Legal Notice
Privacy policy
Last updated: 22 July 2026 · TK Fashion (Odetta s.r.o.)
1. Introduction
Welcome to TK Fashion (the “E-shop”), operated by ODETTA s.r.o. (“ODETTA”, “we”, “our”, or “us”).
Protecting your privacy is one of our core priorities. We process personal data lawfully, fairly, transparently and securely, and we respect the rights and freedoms of everyone whose data we handle.
This Privacy Policy explains how we collect, use, store, disclose and otherwise process your personal data when you:
- visit or use the E-shop available at www.tk-fashion.com;
- create a customer account;
- purchase products through our online store;
- communicate with us by e-mail, contact forms or other communication channels;
- subscribe to our newsletter or receive marketing communications;
- interact with us through our social media pages;
- participate in promotions, surveys or other marketing activities; or
- otherwise share your personal data with us in connection with our business.
It also explains:
- what categories of personal data we process;
- for what purposes and on what legal grounds we process your personal data;
- how long we retain your personal data;
- with whom we may share your personal data;
- whether your personal data may be transferred outside the European Economic Area ("EEA");
- what rights you have under applicable data protection legislation; and
- how you may exercise those rights.
We process personal data under:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation – GDPR);
- Act No. 18/2018 Coll. on Personal Data Protection, as amended;
- Act No. 452/2021 Coll. on Electronic Communications, as amended (governing cookies and direct marketing), Act No. 108/2024 Coll. on Consumer Protection and Act No. 22/2004 Coll. on Electronic Commerce; and
- any other applicable legislation relating to the protection of personal data.
This Privacy Policy covers only the processing carried out by ODETTA s.r.o. in connection with the E-shop and our related business activities.
It does not cover third-party websites, services or apps that may be linked from our E-shop. Please review those third parties’ own privacy policies before sharing your data with them.
Please read this Privacy Policy before using the E-shop or giving us any personal data. Continuing to use the E-shop means you have been informed about the processing described here.
Where the law requires your consent, we always ask for it separately before processing your data for that purpose. Simply using the E-shop does not, by itself, count as consent where consent is legally required.
2. Data Controller
The controller of your personal data within the meaning of Article 4(7) GDPR is:
ODETTA s.r.o.Karola Adlera 1932/1841 02 Bratislava – DúbravkaSlovak Republic
Company ID (IČO): 57 553 157Tax ID (DIČ): 2122824264VAT ID (IČ DPH): SK2122824264Registered in the Commercial Register of the Municipal Court Bratislava III, Section: Sro, Insert No. 198549/B
E-mail: a.belkina@tk-fashion.comE-shop: https://www.tk-fashion.com
ODETTA s.r.o. acts as the data controller for the purposes of applicable data protection legislation: we decide the purposes and means of processing your personal data collected through the E-shop and our related business activities.
The full scope of processing activities this Privacy Policy covers, from account registration through to marketing and legal compliance, is set out in Section 3 (Scope of this Privacy Policy) below.
We are responsible for processing your personal data in line with applicable data protection legislation and for putting in place appropriate technical and organisational measures to protect it against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Contact regarding personal data
If you have questions about this Privacy Policy, the processing of your personal data, or wish to exercise your rights under the GDPR, contact us at:
E-mail: a.belkina@tk-fashion.com
We aim to respond without undue delay and, in any case, within the time limits the law prescribes.
Data Protection Officer
ODETTA s.r.o. assessed its obligations under Article 37 GDPR and concluded that it is not required to appoint a Data Protection Officer (DPO); none has been designated.
All requests relating to the processing of personal data should be addressed using the contact details provided above.
3. Scope of this Privacy Policy
This Privacy Policy applies to the processing of personal data carried out by ODETTA s.r.o. in connection with the operation of the TK Fashion online store available at www.tk-fashion.com and all related services provided through the E-shop.
This Privacy Policy applies whenever you interact with us, including, but not limited to, the following situations:
- visiting and browsing our E-shop;
- creating and managing a customer account;
- placing an order for products offered through the E-shop;
- completing payment for your order;
- requesting delivery of purchased products;
- communicating with our customer support by e-mail or through contact forms;
- subscribing to our newsletter or other marketing communications;
- participating in promotional campaigns, surveys or competitions organised by us;
- contacting us through our official social media channels;
- exercising your consumer rights, including returns, withdrawals from contracts and complaints;
- interacting with analytical, advertising and security technologies used on our E-shop; and
- otherwise providing us with your personal data in connection with our business activities.
This Privacy Policy applies regardless of whether you access the E-shop as:
- a visitor;
- a registered customer;
- a purchaser of our products;
- a subscriber to our newsletter;
- or any other individual whose personal data is processed by ODETTA s.r.o.
The E-shop is intended for customers located within the European Union. Nevertheless, this Privacy Policy also applies where personal data is processed in relation to visitors accessing the E-shop from outside the European Union, to the extent required by applicable law.
This Privacy Policy governs only the processing of personal data carried out by ODETTA s.r.o. It does not apply to personal data processed independently by third parties whose services are accessible through or integrated with the E-shop.
