Data protection policy

1. GENERAL PROVISIONS

Protection of our customers‘ personal data is our priority. We have drawn up this document – Personal Data Processing Principles – to inform you, our customers, how our company acquire, preserves and processes your personal data in connection with sale of our products and provision of related services. This Hannah brand website is run by Outdoor Concept a.s., however, purchasing our products as well as registering into our loyalty club take place via our partner e-shop run by Rock Point a.s.

Processing of your personal data is necessary to perform our contractual commitments properly. Furthermore, certain legal obligations arise when selling our products, including personal data processing and storing for a certain time.

By means of these Personal Data Processing Principles, we would like to provide you with information on how we collect, process and protect your personal data (see chapters 3-6 below), your rights and how to exercise them (see chapter 5 below).

Personal data is any information concerning an identified or identifiable natural person, particularly our customers and other people whose personal data we are allowed to process.

We recommend that you get acquainted with these Personal Data Processing Principles thoroughly. In case you have any questions, do not hesitate to contact us via the contact details below

 

2. ADMINISTRATOR OF PERSONAL DATA

The administrator of personal data is the company Rock Point as , with registered office at Vrážská 1507, 153 00 Prague 5 - Radotín, registered in the commercial register kept at the Municipal Court in Prague, section B, file 7747, ID: 26707233, VAT number: CZ26707233.

Together with the company Rock Point as, they are the joint administrators of the companies Outdoor Concept as and Hannah Czech as, which are part of the group. Specifically, Outdoor Concept as, Americká 54, 30100 Plzeň, ID: 29093724, VAT number: CZ2909372; Hannah Czech as, Americká 54, 30100 Plzeň, ID: 26383519, VAT number: CZ26383519. Hereinafter referred to as "Data Administrator" .

The controller has appointed a data protection manager who you can contact for any personal data protection matters. The contact details for the personal data protection manager are:

Address: Americká 54, 30100 Plzeň

 

E-mail address: osobni.udaje@rockpoint.cz

Please note that we may change these contact details in the future. You can always find the current contact information in the current version of this Privacy Policy.

3. PROCESSING OF PERSONAL DATA DURING THE SALE OF GOODS

In order to supply you with our goods and provide related services, we need to know and further process your personal data. We process personal data mainly for the purpose of concluding and fulfilling a contractual relationship (including negotiations before concluding a contract), and the legal basis for such processing is therefore the fulfillment of a contract, or our legitimate interest, especially in cases where the customer is a legal entity and we process the personal data of its contact persons .

SALE OF GOODS

We process your personal data primarily for the purpose of delivering goods and managing the customer relationship with you. We process some data that we have about you even after the contract has ended. Specifically, we process personal data for the following purposes:

· Sale of goods and related services. We process personal data when selling goods to customers and providing related services. For these purposes, we process your personal data based on the legal basis of contract performance and/or our legitimate interest. We keep your personal data for the duration of the contractual relationship, or for the duration of the warranty periods for the goods and for the period of limitation periods, if the need for longer storage does not result from other processing purposes.

· Payments . Payments on our website are made via an external payment gateway. We therefore only have access to your payment data to the extent of the first 6 and last 4 numbers of your payment card that you used to pay for the purchase. We do not process other data about your means of payment.

· Complaints . If the customer believes that the performance by the Personal Data Manager shows defects, he is entitled to complain about the goods or service in accordance with the relevant regulations of civil law and in accordance with the Complaints Regulations and Business Terms and Conditions . Handling complaints is part of the contractual performance within the framework of the relationship between you and the Personal Data Administrator, and the obligation to handle complaints also follows from legal regulations.

· Customer support . If you contact us via our contact form, by email or in another way, we will keep the information you provide until your request is processed, and for as long as necessary to defend or exercise our legal claims.

· Sending reminders . If the due invoice for the goods you selected is not paid on time, we can send you reminders until it is paid.

· Determination, performance and defense of legal claims. After the termination of the contractual relationship, based on our legitimate interest, we may also retain some of your personal data for the duration of the statute of limitations, the processing of which is necessary for the protection of our rights and the possible defense of legal claims, including the recovery of outstanding payments.

· Accounting and tax documents . Some personal data may be listed on accounting documents (in particular, invoices). According to applicable legal regulations (e.g. Accounting Act or Value Added Tax Act), we are obliged to keep these documents for up to 10 years. Therefore, if we have a legal obligation to archive these documents, we also store your personal data listed on the relevant tax document together with them.

