliance with legal obligations, (iii) in legitimate interest, and (iv) in the performance of contractual relationships with our Customers, or in preparation for contractual relationships with our Potential Customers, and in the performance of contractual relationships with our Business Partners.

USSPA processes your personal data:

  • fairly, lawfully and transparently;
  • only for specified, explicit and legitimate purposes;
  • to a reasonable extent;
  • accurate and up-to-date;
  • for no longer than is necessary for the purposes for which they are processed;
  • in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.

Customer

If you have purchased our products from us, made a purchase in the customer e-shop or used our services, you are our Customers and we will process your personal data to the extent specified below. In the case of our Customers, legal entities, we process the personal data of natural persons representing the Customer.

Purposes of processing personal data

Your personal data may be processed by USSPA in particular for the following purposes:

  • Fulfillment of the contractual relationship;
  • Providing customer benefits, sending commercial communications and offers;
  • Operation of the customer e-shop;
  • Accounting and tax purposes (records within the meaning of accounting and tax legislation);
  • Fulfillment of other legal obligations (other legal obligations that USSPA fulfills include, for example, providing information to public authorities).

Personal data processed

USSPA is authorized to process the following personal data according to the purpose for which it was obtained from individual data subjects:

 

Data of data subjects

Processing purposes:

First and last name

  • Fulfillment of the contractual relationship
  • Providing customer benefits, sending commercial communications and offers
  • Operating the customer e-shop
  • Accounting and tax purposes
  • Fulfillment of other legal obligations
  • Protection of the legitimate interest of the administrator
Function, position or academic title
  • Fulfillment of the contractual relationship
  • Providing customer benefits, sending commercial communications and offers

Contact address

  • Fulfillment of the contractual relationship
  • Providing customer benefits, sending commercial communications and offers
  • Accounting and tax purposes
  • Operating the customer e-shop
  • Fulfillment of other legal obligations
  • Protection of the legitimate interest of the administrator

E-mail

  • Fulfillment of the contractual relationship
  • Providing customer benefits, sending commercial communications and offers
  • Operating the customer e-shop
  • Fulfillment of other legal obligations
  • Protection of the legitimate interest of the administrator
Account number
  • Fulfillment of the contractual relationship
  • Accounting and tax purposes
Company ID, VAT number (if relevant)
  • Fulfillment of the contractual relationship
  • Accounting and tax purposes
  • Fulfillment of other legal obligations
Telephone number
  • Fulfillment of the contractual relationship
  • Operating the customer e-shop
  • Fulfillment of other legal obligations
  • Protection of the legitimate interest of the administrator
Personal identification number or social security number
  • Tax purposes (declaration of the Customer - natural person for VAT rate purposes).
  • Fulfillment of the contractual relationship
  • Fulfillment of other legal obligations
  • Protection of the legitimate interest of the administrator

Personal data is processed by USSPA both manually and automatically.

USSPA may also process other data about its Customers that the Customers provide to it, with regard to the legitimate interests of USSPA, maintaining good business relations, streamlining business communication and also for the purposes of fulfilling the contractual relationship.

Personal data of third parties, which means personal data that USSPA receives from the Customer in connection with the conclusion or performance of the contract, will be processed in accordance with applicable legal regulations in the field of personal data protection.

Recipients of personal data

In USSPA, your personal data is only made available to authorized employees or individual processors and administrators of personal data of USSPA, and only to the extent necessary for the fulfillment of individual processing purposes.

The list of recipients of USSPA personal data is available at the end of the document. Under certain conditions, we are authorized to transfer some of your personal data to public authorities based on applicable legal regulations.

Retention period

We process and store your personal data for the period strictly necessary to ensure all rights and obligations arising from the relevant contractual relationship, for the period of providing customer benefits and for the period for which USSPA, as the controller of personal data, is obliged to store it according to generally binding legal regulations. In other cases, the processing period results from the purpose of the processing or is given by legal regulations in the field of personal data protection.

