Privacy policy

PRIVACY POLICY

 

I. BASIC INFORMATION

This Privacy Policy applies to visitors to the web interface available at https://www.chessbyjass.com (hereinafter also referred to as the “Website”).

The controller of personal data is:

Jasmin Dojčarová, Company ID No. 23526441

Registered office: Čapkova 1439/31, 350 02 Cheb, Czech Republic

Registered in the Trade Register maintained by the Municipal Authority in Cheb

Email: chess.by.jass@gmail.com

Telephone: +420 776 412 578

(hereinafter also referred to as the “Controller”).

The Controller processes the personal data of visitors to the Website and customers (hereinafter also referred to as the “Visitor” and/or the “Data Subject”).

 

II. PERSONAL DATA

The Controller processes personal data provided by the Visitor, including:

  • personal data entered when completing the order form, in particular first name, surname, address, email address, telephone number and other information;
  • information concerning the content of the order, including information about the purchased Goods and their content;
  • information concerning payments made, including the date and amount of payment and information about the account from which the Price was paid. The Controller also collects data relating to the payment card used by the Visitor to pay the Price of the Goods;
  • the content of all electronic communication between the Controller and the Visitor, including electronic addresses, for example the content of email communication concerning questions about the Goods or withdrawal from already concluded Contracts.

The Controller processes certain personal data automatically, including:

  • IP address;
  • date and time of access to the Website;
  • information concerning the Visitor’s internet browser, operating system and language;
  • information concerning the Visitor’s behaviour on the Website, for example which webpage the Visitor entered first, which pages of the Website were visited, how long the Visitor remained on them and which Goods were viewed;
  • information concerning payments made, including the date and amount of payment, information about the account from which the Price was paid and information relating to the payment card used by the Visitor to pay the Price of the Goods.

The Controller generally processes Visitors’ personal data itself. The Controller provides Visitors’ personal data to third parties in the following cases:

  • use of professional accounting and tax services;
  • use of professional marketing services;
  • use of professional legal and advocacy services;
  • use of third-party services, including services provided by Alphabet Inc. (in particular Google services such as Google Analytics) and Facebook, Inc. (including Facebook.com and Instagram.com).

 

III. COOKIES

In addition to the above, the Controller processes cookies.

Cookies are short text files which the Website sends to the Visitor’s browser. They allow the Website and the Controller to record information concerning a visit in order to facilitate future visits by the same Visitor.

Cookies enable a better and more convenient use of and visit to the Website, as they make it possible to store user preferences and other information.

The Controller may use the following types of cookies:

  • technical cookies, used to ensure the proper functioning of the Website, including the correct functioning and display of embedded videos and social media content;
  • session cookies, which are stored only temporarily during a browsing session and are deleted from the Visitor’s device after the browser is closed; these cookies make it possible to optimise the Visitor’s activities on the Website;
  • persistent cookies, which are stored for a predetermined period and are not deleted when the browser is closed. These are used to optimise the Visitor’s activity during repeated visits to the Website. They enable the Visitor’s device to be identified and the Website to be adapted to the Visitor’s needs;
  • marketing cookies, used to personalise content and advertising, provide social media features and analyse Website traffic.

The Visitor may manage the use of cookies through their browser. It is generally possible to delete, block or completely disable cookies. If the Visitor disables or restricts cookies, certain functions of the Website may not be available.

Cookies are also used to personalise content and advertising, provide social media features and analyse Website traffic. The Controller shares the information obtained with partners operating in the fields of advertising, analytics and social media.

By using the Website, the Visitor agrees to connection with Google and Facebook services, to which the Controller may provide information concerning the Visitor’s behaviour on the Website, but not identifying personal data.

 

IV. PURPOSES OF COLLECTION AND PROCESSING OF PERSONAL DATA

The Controller processes personal data for the following purposes:

a) Operation and purpose of the Website

The Controller collects personal data primarily for the purpose of fulfilling contractual obligations towards Visitors to the Website.

For this purpose, the Controller must have information concerning the other party to the Contract in order to fulfil its legal obligations, in particular to deliver the Goods.

b) Communication with Visitors to the Website

The Controller also collects and processes personal data where a Visitor contacts the Controller with a question or comment which the Controller is required to answer, or where the Controller needs to communicate with the Visitor for important reasons, for example in connection with handling a complaint.

c) Ensuring the functionality of user accounts

The Controller also collects and processes personal data in order to enable the functionality of user accounts, which are intended to make it easier for Visitors to use the services of the Website.

The Visitor may change the information entered in their user account.

d) Optimisation of the functionality of the Website

The Controller also processes and collects personal information for the purpose of optimising the functionality of the Website as a whole.

This includes information concerning Visitors’ behaviour on the Website and the content of their orders.

The Controller uses this information to offer relevant Goods to individual Customers and to make the use and navigation of the Website easier and more convenient.

e) Protection of the Controller’s rights

The Controller also collects and processes information for the purpose of protecting its own rights and enforcing claims arising from legal relationships entered into between the Controller and Visitors through the Website.

