PRIVACY POLICY AND USE OF COOKIES

1. Personal Data Controller

The personal data controller is:

Vlčí patroni z. s.
Registered office: Dobrovského 874/29, Přívoz, 702 00 Ostrava, Czech Republic
Identification No.: 19334532
registered in the Associations Register maintained by the Regional Court in Ostrava, Section L, File No. 20819
E-mail: erenhill.vlcipatron@gmail.com
Phone: +420 605 781 046

Hereinafter referred to as the "Controller" or the "Association".

The Controller operates the website and online store at www.vlci-patroni.cz, operates Erenhill Archery School, organises archery training sessions, courses, competitions and events, and maintains records of members of the Association.

The Controller has not appointed a Data Protection Officer because, based on the current scope and nature of the processing activities, there is no legal obligation to do so.

This Privacy Policy explains what personal data the Controller processes, why it is processed, to whom it may be disclosed, how long it is retained and what rights individuals have in relation to the processing of their personal data.

2. Applicable legislation

The Controller processes personal data primarily in accordance with:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council, the General Data Protection Regulation (GDPR),
  • Act No. 110/2019 Coll., on the Processing of Personal Data,
  • Act No. 127/2005 Coll., on Electronic Communications,
  • Act No. 480/2004 Coll., on Certain Information Society Services,
  • the Czech Civil Code,
  • the Accounting Act and other related legislation.

Personal data means any information relating to an identified or identifiable natural person.

Information relating solely to legal entities is not personal data; however, information concerning their representatives, employees or contact persons may constitute personal data.

3. Sources of personal data

The Controller obtains personal data primarily:

  • directly from customers when an order is placed,
  • during registration or use of a user account,
  • through e-mail, telephone or personal communication,
  • through contact, registration and application forms,
  • from applicants for membership and members of the Association,
  • from participants in training sessions, courses, camps, competitions and other events,
  • from legal representatives of minor participants,
  • when payments are made by bank transfer or in cash,
  • during the handling of complaints, withdrawals from contracts and other claims,
  • through cookies, server logs and analytical tools,
  • from photographs, video recordings and competition results created during the activities of the Association,
  • where applicable, from co-organisers of events or partner organisations if the transfer of data is necessary and the participant has been informed.

4. Categories of personal data processed

Depending on the specific situation, the Controller may process the following categories of personal data.

4.1. Identification data

  • first name and surname,
  • date of birth or age, where required for membership, age category placement or safe participation,
  • username or membership number,
  • business identification number, business name and contact person details where the customer is a business.

4.2. Contact details

  • delivery and billing address,
  • e-mail address,
  • telephone number,
  • contact details of a legal representative,
  • emergency contact provided for participation in an event, camp or training session.

4.3. Order and contractual data

  • order contents and order number,
  • purchased goods or services,
  • individual requirements and product configuration,
  • data necessary for the manufacture or modification of archery equipment,
  • delivery method and location,
  • date of order, delivery and receipt,
  • communications relating to the order,
  • information concerning complaints, returned goods, withdrawal from contracts and other claims.

4.4. Payment and accounting data

  • amount paid,
  • payment date,
  • payer's bank account number,
  • variable payment symbol and payment reference,
  • information contained in accounting and cash documents,
  • information about payment of membership fees,
  • signature confirming cash payment of a membership fee.

The Controller does not have access to customers' online banking login details.

4.5. Membership data

  • information provided in the membership application,
  • date of commencement, change or termination of membership,
  • type of membership,
  • records of membership fees,
  • attendance at general meetings and voting, where recorded,
  • club functions, qualifications, certifications or authorisations granted,
  • communication relating to the activities of the Association.

4.6. Training, competition and event data

  • registration and participation in an event,
  • age or competition category,
  • club affiliation,
  • achieved results, rankings, points, records and awards,
  • reserved dates for training sessions or courses,
  • information necessary for the organisation, safety and evaluation of an event.

4.7. Photographs, video recordings and audio recordings

Photographs and video recordings documenting the activities of the Association, sporting results, events or the promotion of archery may be taken during training sessions, competitions, public performances and other events.

More detailed information on the creation and use of recordings may be provided in the rules of a specific event, application form or separate consent form.

4.8. Technical data

  • IP address,
  • device type, operating system and internet browser,
  • language settings,
  • information about visits to the website,
  • pages visited, time of visit and traffic source,
  • cookie identifiers and similar technologies,
  • information necessary for the security and proper functioning of the website.

4.9. Health data

For certain camps, sporting events or other activities, the Controller may exceptionally need information concerning a health restriction, allergy or another circumstance relevant to the protection of the participant's health and safety.