We process personal data according to the purpose of their processing for the following period:

 

Purpose of processing

Retention period

Fulfillment of the contractual relationship

for the duration of the contractual relationship, the period of possible exercise of rights under the contract

Providing customer benefits, sending commercial communications and offers

in accordance with applicable legislation*, we provide customer benefits unless you refuse them, you can refuse the provision of customer benefits and the sending of commercial communications and offers at any time

Accounting and tax purposes

for a period of 10 years from the calendar year following the provision of the service

 

Operation of customer e-shop

for the duration of the contractual relationship and for a period of 10 years from the termination of the contractual relationship

Fulfillment of other legal obligations

for the period specified in the relevant legal regulation

 

* USSPA is authorized to process your e-mail address pursuant to Section 7, Paragraph 3 of Act No. 480/2004 Coll., on certain information society services and on amendments to certain acts (Act on Certain Information Society Services), as amended, for the purpose of distributing commercial communications regarding its own products or services if you have not refused such sending.

If you do not wish to receive our commercial communications and offers, you can inform us at any time, for example by email to gdpr@usspa.cz, and we will immediately stop sending them.

 

Potential customer

If you have expressed interest in purchasing our product, for example by asking us to send you a catalog, we consider you to be our Potential Customer and we will process your personal data to the extent specified below.

Purposes of processing personal data

Your personal data may be processed by USSPA in particular for the following purposes:

  • Negotiating the conclusion of a contract (e.g. product selection and specification, preparation of contractual documentation);
  • Sending commercial communications and offers;
  • Fulfilling other legal obligations (other legal obligations that USSPA fulfills include, for example, providing information to public authorities).

Personal data processed

USSPA is authorized to process the following personal data prior to concluding a contract:

Data of data subjects

Processing purposes:

Name and surname, function, position or academic title

  • Negotiating a contract
  • Sending commercial communications and offers
  • Fulfilling other legal obligations
Contact address
  • Negotiating a contract
  • Sending commercial communications and offers
  • Fulfilling other legal obligations

E-mail

  •  Negotiating a contract
  • Sending commercial communications and offers
  • Fulfilling other legal obligations

Telephone number

  • Negotiating a contract
  • Fulfilling other legal obligations

Personal data is processed by USSPA both manually and automatically.

USSPA may also process other data about its Potential Customers that Potential Customers provide to it, taking into account USSPA's legitimate interests and maintaining good relations with Potential Customers.

In the case of telephone communication with our salespeople, please note that if you give us your consent, these telephone calls may be monitored for the purpose of improving the quality of our services. The recording of such a call may be kept for a maximum of 6 months (longer only exceptionally in relation to the resolution of a specific case).

Personal data of third parties, which means personal data that USSPA receives from a Potential Customer in connection with negotiations on concluding a contract, will be processed in accordance with applicable legal regulations in the field of personal data protection.

Recipients of personal data

At USSPA, your personal data is only made available to authorized employees or individual processors and administrators of USSPA personal data, and only to the extent necessary for the fulfillment of the individual processing purposes.

A list of recipients of USSPA personal data is available at the end of this document. Under certain conditions, we are authorized to transfer some of your personal data to public authorities based on applicable legal regulations.

Retention period

We process and store your personal data for the period strictly necessary to ensure the purpose of the processing, i.e. for the period when you are considering purchasing our product and concluding a contract.

The retention period of personal data for the purposes of sending commercial communications and offers of products and services is governed by applicable legislation. If you do not wish to receive our commercial communications and offers, you can inform us at any time, for example by email to gdpr@usspa.cz, and we will immediately stop sending them.

 

Caller to the service department phone line

If you call our service department's telephone line with a question about the operation of our equipment, a request for service, a complaint or any other matter, the telephone call is recorded. If you do not agree to the recording of the call, you can contact us by e-mail or write to us at our postal address. You can find out why we record the call and how long we process the recording below.

Purposes of processing telephone call recordings

The call recording is processed in particular for the following purposes:

  • Fulfillment of a contractual relationship or request of the caller (for the purposes of proving legal action and protecting the rights of both USSPA and the caller);
  • Legitimate interest (for the purposes of improving the quality of our services).