Such third parties may include, without limitation:
- payment service providers;
- delivery service providers;
- social media platforms;
- analytics providers;
- advertising partners;
- search engines; and
- other independent service providers.
Where a third party acts as an independent controller of your personal data, that processing is governed by its own privacy policy and terms of use. We encourage you to review those before using their services.
Our E-shop may also link to third-party sites or services for your convenience. We aren’t responsible for their privacy practices, security or content; visiting them is your own choice and subject to their own terms.
Where the E-shop is offered in more than one language, this Privacy Policy applies equally to every language version. If versions conflict, the version ODETTA s.r.o. designates as governing prevails, unless mandatory law requires otherwise.
For the purposes of this Privacy Policy, the terms below carry the meanings set out here unless the context requires otherwise.
"Controller" means ODETTA s.r.o., which determines the purposes and means of the processing of Personal Data in accordance with Article 4(7) of the GDPR.
"Processor" means any natural or legal person, public authority, agency or other body that processes Personal Data on behalf of the Controller in accordance with Article 4(8) of the GDPR.
"Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject"). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier or one or more factors specific to that person's physical, physiological, genetic, mental, economic, cultural or social identity.
"Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, restriction, erasure or destruction.
"Data Subject" means any identified or identifiable natural person whose Personal Data is processed by the Controller.
"E-shop" means the online store operated by ODETTA s.r.o. and available at www.tk-fashion.com, including all associated webpages, customer account functionalities and related online services.
"Customer Account" means the password-protected user account created by a customer for the purpose of placing orders, managing personal information, viewing order history and using additional functionalities made available through the E-shop.
"Order" means a legally binding purchase order submitted by a customer through the E-shop for the purchase of products offered by the Controller.
"Customer" means any natural person who purchases products, registers a Customer Account or otherwise uses the E-shop.
"Newsletter" means electronic marketing communications distributed by the Controller to subscribers who have provided their consent where required by applicable law.
"Cookies" means small text files and similar technologies stored on a user's device when visiting the E-shop for the purposes described in this Privacy Policy and the separate Cookie Policy.
"Third-Party Service Provider" means any external entity engaged by the Controller to provide services related to the operation of the E-shop or the performance of the Controller's business activities, including payment processing, website hosting, cloud infrastructure, analytics, marketing, customer communications, logistics and other technical or operational services.
"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
"EEA" means the European Economic Area.
Unless otherwise defined in this Privacy Policy, terms used herein shall have the meanings assigned to them under the GDPR and other applicable data protection legislation.
The categories of personal data we process depend on how you use the E-shop and which services you use. We only collect what is adequate, relevant and limited to what these purposes require.
The table below gives an overview.
| Category of Personal Data | Examples |
|---|---|
| Identification Data | First name, last name, title (if provided). |
| Contact Data | Billing address, delivery address, e-mail address, telephone number. |
| Account Data | Username, encrypted password, account preferences, login history, account status. |
| Order Information | Ordered products, order number, order date, order value, order status, invoices, delivery instructions, returns and complaint history. |
| Payment Information | Selected payment method, payment status, transaction reference provided by the payment service provider. We do not store full payment card details. |
| Delivery Information | Delivery address, delivery method, shipment tracking information, delivery status. |
| Communication Data | Correspondence with customer support, enquiries, complaints, requests, feedback and other communications. |
| Marketing Data | Newsletter subscription status, marketing preferences, records of consent or withdrawal of consent, participation in promotional campaigns. |
| Technical Data | IP address, browser type and version, operating system, device information, language settings, date and time of access, referring URLs, session information and similar technical identifiers. |
| E-shop Usage Data | Information regarding your interaction with the E-shop, including visited pages, browsing behaviour, navigation paths, time spent on pages and similar analytical information. |
| Cookie and Online Identifiers | Cookie identifiers, online identifiers and other technologies described in our Cookie Policy. |
| Legal and Compliance Data | Information necessary for compliance with applicable legal obligations, fraud prevention, dispute resolution, the exercise or defence of legal claims and cooperation with competent authorities where required by law. |
Our E-shop sells clothing and related products, so we do not intentionally collect or ask for:
- special categories of Personal Data within the meaning of Article 9 GDPR (such as data concerning health, biometric data, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data or information concerning a person's sex life or sexual orientation);
- information relating to criminal convictions or offences;
- payment card numbers, card security codes (CVV/CVC) or other sensitive payment credentials.
Payments are processed directly by our authorised payment service providers; we only receive confirmation of whether a payment succeeded.
If you voluntarily give us personal data beyond what these purposes require, we will only process it where we have an appropriate legal basis or where it's needed to handle your request.
Please don’t share personal data about other people with us unless you’re authorised to and it’s genuinely necessary, for example, a recipient’s name and address for a gift order.
6. Sources of Personal Data
We obtain personal data from different sources depending on how you use the E-shop. Most of it comes directly from you, though some is collected automatically or from trusted third parties who help us deliver our services.