 

V. LEGAL BASES FOR PROCESSING PERSONAL DATA

The Controller collects and processes personal data on the following legal bases:

a) Conclusion and performance of a Contract

The Controller operates the Website for the purpose of concluding Contracts.

In order for the Controller to conclude a Contract through the Website and subsequently fulfil its obligations arising from concluded Contracts, it is necessary for the Controller to process Visitors’ personal data.

For this reason, the Controller collects and processes in particular:

  • first name and surname;
  • Company ID No.;
  • address;
  • email address;
  • information concerning the content of the order;
  • information concerning payments made, including information concerning payment cards used.

b) Legitimate interests of the Controller

The Controller operates the Website as part of its business activities and seeks to ensure that the Website is user-friendly for Visitors and offers Goods which may be of interest to them.

The Controller also collects and processes personal data for accounting and tax purposes, statistical purposes, display of advertising, development and administration of the Website, fraud prevention and ensuring the security of the Website and information.

For these purposes, the Controller collects and processes in particular:

  • information concerning the Visitor’s behaviour on the Website;
  • cookies;
  • first name and surname;
  • address;
  • email address;
  • information concerning the content of the order;
  • the likeness of the Data Subject in the form of photographs and video recordings where these are used to provide information about an event on social media, the Website or similar channels.

Personal data is processed both manually and by automated means.

 

VI. RETENTION PERIOD OF PERSONAL DATA

The Controller processes personal data for the period necessary to ensure the rights and obligations arising from the legal relationship, at least for the duration of the obligations arising from the concluded Contract.

The Controller retains Visitors’ personal data for a period of five (5) years from the conclusion of the Contract where the subject matter of the Contract consists of a one-time performance.

Where the subject matter of the Contract consists of repeated performance, for example a subscription, the Controller retains Visitors’ personal data for a period of five (5) years from the termination of the provision of performance under the Contract.

Where the Visitor creates a user account, personal data will be retained until the user account is deleted. The Visitor is entitled to delete the account at any time.

In such a case, personal data may be retained for longer than five (5) years as a result of the Visitor’s actions or omissions. The Visitor may continue to access paid courses through the account even after more than five years, and deletion of such data could interfere with the Visitor’s right to access paid content.

The Controller is required to retain certain data for periods longer than five (5) years where such an obligation arises from generally binding legal regulations. This includes, for example, mandatory retention periods for accounting documents.

 

VII. RIGHTS OF VISITORS TO THE WEBSITE

As a Data Subject, the Visitor has the following rights:

a) Right of access to personal data

At the Visitor’s request, the Controller shall confirm whether personal data concerning the Visitor is or is not being processed.

Where such personal data is being processed, the Visitor also has the right to the information specified in Article 15 of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter also referred to as the “GDPR”).

The Controller shall provide the information to the Visitor without undue delay.

In such a case, the Controller is entitled to reasonable reimbursement which shall not exceed the necessary costs of providing the information.

b) Right to rectification

The Data Subject has the right to have inaccurate personal data concerning them corrected by the Controller without undue delay.

Taking into account the purposes of the processing, the Data Subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.

c) Right to erasure

The Data Subject has the right to obtain from the Controller the erasure of personal data concerning them without undue delay, and the Controller has the obligation to erase such personal data without undue delay.

Erasure is possible where the personal data is no longer necessary for the purposes for which it was processed, there are no legitimate grounds for the processing, or the personal data has been processed unlawfully.

The precise scope of the right to erasure is set out in Article 17 GDPR.

d) Right to restriction of processing

The Data Subject has the right to obtain restriction of processing of personal data from the Controller in the cases specified in Article 18 GDPR.

e) Right to data portability

The Data Subject has the right to receive personal data concerning them which they have provided to the Controller in a structured, commonly used and machine-readable format and has the right to transmit such data to another controller without hindrance from the Controller to whom the personal data was provided.

f) Right to object to processing of personal data

The Data Subject has the right to object at any time to the processing of personal data carried out for the purposes of protecting the legitimate interests of the Controller.

The Controller shall no longer process the personal data unless the Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the Data Subject, or grounds for the establishment, exercise or defence of legal claims.

g) Right to request an explanation

The Data Subject has the right to request an explanation from the Controller concerning the processing of personal data where the Data Subject believes that personal data is being processed contrary to applicable law.

h) Right to lodge a complaint with the Office for Personal Data Protection

Where the Data Subject has doubts as to whether the Controller is complying with its obligations arising from applicable personal data protection legislation, the Data Subject has the right to contact the Office for Personal Data Protection of the Czech Republic.

For the same reason, the Data Subject may also contact the Controller directly using the email address specified above.

All of the above rights, except for the right to contact the Office for Personal Data Protection, may be exercised using the email address specified above.

This Privacy Policy is effective as of 1 November 2025.