Skip to content
Legal

Privacy Policy

This is an informative translation. The Czech version of the policy is legally binding.

Ondřej Hanuš

with registered office at Bubenečská 37, 160 00 Prague 6, Czech Republic

identification number (IČO): 17532965

e-mail: info@dotta.store · telephone: +420 733 339 895

controller of personal data in the operation of the online store at dotta.store and the DOTTA Counter mobile application

1. Introductory provisions

  1. 1.1

    With this document, Ondřej Hanuš, with registered office at Bubenečská 37, 160 00 Prague 6, identification number: 17532965 (the “Controller”), fulfils his information obligation towards customers and visitors of the dotta.store website and users of the DOTTA Counter mobile application within the meaning of Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the “GDPR”).

  2. 1.2

    The Controller has not appointed a data protection officer and is not obliged to do so. In matters of personal data protection, you can contact the Controller at any time at info@dotta.store or by telephone at +420 733 339 895.

  3. 1.3

    This policy is drawn up in the Czech language; the English version made available on the website is an informative translation only, and the Czech version prevails.

2. What personal data we process

  1. 2.1

    When you place an order: your name and surname, delivery address or chosen pickup point, e-mail address, telephone number (for the carrier), and details of the ordered goods and the payment. The Controller never processes and has no access to payment card data — it is processed exclusively by the payment gateway operator Stripe; the Controller only receives information about the result of the payment.

  2. 2.2

    When you withdraw from the contract or make a complaint: the data filled in the relevant form (name and surname, e-mail, order number, address, or a bank account number for refunding the payment).

  3. 2.3

    When you subscribe to the newsletter: your e-mail address and a record of the consent given.

  4. 2.4

    When you use the contact form: your name, e-mail address and the content of the message.

  5. 2.5

    When you visit the website: technical data only to the extent described in the cookie policy (analytics and marketing tools are loaded exclusively with your consent). Forms are protected by Cloudflare Turnstile, which technically verifies that you are not a robot.

3. Purposes, legal bases and retention periods

  1. 3.1

    Processing your order and performing the purchase contract, including delivery of the goods, communication about the order and handling withdrawals or complaints — the legal basis is performance of a contract (Article 6(1)(b) GDPR). We keep the data for the duration of order processing and of the rights and obligations arising from the contract.

  2. 3.2

    Fulfilling the Controller’s legal obligations, in particular issuing and keeping tax and accounting documents and complying with consumer-protection obligations — the legal basis is compliance with a legal obligation (Article 6(1)(c) GDPR). We keep the documents for the period required by law, generally 5 to 10 years.

  3. 3.3

    Protecting the Controller’s legal claims and handling any disputes — the legal basis is the Controller’s legitimate interest (Article 6(1)(f) GDPR). We keep data about concluded contracts for the duration of the limitation periods.

  4. 3.4

    Sending news (newsletter) to persons who have subscribed — the legal basis is consent (Article 6(1)(a) GDPR), until it is withdrawn. The Controller may send customers commercial communications concerning similar goods on the basis of legitimate interest in accordance with Section 7(3) of Act No. 480/2004 Coll.; you can easily opt out at any time in every message.

  5. 3.5

    Answering an enquiry from the contact form — the legal basis is the Controller’s legitimate interest in communicating with the enquirer (Article 6(1)(f) GDPR). We keep messages for no longer than one year after the enquiry is resolved.

  6. 3.6

    Analytics and marketing on the website take place exclusively on the basis of consent given in the cookie banner (Article 6(1)(a) GDPR) — for details and withdrawal of consent, see the cookie policy.

  7. 3.7

    After the above periods expire, we erase or anonymise the personal data.

4. Recipients and processors of personal data

  1. 4.1

    We pass personal data on, only to the extent necessary, to the following recipients and processors:

    • Stripe (Stripe Payments Europe, Ltd.) — payment processing; payment card data is processed exclusively by Stripe,
    • Zásilkovna s.r.o. (Packeta) — delivery of the shipment (name, address or pickup point, e-mail, telephone),
    • Fakturoid s.r.o. — issuing and keeping invoices,
    • Resend — sending transactional and requested e-mails,
    • Render (website hosting, Frankfurt region) and Neon (database) — technical operation of the e-shop,
    • Upstash — short-lived technical records securing the checkout,
    • Cloudflare — protection of forms against robots (Turnstile),
    • Google (Google Analytics 4, Google Ads) — only if you give consent under the cookie policy.
  2. 4.2

    We may also disclose personal data to public authorities where required by law.

5. Transfers of personal data to third countries

  1. 5.1

    We store data primarily on servers in the European Union (hosting and database in the Frankfurt region). Some of the providers listed above (in particular Stripe, Google, Cloudflare and Resend) may also process personal data in the United States; such transfers take place on the basis of the European Commission’s adequacy decision (the EU–U.S. Data Privacy Framework) or standard contractual clauses under Article 46 GDPR.

6. The DOTTA Counter mobile application

  1. 6.1

    The DOTTA Counter application does not require any account and does not send any personal data to the Controller. Scores, matches, statistics and player names you enter into the application are stored on your device.

  2. 6.2

    If you enable iCloud sync, this data is stored in your private part of iCloud operated by Apple; the Controller has no access to it. The processing is governed by Apple’s terms.

  3. 6.3

    The optional workout recording on Apple Watch writes activity data into the Health app (HealthKit) on your device. The Controller has no access to data in the Health app and does not process it in any way.

  4. 6.4

    Technical diagnostic records about the connection to the DOTTA device are stored only on your phone. They reach the Controller only if you voluntarily send them yourself using the diagnostics sharing feature; they are used exclusively to resolve your technical issue and are deleted afterwards.

  5. 6.5

    The application contains no advertising and no third-party analytics or tracking tools.

7. Your rights

  1. 7.1

    In connection with the processing of personal data, you have in particular the following rights:

    • the right of access to personal data (Article 15 GDPR),
    • the right to rectification of inaccurate data or completion of incomplete data (Article 16 GDPR),
    • the right to erasure (Article 17 GDPR),
    • the right to restriction of processing (Article 18 GDPR),
    • the right to data portability (Article 20 GDPR),
    • the right to object to processing based on legitimate interest, including an objection to direct marketing (Article 21 GDPR), and
    • the right to withdraw consent at any time, without affecting the lawfulness of processing before its withdrawal.
  2. 7.2

    You can exercise your rights by e-mail at info@dotta.store. The Controller will inform you about the handling of your request without undue delay, at the latest within one month of receiving it.

  3. 7.3

    You also have the right to lodge a complaint with the supervisory authority, which is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, https://uoou.gov.cz.

8. Automated decision-making and profiling

  1. 8.1

    The Controller does not carry out automated individual decision-making or profiling within the meaning of Article 22 GDPR. Prices of goods are not personalised to the buyer on the basis of automated decision-making.

9. Final provisions

  1. 9.1

    The use of cookies and similar technologies on the website is governed by the separate cookie policy available on the website.

  2. 9.2

    The Controller may update the wording of this policy, in particular when the services used or legal regulations change. The current version is always available on the website.

Prague, 1 August 2026