Privacy Policy
(part of the General Terms and Conditions for use of the Portal located at the website (URL) www.biano.cz)
(hereinafter referred to as the “Privacy Policy”)
1. Introductory provisions
1.1. This Privacy Policy constitutes an integral and binding part of the General Contractual Terms of Use of the Portal.
1.2. Capitalized terms and definitions used in this Privacy Policy but not defined herein have the meanings assigned to them in the General Contractual Terms of Use of the Portal.
2. Processing of personal data and contact details of the controller
2.1. Personal data means any information relating to an identified or identifiable data subject (natural person) (hereinafter referred to as “Personal Data”). All Personal Data of the User (natural person) is processed in accordance with the Terms and generally binding legislation, in particular Act No. 101/2000 Coll., on the Protection of Personal Data and on Amendments to Certain Acts, as amended (hereinafter referred to as the “Personal Data Protection Act”). This does not affect the obligation of the Personal Data controller to provide information about the User to third parties or public authorities in cases provided for by legislation.
2.2. The User's rights relating to the processing of their Personal Data are governed by the Personal Data Protection Act.
2.3. The controller of the Personal Data of the User of the Portal is Biano.cz s.r.o., company registration number: 04146905, with its registered office at Křižíkova 148/34, 186 00 Praha 8 – Karlín (hereinafter referred to as the “Controller”). You can contact the Controller by email at info@biano.cz or at its registered office at Křižíkova 148/34, 186 00 Praha 8 – Karlín. The Personal Data Controller determines the purposes and means of processing Personal Data, carries out the processing and is responsible for it.
3. Sources and purpose of processing Personal Data
3.1. Personal Data is processed when using the Portal in the following cases:
3.1.1. when completing the registration form (user account). The Controller processes the following Personal Data:
- email and password;
- name, nickname, gender, date of birth, photograph – if you provide them.
The Controller needs this data to enable the User to log in to their customer account. Without this data, the Controller cannot enable login and use of the account. The password is stored in encrypted form and the Controller does not have access to it.
3.1.2. when completing the registration form (e-shop account). The Controller processes the following Personal Data:
- email and password;
- basic details – e-shop name, contact person, e-shop URL, telephone number, feed URL;
- e-shop description – if you provide it;
- product feed file – if you upload it;
- billing details – company registration number, company name, street, city, postal code, country, billing email;
- country, currency, VAT identification number – if you provide them;
The Controller needs this data to enable the User to log in to their e-shop account. Without this data, the Controller cannot enable login and use of the account. The password is stored in encrypted form and the Controller does not have access to it. Basic e-shop details are needed to identify the e-shop. Billing details are needed to issue an invoice.
3.1.3. if you contact the Controller. The Controller processes the following Personal Data:
- email and message content;
- telephone number – if you provide it;
The Controller needs this data to respond to the User and to know what the User asked about and what interested them.
3.1.4. if the User searches for goods using a photograph. The Controller processes the uploaded photograph for search purposes.
4. Legal basis for processing Personal Data
4.1. The User's Personal Data is processed on 4 legal grounds:
4.1.1. on the basis of the User's consent;
4.1.2. on the basis of the Controller's legitimate interest;
4.1.3. if the Controller and the User have entered into a service agreement, the Controller processes Personal Data for the purpose of performing the agreement;
4.1.4. if the Controller is required to process the data by applicable legislation.
4.2. By ticking the box “I agree to the processing of my personal data in accordance with the General Contractual Terms of Use and the Privacy and Cookies Policy”, which is located in the registration form for registration on the Portal, the User gives consent to the processing of their Personal Data in accordance with the Terms and this Privacy Policy. Before completing registration on the Portal, the User must familiarize themselves with the Terms and the Privacy Policy. Giving consent to the processing of Personal Data under this article is one of the conditions for completing Registration on the Portal and using the related services.
4.3. The User acknowledges that consent to the processing of their Personal Data may be withdrawn at any time by written notice sent by registered mail to the Controller's registered office or by email to the Controller at info@biano.cz.
4.4. We intend to maintain regular contact with Users. Therefore, if you have entered into an agreement with us, we may send commercial communications (a newsletter) to your email address, or, if you have created an account, we may also send you informational emails about your activities on our website. These are email messages in which the Controller informs the User, in particular, about news and interesting offers related to the services provided under the service agreement entered into by the User and the Controller. The Controller sends these email messages on the basis of legitimate interest. The User can unsubscribe from these messages in each email. The User can refuse to receive such messages in advance by sending an email to info@biano.cz or by adjusting the settings of your user account.
