Personal data protection (GDPR) for MEWATR CR s.r.o.
Data controller:
MEWATR CR s.r.o.
Company ID (IČO): 214 10 402
Tax ID (DIČ): CZ21410402
Registered Office: Korunní 2569/108, Vinohrady, 101 00 Prague
Phone: +421 915 650 379
E-mail: info@mewatr.cz
Purpose of personal data processing
At MEWATR CR s.r.o., we collect and process personal data only to the extent necessary to achieve specific purposes. We process personal data for the following reasons:
- Provision of services and fulfillment of contractual obligations – We process your personal data to execute our business relationships, fulfill contracts, communicate, and process orders.
- Responding to inquiries and requests – If you contact us via e-mail or a contact form, we process your data to answer your questions or address your request.
- Compliance with legal obligations – When necessary, we store your data for accounting purposes, tax records, and the fulfillment of other legal duties.
- Marketing purposes – If you grant us consent, we may use your data for marketing purposes, including sending newsletters, business offers, and updates regarding our products and services.
- Ensuring security – Personal data may be processed to ensure the security of our systems and platforms and to prevent fraud.
What personal data we collect
We only collect data that is essential for providing our services. This includes:
- Identification data – First and last name, company name.
- Contact information – E-mail address, phone number, delivery and billing address.
- Transaction and payment data – Information required for invoicing and the fulfillment of contractual obligations.
- Communication data – All communication between us and you, whether by e-mail, phone, or other forms of communication.
- IP addresses and related technical data – When you visit our website, we collect certain technical data, such as IP address, device type, browser type, etc., for traffic analysis and security purposes.
Legal basis for processing personal data
All processing of personal data is carried out based on the legal grounds set out in the GDPR. These legal bases include:
- Performance of a contract – We process data necessary to fulfill our contractual obligations.
- Legitimate interest – We process data for the purposes of the company’s legitimate interests as stated above (e.g., marketing communication, ensuring security).
- Consent – Where necessary, we obtain your consent to process your personal data for specific purposes (e.g., marketing).
- Compliance with legal obligations – Data processing may be necessary to comply with legal obligations, such as in the fields of accounting and taxation.
Data retention period
We retain your personal data for the period necessary to fulfill the purposes for which it was collected. Once we no longer have a reason to keep the data (e.g., after the fulfillment of contractual obligations, processing an inquiry, or the expiration of consent), the data will be securely deleted or anonymized. Certain data (e.g., accounting documents) must be kept for the period specified by law.
Who has access to your data
Your personal data is not routinely shared with third parties. In some cases, it may be necessary to provide it to our processors who assist us with administrative, legal, or technical tasks. These processors only have access to the necessary data and are committed to protecting it and using it solely for our purposes. Examples of these processors may include accounting firms, lawyers, IT specialists, or cloud service providers.
Transfer of data to third countries
Currently, we do not transfer personal data to third countries outside the European Union unless it is necessary for the provision of services (e.g., cloud storage providers or external platforms). In such cases, we ensure that the data transfer complies with applicable laws and protects your personal data.
Data subject rights
Under the GDPR, you have the following rights:
- Right of access – You can request confirmation of whether we are processing your personal data and, if so, request a copy of it.
- Right to rectification – If your personal data is inaccurate or incomplete, you have the right to have it corrected.
- Right to erasure – You can request the deletion of your personal data if it is no longer needed for the purposes for which it was collected or if you have withdrawn your consent.
- Right to restriction of processing – You can request that the processing of your data be restricted in certain cases (e.g., if you contest its accuracy).
- Right to data portability – You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transfer it to another controller.
- Right to object – You can object to the processing of your data based on our legitimate interests or for direct marketing purposes.
- Right to lodge a complaint – If you believe your data protection rights have been violated, you have the right to lodge a complaint with the supervisory authority, which in the Czech Republic is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů).
Security measures
At MEWATR CR s.r.o., we have implemented appropriate technical and organizational measures to ensure the protection of personal data against unauthorized access, loss, or damage. We regularly update these measures and adapt them to the risks that may arise during the processing of your data.
Contact information:
If you have any questions regarding personal data protection or wish to exercise your rights listed above, you can contact us at info@mewatr.cz or by phone at +421 915 650 379.