Privacy Policy
About Us
The controller of your personal data is IMPNET s.r.o., ID No.: 12345678, with its registered office at Na Příkopě 1, 110 00 Prague 1, registered with the Municipal Court in Prague.
Email: privacy@impnet.cz, tel.: +420 123 456 789
Data Protection Officer (DPO): dpo@impnet.cz
What data we process
- Identification data (first name, last name, company name, ID number).
- Contact information (email, phone, address).
- Contract and performance data (orders, invoicing, communication).
- Technical and operational data (IP, device identifiers, logs, basic diagnostics).
- Marketing preferences and interaction history (if you give us your consent).
- Cookies and similar identifiers – see the Cookies section.
Purposes and Legal Bases
1) Performance of a contract and pre-contractual measures
Processing is necessary to provide our services, deliver orders, and provide customer support.
2) Legal obligation
Accounting and tax records in accordance with applicable regulations (retention of invoices, bookkeeping).
3) Legitimate interest
- Service and network security, prevention of misuse.
- Internal analytics and reporting in aggregated form.
- Direct marketing to existing customers (newsletter about similar products). You have the right to object at any time.
4) Consent
Communication regarding special offers, personalization, and optional analytical cookies. You may withdraw your consent at any time.
Retention period
- Contractual and operational data: for the duration of the contract and 3 years after its termination.
- Accounting documents: 10 years from the end of the fiscal year.
- Consent-based marketing: until consent is withdrawn or for a maximum of 3 years from the last interaction.
- Security logs: 6–24 months depending on severity.
Sharing and Processors
We share data only when necessary. Typically with these categories of recipients:
- IT and cloud infrastructure (hosting, email, monitoring).
- Payment gateways and banks (payment processing).
- Accountants and tax advisors, legal representatives.
- Delivery services and logistics.
- Marketing and analytics tools (based on consent).
Your rights
Under the GDPR, you have the following rights in particular:
- Right of access to data and a copy of data.
- Right to rectification of inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”) in cases provided for by law.
- Right to restriction of processing.
- Right to data portability.
- Right to object to processing based on legitimate interest or direct marketing.
- Right to withdraw consent at any time if processing is based on consent.
Please send requests to privacy@impnet.cz. We will respond without undue delay, typically within 30 days.
How we protect data
- Transmission encryption (HTTPS/TLS), access restrictions, and multi-factor authentication.
- Network segmentation, regular backups, and access logging.
- Internal policies and training, principle of least privilege.
- Risk assessments and security testing.
Transfers outside the EU/EEA
If it is necessary to transfer personal data to countries outside the EU/EEA, this is done on the basis of appropriate safeguards, in particular Standard Contractual Clauses (SCCs) or an adequacy decision. We will provide details upon request.
Contact and Complaints
If you have any questions or requests, please write to privacy@impnet.cz. You also have the right to file a complaint with the supervisory authority: Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7.