You provide Personal Data directly to us when you:
- create a Customer Account;
- place an order through the E-shop;
- provide billing or delivery information;
- contact our customer support by e-mail or through contact forms;
- subscribe to our newsletter or other marketing communications;
- submit a request relating to your rights under applicable data protection legislation;
- participate in surveys, promotional campaigns or competitions organised by us;
- communicate with us through our official social media channels; or
- otherwise voluntarily provide information in connection with our services.
You’re responsible for making sure the personal data you give us is accurate and up to date, and for telling us promptly if anything changes.
6.2 Personal Data Collected Automatically
When you use the E-shop, some technical information is collected automatically through your browser, device and the technologies that run the E-shop.
Depending on your settings and your choices in our Cookie Consent Platform, this can include:
- IP address;
- browser type and version;
- operating system;
- device type;
- language preferences;
- date and time of access;
- referring website;
- pages visited;
- session identifiers;
- browsing behaviour;
- technical logs required for security and fraud prevention; and
- information generated through cookies and similar technologies.
This information helps us keep the E-shop secure, functional and fast, understand how it’s used, and improve the experience.
6.3 Personal Data Received from Third Parties
We may also receive limited personal data from carefully chosen third-party providers, where necessary for a contract, a legal obligation, or our legitimate interests.
Examples include:
- payment service providers, for payment confirmation and transaction status;
- delivery service providers, for shipment tracking and delivery confirmation;
- fraud prevention and security service providers;
- analytics providers;
- marketing partners where you have consented to the relevant processing; and
- public authorities where disclosure is required by applicable law.
We never buy personal data from data brokers or other commercial sources for marketing purposes.
6.4 Information Obtained Through Cookies and Similar Technologies
Some information is also collected automatically through cookies, pixels and similar technologies on the E-shop.
Which of these apply depends on the type of cookie and, where the law requires it, your consent.
For full details — including:
- the categories of cookies used;
- their purposes;
- retention periods;
- third-party providers;
- your choices concerning cookies; and
- how to withdraw or modify your consent,
see our separate Cookie Policy, which complements this document.
6.5 Personal Data Relating to Third Parties
If you give us personal data about someone else (for example, a gift recipient), you're confirming that:
- you are authorised to provide such Personal Data;
- the information is accurate;
- the disclosure is necessary for the relevant purpose; and
- where required by applicable law, the individual concerned has been informed that their Personal Data has been provided to us.
We may ask for additional information where reasonably necessary to check this.
7. Purposes and Legal Bases for Processing Personal Data
We process personal data only where the GDPR gives us a valid legal basis, and only to the extent each purpose actually requires.
The table below sets out our purposes, the data categories involved, the Article 6 GDPR legal basis, and the retention period.
| Purpose of Processing | Categories of Personal Data | Legal Basis (GDPR) | Retention Period |
|---|---|---|---|
| Creating and managing a Customer Account | Identification Data, Contact Data, Account Data | Article 6(1)(b) – Performance of a contract or steps prior to entering into a contract | Until the Customer Account is deleted and thereafter for the period necessary to comply with legal obligations or resolve disputes |
| Processing and fulfilling customer orders | Identification Data, Contact Data, Order Information, Delivery Information | Article 6(1)(b) – Performance of a contract | During contract performance and thereafter for the period required by applicable law |
| Processing payments | Identification Data, Order Information, Payment Information | Article 6(1)(b) – Performance of a contract | For the period necessary to complete the transaction and comply with applicable accounting and tax legislation |
| Issuing invoices and maintaining accounting records | Identification Data, Contact Data, Order Information, Payment Information | Article 6(1)(c) – Compliance with a legal obligation | For the retention period required under applicable accounting and tax legislation |
| Delivering products and managing shipments | Identification Data, Contact Data, Delivery Information | Article 6(1)(b) – Performance of a contract | Until delivery is completed and thereafter where necessary for legal claims or statutory obligations |
| Handling returns, withdrawals from contracts and complaints | Identification Data, Contact Data, Order Information, Communication Data | Article 6(1)(b) and Article 6(1)(c) | For the period required under consumer protection and other applicable legislation |
| Providing customer support | Identification Data, Contact Data, Communication Data | Article 6(1)(b) and, where appropriate, Article 6(1)(f) – Legitimate interests | For the period necessary to resolve the request and any related legal claims |
| Responding to enquiries submitted through contact forms or e-mail | Identification Data, Contact Data, Communication Data | Article 6(1)(b), or Article 6(1)(f), depending on the nature of the enquiry | For the period necessary to respond and any subsequent follow-up |
| Sending newsletters and marketing communications | Contact Data, Marketing Data | Article 6(1)(a) – Consent | Until consent is withdrawn or another lawful basis applies |
| Managing marketing preferences and consent records | Identification Data, Contact Data, Marketing Data | Article 6(1)(c) and Article 6(1)(f) | For the duration of the marketing relationship and thereafter where required to demonstrate compliance |
| Ensuring website security, fraud prevention and protection against misuse | Technical Data, E-shop Usage Data, Legal and Compliance Data | Article 6(1)(f) – Legitimate interests | For the period reasonably necessary to ensure security and investigate incidents |
| Operating, maintaining and improving the E-shop | Technical Data, E-shop Usage Data | Article 6(1)(f) – Legitimate interests | As necessary for the operation and improvement of the E-shop |
| E-shop analytics (where consent is required) | Technical Data, E-shop Usage Data, Cookie and Online Identifiers | Article 6(1)(a) – Consent | Until consent is withdrawn or the applicable retention period expires |
| Personalised advertising and marketing cookies (where consent is required) | Technical Data, E-shop Usage Data, Cookie and Online Identifiers | Article 6(1)(a) – Consent | Until consent is withdrawn or the applicable retention period expires |
| Establishing, exercising or defending legal claims | Any data relevant to the specific matter | Article 6(1)(f) and, where applicable, Article 6(1)(c) | Until the final resolution of the relevant claim and for any additional period required by law |
| Compliance with legal obligations and requests from public authorities | Any data required by applicable law | Article 6(1)(c) – Compliance with a legal obligation | As required by applicable legislation |
Legitimate Interests
Where we rely on legitimate interests under Article 6(1)(f) GDPR, we carefully weigh those interests against your fundamental rights and freedoms.
