INFORMATION ON THE PROCESSING OF PERSONAL DATA
(hereinafter referred to as "Information")
TasteTown s.r.o., with its registered office at Těšetice 180, Těšetice 671 71, ID: 21451265, VAT ID: CZ21451265, registered in the Commercial Register maintained by the Regional Court in Brno, under file number C138964 (hereinafter referred to as the "Company" or "we" in all forms), as the controller of your personal data, hereby informs you about how it processes and protects your personal data.
We always provide you with this Information at the beginning of our interaction, and it is also available on our website [https://tastetown.cz/gdpr](https://tastetown.cz/gdpr).
--
1. WHAT PERSONAL DATA PROCESSING DOES THIS INFORMATION COVER?
This Information relates to the processing of personal data of:
- Users of the TasteTown application, Registered users of the TasteTown application (including the START Contract and the full version) ("Application Users"),
- Other visitors or users of our website (hereinafter referred to as "Website Users"),
- Participants in our games, contests, voucher giveaways, and other promotional or PR projects (hereinafter referred to as "Contestants"),
- Our contractual partners, such as Partner businesses, vendors, and business customers (hereinafter referred to as "Business Partners").
If you do not fall into any of the above categories, please contact us at support@tastetown.cz, and we will provide you with the version of the Information on the processing of personal data applicable to you.
TasteTown is the operator of the website (hereinafter referred to as the "Website") available at [www.tastetown.cz](http://www.tastetown.cz) and the mobile application TasteTown (hereinafter referred to as the "Application").
---
2. WHAT DATA DO WE COLLECT ABOUT YOU
We collect and process your personal data during our interactions, including identification and contact details, and technical data and information we obtain from you when using our Website, Application, or through our telephone, electronic, or other communications.
This includes information you provide to us when you register as a user in our Application, order our services, use our Website or services, contact us by phone or email, comment on Businesses in the Application, participate in a contest, promotion, or survey, fill out an application or other form, such as to obtain a free voucher, or when you report issues with our Website or Application. The information you provide may include your name, address, email, phone number, customer ID, financial and payment information, personal description and photo, age and date of birth, and technical data about your IP address, approximate location based on this IP address, your device from which you access our services, your navigation within the Website or Application environment.
We will not collect or process your sensitive personal data (such as information about your health, sexuality, race, or ethnicity) unless such sensitive personal data is related to a specific purpose for which we process personal data if required by law, and/or if you give us your special explicit consent. Personal data that you voluntarily provide (including sensitive personal data) during our interaction (e.g., by voluntarily disclosing sensitive personal data in comments on the Website) of your own volition and not at our request will be deleted from our systems unless we find the processing of this data necessary for legitimate reasons unless such data is made publicly available (e.g., on publicly accessible online bulletin boards) - in such a case, we will delete this data from our Website only if required by law or if we choose not to keep it further.
We may receive your personal data from third parties, such as our Business Partners, subcontractors of technical, payment, and delivery services, advertising networks, analytics service providers, and search information providers. For example, we may receive your personal data from an external agency when searching for new employees.
If we receive your personal data from third parties, we will provide you with all relevant information about the processing at the earliest opportunity but in any case no later than one month after receiving your personal data, including information about the types of personal data processed, the purpose of processing, and its legal basis.
---
3. HOW AND ON WHAT LEGAL BASIS DO WE USE YOUR PERSONAL DATA
General
We are authorized to process your personal data if it is necessary for the performance of our mutual contract if it is necessary to fulfill our legal obligations (e.g., accounting regulations), if it is necessary for our legitimate interests (or the legitimate interests of third parties), provided these interests do not override your fundamental rights, if it is necessary to protect your vital interests (or the vital interests of others), and/or if required by public interest or official purposes.
We process your personal data for various technical, administrative, and operational purposes, such as ensuring that the Application and our Website are presented to you in the most efficient way possible for you and your mobile device, improving our Website and its functionality, managing our contractual relationship, internal processes including troubleshooting, data analysis, testing, research, statistics, and surveys, for promotional purposes including targeted marketing, presenting content that may interest you, and maintaining the security of our Website and Application.
Your personal data may be subject to profiling. This means we set up processes that create specific groups (segments) that include individual data subjects based on data we process about them. If your personal data is subject to profiling, you will find out in the section of this Information that pertains to you.
In some cases, we will process your personal data only with your consent. In such cases, we will specifically request your explicit consent when providing personal data. You may withdraw this consent at any time via support@tastetown.cz. However, the withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. In relation to the use of cookies (except for strictly necessary cookies), you can grant your consent in the pop-up window that appears when you first visit our site or can be triggered by clicking on the link "Change cookie settings" at [https://tastetown.cz](https://tastetown.cz). The same way you can also withdraw the consent already given (and block further use of cookies).