For the above purposes, we process personal data that you provide to us as part of the contractual agreement. This is in particular the following data:

· identification data (name, surname, delivery and billing data);

· contact details (e-mail address and telephone number);

· data on the performance provided (data on delivered goods and services, payment history);

· the first 6 and last 4 numbers from your payment card;

· Bank account number

CUSTOMER ACCOUNT AND LOYALTY CLUB

If you decide to create a customer account, we also use your personal data for the purposes of managing the loyalty club , which you become a member of when you create a customer account online.

If you no longer wish to be a member of our loyalty club, please let us know. We will cancel your customer account and will no longer process your personal data for this purpose. In this case, however, you will lose the points earned in the loyalty program.

In the event that you do not log in to your customer account for more than 3 years or do not make any further purchases with us during this time, we will contact you to ask whether you wish to continue to maintain your customer account. If you tell us no, we will delete your personal data, unless there is another legal reason for keeping them, and we will no longer consider you our customer.

For the above purposes, for the needs of the management of the loyalty club, we use in particular the following personal data:

· identification data (in particular name, surname, delivery and billing data);

· contact details (e-mail address and telephone number);

· data on earned points within the loyalty program;

· Transaction history

MARKETING COMMUNICATION

Based on you consent, we can use your personal data to send you marketing offers and other business messages, particularly to send news about our goods and services and other business messages related to our goods and services. These are particularly the news and offers which might be relevant based on your previous purchases and selected preferences. We might also send other messages related to your purchase (e.g. an assembly manual) or reminders of purchases which have not been completed. We will send you news and other messages via your contact details. The lawful basis of such processing is your consent which is consensual, can be withdrawn at any time and which you grant to us when registering your customer account. For this purpose, we process the data for the duration of the consent validity or until you withdraw your consent. If you do so, we will immediately stop processing your personal data for the purposes of sending marketing messages.

We can also contact you (a current customer) without your consent to a limited extent, to offer our products or services related to a product or services you have already purchased. gdsg In this case, we only process your personal data to limited extent which is necessary to send a relevant offer. If you express your disagreement or object to such processing, it will be stopped immediately.

The lawful basis of such processing is our legitimate interest to keep our customers informed about similar products and services we offer.

  • Identification data (particularly name, surname);
  • Contact details (e-mail address, delivery address);
  • Information about goods and services we have supplied you with;
  • Information about your selected preferences

We can organize consumer’s competitions within a selling season. In case you enrol for a competition, we will process your personal data in order to enable you to attend and for the purpose of evaluation, including data which is essential for the competition (e.g. information about purchases, answers to knowledge-based questions, etc…) Processing of your data when organizing competitions is done based on your consent which you have granted by enrolling for a competition. You can withdraw your consent to participate in competitions at any time and unsubscribe from a competition and we will stop processing your data.

For these purposes, we use this personal data in particular:

  • Identification data (particularly name, surname);
  • Contact details (e-mail address, delivery address);
  • Date of birth (if it is relevant to a competition);

As part of the sales season, we can organize consumer competitions. If you sign up to participate, we will process your data for the purpose of enabling your participation in such a competition and its evaluation, including the data on which the competition is based (e.g. purchase data, answers to knowledge questions, etc.) Processing your data in the context of organizing competitions is based on the consent we obtain by registering for the competition. You can revoke your consent to participate in competitions organized by our company at any time, opt out of the competition and we will stop processing your data.

For these purposes, we use in particular the following personal data:

· identification data (especially name, surname);

· contact details (e-mail address, correspondence address)

· date of birth (if required by the nature of the competition)

TRAFFIC TO THE WEBSITE ANALYSIS

We use cookies to make using our website as easy as possible. They are small data files saved into your computer‘s hard-drive. We use cookies to get better understanding of how our website is used and to optimize it. Cookies can tell us, for example, whether you have already visited our website or whether you are a new customer.

If you don’t want to receive cookies, you can go to the settings of your browser and delete them from your computer, block them or browse in private, using an incognito window (which means all the cookies will be deleted once you close it). To get more detailed information, see the help/support section of your browser concerning cookies:​​​​​​

·        Google Chrome

·        Firefox

·        Microsoft Edge a Microsoft Internet Explorer

·        Safari

DETAILED DESCRIPTION OF COOKIE CATEGORIES

STRICTLY NECESSARY COOKIES (TYPE 1)

Basic cookies are necessary for our website to perform its basic functions. These cookies allow you to navigate the pages and use the elements you require, e.g. access to secure areas of the pages, cart contents, user login, etc. Without these cookies, we would not be able to provide the services that enable the operation of these pages.