Our legitimate interests typically include:
- ensuring the security and integrity of the E-shop;
- preventing fraud, abuse and unauthorised access;
- improving the quality, functionality and performance of our services;
- responding to customer enquiries;
- establishing, exercising or defending legal claims;
- maintaining appropriate business records; and
- ensuring the effective administration of our business.
Whenever we rely on legitimate interests, we apply appropriate safeguards and think through the impact on your privacy before we start.
Withdrawal of Consent
Where processing rests on your consent, you can withdraw it at any time.
Withdrawing consent doesn’t affect the lawfulness of processing carried out before the withdrawal.
You can withdraw consent by:
- changing your preferences through our Cookie Consent Platform (where applicable);
- using the unsubscribe link included in our marketing communications; or
- contacting us using the contact details provided in this Privacy Policy.
8. Customer Account
Creating a Customer Account is optional. You can order through the E-shop with one or, where available, as a guest.
An account simply makes future purchases easier and improves your overall experience.
8.1 Purpose of the Customer Account
A Customer Account lets you:
- manage your personal profile and contact information;
- save and update billing and delivery addresses;
- view your order history;
- monitor the status of current and previous orders;
- manage communication preferences;
- access invoices where available;
- simplify future purchases by avoiding repeated entry of the same information; and
- use additional account-related features that may be introduced from time to time.
Which features are available may change as we develop the E-shop further.
8.2 Personal Data Processed
When you create and maintain a Customer Account, we may process:
- first name and last name;
- e-mail address;
- telephone number (if provided);
- billing and delivery addresses;
- encrypted password;
- account preferences;
- order history;
- saved delivery information;
- communication preferences;
- login records;
- account activity logs necessary for security purposes.
Passwords are stored only in encrypted form, using industry-standard security. ODETTA s.r.o. never has access to the plain-text version.
8.3 Legal Basis
Processing account-related personal data relies mainly on:
- Article 6(1)(b) GDPR – processing necessary for the performance of a contract or for taking steps at the request of the data subject prior to entering into a contract;
and, where relevant, also on
- Article 6(1)(f) GDPR – our legitimate interest in keeping accounts secure, preventing fraud, improving our services and fixing technical issues.
8.4 Account Security
You’re responsible for keeping your login credentials confidential.
In practice, that means you should:
- choose a sufficiently strong password;
- not disclose your password to third parties;
- notify us without undue delay if you suspect unauthorised access to your account;
- ensure that your contact information remains accurate and up to date.
We may temporarily suspend or limit access to an account where reasonably necessary to protect the E-shop, the account, or other users.
8.5 Account Deletion
You can request deletion of your account at any time by contacting us.
Deleting your account doesn’t automatically delete all your personal data where the law requires us to keep processing it, or the GDPR otherwise allows it.
In particular, we may keep certain data where necessary:
- to comply with accounting, tax or consumer protection legislation;
- to establish, exercise or defend legal claims;
- to investigate fraud or security incidents;
- to comply with requests from competent public authorities; or
- to fulfil other legal obligations applicable to ODETTA s.r.o.
Once continued retention is no longer necessary, we delete or anonymise the data securely, following our retention procedures.
8.6 Account Inactivity
We may deactivate or remove accounts left inactive for an extended period, once retention is no longer needed for the purpose the data was collected for.
Where practical, we’ll try to notify you before permanently deleting an inactive account.
Deleting an inactive account doesn’t affect our right or obligation to keep data the law requires us to retain.
9. Orders and Contract Performance
When you place an order, we process your personal data to conclude, perform and manage the purchase contract, deliver your products, process payment, meet our legal obligations and support you throughout the order’s lifecycle. The rules governing the conclusion, performance and termination of the purchase contract, including delivery, payment, withdrawal and complaints, are set out in our General Terms and Conditions.
We only process what these purposes actually require, following GDPR principles.