Such data is processed only to the extent necessary and on the basis of explicit consent or another legal basis provided by applicable legislation.

Access is limited to persons who need the information to ensure the participant's safety.

5. Purposes and legal bases for processing

5.1. Processing orders and performance of contracts

Personal data is processed for the purposes of:

  • receiving and confirming orders,
  • communicating with customers,
  • preparing or manufacturing goods,
  • receiving and matching payments,
  • packaging and delivering goods,
  • providing ordered services,
  • handling withdrawals, complaints or claims.

The legal basis is performance of a contract or taking steps prior to entering into a contract pursuant to Article 6(1)(b) GDPR.

Consent to personal data processing is not required for processing an order.

However, without the necessary personal data, the order cannot be processed and the contract cannot be performed.

5.2. Accounting and compliance with legal obligations

Information contained in accounting, payment, cash and other legally required documents is processed for accounting purposes, compliance with tax obligations and, where necessary, cooperation with public authorities.

The legal basis is compliance with a legal obligation pursuant to Article 6(1)(c) GDPR.

5.3. Membership in the Association

Personal data of membership applicants and members is processed for the purposes of:

  • reviewing membership applications,
  • maintaining the membership register,
  • administering and organising membership,
  • recording membership fees,
  • communicating with members,
  • ensuring membership rights and obligations,
  • organising general meetings and the activities of the Association.

The legal basis is performance of the contractual or membership relationship, compliance with the Association's legal obligations and the legitimate interest of the Controller in the proper administration and organisation of the Association.

Where the member is a minor, data relating to their legal representative may also be processed.

5.4. Training sessions, courses, competitions, camps and other events

Participants' data is processed for the purposes of:

  • registration and reservation of places,
  • placement in the appropriate category,
  • organisation and safe operation of the event,
  • communication with participants,
  • processing results and awarding prizes,
  • handling possible insurance or liability incidents.

The legal basis may be performance of a contract, the Controller's legitimate interest in properly organising the event, compliance with legal obligations and, in certain cases, the consent of the participant or their legal representative.

5.5. Results lists, awards and sporting history

A participant's name, club affiliation, competition category, result, ranking, award or record may be published in results lists, on websites, social media or in the competition archive.

The legal basis is fulfilment of the conditions of participation in the competition and the Controller's legitimate interest in transparent evaluation, publication of results and maintenance of sporting history.

Where specific circumstances require the participant's or legal representative's consent, the Controller will obtain such consent before publication.

5.6. Photographs and video recordings

Documentary and report-style photographs and recordings from public or Association events may be processed on the basis of the Controller's legitimate interest in documenting its activities, informing the public and promoting archery.

Close-up portraits, individual promotional materials or other uses exceeding ordinary event documentation are published on the basis of consent where such consent is required by the nature of the use.

The Controller exercises increased caution in relation to minors and, where necessary, obtains the consent of their legal representative.

A person who does not wish to be photographed, recorded or published in documentary materials may contact the Controller in advance or without undue delay.

The Controller will assess the request taking into account the circumstances, the rights of other persons and the technical possibility of removing the recording.

5.7. Protection of rights and security

The Controller may also retain and use personal data for the purposes of:

  • protecting its property and rights,
  • securing websites and user accounts,
  • preventing fraud and misuse,
  • demonstrating the conclusion and performance of contracts,
  • resolving legal claims, disputes or insurance incidents.

The legal basis is the Controller's legitimate interest pursuant to Article 6(1)(f) GDPR.

5.8. Commercial communications

The Controller may send commercial communications:

  • on the basis of the recipient's consent, or
  • to existing customers in connection with offers of the Controller's own similar goods or services where permitted by applicable law.

The recipient may unsubscribe from commercial communications at any time by using the unsubscribe link in the e-mail or by contacting:

erenhill.vlcipatron@gmail.com

Unsubscribing from commercial communications does not affect messages necessary for processing an order, membership, reservation or participation in an event.

5.9. Analytics and website improvement

Where a visitor gives consent to analytical cookies, the Controller may evaluate website traffic, use of individual parts of the website, traffic sources and the technical functioning of the website.

The legal basis is the visitor's consent pursuant to Article 6(1)(a) GDPR and Section 89(3) of Act No. 127/2005 Coll.

6. Data retention periods

The Controller retains personal data only for as long as necessary for the purpose for which it is processed.

