Shufflescape logo

Personal Data Protection

1. Introduction

The Provider is responsible for complying with generally binding regulations on personal data protection, in particular, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as 'GDPR') and Act No. 18/2018 Coll. on the Protection of Personal Data and on the amendment and supplementation of certain laws.

The Provider reserves the right to change or modify the information in this Notice, in particular to align it with changes in relevant legislation or to incorporate changes in the purposes, legal bases, or means of processing personal data. Any changes related to the processing of your personal data will be secured by updating this document.

2. Provider

The Provider is Lucia Hozzová, with its registered office at Višňové 85, 013 23 Višňové, ID No.: 56293950, a company registered in the Trade Register of the District Office Žilina, register no.: 580-80549 (hereinafter also referred to as 'Provider').

3. Personal Data and Scope of Processing

Personal data is any information relating to you that can directly or indirectly identify you. This includes, in particular, your first and last name, your email address, age, and contact details of a contact person.

The Provider processes your personal data for the purposes listed below, to the extent of the data you provided when giving consent for the processing of personal data or to achieve the Provider's legitimate interests or to fulfill its legal and contractual obligations, always depending on the specific purpose of the processing.

These are the following categories of personal data:

  • identification data (e.g., name, surname, age)
  • contact details (e.g., email address, phone number)
  • photographs and video recordings (records from courses)

4. Purpose and Legal Basis for Personal Data Processing

The Provider never processes your personal data without reason. Based on a certain legal basis, data is processed only for specific purposes. These data will be retained by the Provider for the necessary period in view of the purposes for which the data are processed and after its expiry, your data will be deleted.

The specified purpose includes in particular

  • identification of customers;
  • proper fulfillment of services provided by the Provider to customers;
  • receiving and handling customer suggestions and complaints;
  • protection of rights and enforcement of rights by the Provider against customers;
  • fulfillment of tasks and obligations of the Provider arising from applicable legal regulations;
  • entering into contractual relationships with customers, including pre-contractual relationships;
  • management of contractual relationships, including making changes and their termination;
  • activities related to fulfilling archiving obligations.

If the scope of personal data specified by the above-mentioned legal regulations is insufficient to achieve the defined purpose of processing, the Provider may also process your personal data in cases

  • if you have given consent for the processing of your personal data;
  • if the processing of personal data is necessary for the performance of contractual obligations;
  • if the processing of personal data is necessary to protect the Provider's legitimate interests;
  • if the processing is necessary for proving, asserting, or defending the Provider's legal claims.

Marketing

The Provider has a legitimate interest in caring for its customers and developing business relationships, and thus informing them about its products, innovations, services, and possibly offers of various benefits. In this context, the Provider may contact you even without your prior consent. This, of course, does not apply if you have expressed disapproval of such contact or if you object to it.

5. Data Retention Period

Personal data will be retained by the Provider for these purposes for 5 years unless specific legal regulations (such as tax, labor, archiving, accounting regulations) provide otherwise, or until you revoke your consent (provided we are not required to continue archiving your data under specific regulation).

Processing of your personal data will be lawful from the moment consent is given until it is revoked, even if you revoke consent after it has been granted.

6. Recipients of Personal Data

In some cases, your personal data may be provided by the Provider to third parties to achieve proper fulfillment of the Provider's obligations. These are the following categories of persons

  • courts, state administration and self-government authorities, public law institutions, law enforcement authorities, tax offices, customs offices, and financial administration authorities, notary offices, executor offices, etc.;
  • processors who process personal data for the Provider;
  • companies for which the Provider processes personal data as a processor;

7. Cookies

Cookies are small files a site stores in your browser. The Provider uses those the site cannot work without, one that remembers your consent choice, and — only if you agree to it — analytics cookies that measure traffic.

  • sign-in and account security — kept for the length of your session;
  • the site language you picked;
  • your consent decision — kept for 12 months;
  • traffic measurement through Google Analytics — only with your consent, kept for at most 24 months.

The Provider uses no advertising cookies, builds no advertising profiles, and does not track your behaviour on other sites.

You can change your decision at any time through the “Cookie settings” link in the site footer.

8. Traffic measurement

If you agree to it, the Provider measures site traffic using Google Analytics 4 (Google Ireland Limited). Without your consent the measurement script is not loaded at all and nothing is sent to Google.

  • which pages you visited and when;
  • approximate city-level location, derived from a truncated IP address;
  • device, browser and operating system type;
  • where you arrived at the site from.

The legal basis is your consent under Art. 6(1)(a) GDPR. The data is evaluated in aggregate to improve the content and workings of the site, is not used for advertising, and is not linked to your customer account.