9.1 Processing of Orders
Placing an order may involve processing:
- identification data;
- contact data;
- billing information;
- delivery information;
- information relating to the ordered products;
- payment-related information;
- communication relating to the order;
- information concerning returns, withdrawals from contracts and complaints.
Some checkout information is mandatory because the contract can’t be concluded or performed without it. We may not be able to process your order.
9.2 Purposes of Processing
We process order-related personal data to:
- verifying and confirming your order;
- concluding and performing the purchase contract;
- processing payments;
- issuing invoices and other accounting documents;
- preparing, packaging and dispatching products;
- arranging delivery through our logistics partners;
- providing order updates and delivery notifications;
- responding to customer enquiries relating to the order;
- processing returns, withdrawals and complaints;
- complying with legal obligations relating to accounting, taxation, consumer protection and product safety;
- preventing fraud and protecting our legitimate business interests;
- establishing, exercising or defending legal claims where necessary.
We won’t use your data for marketing unless we have a proper legal basis for it, typically your prior consent, where the law requires it.
9.3 Legal Basis
Processing order-related personal data relies mainly on:
- Article 6(1)(b) GDPR – processing necessary for the performance of a contract or in order to take steps at your request prior to entering into a contract;
and, where relevant, also on:
- Article 6(1)(c) GDPR – compliance with legal obligations, including accounting, tax and consumer protection legislation; and
- Article 6(1)(f) GDPR – our legitimate interests in preventing fraud, protecting our legal rights, resolving disputes and keeping our operations secure.
9.4 Guest Checkout
Where available, you can order without creating a Customer Account.
In that case, we only process what's necessary to fulfil the order and meet our legal obligations.
Not having an account doesn’t change your rights under the GDPR or consumer protection law.
9.5 Order Communications
In connection with your order, we may send communications necessary to perform the purchase contract, such as:
These communications may include, for example:
- order confirmation;
- payment confirmation;
- invoice or receipt;
- shipment confirmation;
- delivery updates;
- notifications concerning delays or delivery issues;
- information relating to returns or complaints;
- important safety or product-related notices where applicable.
These are service communications tied to performing the contract, not marketing, so they don’t need separate marketing consent.
9.6 Verification and Fraud Prevention
To protect our customers, our business and our payment systems, we may process certain personal data to detect, prevent and investigate fraud, abuse or other unlawful activity.
This relies on our legitimate interests under Article 6(1)(f) GDPR and is limited to what’s necessary and proportionate.
We don’t make decisions with legal or similarly significant effects based solely on automated processing for fraud prevention.
9.7 Record Retention
We may keep order-related information after the contract is complete where necessary to:
- to comply with legal obligations;
- to fulfil accounting and tax requirements;
- to comply with consumer protection legislation;
- to process warranty, complaint or return requests;
- to establish, exercise or defend legal claims; or
- for other purposes permitted or required by applicable law.
See Section 17 (Data Retention) for the specific periods.
10. Payments
To complete purchases, we work with trusted third-party payment providers who process electronic payments securely.
We never process or store full card numbers, CVV/CVC codes, online banking credentials or other confidential payment data entered directly into our payment providers’ own interfaces.
Payments run through secure systems operated by those providers, under their own privacy policies, security standards and legal obligations.
10.1 Payment Methods
Depending on your location and what’s available at checkout, you can pay by:
- payment cards;
- Apple Pay;
- Google Pay;
- PayPal;
- SEPA Direct Debit;
- Cash on Delivery (where available); and
- any other payment methods made available on the E-shop from time to time.
Which methods are available can depend on the delivery country, order value, technical factors or fraud checks.
10.2 Personal Data Processed for Payment Purposes
For payment purposes, we may process:
- customer identification data;
- contact details;
- billing address;
- order number;
- order value;
- selected payment method;
- payment status;
- transaction reference;
- invoice information; and
- information necessary to resolve payment-related enquiries or disputes.
Sensitive payment credentials go directly to the payment provider and are never accessible to ODETTA s.r.o.
10.3 Legal Basis
Processing payment-related personal data relies on:
- Article 6(1)(b) GDPR – processing necessary for the performance of the purchase contract;
and, where relevant,
- Article 6(1)(c) GDPR – compliance with accounting, tax and other legal obligations;
and
- Article 6(1)(f) GDPR – our legitimate interests in preventing fraud, protecting our legal rights and ensuring the security of payment transactions.
10.4 Payment Service Providers
To process payments securely, we share the personal data necessary for the transaction with our authorised payment providers, for example:
Depending on the payment method selected by the customer, this may include, for example:
- customer identification details;
- billing information;
- order details;
- transaction amount;
- transaction identifiers; and
- other information strictly necessary to process the payment.
Each provider processes personal data under its own privacy policy, and may act as an independent controller or as our processor depending on the activity and applicable law.
We’d encourage you to check your chosen provider’s privacy policy before paying.
10.5 Payment Security
We take appropriate technical and organisational measures to protect payment information sent through the E-shop.
Payments run over encrypted channels using industry-standard security.