Where we require personal data due to fulfilling legal or contractual obligations, providing such personal data is mandatory. This means that if such personal data is not provided, we would not be able to manage our contractual relationship or fulfill the obligations imposed on us. Where we ask for consent to process your personal data, providing personal data is voluntary, and you are not obliged to provide it.
We may also process your personal data, such as identification and contact details and home address, for the potential future assertion of our rights and claims against you. This processing is based on our legitimate interest in asserting our rights in potential legal disputes.
We will most often use your personal data in the following situations:
(a) Application Users
In connection with your status as a registered user of our Application, our services, or if you subscribe to our marketing and business communications, we may collect and process your personal data:
- when you download and browse the Application, register in the Application, activate the START service or order the full version of the TasteTown service;
- regarding geographical location determined at the level of a specific city/town according to the IP address of a mobile or other device;
- when using the Application, we process information about your user behavior and preferences (what content/businesses/categories you follow, for how long, when you stop following content, etc.);
- when you contact us for customer support regarding the services provided, we will process your identification and contact details, the content of the request, and if you contact us via the customer line, also the necessary record of the telephone communication;
- when you communicate with us in any other way, such as by phone, SMS, email, social media, or comments;
- when you register for our Applications (including the free trial period) and in this context provide us with your personal data,
- when you attach a comment, rating, or other type of response to our Application,
- when you use our Application;
- when you communicate with us through the use of our Application.
For the purpose of providing the full version of the TasteTown service, making payments under relevant contracts (including any subscription to our services), and fulfilling legal obligations (particularly tax and archiving obligations), we may process your personal data, such as identification and contact details and payment data, according to the type of service. In such cases, we only have access to the most essential payment data. When making an electronic payment, we store information about the price, name and surname, email, payment ID to verify the payment, payment method (card, Google Pay, or Apple Pay), card brand and type, bank name, card issuing country, the first 6 and last 4 digits of your card number, in the case of unfinished transactions, the reasons for transaction failure and accompanying technical payment data; the remaining data necessary for card payment is exclusively held by the secured payment gateway STRIPE and the relevant banking institution.
With the STRIPE payment gateway, we are joint controllers of the data entered in the payment form and associated data with it when making a payment for ordered services. However, most of the processed payment information is strictly available to the relevant payment gateway. In the case of STRIPE, the following data are processed: name, surname, address, email, phone number, account number, account holder's name, card number, IP address, and payment reference number.
For user management purposes, subscription management, communication with payment gateways, documentation of granted consents, expression of dissent, etc., and correct personalization and business analysis, we mainly use your registration and voluntarily completed or otherwise provided data, including the above payment data, data on your user behavior (search duration, time to activation, etc.), and subscription history data. For these purposes, we use modern information systems that ensure the maximum security of your data. To protect your personal data to the maximum extent possible and for each purpose, only the necessary data are used, personal data is combined through a technical identifier.
This personal data processing is based on
- the performance of our mutual contract(s)
- the fulfillment of the legal obligation to archive documents,
- our legitimate interest.
- For receiving news about the Company's services and products, this data is subject to profiling.
- If you are already an Application User, we may contact you via email, social media, or SMS with information about TasteTown products and services similar to those you use or have previously purchased unless you express your disagreement when providing your contact details or in the manner specified in each individual business communication. You may withdraw your consent to communicate business messages at any time by emailing support@tastetown.cz or in the manner specified in each relevant business communication.
- our legitimate interest in verifying user access data to services provided in the territory where you reside for the proper functioning of the application.
We may also disseminate business communications through so-called push notifications (banners). Push notifications are short messages that will be displayed on your terminal device, even if you are not currently viewing our Website or mobile Application. These notifications will only be displayed if you allow them on your terminal device. You can disable push notifications in your mobile device settings.
In addition, we may disseminate business communications via SMS. These notifications will only be displayed if you enable them when registering or logging into the Application. You can disable SMS notifications in the manner indicated with each SMS.
We will not share your personal data with third parties for third-party marketing purposes without your explicit prior consent.
For proper personalization and targeting of business communications, in addition to your email, we also use personal data available to us for other reasons: especially your registration and voluntarily filled data (e.g., setting the frequency of individual types of notifications) or otherwise provided data, data about your user behavior when using the Application and data about how you respond to our business communications. For these purposes, we use modern information systems that ensure the maximum security of your data.
This personal data processing for receiving news about the Company's services and products or our Business Partners is based on
- the performance of our mutual contract,
- our legitimate interest in sending business communications to customers, or your consent to receive business communications.