You can withdraw consent at any time through the “Cookie settings” link in the site footer. Withdrawal takes effect immediately — measurement stops there and then, and it does not affect the lawfulness of processing before it.

9. Third-party content

Some pages embed content from external services. It loads only after you agree — until then nothing is sent to them. Once loaded, these services see your IP address and browser details, and may store cookies of their own.

Privacy terms of the individual services:

Google, Meta and Spotify are based outside the European Union. Transfers rely on the European Commission's adequacy decisions, or on standard contractual clauses.

10. Contractual Requirement

Providing your personal data is a contractual requirement necessary for entering into a contractual relationship with you, and without providing it, the Provider would not be able to provide the services you have subscribed to by registering.

11. Your Rights Related to Personal Data Processing

Right to Withdraw Consent to Processing

If your personal data is processed based on the consent you have provided, you are entitled to withdraw this consent at any time. The withdrawal of consent will not affect the lawfulness of the processing of your personal data prior to the withdrawal of this consent.

Right to Access Data

You have the right to request information about your data processed by the Provider at any time, including information about its origin, data recipients, and the purpose of processing. Furthermore, you are entitled to request information about the expected retention period of your data.

Right to Rectify Data

You have the right to request that the Provider corrects your incorrect personal data without undue delay and/or that personal data be supplemented.

Right to Erase Data and Restrict Data Processing

You have the right to request that the Provider erases your personal data without undue delay if one of the following reasons is met: a) the data is no longer needed for the purposes for which it was collected or otherwise processed, b) the provided consent for the processing of personal data has been withdrawn and there is no other legal basis for processing, c) you exercise the right to object to the processing of personal data and there are no overriding legitimate interests for processing, d) the data was processed unlawfully, e) the data must be erased to fulfill a legal obligation, f) the data was collected in connection with the offer of information society services directly to a child. You also have the right to request restriction of processing of your data in cases where: a) you challenge the accuracy of the data, b) the processing of data would be unlawful, c) the Provider no longer needs personal data for processing purposes, but you need it to prove, assert or defend legal claims, d) you have objected to the processing of personal data.

Right to Object to Processing

You have the right to object at any time to the processing of your personal data on grounds relating to your particular situation against the processing of your personal data carried out in the public interest or on the basis of the Provider's legitimate interest. At the same time, you have the right to object to profiling based on Article 6(1)(e) or (f) of the GDPR. You have the right to object to the processing of personal data for direct marketing purposes, including profiling to the extent that it is related to such direct marketing.

Right to Data Portability

You have the right to obtain your personal data from the Provider, which you have provided, in a structured, commonly used, and machine-readable format. You have the right to transfer such obtained personal data to another controller without the Provider obstructing you. Such data portability is possible if your personal data was processed based on provided consent or based on a contract and if the processing was carried out by automated means. If technically feasible, you have the right to direct transfer from one controller (Provider) to another controller.

Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with the supervisory authority responsible for overseeing the processing of personal data. In the territory of the Slovak Republic, this authority is the Office for Personal Data Protection of the Slovak Republic with its registered office at Hraničná 4826/12, 820 07 Bratislava.

Right to Notification of Personal Data Breach

You have the right to be notified by the Provider without undue delay about a personal data breach that is likely to result in a high risk to your rights and freedoms.

Exercising Your Rights

If you exercise any of the above rights, the Provider will inform you about the measures taken based on your request within one month from the date of receipt of your request. This period may be extended by another two months, taking into account the complexity and number of requests. In the event of an extension of the period, the Provider will inform you of such extension within one month from the date of receipt of your request, including the reasons for the delay. The requested information will be provided to you in writing or by other means, including electronic means. If you request information by telephone, the information will be provided to you after proving your identity in accordance with the GDPR regulation. The Provider will provide information and take action free of charge. If your requests are manifestly unfounded or excessive, in particular because of their repetitive nature, the Provider is entitled to: (i) charge a reasonable fee, taking into account the administrative costs of providing information or communication or taking action; or (ii) refuse to act on the request.

lucy@shufflescape.com

12. Data Sources

The Provider obtains personal data primarily from the data subjects (directly or through intermediaries who process personal data on behalf of and based on the Provider's instructions for the purposes determined by the Provider). The Provider may also obtain your personal data from other sources, such as publicly accessible sources and registers, especially in connection with the conclusion or fulfillment of a contract or in connection with exercising its rights, entitlements, or obligations arising from applicable legal regulations, court decisions, or contractual relationships.