1. This document explains which data are collected in connection with KINGDOM COME STORE services.
2. It also explains how we use that data, where we store it, and how we protect it.
3. In short:
- In order for you to use our services we need to process some of your data.
- If we need to process your data for any other purpose, we will always ask for your consent in advance.
- Some partners, such as WARHORSE STUDIOS, help us in providing our services and we may share limited data with them — but only for this purpose.
- We will not share your data for third party advertising purposes.
4. Finally, it explains your rights in relation to your personal data.
1. WHO WE ARE
We are Xzone s.r.o., Company ID: 28675703, Husova 869, 440 01, Louny, a company incorporated in Czech Republic and a data controller under European Union data protection legislation (hereinafter "XZONE" or "we"). You may contact us via email at email@example.com or by mail: Xzone s.r.o., Husova 869, 440 01, Louny, Czech Republic
2.3. We respect your right to privacy and will only process personal data in accordance with applicable legislation.
3. PROTECTING CHILDREN
We recognize that we have a special obligation to protect personal data obtained from children. We do not and will not knowingly collect personal data from any child under 16. If for any reason we decide to collect personal information of children between the ages of 13 and 16 we will ask for their parent or guardian's consent. If you are a parent or guardian and are concerned about the transfer of your child's personal information, please contact firstname.lastname@example.org.
4. INFORMATION WE COLLECT
When you use STORE services, we may collect the following data if relevant (how we use it is described later in this document).
In the context of order handling and customer accounts, we will process your basic personal data such as:
a) your name and surname;
b) email address;
c) residence address;
d) shipping address;
e) phone number;
f) IP address;
g) country, where you place your order;
h) order and payment history (including identifiers, order values and ordered items);
i) data resulting from your use of STORE functionalities and optional data which you may provide in account settings (wishlist items, account settings, product reviews and ratings, day and month of your birthday, gender);
j) additionally — if you place your order as part of your business activity — invoicing address, business name, VAT number.
Moreover, depending on the payment method you choose, we will process the following payment-related data:
a) debit/credit card data — card number, name and surname of the card holder, validity date;
b) bank account number, name and surname of the account holder;
c) e-mail address linked to PayPal account.
If you take part in contests organized by XZONE, we may additionally process data necessary for the purpose of holding contests and announcing their results, such as your correspondence address, phone number, identifiers in social media, image of yourself or your bank account number.
We may also collect some non-personal data about our users (statistical information on the use of our services, information on devices used to connect to them) in order to better understand how our goods and services are used and to improve them based on this knowledge.
In order for you to use our services, we need to process the data described above — provision of the data is voluntary, but without it, you will not be able to use our services.
5. HOW IS YOUR INFORMATION USED
Your data may be used for the following purposes:
a) providing access to STORE services, including account registration and personalization, order history, status.
b) organizing contests, including contacting participants, evaluation of applications, distribution of prizes, payment of tax on prizes;
c) sale and delivery of goods and payment handling;
d) preventing payment fraud in the use of STORE services;
e) providing technical support and customer service, as well as providing information about changes regarding goods and services of the STORE;
f) monitoring operations of STORE services and introducing improvements based on submitted remarks and suggestions;
g) in applicable cases - for the purposes of asserting claims and legal defense, including litigation, arbitration or mediation;
h) fulfilling the obligations resulting from provisions of law, including tax and accounting law;
i) documenting personal data processing, i.e. for accountability purposes as required by the General Data Protection Regulation (GDPR);
j) providing you with marketing information (including personalized and targeted marketing emails), which we feel may interest you. For example, we may send you newsletters or emails about our services (of course, this is optional and we will ask you for permission first).
Whenever we personalize or target our marketing communications, offers and advertisements, we may profile your personal data, which means that we may use the data we collect to adjust the communication addressed to you to meet your needs. In such cases, we do not use your personal data for profiling, which would constitute automated decision-making that could affect your legal situation (for example, we will not deny you access to our services based on your activity in the STORE).
If you decide that you no longer wish to receive personalized offers, product recommendations from us, or any advertising news at all, you can withdraw your consent at any time.
6. WHY DO WE USE YOUR DATA (LEGAL BASIS FOR DATA PROCESSING)
We process your personal data to perform the agreement between us, which includes enabling you to use our STORE. This happens in the case of purposes (a)-(c) and (e) of Section 5.1. above (if you contact us as a registered customer).
Also, we process information about you for the purpose of and in scope necessary to pursue our legitimate interests (ensuring security of payment processing and IT systems of the Store, communication with unregistered users), within the purposes indicated in points (d)-(g) of Section 5.1.
Moreover, we process your personal data to fulfill our legal obligations. This refers to the purposes indicated in points (h)-(i) of Section 5.1.
In other cases, your personal data is processed based on your consent (this primarily includes processing your data for marketing purposes, in particular providing you with our newsletter). You can withdraw your consent at any time; however, withdrawal of consent will not affect the lawfulness of prior processing.
