GDPR

Privacy Policy and Use of Cookies

Effective Date: May 26, 2026

This document sets forth the privacy policy and cookie policy for the EARMORSHOP.COM online store, operated by PM Commerce s.r.o., in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), Act No. 110/2019 Coll., on the Processing of Personal Data, and related Czech and European legislation.

1. Data Controller

The data controller pursuant to Article 4(7) of the GDPR is:

PM Commerce s.r.o.

Rybná 716/24, 110 00 Prague 1, Czech Republic

Company ID: 11677511

Tax ID: CZ11677511

Email: sales@earmorshop.com

Phone: +420 245 008 818

2. What personal data do we process

We process only the data necessary for providing our services and fulfilling our legal obligations:

  • First and last name
  • Billing and shipping address
  • Phone number
  • Email address
  • Order history and purchased items
  • IP address, network identifiers, and technical device data
  • Cookies and data on website behavior
  • Communication with customer support

3. Purposes and legal bases for processing

We process your personal data for the following purposes based on the legal grounds listed below:

Purpose of processing

Legal basis under the GDPR

Data retention period

 

Order processing, delivery of goods, and handling of complaints

Performance of a contract pursuant to Article 6(1)(b) of the GDPR

For the period necessary to process the order and for the duration of the warranty period.

Compliance with accounting, tax, and legal obligations

Compliance with a legal obligation pursuant to Article 6(1)(c) of the GDPR

10 years from the end of the tax period (pursuant to the VAT Act).

Maintenance of user account (registration)

Performance of a contract pursuant to Article 6(1)(b) of the GDPR; consent pursuant to (a) only for optional account features

For the duration of the account’s existence, or until deleted by the user.

Direct marketing (sending newsletters to existing customers)

Legitimate interest of the controller pursuant to Article 6(1)(f) of the GDPR

For a maximum of 5 years from the last order or until unsubscription.

Marketing communications and ad personalization

Consent of the data subject pursuant to Article 6(1)(a) of the GDPR

Until consent is withdrawn, but for a maximum of 5 years.

Service improvement, traffic analysis, and website security

Legitimate interest (necessary technical data) or Consent (analytics/marketing)

Depending on the validity of specific cookies (see the Cookies section).

Every commercial communication (newsletter) sent includes a direct option to unsubscribe via a link in the email footer.

4. Recipients of personal data and processors

To ensure the operation of the e-shop and the delivery of goods, we use the services of verified third parties that act as processors or independent data controllers:

  • Shipping and logistics services: Zásilkovna (Packeta), PPL, Česká pošta, DHL, Direct Parcel Distribution (DPD), and other contracted carriers.
  • Payment gateway providers: ComGate Payments, a.s., GOPAY s.r.o., or PayPal (Europe) S.à r.l. et Cie, S.C.A.
  • E-shop operation and IT infrastructure: Providers of web hosting, cloud services, and e-shop platforms.
  • Accounting and tax consulting: External accounting firms and invoicing system providers.
  • Analytics and marketing tools: Google Ireland Ltd. (Google Analytics, Google Ads), Meta Platforms Ireland Ltd. (Meta Pixel), Seznam.cz, a.s. (Sklik), Heureka Group a.s. (Verified by Customers).

5. Transfer of Personal Data to Third Countries

The controller does not primarily transfer personal data to third countries outside the European Economic Area (EEA). However, when using certain global analytics and marketing services (e.g., from Google or Meta), data may be transferred to the U.S. In such cases, transfers are carried out exclusively on the basis of the European Commission’s decision on adequate data protection (the so-called EU-U.S. Data Privacy Framework) or on the basis of standard contractual clauses approved by the European Commission, which ensure a high level of security.

6. Cookie Policy

This website uses cookies and similar tracking technologies to ensure basic functionality, analyze traffic, and personalize advertising content. Cookies are divided into the following categories:

  • Essential (Technical) Cookies: These are essential for the website to function properly (e.g., adding items to the cart, logging into an account). Without these cookies, the e-shop cannot function, and they cannot be refused.
  • Functional and Preference Cookies: These allow the website to remember your choices (e.g., language, currency, or page layout) and tailor the website to your needs.
  • Analytical cookies: These help us understand how visitors use the website (e.g., which pages they visit most often). These scripts are activated solely based on your active consent.
  • Marketing and advertising cookies: These are used to profile visitors’ interests and display relevant (targeted) ads on our website and on third-party sites, including remarketing campaigns. These scripts are triggered solely based on your active consent.

Managing and Withdrawing Consent to Cookies

An interactive cookie banner will appear on your first visit to our e-shop. You have the option to:

  • Click “Accept All” to consent to all types of cookies.
  • Click “Reject All” to reject all non-essential cookies (analytical and marketing) – in this case, only necessary technical cookies will be stored.
  • Adjust preferences in the detailed settings and allow only selected categories.

You can change or completely revoke your consent at any time via the permanent link located in the website footer, which will bring up the cookie banner again.

7. Your Rights as a Data Subject

In connection with the processing of personal data, you have the following rights under the GDPR, which you may exercise:

  • Right of access: You have the right to know what data we process about you, for what purpose, and to whom we disclose it.
  • Right to rectification: If your data is inaccurate or incomplete, you have the right to request its immediate correction.
  • Right to erasure (“right to be forgotten”): You have the right to request the deletion of your data if it is no longer necessary for the specified purposes, if you withdraw your consent, or if the processing is unlawful. This right cannot be exercised with respect to data that we are required by law to retain (e.g., invoices).
  • Right to restriction of processing: You have the right to request that, in certain cases, we only block your data and cease further processing.
  • Right to data portability: You may request your data from us in a structured, commonly used, and machine-readable format for transfer to another controller.
  • Right to object: You have the right to object to processing based on our legitimate interest (including direct marketing). In the case of marketing, we will immediately cease processing.

You may exercise all your rights, including the right to withdraw previously granted consent, by sending a written request to our primary contact email: sales@earmorshop.com. We will respond to your request without undue delay, no later than 30 days.

If you believe that we are handling your data in violation of legal regulations, you have the right to file a complaint with the supervisory authority, which is the Office for Personal Data Protection (ÚOOÚ), with the address Pplk. Sochora 27, 170 00 Prague 7 (web: ).

8. Security of Personal Data

The controller declares that it has taken all appropriate technical and organizational measures to secure personal data. Only authorized persons bound by confidentiality have access to the data. Web communication and data transmission between the user and the server are fully encrypted using the SSL/TLS protocol (HTTPS). Data is protected against unauthorized access, loss, misuse, or damage.

9. Final Provisions

Information regarding the processing of personal data is made available to the buyer prior to the conclusion of the contract as part of the ordering process. A link to this document is also provided in the email confirming receipt of the order and in the General Terms and Conditions available at www.earmorshop.com/cs/business-terms. Use of the earmorshop.com website or the conclusion of a purchase contract is not conditional upon consent to this document as a whole—the processing of personal data is governed by the specific legal bases set forth in Section 3.

The controller reserves the right to update this policy as necessary and in accordance with legislative developments. The current version is always freely available on the e-shop’s website.