The following cookies fall into this category:

· identification of your visit (session)

· shopping cart identification

PERFORMANCE AND ANALYTIC COOKIES (TYPE 2)

Performance-related cookies gather anonymous information about the way visitors use our website. These cookies show the interaction between visitors and our website as they provide us with data for the aggregate analysis of our business activities – information about visited areas, time spent at the website or occurrence of potential problems, e.g. error messages. This information helps usimprove our website performance. These cookies cannot gather information about user activity at other websites.

This category contains these cookies:

· Identifier for Google Analytics (more information)

  Identifier for Hotjar™ Analytics Tool (more information)

FUNCTIONAL COOKIES (TYPE 3)

These cookies enable to improve website efficiency and comfort and make different functions accessible. For example, you can set language preferences in functional cookies.

The following cookies fall into this category:

      Information about granting / denying consent to process cookies for targeted advertising

·    Information about setting a level of consent to cookies processing

 

TARGETING AND ADVERTISING COOKIES (TYPE 4)

These cookies are used for advertising which is relevant to users and their interests. They can also be used for saving and measuring efficiency of the campaign which a visitor has come across when visiting a particular website, which enables to communicate better with potential advertiser. Our company uses this type of cookies for the purpose of marketing (you can choose to allow using these cookies when visiting our website for the first time). With your consent granted, we will use the information we have gathered to analyse your behaviour at our website and to display specific advertising for some of our products. We believe this function is beneficial for you as we are going to display only the advertisements or content which correspond to your interests.

The following cookies fall into this category:

Google targeted advertising (Adwords, DoubleClick, Analytics) (more information)

Facebook targeted advertising (more information)

Seznam targeted advertising (more information)

PROFILING AND AUTOMATED PROCESSING

We do profiling and automated processing in our campaigns only for the purposes of targeted offer of our goods and services – we want to offer you only those which are relevant to you, not to bother you with useless things. We do not use profiling or automated processing for the purposes of automated decision-making which would impose any legal effects on you or concern you in any significant way

4. PERSONAL DATA SECURITY, SHARING AND TRANSFER

We have introduced and we follow necessary and adequate technical measures, inner checks and processes of data security in compliance with the best business practice corresponding with potential risk to you as the data subject. We also take in consideration the condition of technological development to protect your personal data from accidental loss, damage, changes and unauthorized release or access. We also take in consideration the condition of technological development to protect your personal data from accidental loss, damage, changes and unauthorized release or access. These measures particularly involve the measures to ensure physical security, employee training programs, regular backups, processes for data recovery and incident controls, software protection of the devices where personal data is stored, etc.

PERSONAL DATA RECIPIENTS

The personal data we process for the purposes stated above can be shared with third parties which secure some services related to providing our services, e.g. administrative support, providing software tools, etc. These are personal data processors. In particular, we can share your personal data:

    with other companies related to Rock Point a.s. in order to provide administrative support when providing services and to provide some shared services and other processing activities. We give this data particularly to Outdoor Concept a.s. which is a part of the group (see Joint controller)

with companies whose tools we use particularly in on-line services in order to be able to offer you products tailored to your needs. The companies are:

   Google

   Adform

  Facebook

with external companies arranging service and maintenance of our products. These are primarily manufacturers or suppliers of these products with whom we have customer supplier relationships.

We are obliged to make this data available to public authorities up to the necessary extent on the basis of law or other legal acts if they refer to us when exercising their powers and they ask us to provide information which can contain your personal data.

External auditors, tax advisors or lawyers can access some of your personal data on rare occasions, e.g. if it is necessary to collect or book sums owed or to protect our legitimate interests or an insurance company in case of insured events.

with external companies arranging service and maintenance of our products. These are primarily manufacturers or suppliers of these products with whom we have customer supplier relationships.

We are obliged to make this data available to public authorities up to the necessary extent on the basis of law or other legal acts if they refer to us when exercising their powers and they ask us to provide information which can contain your personal data.

External auditors, tax advisors or lawyers can access some of your personal data on rare occasions, e.g. if it is necessary to collect or book sums owed or to protect our legitimate interests or an insurance company in case of insured events.

 

PROCESSING SAFEGUARDS

We have made contracts about data processing with data processors. These contracts ensure at least the same level of your personal data security as these Personal Data Processing Principles.