We may process some aggregated and general non-personal data on user behavior (e.g. sales per region, number of reported technical issues) with third party partners who work with us to provide STORE services to you (for example, producers of our gadgets or payment providers) in order to support, improve or amend STORE services. We may also share non-personal data with data analysis services to help us run STORE services. As mentioned above, everything is anonymized, so you cannot be identified.
7. HOW DO WE HANDLE YOUR PERSONAL INFORMATION
How long will we store your data?
b) if you contact us and do not use our services, we will retain correspondence with you as long as necessary to assist you, followed by a period necessary for legal or accountability purposes;
c) for marketing purposes, we will store data as long as we have valid consent, and in case of its withdrawal, we will remove it without undue delay and no later than within 30 days from the moment we receive your request to cease data processing.
8. DATA SHARING
Please remember that any communications you have via XZONE services (e.g. reviews or comments published on product pages in the Store) may reveal details about you. Also, any data you post publicly using XZONE services will be publicly available for Store users and others. We are not responsible for your use of any private personal data which you choose to make available via XZONE services, or the activities of other users or other third parties to whom you give or make available your data.
9. THIRD PARTY INFORMATION COLLECTION AND EXTERNAL SERVICES
10. OUR TRUSTED PARTNERS AND OTHER CASES OF DATA SHARING
We may share your data with the following Trusted Partners, who were engaged by us to help deliver our services and functionalities to you. Please rest assured that we always provide our partners with the minimum data necessary for them to achieve the purpose of their cooperation with us. They may have access to limited data about you and process it on our behalf for the purposes set out below:
a) Google LLC, 1600 Amphitheatre Parkway, CA 94043 Mountain View
b) Facebook Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, D2 Dublin, Ireland
c) Czech Post, s.p., Politických vězňů 909/4, 225 99 Praha 1
d) courier company PPL CZ s.r.o., K Borovému 99, Jažlovice, 251 01, Říčany
e) courier company Packeta s.r.o., Drahobejlova 1019/27, 190 00 Praha 9
f) courier company IN TIME SPEDICE, spol. s r.o., Na hřebenech II 1718/8, Praha 4, 14000
g) payment provider Československá obchodní banka, a. s., Radlická 333/150, 150 57, Praha 5
h) payment provider Paypal, 2211 North First Street, San Jose, California 95131
i) partners providing assembly and shipping services;
j) our partners who help us in data analysis by providing us with analytical tools;
k) our partners who help us manage our newsletters and email communications;
l) our professional advisors who assist us with legal, tax, audit or accounting matters;
m) advertising partners for the purpose of personalized and targeted marketing (for example, to inform you via advertisements on websites you visit about our services you may enjoy).
When required by law, we may also share your data with the police or other government authorities (including your IP address and details of suspected unlawful or fraudulent activity such as unauthorized use of payment methods and security risk scores - so if, e.g. it seems for us your card was stolen, we can inform the police about it).
Your data may be processed, stored and transferred to countries outside your country of residence and beyond the European Economic Area (EEA), such as the United States. Privacy laws in these countries may not offer the same level of protection as in your country or in the EEA. But whenever we share your personal data outside the EEA, we will ensure the adequate protection of your personal data and apply lawful measures of data transfer, such as EU standard contractual clauses or the Privacy Shield Framework.
Please be aware that we are subject to various laws and may be required to release personal data to comply with law enforcement and other legal requirements.
11. YOUR RIGHTS
You can withdraw your consent for processing of your personal data, including processing for marketing purposes, at any time. You can do so by clicking the appropriate link in the footer of our newsletter, or by sending us a request at: email@example.com
You may apply the following rights:
a) right to rectify data — if data is incorrect or incomplete;
b) right to erase of data — if your personal data is no longer necessary in relation to the purposes for which was collected by us; if you withdraw your consent on which the processing is based (in the scope of such consent); if you object to data processing; your data has been processed unlawfully; if your data must be erased in order to comply with a legal obligation;
c) right of processing: if data is incorrect — for a period enabling us to verify your data; if data has been processed unlawfully, but you don’t want it to be removed; if we no longer need your data, but you may need it for the exercise or defense of your legal claims; if you object to processing of your data - until it is verified whether our legitimate grounds override the grounds of objection;
d) right to transfer data: if the processing is based on consent or on a contract and the processing is carried out by automated means;
e) right to object to the processing of personal data: when such data is processed on a legitimate interest basis, and the objection is justified by your particular situation.
You can exercise these rights on your own (for example, by correcting your data in account settings) or by contacting us at firstname.lastname@example.org
In case of any concerns or questions about your privacy, please do contact us and we will do our best to assist you.
If, however, you feel we have not satisfactorily dealt with your concern, you can report it to your local data protection authority or the Czech regulator — Úřad pro ochranu osobních údajů. (The office for personal data protection)