In some cases, your personal data obtained through social networks you visit may be processed to send personalized direct marketing. These personal data may be processed jointly between TasteTown and the operator of the specific social network or analytics tool through which personalized direct marketing is sent.
TasteTown processes your personal data to maximize the customization of displayed advertising based on (i) the data you provided to TasteTown; or (ii) according to the data that TasteTown obtained from you when using its services; and at the same time according to (iii) the data you provided to the specific social network/analytics tool operator; or according to (iv) data available to the specific social network/analytics tool operator due to your activity on this social network.
Further information on the processing of your personal data and the possibilities for protecting your rights can be found on the websites of individual social network/analytics tool operators:
- [Facebook Privacy Policy](https://www.facebook.com/privacy/policy/?entry_point=data_policy_redirect&entry=0)
- [Instagram Privacy Policy](https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect)
- [YouTube Privacy Policy](https://www.youtube.com/howyoutubeworks/user-settings/privacy/#your-data-in-youtube)
- [TikTok Privacy Policy](https://www.tiktok.com/legal/page/eea/privacy-policy/en#privacy-eea)
(b) Website Users
In connection with your use of our Website and related services, we may collect and process your personal data:
- when you enter our Website and navigate through it;
- when you post your contributions on our Website, whether in text, image, or audiovisual form, including comments, ratings, or other types of responses;
- when you communicate with us through our Website,
- when you communicate with us in any other way, such as by phone, SMS, email, social media, or comments.
- Our Website uses cookies to distinguish you from other users. These files help us provide you with good user conditions while browsing the Website and enable us to improve the quality of the Website.
When you visit our Website, we will ask for your consent to process personal data obtained from cookies in a pop-up window. These personal data are then processed based on your consent, which you can withdraw at any time. In addition to personal data processed based on your consent, we process other personal data obtained from cookies, namely those obtained from strictly necessary cookies. This processing is based on our legitimate interest in the operability of the Website. If you communicate with us, we process your personal data based on our legitimate interest in your pleasant user experience.
Such processed data may include, for example:
- technical data, which may include the type and version of the browser, IP addresses, and other online identifiers of the user or used device, time zone settings, types and versions of browser plugins, operating system and platform, type of device and brand of mobile phone, or records of (non)granted consent to the use of cookies;
- data about your visit, which may include Uniform Resource Locators (URLs), data about navigation on our Website, where you accessed them and where you left them (including date and time), information or products you viewed or searched for (including the most read articles, most visited categories, page response times, download errors, duration of visits to certain pages (including average time spent on certain pages, viewing certain content or videos), average time spent in the application and the number of views from these applications, the average number of articles viewed on our Website, information about page interaction (such as scrolling, clicking, and cursor position), exit methods from the page, data about user behavior, and phone numbers or email addresses from which representatives of our customer services were contacted;
- your identification and contact details and the content of the request when you contact us for customer support regarding the provided services; if you contact us via the customer line, then also a record of the telephone communication to the necessary extent.
This personal data processing is based on
- your consent,
- our legitimate interest in the operability of the Website and your pleasant user experience.
(c) Contestants
In connection with your participation in a game, contest, timed competition for a voucher, or another promotional or PR project organized by us (hereinafter collectively referred to as the "Contest"), we may collect and process your personal data, such as your name and surname or username, home address, email address, phone number, and possibly other data depending on the type of Contest, e.g., age, photographs, etc.
If you provide us with personal data of third parties in connection with your participation in the Contest, especially their photographs, you are responsible for ensuring that their rights are not infringed, and you are obliged to obtain their written consent.
The above personal data are processed during the realization of the Contest for the purpose of maintaining a database of Contestants and subsequently evaluating the Contest and for securing communication with Contestants during the Contest, especially messages regarding the Contest, containing information about the Contest, its course, and possibly informing about winning the Contest.
In addition to the above personal data, other information related to participation in the Contest may be processed, e.g., answers to contest questions, fulfillment of contest tasks, contest entries submitted by Contestants, whether in text, image, or audiovisual form, etc.
The Company also processes and collects the following personal data from winners: name, surname, and address for the purpose of publishing Contest results and distributing prizes (winnings). The data about the winners is published on the website and possibly on social networks, usually in the following scope: name, surname, city where the winner is from, and the prize (win). The contact details of the winners may be passed on to the person/company providing the respective prize for the Contest, exclusively for the purpose of distributing the prize (win).
(d) Business Partners
For the purpose of providing services, mediation, delivering goods, and making payments under relevant contracts, we may process your personal data, such as identification data including Company Registration Number, business contact data, bank connection, VAT ID, contact person, and others.