Typical retention periods include:

  • order and contractual data for the duration of the contract and generally for a further three years for the protection of legal claims,
  • accounting and cash documents for the period required by accounting and tax legislation, generally at least five years,
  • complaint and claim data for the duration of the complaint procedure and generally for a further three years,
  • user account data for the duration of the account and subsequently for the period necessary to protect the Controller's rights,
  • membership data for the duration of membership and generally for a further three years; information contained in accounting documents may be retained for longer,
  • registration and organisational data relating to training sessions, courses and events for the duration of the event and generally for a further three years,
  • results lists, historical results, awards and records of sporting activities may be retained long-term as part of the sporting and Association archive,
  • health information only for the period necessary for the safe organisation of the relevant event and resolution of any related incident,
  • data processed on the basis of consent until consent is withdrawn or until the purpose for which consent was given ends,
  • evidence of granting or withdrawing consent for the period necessary to demonstrate the lawfulness of processing,
  • technical data and cookies for the period specified in the cookie settings or by the relevant service.

If judicial, administrative, complaint, insurance or other proceedings are underway, necessary data may be retained until the proceedings have been finally concluded and all related claims have been resolved.

After the applicable retention period expires, the Controller shall delete or anonymise the data or retain only the information that it is legally required to continue storing.

7. Recipients of personal data

Personal data may, to the extent necessary, be made available to:

  • Webnode AG, which provides the website and online store system,
  • the selected carrier, particularly Česká pošta, s. p., or another carrier selected or agreed upon for the order,
  • banking and payment service providers,
  • e-mail, cloud, hosting and IT service providers,
  • the Controller's accountant, tax adviser or another professional adviser,
  • Google Ireland Limited in connection with the use of Google Analytics, Google Tag Manager, YouTube or other activated Google services,
  • co-organisers of competitions, courses, camps or other events where transfer of the data is necessary for organisation,
  • an external manufacturer or business partner where the customer orders a product or service provided by that partner and has been informed of this in advance,
  • an insurance company or persons handling an insurance incident,
  • public authorities where disclosure is required by law.

Only personal data necessary for the specific purpose is disclosed to recipients.

An external manufacturer, organiser or other partner may in certain circumstances act as an independent personal data controller.

The individual will be informed of such disclosure in the product description, application form, event rules or through communication with the Controller.

The Controller does not sell personal data.

The Czech version expressly includes Webnode, carriers, Google services, co-organisers and external manufacturing partners among possible recipients.

8. International transfers of personal data

Some technical service providers are based or use servers outside the Czech Republic.

Webnode AG is based in Switzerland. The European Commission recognises Switzerland as providing an adequate level of protection for personal data.

When using Google, YouTube or other international service providers, personal data may in certain circumstances be processed outside the European Economic Area, particularly in the United States of America.

Any such transfer shall take place only in compliance with the GDPR, particularly on the basis of:

  • an adequacy decision,
  • the EU–US Data Privacy Framework,
  • Standard Contractual Clauses adopted by the European Commission,
  • or another legally recognised mechanism.

9. Cookies and similar technologies

The website uses cookies and similar technologies, such as local browser storage.

Cookies are small files stored on a visitor's device.

They may be used, for example, to ensure the proper functioning of the shopping cart, remember settings or analyse website traffic.

9.1. Necessary cookies

Necessary cookies support:

  • secure operation of the website,
  • operation of the shopping cart,
  • processing of orders,
  • remembering privacy settings,
  • technical security and correct display of the website.

These cookies may be used without consent because they are necessary for operation of the website or provision of a service requested by the visitor.

9.2. Functional cookies

Functional cookies may remember user preferences, language, currency or other settings that improve use of the website.

Where such functional cookies are not necessary for a service requested by the visitor, they are used only on the basis of consent.

9.3. Analytical cookies

Analytical cookies help the Controller understand how visitors use the website, which pages they visit and whether technical issues occur.

Google Analytics or another analytical tool may be used for this purpose.

Analytical cookies are activated only with the visitor's consent.

9.4. Marketing cookies

Marketing cookies may be used to measure the effectiveness of promotion, display more relevant content or evaluate advertising campaigns.

These cookies are used only with the visitor's prior consent.

9.5. Embedded content and third-party services

The website may contain YouTube videos, maps, social media elements or other third-party content.

When such content is loaded, the provider may receive technical information about the visitor and may use its own cookies.

Where embedded content uses non-essential cookies, it should be loaded only after the relevant consent has been given.

A simple link to Facebook, Instagram, YouTube or another external website does not itself constitute disclosure of personal data by the Controller.

After the visitor clicks the link, processing is governed by the privacy rules of the external service provider.

9.6. Cookie settings and withdrawal of consent

On their first visit to the website, visitors may:

  • accept all optional cookies,
  • reject all optional cookies,
  • or configure individual cookie categories.

Consent to cookies may be changed or withdrawn at any time through the cookie settings available on the website.

Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.

Cookies may also be deleted through the settings of the visitor's internet browser.