Where technically available, transactions may also require additional authentication under payment services legislation, including Strong Customer Authentication (SCA).
10.6 Fraud Prevention
To protect customers and our business against fraud and unauthorised use of payment methods, we may process certain payment-related data for fraud detection.
This relies on our legitimate interests under Article 6(1)(f) GDPR and is limited to what’s necessary and proportionate for payment security.
Where the law requires it, we may share relevant information with public authorities, payment providers or financial institutions.
10.7 Refunds
For refunds, we process the data necessary to return payment: to the original payment method where possible, or another lawful method.
This can mean exchanging relevant information with payment providers, financial institutions or others involved in the original transaction.
We don’t keep refund-related personal data any longer than these purposes, or the law, require.
11. Delivery
To deliver your order, we work with trusted logistics and delivery providers within the EU and, where needed, beyond it.
We only process and share the personal data necessary to prepare, dispatch and deliver your order efficiently and securely.
11.1 Purpose of Processing
Delivery-related processing serves these purposes:
- preparing your order for dispatch;
- arranging transportation of purchased products;
- verifying delivery details;
- communicating delivery-related information;
- providing shipment tracking where available;
- completing delivery;
- handling failed delivery attempts;
- processing returned shipments;
- resolving delivery-related enquiries or disputes; and
- complying with legal obligations relating to transportation and consumer protection.
11.2 Categories of Personal Data Processed
For delivery purposes, we may process:
- first name and last name;
- delivery address;
- billing address (where relevant);
- telephone number (where required by the carrier);
- e-mail address;
- order number;
- shipment reference;
- delivery instructions provided by the customer;
- delivery status;
- tracking information;
- records relating to completed or unsuccessful deliveries.
We do not disclose Personal Data that is not necessary for the delivery of your order.
11.3 Sharing Personal Data with Delivery Service Providers
To complete delivery, we may share the personal data necessary for it with our logistics and delivery partners, limited to what the specific service reasonably needs, such as:
- customer identification details;
- delivery address;
- contact telephone number;
- e-mail address;
- shipment reference;
- delivery instructions where applicable.
Delivery providers process personal data under applicable data protection law and their own privacy policies.
11.4 Shipment Tracking
Where tracking is available, you can follow your delivery’s progress.
Tracking information may come:
- directly by us;
- by the relevant delivery service provider; or
- through links to the carrier's tracking system.
It’s provided solely so you can monitor your shipment.
11.5 Failed Deliveries and Returned Shipments
If delivery fails (wrong address, repeated failed attempts, refusal to accept the parcel, or similar), we may keep processing the relevant data to:
- contact the customer;
- arrange redelivery where appropriate;
- process returned shipments;
- administer refunds where applicable;
- resolve disputes concerning delivery.
11.6 Legal Basis
Delivery-related processing relies mainly on:
- Article 6(1)(b) GDPR – processing necessary for the performance of the purchase contract;
and, where relevant,
- Article 6(1)(c) GDPR – compliance with legal obligations;
and
- Article 6(1)(f) GDPR – our legitimate interests in ensuring reliable delivery services, preventing fraud and resolving delivery-related disputes.
11.7 Retention of Delivery Information
We may retain delivery-related information for as long as necessary to:
- demonstrate proper performance of the purchase contract;
- process complaints and returns;
- establish, exercise or defend legal claims;
- comply with accounting, tax and consumer protection legislation; and
- fulfil other legal obligations applicable to ODETTA s.r.o.
See Section 17 (Data Retention) for specifics.
12. Customer Support and Communications
Good customer support matters to us. When you contact us, we only process the personal data necessary to answer you, handle your request, resolve order issues, or meet our legal obligations.
12.1 How You May Contact Us
You can reach us through:
- e-mail;
- contact forms;
- customer account (where available);
- social media channels operated by ODETTA s.r.o.; and
- other communication channels that we may introduce from time to time.
Which channels are available may change as our services evolve.
12.2 Categories of Personal Data Processed
Depending on your enquiry, we may process:
- your name;
- e-mail address;
- telephone number (if provided);
- order number;
- customer account information (if applicable);
- correspondence exchanged with you;
- information relating to your enquiry, request, complaint or return;
- attachments voluntarily submitted by you (for example, photographs of a product where necessary to assess a complaint);
- records of previous communications where relevant to your request.
Please only share what we actually need to help you.
12.3 Purposes of Processing
We process communications-related personal data to:
- respond to enquiries;
- provide customer support;
- verify customer identity where appropriate;
- process returns, complaints and warranty claims;
- investigate delivery or payment issues;
- resolve technical problems relating to the E-shop or Customer Account;
- improve the quality of our customer service;
- maintain records of customer communications where necessary;
- establish, exercise or defend legal claims; and
- comply with applicable legal obligations.
12.4 Legal Basis
Depending on your request, this relies on one or more of:
- Article 6(1)(b) GDPR – where processing is necessary for the performance of a contract or to take steps at your request prior to entering into a contract;
- Article 6(1)(c) GDPR – where processing is necessary to comply with a legal obligation;
- Article 6(1)(f) GDPR – where processing is necessary for our legitimate interests, including maintaining effective customer service, protecting our legal rights and resolving disputes.
