Identity and contact data
Name, email, phone number, delivery and billing address and, where relevant, business name, company number and VAT number.
This notice explains what personal data TIPIDI processes, why we need it, who receives it, how long it is kept and how you can exercise your rights.
The controller is TIPIDI s.r.o., Company ID 296 59 043, registered office at Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic, registered with the Regional Court in Brno, section C, file 152150. This notice applies to TIPIDI national stores, customer accounts, orders, customer support, back-in-stock alerts and marketing communications.
For privacy matters, contact us at info@tipidi.cz or +420 776 568 227.
We have not appointed a data protection officer because the current nature and scale of our processing do not require one. We will update this information if the circumstances change.
We process only data relevant to a particular service and apply data minimisation. The usual categories are:
Name, email, phone number, delivery and billing address and, where relevant, business name, company number and VAT number.
Order contents and history, prices, discounts, payment and delivery method, payment and delivery status, returns, complaints and accounting documents.
Customer-account data, securely stored authentication data, wishlist, newsletter choices, queries, messages and communications concerning returns or complaints.
IP address, device, browser, visit events, server logs, cookies, consent records and information needed to prevent fraud and protect forms and accounts.
The table sets out the main purposes, typical data and legal bases under Article 6 GDPR. More than one legal basis may apply in a particular case.
| Purpose | Typical data | Legal basis |
|---|---|---|
| Purchase, payment, delivery, account and services requested by the customer | Identity, contact, order, payment and delivery data | Performance of a contract and pre-contract steps – Article 6(1)(b) GDPR |
| Accounting, tax, statutory records and cooperation with authorities | Orders, payments, invoices, refunds and legally required information | Legal obligation – Article 6(1)(c) GDPR |
| Support, complaints, withdrawal and protection of legal claims | Communications, order data, evidence and handling history | Contract, legal obligation and legitimate interests – Article 6(1)(b), (c) and (f) GDPR |
| Security, fraud prevention, logging and service stability | IP address, technical logs, events, account and order status | Legitimate interests in security and protection of rights – Article 6(1)(f) GDPR |
| Newsletter and optional personalisation or analytics | Email, consent history, marketing preferences and online identifiers | Consent – Article 6(1)(a) GDPR; legitimate interests where a lawful customer exception applies |
When relying on legitimate interests, we assess necessity, proportionality and the impact on your rights. Further information about the relevant balancing assessment is available on request. A separate, unconditional right to object applies to direct marketing.
Fields marked as mandatory during checkout are needed to enter into and perform the contract, deliver goods, accept payment or comply with law. Without them, we may be unable to accept or fulfil the order.
Creating an account, subscribing to the newsletter, optional cookies, marketing choices and most profile information are voluntary. Refusing or withdrawing consent does not prevent an ordinary purchase.
We disclose data only to the extent necessary and according to each recipient’s role. The exact partner depends on the selected delivery, payment, country and active functions.
Carriers, pickup-point operators, warehouse and dispatch services that need information to pack, deliver, return or handle a complaint.
Mollie, banks and other selected payment services. They may act as independent controllers for their own legal obligations and fraud prevention.
Hosting, server administration, email, backups, e-shop maintenance, security and customer-service tools acting as our processors.
Accountants, tax and legal advisers, insurers and public authorities where required by law or needed to protect rights.
Google and any other providers only where the relevant service is active and supported by the required legal basis and cookie settings.
We put appropriate processing agreements in place with processors. Some recipients, in particular banks, carriers or payment institutions, may act as independent controllers for parts of their own activities. Current, more detailed information is available on request.
We prefer processing within the EU/EEA. Some cloud, security, analytics or advertising services may nevertheless involve access from or a transfer to a third country. In that event, we verify the transfer mechanism and appropriate supplementary measures.
A transfer may rely on an adequacy decision, the EU–US Data Privacy Framework for a certified recipient, Standard Contractual Clauses or another safeguard permitted by the GDPR. You may request a copy of the relevant safeguard, or information about where it is available, by email.
We do not apply one universal deletion date. Data is kept for as long as needed for the relevant purpose, statutory duties and the defence of legal claims. As a guide:
In setting a period, we consider purpose, statutory archiving, limitation periods, dispute risk, security and data minimisation. Backups are deleted through the normal rotation cycle.
Cookies and similar technologies are used according to their purpose and your choices. Optional analytics and marketing technologies are activated only after the required consent. Details, the current list and the option to change your choice are available in the Cookie Policy.
We send newsletters after subscription and email verification, or to existing customers only where national law permits. Every marketing message provides an unsubscribe option. Withdrawing consent or objecting does not affect processing needed for an order.
Electronic direct marketing is also subject to the national ePrivacy and marketing rules of the country in which the recipient is located. Where a customer exception applies, every message still provides an easy and free opt-out.
We do not carry out solely automated individual decision-making under Article 22 GDPR that produces legal or similarly significant effects. Basic product recommendations, campaign measurement or segmentation do not by themselves amount to such decision-making, and optional online profiling depends on your consent settings.
Subject to the GDPR conditions, you have the right to:
You may object to the processing of personal data for direct marketing at any time and free of charge. Once we receive the objection, we stop using your data for that purpose, including related profiling. The quickest methods are the unsubscribe link in an email or a message to info@tipidi.cz.
Send requests to info@tipidi.cz. Describe the right you wish to exercise and provide enough information for us to identify you reasonably. If we have reasonable doubts about identity, we may ask for proportionate additional verification and will not request more information than necessary.
We respond without undue delay, normally within one month. For complex requests, the GDPR allows an extension of up to two further months; we will inform you of the extension and reasons in time. Requests are generally free of charge, subject to the exceptions in the GDPR.
You may also complain to a supervisory authority in another Member State, particularly where you live, work or where the alleged infringement occurred. Cross-border matters are handled by the authorities through the GDPR cooperation mechanisms.
We use technical and organisational measures proportionate to risk, including encrypted connections, access controls, role separation, updates, backups, monitoring and incident-response procedures. No system can be described as absolutely secure.
We may update this notice when services, partners, technology or legal requirements change. The current version and update date will always be available here, and material changes will be communicated appropriately.
TIPIDI s.r.o.Company ID: 296 59 043Nové sady 988/2, Staré Brno, 602 00 Brno, Czech RepublicRegional Court in Brno, section C, file 152150info@tipidi.cz+420 776 568 227Effective from: 12. 7. 2026.