This processing is based on
- the performance of the contract, of which you, as our Business Partner, are a contractual party,
- the obligation imposed on us by law and
- our legitimate interest.
In some cases, we process personal data, such as the name and contact details of employees or suppliers of our Business Partners, for communication purposes in connection with the performance of a specific contract concluded with the Business Partner.
As you are our Business Partner, we may send you business communications pursuant to §7, paragraph 3 of Act No. 480/2004 Coll., on certain services of the information society, about products and services related to our previous contractual cooperation. If you do not wish to receive these messages further, you can unsubscribe at support@tastetown.cz.
For the purpose of properly targeting business communications, in addition to your email, we also use personal data available to us for other reasons: especially your contractual identification data, data provided within our business cooperation, information voluntarily provided by you, and data about how you respond to emails with our business communications. For these purposes, we use modern information systems that ensure the maximum security of your data, ensuring that your personal data is protected to the maximum extent possible and that only the necessary data is used for each purpose.
---
4. HOW AND TO WHOM CAN WE DISCLOSE YOUR PERSONAL DATA
Only a limited number of Company employees will have access to your personal data according to the purpose of
the processing, such as the trade section, legal section, marketing section, IT section, and only to the necessary extent. These employees are bound by a duty of confidentiality in connection with your personal data. Appropriate technical and organizational security measures have been taken to secure your personal data. Company employees may handle personal data only at the Company's instructions and if it is necessary in connection with their work duties.
Personal data may be provided to government authorities and/or law enforcement authorities if required by applicable law or if it is necessary to assert our rights, including our terms of use, or to protect our legitimate interests (including the legitimate interests of third parties) in accordance with applicable laws.
Your personal data may also be disclosed to third parties, including:
- service providers who provide the Company with administrative, professional, and technical support in IT, administration, customer support, security, and business resources,
- Business Partners, suppliers, and subcontractors, including payment gateways and payment services providers, if necessary to perform any of our contracts with you (including any subscription to our services), partners based on your consent, for the purpose of personalizing business communications, analytics service providers, and search engines that help us improve and optimize our Website.
If necessary, the Company is entitled to share personal data with external consultants (such as legal advisors, accountants, and auditors).
The Company endeavors to conduct appropriate due diligence when selecting external service providers and requires these service providers to implement appropriate technical and organizational security measures to secure personal data and to process this personal data only in accordance with the Company's instructions. Service providers may use subcontractors to provide services to the Company, provided that the subcontractor undertakes to comply with the same obligations regarding the protection of personal data as the service providers.
---
5. RETENTION OF YOUR PERSONAL DATA AND THEIR TRANSFER ABROAD
The personal data we collect is stored within the European Union (hereinafter referred to as "EU") and the European Economic Area (hereinafter referred to as "EEA"). Information collected by third parties through cookies may be processed on servers located in the EEA and transferred outside the EEA.
Your personal data may also be transferred and stored outside the EU and EEA. When transferring your personal data from your country to another, the laws and regulations protecting your personal data in the country to which your personal data is transferred may be different (or provide weaker protection) than the laws and regulations applicable in your country of residence.
Our goal is not to transfer your personal data outside the EEA unless adequate protection is ensured, in particular:
- by a decision of the European Commission on acceptable protection in the country or countries receiving personal data,
- by appropriate binding internal regulations,
- by an approved code of conduct with binding and enforceable commitments of the controller or processor in a country outside the EU and EEA,
- by an approved certification mechanism with binding and enforceable commitments of the controller or processor in a country outside the EU and EEA to apply appropriate protective measures, or
- by standard contractual clauses in accordance with EU standards approved by the European Commission.
---
6. YOUR RIGHTS
You may request confirmation from us whether we process your personal data, a copy of your personal data, and/or their correction. Under certain circumstances, you may request us to delete your personal data or, based on the right to portability, ask us to transfer some of your personal data to you or other entities. You also have the right to object to certain types of processing of your personal data (such as their use and processing for direct marketing purposes). Where we have asked for your consent to process personal data, you may withdraw your consent without adverse consequences. You also have the right to object where we process your personal data because we have a legitimate interest (as explained above). Under certain circumstances, you also have the right to request a restriction on processing your personal data.
Please note that your above rights may be limited in certain situations and subject to applicable data protection laws and regulations; for example, your right to object to the processing of your personal data may be limited where we can demonstrate compelling legitimate grounds for processing your personal data that override your interests. To respond to your request, you will need to verify your identity and provide us with additional personal data. We will not charge you any fees for responding to your request unless permitted by law, and if we charge a fee, it will be in a reasonable amount corresponding to the scope of your request.