12.5 Communication Records
For quality assurance, training, dispute resolution and legal compliance, we may keep records of customer communications for as long as these purposes require.
We don’t use your correspondence for marketing unless we have an appropriate legal basis to do so.
12.6 Attachments and Supporting Documents
Where it helps us handle your enquiry, return or complaint, you can voluntarily send supporting documents or images - for example:
For example, you may submit:
- photographs of a product;
- photographs of packaging damaged during transport;
- documents confirming delivery issues;
- other documents relevant to your request.
Please make sure such documents contain only what’s needed to resolve your enquiry, and no unnecessary personal data about other people.
12.7 Response Times
We aim to respond to enquiries within a reasonable time.
Requests about your GDPR rights are handled within the legal time limits.
12.8 Security of Communications
We use appropriate technical and organisational measures to protect our communications with you, though no method of electronic communication can be guaranteed fully secure.
We’d recommend not sending unnecessary confidential information or special categories of data when contacting us, unless we’ve specifically asked and the law requires it.
13. Marketing Communications
We only send marketing communications where the law allows it and we have an appropriate legal basis.
We respect your preferences - you stay in control of whether and how you hear from us.
13.1 Types of Marketing Communications
Subject to applicable law, we may send communications about:
- new product launches;
- seasonal collections;
- promotional offers;
- discounts and special campaigns;
- exclusive customer benefits;
- fashion inspiration and styling recommendations;
- newsletters;
- invitations to events or promotional activities organised by TK Fashion.
Marketing messages may reach you by:
- e-mail;
- other electronic communication channels that you have chosen to use; or
- other communication methods permitted by applicable law.
13.2 Legal Basis
We only process personal data for marketing where the GDPR gives us an appropriate legal basis.
Depending on the situation, that may be:
Consent
Where the law requires it, we send marketing only after getting your prior consent under Article 6(1)(a) GDPR.
Your consent has to be freely given, specific, informed and unambiguous.
Existing Customer Relationship
Where the law permits it, we may tell existing customers about our own similar products or services following a previous purchase, provided:
- the marketing relates to products or services similar to those previously purchased;
- you were clearly informed of this possibility when your contact details were collected; and
- you have the opportunity to object to such communications at any time, free of charge.
Where we rely on this basis, we always respect your right to opt out of future marketing.
Under Act No. 452/2021 Coll. on Electronic Communications, as amended by Act No. 297/2025 Coll. (in effect since 12 November 2025), this exemption is time-limited: contact details obtained in connection with a sale may be used for this kind of marketing only for a defined period after the customer relationship ends, after which fresh consent is required. We keep our marketing lists aligned with this limit.
13.3 Newsletter Subscription
You can subscribe to our newsletter by giving your e-mail address through the form on the E-shop.
Where consent is required, your subscription only takes effect once you’ve completed the relevant verification step (such as double opt-in, where we use it).
Where the law requires it, we keep records showing when and how you gave consent.
13.4 Withdrawal of Consent and Unsubscribing
You can withdraw your marketing consent at any time by:
You may do so by:
- clicking the "Unsubscribe" link included in every marketing e-mail;
- updating your communication preferences within your Customer Account (where available); or
- contacting us using the contact details provided in this Privacy Policy.
Withdrawing consent doesn’t affect the lawfulness of processing before the withdrawal.
Unsubscribing from marketing doesn’t affect service messages about your orders, payments, deliveries, returns, complaints or other contractual matters.
13.5 Marketing Preferences
We try to keep marketing relevant and not excessive.
You can update your preferences any time this feature is available.
We’ll respect your choices about:
- receiving newsletters;
- promotional communications;
- personalised offers;
- marketing based on cookies or similar technologies (where applicable).
13.6 Personalisation
Where you’ve given consent, or another lawful basis applies, we may use limited information about your E-shop activity and purchase history to make marketing more relevant to you.
This is only meant to improve your experience. It doesn’t involve automated decision-making with legal or similarly significant effects under Article 22 GDPR.
13.7 Third-Party Marketing
We don’t sell or rent your personal data to third parties for their own marketing.
Where third parties distribute our newsletters or manage campaigns for us, they process personal data only under our instructions or their own legal duties, subject to appropriate contractual and legal safeguards.
13.8 Retention of Marketing Data
We keep marketing preferences, subscription status and consent records only for as long as needed to demonstrate compliance, run our marketing and protect our legal rights.
See Section 17 (Data Retention) for specifics.
14. Cookies and Similar Technologies
Our E-shop uses cookies and similar technologies to keep it running properly, improve security and functionality, analyse traffic and, with your consent, where the law requires it, support marketing and personalised content.
This section gives a general overview. For details on individual cookies, their providers, purposes, storage periods and your choices, see our separate Cookie Policy.
14.1 What Are Cookies?
Cookies are small text files stored on your device when you visit a website.