Phone call recording processing time

 

Purpose of processing

Retention period

Fulfillment of the contractual relationship

for the duration of the contractual relationship, the period of possible exercise of rights under the contract

Legitimate interest

For the purpose of improving the quality of services, the call recording is kept for a maximum of 6 months (longer only exceptionally in relation to the resolution of a specific case).

Business partner

If you have concluded a contract with us as part of your business, you are our Business Partner and we will process your personal data to the extent set out below. In the case of Business Partners, legal entities, we process the personal data of natural persons representing our Business Partner.

Purposes of processing personal data

Your personal data may be processed by USSPA in particular for the following purposes:

  • Fulfillment of the contractual relationship;
  • Sending commercial communications and offers;
  • Accounting and tax purposes (records within the meaning of accounting and tax legislation);
  • Fulfillment of other legal obligations (other legal obligations that USSPA fulfills include, for example, providing information to public authorities).

Personal data processed

USSPA is authorized to process the following personal data according to the purpose for which it was obtained from individual data subjects:

Data of data subjects

Processing purposes:

First and last name

  • Sending commercial communications and offers
  • Accounting and tax purposes
  • Fulfillment of other legal obligations
  • Protection of the legitimate interest of the controller 

Function, position or academic title

  • Fulfillment of the contractual relationship

Contact address

  • Fulfillment of the contractual relationship
  • Sending commercial communications and offers
  • Accounting and tax purposes
  • Fulfillment of other legal obligations
  • Protection of the legitimate interest of the controller 

E-mail

  • Fulfillment of the contractual relationship
  • Sending commercial communications and offers
  • Fulfillment of other legal obligations
  • Protection of the legitimate interest of the controller 

Account number

  • Fulfillment of the contractual relationship
  • Accounting and tax purposes
  • Fulfillment of other legal obligations
  • Protection of the legitimate interest of the controller 

ID number, VAT number

  • Fulfillment of the contractual relationship
  • Accounting and tax purposes
  • Fulfillment of other legal obligations
  • Protection of the legitimate interest of the controller 

Telephone number

  • Fulfillment of the contractual relationship
  • Fulfillment of other legal obligations
  • Protection of the legitimate interest of the controller 

Personal data is processed by USSPA both manually and automatically.

USSPA may also process other data about its Business Partners, or about natural persons representing Business Partners, with regard to the legitimate interests of USSPA, maintaining good business relations with Business Partners, streamlining business communication and also for the purposes of fulfilling the contractual relationship with Business Partners.

Personal data of third parties, which means personal data of employees and customers of USSPA's business partners and other natural persons participating in cooperation with USSPA, or other data that USSPA receives from the business partner in connection with the conclusion or performance of the contract, will be processed in accordance with applicable legal regulations on personal data protection. USSPA will use this personal data for the purpose of fulfilling contracts with business partners. The business partner hereby acknowledges that USSPA will process personal data of third parties for the duration of the contractual relationship and for the period specified in special legal regulations, if any. They will then be stored for a longer period if, in a justified case, there is a need to store data in connection with a specific case. The business partner is obliged to properly inform its employees, customers and other natural persons participating in cooperation with USSPA on the business partner's side about the processing of personal data by USSPA.

Recipients of personal data

At USSPA, your personal data is only made available to authorized employees or individual processors and administrators of USSPA personal data, and only to the extent necessary for the fulfillment of the individual processing purposes.

A list of recipients of USSPA personal data is available at the end of this document. Under certain conditions, we are authorized to transfer some of your personal data to public authorities based on applicable legal regulations.

 

Retention period

We process and store your personal data for the period strictly necessary to ensure all rights and obligations arising from the relevant contractual relationship, and for the period for which USSPA, as the controller of personal data, is obliged to store it according to generally binding legal regulations. In other cases, the processing period results from the purpose of the processing or is given by legal regulations in the field of personal data protection.