If you wish to exercise these rights, contact us via the contact details below. We hope we can answer any questions you have about how we process your personal data. However, you also have the right to lodge a complaint with the relevant data protection authorities. You can file a complaint in the Member State where you reside, where you work, or where the alleged breach of data protection regulations occurred.
---
7. HOW LONG DO WE RETAIN YOUR PERSONAL DATA
We intend to retain your personal data only as long as necessary following our personal data retention policies, no longer than necessary to fulfill the purposes specified in this Information and/or as required by applicable laws, including compliance with the statutory minimum retention period for personal data, and/or as necessary to assert our legitimate rights (and the legitimate rights of third parties). We regularly review the scope of processed personal data and delete it if the purpose of its processing has been achieved without the existence of another reason for processing. For example, if you are our Business Partner, we will retain your personal data for the duration of our contractual relationship and, if applicable, for the period required by local laws (especially tax and accounting). If we have a long-term business relationship with you as a Business Partner (e.g., if we repeatedly use the same personal data in contracts with you), we will retain your personal data until our business relationship ends, for the statutory minimum retention period for personal data, and in accordance with our personal data retention policies. If you are an Application User, we will retain your personal data for the period you have the Application downloaded or for the period specified by relevant laws and in accordance with our personal data retention policies. In the case of customer support inquiries, we will process your data for the duration of handling your request.
In cases where we process your personal data based on your consent, your personal data will only be processed for the duration of your consent, which you may revoke entirely or partially before its expiration. In such a case, we will stop processing the personal data regarding which the consent was revoked for the specified purposes, subject to any legal obligation to process such personal data and/or use it for the purposes of asserting our legitimate rights (and the legitimate rights of third parties).
For further information on how long we retain your personal data, please contact us via the contact details provided in the section below. Please note that we may process your anonymized personal data without further informing you.
---
8. SECURITY OF PERSONAL DATA
We store your personal data on our servers and third-party servers (including external cloud storage services). We use appropriate technical and organizational measures to protect your personal data and prevent unauthorized access. We have concluded agreements with external hosting providers that include provisions on the organizational and technical security of personal data. Any payment transactions will be encrypted (e.g., using the TLS protocol). You are responsible for keeping your access credentials confidential.
Sending personal data over the internet is not completely secure. Although we do everything in our power to protect your personal data, we cannot guarantee the security of your personal data provided through our Website, and any such transmission is at your own risk. Once we receive your personal data, we will strive to prevent unauthorized access by adhering to strict processes and using security features.
---
9. BUSINESS COMMUNICATIONS
If you are our Application User and have not previously unsubscribed from receiving business communications, we may send you business communications electronically or contact you with information about goods and services similar to those you have previously purchased or negotiated to purchase from us, in accordance with § 7 paragraph 3 of Act No. 480/2004 Coll., on certain services of the information society. Business communications regarding any other services of TasteTown, including those unrelated to goods and services similar to those you have previously purchased or negotiated to purchase from us, as well as offers from our business partners, may be sent to you electronically if you have given us your explicit consent.
Consent to electronic sending of business communications is granted under § 7 paragraph 2 of Act No. 480/2004 Coll., on certain services of the information society, and according to your preference, may include only offers of TasteTown products and services or offers from our business partners or offers from our Affiliated Companies.
---
10. LINKS TO OTHER WEBSITES
Our Application and Website contain links to websites not under the control of the Company. Upon clicking on an external link, you will be directed to a third-party website. When visiting these linked websites, you should familiarize yourself with their privacy policies. We are not responsible for the policies and practices of other companies. Our Company has no control over the content, privacy policies, and policies or practices of third-party websites or services and is not responsible for them.
---
11. CONTACT DETAILS
If you have questions or concerns about processing your personal data, or if you wish to exercise any of your rights, contact us at TasteTown s.r.o., Těšetice 180, Těšetice 671 71, and at the email address support@tastetown.cz.
You can also contact the Office for Personal Data Protection, located at Pplk. Sochora 27, 170 00 Praha 7, email: posta@uoou.cz, [https://www.uoou.cz](https://www.uoou.cz).
When contacting us, please do not disclose any sensitive personal data (e.g., information about your ethnic origin, political opinions, religious or other beliefs, health status, or trade union membership), social security numbers, or information about criminal records.
---
Last updated: 05.08.2024
We may occasionally
update this Information, in which case we will notify you of any changes by publishing new Information on the Website [www.tastetown.cz/gdpr](http://www.tastetown.cz/gdpr). If you have provided us with contact details and allowed us to contact you, we will notify you of significant changes to this Information. Please check regularly to see if this Information has changed.