Last updated: August 2024
Jóga Studio Pohoda is committed to ensuring the protection of personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council, known as the General Data Protection Regulation (GDPR). This document outlines how we comply with GDPR requirements.
Data Controller
Jóga Studio Pohoda acts as the data controller for personal data collected through our website and services. Our contact details are:
Jóga Studio Pohoda
Vinohradská 48
120 00 Prague 2
Czech Republic
Email: [email protected]
Principles of Data Processing
We adhere to the following principles when processing personal data:
- Lawfulness, fairness, and transparency: We process data lawfully, fairly, and in a transparent manner.
- Purpose limitation: We collect data for specified, explicit, and legitimate purposes.
- Data minimization: We only collect data that is adequate, relevant, and limited to what is necessary.
- Accuracy: We keep personal data accurate and up to date.
- Storage limitation: We retain data only for as long as necessary.
- Integrity and confidentiality: We process data securely to protect against unauthorized access or loss.
Legal Basis for Processing
We process personal data based on one or more of the following legal bases:
- Consent: You have given clear consent for us to process your personal data for a specific purpose.
- Contract: Processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract.
- Legal obligation: Processing is necessary for compliance with a legal obligation.
- Legitimate interests: Processing is necessary for our legitimate interests or the legitimate interests of a third party, unless overridden by your rights and interests.
Your Rights Under GDPR
Under the GDPR, you have the following rights:
- Right of access: You can request a copy of your personal data we hold.
- Right to rectification: You can request correction of inaccurate or incomplete data.
- Right to erasure: You can request deletion of your personal data in certain circumstances.
- Right to restrict processing: You can request limitation of how we use your data.
- Right to data portability: You can request transfer of your data to another organization.
- Right to object: You can object to certain types of processing, including direct marketing.
- Rights related to automated decision-making: You have rights concerning automated processing and profiling.
How to Exercise Your Rights
To exercise any of your rights under GDPR, please contact us using the details provided above. We will respond to your request within one month of receiving it. If your request is complex or we receive multiple requests, we may extend this period by two additional months, but we will inform you of any extension within the first month.
Data Transfers
If we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place to protect your data in accordance with GDPR requirements.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.
Supervisory Authority
If you believe that our processing of your personal data infringes GDPR, you have the right to lodge a complaint with a supervisory authority. In the Czech Republic, the relevant authority is:
Office for Personal Data Protection (ÚOOÚ)
Pplk. Sochora 27
170 00 Prague 7
Czech Republic
Updates to This Document
We may update this GDPR compliance document from time to time. Any changes will be posted on this page with an updated revision date.