5. YOUR RIGHTS AS A DATA SUBJECT

In compliance with the law, you have the right to require information about the ways your personal data is processed and the right to have the data we keep about you – data subject corrected. In certain cases, you have the right to require deleting your personal data, to access your personal data or to transfer your personal data (for example to transfer it to a different service provider). In some cases, you have the right to raise objections and the right to require restriction of your personal data processing. In case you have provided us with your consent to process your personal data, you can withdraw it at any time. Individual rights and ways how to exercise them are described below.

EXERCISING YOUR RIGHTS

If you exercise any of your rights according to this article or the effective law, each recipient who has been provided with the data according to Chapter 4 of these Personal Data Processing Principles will be informed about the measures which have been taken or erasing your personal data or processing restriction, in compliance with your requirement, in case such notification is feasible and does not require inadequate effort.

If you wish to exercise your rights and/or receive relevant information, you can do so via contact details listed in Chapter 2 of these Personal Data Processing Principles.

If you exercise your rights, we might ask you to provide some additional personal data which you have already provided before. Providing this data is necessary to confirm that the requirement has really been sent by you. We will reply within one month after receiving your request, however, in some difficult cases we reserve the right to extend this period by two more months.

RECTIFICATION OF YOUR PERSONAL DATA

According to the law, you have the right to rectify your personal data which you share with us. You can rectify your personal data yourself when you log into your customer account at https://www.hannahooutdoor.com

 

ERASING YOUR PERSONAL DATA

You can ask us to erase your personal data at any time. If you contact us with such a request, we will immediately erase all your personal data we have at our disposal in case we don’t need it to perform contractual or legal obligations anymore or to protect our legitimate interests described above.

CONSENT WITHDRAWAL

You can withdraw your consent to process your personal data at any time and without giving reasons. In that case, we will immediately erase your personal data and ensure our data processors do the same.

Please, be aware that withdrawing your consent doesn’t influence the lawfulness of any processing which had been done before you withdrew your consent.

DISCLOSURE AND PORTABILITY OF YOUR PERSONAL DATA

You have the right to require information whether we process your personal data and to what extent. You also have the right to require us to disclose your personal data and other personal details you have provided us with to you.

If you require transfer of your personal data which we process on the basis of the contract performance and/or your consent, you can ask us to transfer it directly to a third party (a different data controller) which you state in your application, supposing this request doesn’t have a negative effect on rights and freedoms of other persons and is technically feasible.

Please, be aware that withdrawing your consent doesn’t influence the lawfulness of any processing which had been done before you withdrew your consent.

 

RIGHT TO OBJECT

In case we process your personal data on the basis of our legitimate interest (e.g. when we process personal data of you as a contact person of our customer) you have the right to object to such processing at any time, concerning your particular situation. If we fail to prove legitimate grounds for processing which would override your interests or rights and freedoms or to prove this data is necessary to establishment, exercise and defence of our legal claims, we will not process the data any longer and erase it immediately. If we process your personal data for direct marketing purposes on the basis of our legitimate interest and you object to processing of your personal data for such marketing, we will immediately stop processing your personal data for this purpose.

PROCESSING RESTRICTION

If you ask us to restrict your personal data processing, e.g. when you question accuracy, lawfulness or our need to process your personal data, we restrict processing of your personal data to a strict minimum (storage). However, we might continue processing it for establishment, exercise and defence of legal claims or to protect the rights of other legal and natural persons or other limited reasons specified by valid laws. If the restriction is cancelled and we continue processing your personal data, we will inform you of this fact immediately.

COMPLAINT WITH ÚOOÚ (ÚŘAD PRO OCHRANU OSOBNÍCH ÚDAJŮ – PERSONAL DATA PROTECTION OFFICE)

 

You have the right to file a complaint concerning our processing of your personal data with Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7. Office website: www.uoou.cz.

6. PERSONAL DATA PROCESSING PRINCIPLES UPDATES

We might continuously amend or update these Personal Data Processing Principles. Any changes to these Personal Data Processing Principles come into force on the effective date and after they have been published at the following link: https://www.hannahoutdom.com/ochrana-osobnich-udaju.

We will inform you of any significant changes via e-mail before the effective date when the changes come into force.

These Personal Data Processing Principles come into force on 25th May 2022

Still don't have account?

Sign in, and claim the benefits

  • Hints and tips from us

Cookies

We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.

Your cookies settings

Here you can enable cookies according to your own preferences.You can change those settings any time in the future by clicking 'Cookie settings' link in our website's footer.

Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.

Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.

These cookies are used by advertising and social networks, including Google, to transmit personal data and personalise ads to make them interesting to you.