Blocking necessary cookies may, however, limit the proper operation of the website, shopping cart or ordering process.

The current list of specific cookies, their providers, purposes and storage periods is available in the website's cookie banner settings.

The new Czech text distinguishes necessary, functional, analytical and marketing cookies and separately addresses embedded YouTube, maps and social media content.

10. Commercial communications and club communications

Messages necessary for processing orders, membership, registration for training sessions, reservations or participation in competitions are not commercial communications and may be sent without marketing consent.

Commercial and promotional communications are sent only:

  • on the basis of consent, or
  • to customers under conditions permitted by applicable legislation.

Recipients may unsubscribe from commercial communications at any time.

Unsubscribing does not affect organisational messages concerning active membership, an order or an event for which the person is registered.

11. Processing of children's personal data

The Controller processes personal data of minors primarily in connection with:

  • membership,
  • training sessions,
  • courses,
  • camps,
  • competitions,
  • and other sporting activities.

The data is processed only to the extent necessary for organisation, safety, communication, attendance records and compliance with legal obligations.

Where required by the child's age, the nature of the service or applicable legislation, the Controller communicates with the legal representative and obtains their consent.

Contact details of the legal representative may be used for organisational communication and in emergency situations.

12. Personal data security

The Controller implements appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, loss, destruction or misuse.

These measures include in particular:

  • restricting access to authorised persons only,
  • use of passwords and secure user accounts,
  • keeping devices and software up to date,
  • protection of e-mail, cloud and accounting systems,
  • backup of important data,
  • secure storage of paper documents,
  • instruction and training of persons who work with personal data,
  • disclosure of only the necessary amount of personal data to contractual partners.

No method of electronic storage or transmission can guarantee absolute security.

The Controller nevertheless continuously implements measures appropriate to the nature of the data and existing risks.

13. Rights of data subjects

Under the conditions laid down by the GDPR, a person whose personal data is processed by the Controller has the following rights.

13.1. Right of access

The right to request confirmation as to whether the Controller processes their personal data and to obtain access to that data and related information.

13.2. Right to rectification

The right to request correction of inaccurate personal data or completion of incomplete data.

13.3. Right to erasure

The right to request deletion of personal data where the data is no longer necessary, consent has been withdrawn or there is no other legal basis for processing.

The right to erasure is not absolute.

The Controller cannot delete data that it is legally required to retain or needs for the establishment, exercise or defence of legal claims.

13.4. Right to restriction of processing

The right to request temporary restriction of processing in the circumstances specified by the GDPR.

13.5. Right to data portability

The right to receive data provided to the Controller in a structured, commonly used format or request its transfer to another controller where processing is based on consent or a contract and is carried out by automated means.

13.6. Right to object

The right to object to processing based on the Controller's legitimate interests.

Where the objection concerns direct marketing, the Controller shall stop such processing.

13.7. Right to withdraw consent

Where processing is based on consent, consent may be withdrawn at any time.

Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

13.8. Right to lodge a complaint

If an individual believes that their personal data is not being processed lawfully, they may lodge a complaint with:

Office for Personal Data Protection
Pplk. Sochora 727/27
170 00 Prague 7
Czech Republic
E-mail: posta@uoou.gov.cz
Website: https://uoou.gov.cz/

13.9. Exercising your rights

Requests may be submitted:

  • by e-mail to erenhill.vlcipatron@gmail.com,
  • in writing to Vlčí patroni z. s., Dobrovského 874/29, Přívoz, 702 00 Ostrava, Czech Republic.

The Controller may request reasonable verification of the applicant's identity to ensure that personal data is not disclosed to an unauthorised person.

The Controller shall respond without undue delay and no later than one month after receiving the request.

In complex cases, this period may be extended by a further two months subject to the conditions laid down by the GDPR.

These rights and the current contact details of the Czech supervisory authority are set out in the new Czech version.

14. Automated decision-making

The Controller does not carry out automated individual decision-making or profiling that would have legal or similarly significant effects on the individual concerned.

Ordinary statistical analysis of website traffic does not constitute such automated decision-making.

15. Final provisions

This Privacy Policy is an information document.

Reading or acknowledging this Privacy Policy does not constitute consent to the processing of personal data.

The Controller does not require consent for processing that is necessary for:

  • performance of a contract,
  • membership,
  • or compliance with legal obligations.

Where consent is required for a specific processing activity, such as certain promotional photographs, marketing communications or optional cookies, consent will be requested separately and the individual will have the option to refuse or subsequently withdraw it.

The Controller may update this Privacy Policy, particularly where legislation, services used or the scope of its activities change.

The current version will always be published on the website.

This Privacy Policy is effective from 12 August 2026.