Privacy Policy
Účinné od 30 September 2026
This document sets out what personal data we process about you, for what purposes and on what legal basis, who we share it with, how long we keep it and what rights you have. Processing is governed by Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 Coll. on personal data processing.
1. Data controller
1.1 The controller of your personal data is Krabičkárna s.r.o., company ID 08805156, registered at K Brnkám 448/1, Dolní Chabry, 184 00 Prague 8, Czech Republic, premises at Karla Hlaváčka 2343/6, 180 00 Prague 8, Czech Republic.
1.2 Contact for data protection matters: info@tapizza.cz, +420 799 906 366.
1.3 We have not appointed a data protection officer — we do not meet the conditions in Article 37(1) of Regulation (EU) 2016/679 (the GDPR) that would require one.
2. What data we process
2.1 We process only data you provide yourself and data arising from your use of the website. We do not buy data from third parties or take it from public registers.
2.2 When you place an order:
- identification and contact details — name, phone number, email address;
- delivery address including details such as floor, doorbell or entry code, and the coordinates of the chosen location;
- order contents, total amount, chosen collection and payment method, and any note;
- order progress — time of receipt, status and its number in the point-of-sale system.
2b. Customer account data
2b.1 If you create an account, we additionally process:
- your email address as the login;
- a hash of your password — we do not store the password itself, only a one-way cryptographic hash (argon2) from which it cannot be derived;
- saved delivery addresses and the names you give them;
- your order history;
- sign-in data — time, IP address and browser identification (user agent).
3. Purposes and legal bases
3.1 Performance of a contract (Article 6(1)(b) GDPR) — handling your order, preparing it, handing it over or delivering it, communicating about it and running your account. Without these data the order cannot be fulfilled; providing them is a contractual requirement.
3.2 Compliance with a legal obligation (Article 6(1)(c) GDPR) — accounting and retention of tax documents under Act No. 563/1991 Coll. on accounting and Act No. 235/2004 Coll. on value added tax; handling complaints under Act No. 634/1992 Coll. on consumer protection.
3.3 Legitimate interest (Article 6(1)(f) GDPR) — securing accounts and the website, preventing misuse and fraudulent orders, and establishing, exercising or defending legal claims. We have balanced our interest in secure operation against your right to privacy and process only what is necessary.
3.4 Consent (Article 6(1)(a) GDPR) — only where you give it explicitly. Consent may be withdrawn at any time; withdrawal does not affect the lawfulness of processing before it.
4. Recipients and processors
4.1 We share only what is necessary for the purpose. Each recipient processes the data under a processing agreement pursuant to Article 28 GDPR and solely on our instructions.
4.2 The processors are:
- Dotypos s.r.o. (the Dotykačka point-of-sale system) — name, phone, email and order contents; for delivery also the address, so staff can see it on the order;
- Wolt Enterprises Oy / Wolt Česko s.r.o. (Wolt Drive delivery) — name, phone number and delivery address, so the courier knows to whom and where;
- komoot GmbH (the Photon address autocomplete) — solely the text you type into the address field. No name or other identifier is sent with it that would link the query to you;
- Microsoft Ireland Operations Limited / Microsoft Corporation, United States (the Microsoft Clarity analytics service) — only if you consent: data on how you move around the site, i.e. clicks, scrolling, device type and approximate location from your IP address. No name, email or order contents are sent. For the transfer outside the EEA see section 5;
- Plus Five Five, Inc., United States (the Resend email service) — email address and message contents: order confirmations and cancellations, sign-in and password reset codes. For the transfer outside the EEA see section 5;
- Softo s.r.o., Company ID 14087260, Na Ladech č. ev. 198, 250 66 Zdiby, Czech Republic (development and operation of the website, the admin interface and the server) — technical administration of all data stored on the server;
- INTERNET CZ, a.s., Company ID 26043319, Ktiš 2, 384 03 Ktiš, Czech Republic, trading as FORPSI (server housing and data centre in the Czech Republic) — provides the environment the server runs in; it does not access the data itself;
- Comgate, a.s., Company ID 27924505, Gočárova třída 1754/48b, 500 02 Hradec Králové, Czech Republic (payment gateway) — data needed to process payment. Card numbers are entered directly with the provider and never reach us.
