Legal

Privacy Policy

How we handle your personal data under GDPR and Czech law.

Last updated: 30 April 2026

[INSERT LEGAL ENTITY NAME] ("we", "us") respects your privacy. This policy explains what personal data we collect, why we collect it, who we share it with, and what rights you have under Regulation (EU) 2016/679 (GDPR) and Act No. 110/2019 Coll. (Czech Personal Data Processing Act).

1. Data controller

[INSERT LEGAL ENTITY NAME], IČO [INSERT IČO], registered seat [INSERT REGISTERED ADDRESS], [INSERT POSTCODE] [INSERT CITY], Czech Republic.

Contact: support@xflowtrading.com.

2. What data we collect

When you place an order, we collect the data you enter into the checkout form:

  • Name and surname
  • Delivery address (street, city, postcode, country)
  • Phone number and email address
  • Order details (product, quantity, total amount)
  • Optional courier note

3. Why we process your data and on what legal basis

  • Order fulfilment (Art. 6(1)(b) GDPR — performance of the purchase contract): name, address, phone, email, order details.
  • Tax and accounting obligations (Art. 6(1)(c) GDPR): we are required to retain order documents for 10 years under Czech accounting law.
  • Customer support (Art. 6(1)(f) GDPR — legitimate interest): we use your contact details to answer your questions and resolve disputes.

4. Recipients of your data

We share your data only with parties that need it to fulfil your order:

  • Shipmall (Comgate s.r.o.) — our logistics provider, processes your delivery address and order details to ship the package.
  • The carrier you select (e.g. GLS, Zásilkovna) — receives only the data needed to deliver and contact you.
  • Our accountant — receives invoice data for tax purposes.
  • Vercel Inc. — hosts the website (no personal data is stored on Vercel except web access logs).

5. International transfers

We do not transfer your personal data outside the European Economic Area unless required by a service provider listed above operating under standard contractual clauses approved by the European Commission.

6. Retention period

Order data: 10 years from the end of the calendar year of purchase, as required by Czech accounting law.

Marketing-related data (if you sign up): until you withdraw consent.

After the retention period expires, we delete or anonymise the data.

7. Your rights

Under GDPR you have the right to:

  • Access your personal data and obtain a copy
  • Rectify inaccurate data
  • Erase your data (where the legal basis allows)
  • Restrict processing
  • Data portability
  • Object to processing based on legitimate interest
  • Withdraw consent at any time (without affecting prior lawful processing)

8. Right to lodge a complaint

You have the right to lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů — ÚOOÚ): https://www.uoou.cz.

9. Cookies and similar technologies

We describe our use of cookies and browser storage in our separate Cookie Policy.

10. Changes to this policy

We may update this policy to reflect changes in law or our practices. The latest version is always available on this page; the date at the top reflects the last revision.

Contact

Questions about this policy? Email support@xflowtrading.com.