4.5. If the User agrees, the Controller may also retain the user's email address for purposes other than those stated above. For example, to communicate information about other offers and goods. The User may withdraw consent at any time.
4.6. A User who is a business partner of the Controller (typically an e-shop operator) acknowledges the processing of their Personal Data to the following extent: first name, surname, residence and, where applicable, registered office, email address, telephone number and any other Personal Data provided by the User within the Portal. To speed up payment transactions, we may process personal data consisting of name, email address, telephone number, billing address and delivery address. Personal data is shared with the payment card issuer to facilitate assessment of transaction risk and speed up the purchasing process. Only the payment card issuer has complete information about the transaction. Personal data is retained for the duration of the transaction assessment. Personal data is shared through the payment gateway operated by Global Payments s.r.o., which acts as a personal data processor in this case. Processing is based on the legitimate interest in processing payment transactions. This processing is based on performance of the agreement.
4.7. A User who is a business partner of the Controller (typically an e-shop operator) acknowledges that they must provide their Personal Data correctly and truthfully and must inform the Controller of any change to their Personal Data without undue delay.
5. Retention period for Personal Data
5.1. All Personal Data of the User will be processed for the period necessary to achieve the purposes of processing specified in the Terms and in generally binding legislation. After this period expires, the Controller anonymizes the data. The data is retained for the specified period so that the Controller knows what it has committed to and can respond appropriately.
5.1.1. The Controller processes Personal Data from the account for as long as the account is active. After 2 years of inactivity, the Controller deletes the account and retains the data for a further 5 years.
5.1.2. If the Controller processes Personal Data on the basis of the User's consent, the data is retained until the User withdraws consent, but for no longer than 2 years from the date consent was given. If the User withdraws consent, the Controller deletes the Personal Data or ceases to use it for the purposes for which the user gave express consent.;
5.1.3. Legislation requires the Controller to retain certain personal data for a longer period.
6. Recipients of Personal Data
6.1. Personal Data processed by the Controller will be made available to the Controller's employees, auditors and advisers.
6.2. Personal Data processed by the Controller may, under the conditions set out in the Personal Data Protection Act, be transferred to a third party and abroad, in particular to the Controller's subsidiaries. These processors are: Google, Meta, Seznam, RTB House, Criteo, Performio, Microsoft (Bing), eHub, Taboola, Hubspot, Mailchimp.
7. Rights of the User
7.1. If the User discovers or believes that the Controller is processing their Personal Data in a manner contrary to the protection of their privacy and personal life or contrary to the Personal Data Protection Act, the User is entitled to:
7.1.1. request rectification from the Controller – if the Personal Data is incorrect or out of date;
7.1.2. object – if the User believes that the Controller is processing personal data beyond the scope of our legitimate interest, they may object to such processing, and we must address the objection;
7.1.3. request erasure from the Controller (the right “to be forgotten”) – at the User's request, the Controller deletes all personal data it holds about them. However, there may be another reason that entitles or obliges the Controller to retain the data (for example, an obligation arising from the Accounting Act), in which case erasure cannot be carried out
7.1.4. request restriction of processing – in some cases, the Controller may retain Personal Data but must not otherwise use it; these are the following situations:
- if the User contests the accuracy of the data and the Controller needs to verify the User's statement;
- if Personal Data is processed unlawfully, but the User does not wish the Controller to erase it and instead requests only restriction of processing;
- if the Controller no longer needs the personal data, but the User requests that it be retained to exercise their legal claims;
- if the User objects to processing, for the period until the Controller verifies whether the Personal Data will continue to be processed in the Controller's overriding interest or will no longer be processed;
7.1.5. request data portability – if the User requests it, the Controller provides the User with Personal Data that it processes on the basis of an agreement or consent and that it also processes by automated means. Such data is provided in a commonly used, machine-readable format. Alternatively, the data may be transferred to a controller designated by the User, provided that controller agrees to the transfer
7.1.6. If the User believes that the Controller is violating the rules for processing personal data, they may contact the Office for Personal Data Protection and lodge a complaint
8. Cookies
8.1. Cookies are used in the operation of the Portal. Cookies are small data files that are stored when visiting websites on the User's computer, smartphone or other terminal device through which the User accesses the internet. Cookies enable the Controller to make use of the website more pleasant and easier for Users. You can find out more about the processing of cookies here.
9. Final provisions
9.1. These Terms take effect on 29 April 2025