 

Purpose of processing

Retention period

Fulfillment of the contractual relationship

for the duration of the contractual relationship and for a period of 10 years from the termination of the contractual relationship, or for the period of possible exercise of rights under the contract

Sending commercial communications and offers

in accordance with applicable legislation*

Accounting and tax purposes

for a period of 10 years from the calendar year following the provision of the service

Fulfillment of other legal obligations

for the period specified in the relevant legal regulation

We process personal data according to the purpose of their processing for the following period:

* USSPA is authorized to process your e-mail address pursuant to Section 7, Paragraph 3 of Act No. 480/2004 Coll., on certain information society services and on amendments to certain acts (Act on Certain Information Society Services), as amended, for the purpose of distributing commercial communications regarding its own products or services, if you have not refused such sending.

Job seeker

If you are interested in employment at USSPA and have therefore sent us your personal data, for example in the form of a CV, we will process your personal data.

Purposes of processing personal data

Your personal data may be processed by USSPA for the following purposes:

  • selection of a suitable candidate for a job position;
  • offering future employment opportunities at USSPA.

Personal data processed

USSPA is authorized to process the data provided by the job applicant.
Personal data is processed both manually and automatically at USSPA

Recipients of personal data

At USSPA, your personal data is made available only to authorized USSPA employees, and only to the extent necessary to fulfill the individual processing purposes.
Under certain conditions, we are authorized to transfer some of your personal data to public authorities based on applicable legal regulations.

Retention period

Osobní údaje zpracováváme dle účelu jejich zpracování po takto uvedenou dobu:

Purpose of processing

Retention period

Selecting a suitable candidate for a job position

no later than three months after the selection of a suitable candidate for the job position.

Offer future job opportunities.

for the period for which the applicant for employment was granted consent.

Website visitor

You can learn about the processing of personal data of visitors to our website
https://usspa.dev.portadesign.cz/en/zpracovani-osobnich-udaju/cookies

RIGHTS OF DATA SUBJECTS

The Customer, Potential Customer, Business Partner, Job Seeker or Website Visitor, as a data subject, has rights arising from legal regulations in connection with the processing of personal data that can be exercised at any time. These are the right to (i) access to personal data, (ii) correction of inaccurate and completion of incomplete personal data, (iii) erasure of personal data if the personal data are no longer necessary for the purposes for which they were collected or otherwise processed, or if it is found that they have been processed unlawfully, (iv) restriction of processing of personal data, (v) data portability, (vi) the right to object, after which the processing of personal data will be terminated, unless it is proven that there are compelling legitimate grounds for the processing which override the interests or rights and freedoms of the data subject, in particular if the reason is the possible enforcement of legal claims and (vii) the right to contact the Office for Personal Data Protection (www.uoou.cz).

  • Right to access personal data: if you want to know whether USSPA processes personal data, you have the right to obtain information about whether your personal data is being processed and, if so, you also have the right to access your personal data. In the case of unfounded, excessive or repeated requests, USSPA will be entitled to charge a reasonable fee for a copy of the personal data provided or to refuse the request (the above applies mutatis mutandis to the exercise of the rights listed below).
  • Right to rectification of inaccurate or incomplete personal data: If you feel that USSPA is processing inaccurate or incomplete personal data about you, you have the right to request its correction and completion. USSPA will correct or complete the data without undue delay, always taking into account technical possibilities.
  • Right to erasure: If you request erasure, USSPA will erase your personal data if (i) it is no longer necessary for the purposes for which it was collected or otherwise processed, (ii) the processing is unlawful, (iii) you object to the processing and there are no overriding legitimate grounds for the processing of your personal data, or (iv) USSPA is required to erase it by law.
  • Right to restrict the processing of personal data: if you request restriction of processing, USSPA will make personal data inaccessible, temporarily delete or store it, or perform other processing operations that are necessary for the proper exercise of the right exercised;
  • Right to data portability: If you want USSPA to transfer your personal data to a third party, you can exercise your right to data portability. If the exercise of this right would adversely affect the rights and freedoms of others, USSPA will not be able to comply with your request.
  • Right to object: the right to object to the processing of personal data which is processed for the performance of a task carried out in the public interest or in the exercise of official authority or for the protection of the legitimate interests of USSPA. Unless USSPA demonstrates compelling legitimate grounds for the processing which override the interests or rights and freedoms of the customer, the processing shall be terminated without undue delay based on the objection.