- We may also disclose data to public authorities where required by law.
5. Transfers outside the European Economic Area
5.1 The website, the admin interface and the database run on a server in a data centre in the Czech Republic. The other processors listed in section 4 are established within the European Economic Area.
5.2 The one exception is email delivery: the Resend service is operated by Plus Five Five, Inc., a United States company, so your email address and the contents of the message are transferred to the United States. This takes place under the standard contractual clauses approved by the European Commission (Implementing Decision 2021/914) pursuant to Article 46(2)(c) GDPR, which form part of the processing agreement with that provider.
5.3 If you consent to analytics cookies, data on how you move around the site is shared with Microsoft, which processes it outside the EEA as well. Microsoft Corporation is on the list of participants in the EU–US Data Privacy Framework, for which the European Commission issued an adequacy decision (Implementing Decision 2023/1795) under Article 45 GDPR; standard contractual clauses apply in addition. Without your consent nothing is transferred.
5.4 Should any other processor transfer data to a third country, this will occur only under Chapter V of the GDPR — in particular on the basis of an adequacy decision or standard contractual clauses.
6. Retention periods
6.1 We keep data only for as long as necessary:
- order data and tax documents — 10 years from the end of the tax period in which the supply took place; accounting records 5 years under the Accounting Act;
- customer account — for as long as it exists; after closure we delete the data except what the previous point requires us to keep;
- sign-in sessions — at most 90 days from last use, after which the session expires;
- password reset codes — 10 minutes, then discarded;
- complaints and related correspondence — 4 years after settlement, for the period in which claims may be raised.
7. Cookies and browser storage
7.1 Strictly necessary technical means are used without consent — the site would not work without them (Section 89(3), second sentence, of Act No. 127/2005 Coll. on electronic communications). These are:
- session cookie — keeps you signed in. It is marked httpOnly, so scripts on the page cannot access it;
- a cookie recording your choice in the cookie settings — so the site does not ask again on every visit. Expires in 6 months;
- browser local storage — your cart, unfinished order and language choice. It remains solely on your device and is not sent to us.
7.2 Analytics cookies are stored only with your prior consent under Section 89(3) of Act No. 127/2005 Coll. and Article 6(1)(a) GDPR. Until you consent, the measurement script is not loaded onto the page at all. The service is Microsoft Clarity (heatmaps and session recordings), which stores the cookie _clck expiring in 1 year and _clsk expiring in 1 day, and records mouse movement, clicks and the contents of the pages displayed. What you type into form fields is not recorded.
7.3 You may withdraw consent at any time via the “Cookie settings” link in the site footer. Once withdrawn, the analytics cookies are deleted and measurement stops; the lawfulness of processing before withdrawal is unaffected.
8. Your rights
8.1 In relation to your personal data you have the right under the GDPR:
- of access and to a copy of the data processed (Article 15);
- to rectification of inaccurate data or completion of incomplete data (Article 16);
- to erasure, where the data are no longer needed and no legal obligation prevents it (Article 17);
- to restriction of processing (Article 18);
- to portability of data processed on the basis of contract or consent, in a machine-readable format (Article 20);
- to object to processing based on legitimate interest (Article 21);
- to withdraw consent where given (Article 7(3)).
8b. How to exercise your rights
8b.1 Write to info@tapizza.cz. We will respond without undue delay and no later than one month from receipt; in complex cases this may be extended by a further two months, of which we will inform you.
8b.2 To avoid disclosing data to the wrong person, we may ask for additional information to verify your identity.
9. Automated decision-making
9.1 There is no automated decision-making or profiling within the meaning of Article 22 GDPR that would produce legal effects concerning you or similarly significantly affect you.
10. Supervisory authority
10.1 If you believe our processing infringes the GDPR, we would welcome hearing from you first.
10.2 You also have the right to lodge a complaint with the supervisory authority: Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, uoou.gov.cz, posta@uoou.gov.cz.
11. Changes
11.1 We may update this information. The current version is always available on this page and carries its effective date.