CONTACT

To exercise your rights, please contact us at the USSPA registered office or by email at gdpr@usspa.cz. USSPA reserves the right to verify the identity of the applicant for the rights in question in an appropriate manner.

 

CONTACT THE SUPERVISORY AUTHORITY

Address:
Office for Personal Data Protection
Pplk. Sochora 27
170 00 Prague 7
Databox: qkbaa2n
e-mail: posta@uoou.cz
telephone: +420 234 665 111 (Switchboard)

GLOSSARY OF TERMS

In accordance with the Regulation, for the purposes of these Principles, the following shall apply:

  1. Administrator is an entity that alone or jointly with others determines the purposes and means of processing personal data or that is obliged to process personal data by valid and effective legal regulations; for the purposes of these Principles, the administrator is USSPA s.r.o.;
  2. processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
  3. data subject is an identified or identifiable natural person (not a legal person - a company or organization);
  4. recipient means a natural or legal person, public authority, agency or other body to which the personal data are disclosed, whether a third party or not (with the exception of public authorities which may obtain personal data on the basis of valid and effective legislation);
  5. personal data means any information about a natural person (data subject) who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, date of birth, identification number, address and contact details, location data, network identifier or to one or more specific elements of the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; personal data also includes data that does not in itself relate to a natural person, but in combination with other information could already be attributed (even potentially) to a specific natural person (e.g. the colour and make of a passenger car, as data relating to a matter that is not in itself related to a natural person);
  6. special categories of personal data are personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person and data concerning a natural person's health or sex life or sexual orientation; data relating to criminal convictions are subject to special protection;
  7. biometric data means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person which enables or confirms unique identification, such as a facial image or dactyloscopic data;
  8. anonymous data means data that, either in its original form or after processing, cannot be attributed to an identified or identifiable data subject – it is therefore not personal data;
  9. processing of personal data means any operation or set of operations which is performed upon personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
  10. collection of personal data means a systematic procedure or set of procedures aimed at obtaining personal data for the purpose of their further storage on a data carrier for immediate or later processing;
  11. retention of personal data means maintaining data in a form that enables further processing;
  12. destruction of personal data means physical destruction of their carrier, physical deletion or permanent exclusion from further processing; anonymization is also a form of destruction of personal data;
  13. anonymization means an activity in which identifiers that can be used to identify a specific natural person are permanently deleted or disconnected;
  14. by pseudonymising the processing of personal data in such a way that they can no longer be attributed to a specific data subject without the use of additional information, provided that this additional information is kept separately and is subject to technical and organisational measures to ensure that it is not attributed to an identified or identifiable natural person; after re-assignment of the additional information, it is possible to re-identify the specific natural person;
  15. profiling means any form of automated processing of personal data consisting of their use to evaluate certain personal aspects relating to a natural person, in particular to analyze or estimate aspects relating to, for example, their work performance, economic situation, health status, personal preferences, interests, reliability, behavior, location or movements, etc.;
  16. consent of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by another clear affirmative action, signifies agreement to the processing of his or her personal data;
  17. database/records any structured set of personal data accessible according to specific criteria, whether centralized, decentralized, or distributed according to functional or geographical aspects;
  18. Personal data breach (so-called "Data Breach") is a breach of security that leads to the accidental or unlawful destruction, loss, alteration or unauthorized provision or disclosure of transmitted, stored or otherwise processed personal data.

The Personal Data Processing Policy (hereinafter referred to as the "Principle") is valid from September 1, 2025.

RECIPIENTS OF PERSONAL DATA

  • Tiskárna H.R.G. spol. s r.o. - a company providing printing and distribution of the magazine Bublinky (applies only to Customers)
  • attorney – as needed
  • auditor
  • external accountant
  • IT suppliers
  • Company doctor