Depending on their purpose, they may:
- enable essential E-shop functionality;
- remember your preferences and settings;
- improve website performance;
- help us understand how visitors use the E-shop;
- support security and fraud prevention;
- measure the effectiveness of marketing campaigns.
- We also use similar technologies (pixels, tags, scripts, local storage) where appropriate. For simplicity, we call all of these “cookies” throughout this Privacy Policy.
14.2 Categories of Cookies
Depending on their purpose, our E-shop may use:
Strictly Necessary Cookies
These keep the E-shop running and secure.
They power core functions like:
- navigation;
- secure login;
- shopping cart functionality;
- fraud prevention;
- load balancing;
- security monitoring; and
- other features required for the proper functioning of the E-shop.
Because they’re necessary for the E-shop to work, they generally don’t need your consent where the law permits this.
Functional Cookies
These remember your preferences and add functionality, such as:
- preferred language;
- selected currency;
- saved user preferences;
- improved user experience.
Where the law requires it, we only use these after you’ve consented.
Analytics Cookies
These help us understand how visitors use the E-shop.
They may collect things like:
- pages visited;
- navigation paths;
- session duration;
- interactions with E-shop features;
- technical performance of the E-shop.
We use this information to improve the E-shop’s quality, usability and performance.
Where the law requires it, these only activate after you’ve consented.
Marketing Cookies
These may be used to:
- measure the effectiveness of advertising campaigns;
- limit repeated display of advertisements;
- provide more relevant advertising;
- analyse interactions with marketing campaigns.
These cookies are used only where you have provided your consent, unless applicable law provides otherwise.
14.3 Cookie Consent
When you first visit our E-shop, you will be presented with a cookie banner allowing you to choose which categories of non-essential cookies you wish to accept.
You may:
- accept all cookies;
- reject all non-essential cookies; or
- customise your cookie preferences.
Your preferences can be changed at any time through the "Cookie Settings" option available on our E-shop.
Withdrawal or modification of your consent does not affect the lawfulness of processing carried out before your updated preferences became effective.
14.4 Third-Party Technologies
Some cookies and similar technologies may be placed or operated by trusted third-party service providers that assist us with services such as:
- website analytics;
- advertising and marketing;
- security;
- website performance;
- embedded content;
- payment functionality.
Such third parties may process certain information in accordance with their own privacy policies and applicable legal requirements.
14.5 Managing Cookies
Most web browsers allow you to:
- view stored cookies;
- delete cookies;
- block cookies;
- receive notifications before cookies are stored; and
- configure browser settings relating to cookies.
Please note that disabling certain cookies may affect the functionality, performance or availability of some parts of the E-shop.
You can change your cookie preferences at any time using the “Cookie settings” link, available at the bottom of every page on the E-shop.
14.6 Cookie Policy
For full details - including:
- the cookies used on our E-shop;
- their providers;
- their purposes;
- retention periods;
- legal basis for processing;
- cookie categories;
- instructions on how to manage cookies; and
- information about third-party providers,
is available in our separate Cookie Policy, available at:
https://www.tk-fashion.com/cookie-policy
The Cookie Policy is a complementary part of the privacy information we provide.
15. Recipients of Personal Data
We treat your Personal Data as confidential and disclose it only where necessary for the purposes described in this Privacy Policy, where required by applicable law, or where you have otherwise authorised such disclosure.
Recipients only get what they need to do their job, and must process it under applicable data protection law.
15.1 Categories of Recipients
Depending on the purpose, we may share personal data with these categories of recipients.
| Category of Recipient | Purpose of Disclosure |
|---|---|
| Payment service providers | Processing electronic payments, payment verification, fraud prevention and refunds. |
| Logistics and delivery service providers (in particular FHB Group, s.r.o., our fulfilment and warehousing partner) | Order fulfilment, shipment tracking and delivery of purchased products. |
| IT hosting and cloud infrastructure providers | Operation, maintenance and security of the E-shop and supporting systems. |
| E-shop development and technical support providers | Maintenance, troubleshooting, security updates and development of E-shop functionality. |
| E-mail communication providers | Sending transactional e-mails, order confirmations, invoices and, where permitted, marketing communications. |
| Analytics providers | Measuring E-shop performance, improving usability and understanding visitor behaviour. |
| Advertising and marketing service providers | Managing advertising campaigns and measuring their effectiveness where you have provided the necessary consent. |
| Customer support service providers | Assisting in responding to customer enquiries and resolving customer requests where external support is used. |
| Professional advisers | Lawyers, auditors, accountants, tax advisers and other professional advisers where disclosure is necessary for the provision of professional services. |
| Public authorities | Courts, law enforcement authorities, tax authorities, supervisory authorities and other public bodies where disclosure is required by law or necessary for the protection of legal rights. |
15.2 Service Providers
To run the E-shop and deliver our services efficiently, we work with carefully chosen third-party providers.
They only process personal data:
- on our documented instructions, where they act as processors;
- for their own purposes where they act as independent controllers under applicable law; or
- in another capacity recognised by applicable data protection legislation.
Where Article 28 GDPR requires it, we have data processing agreements with our processors, so data stays secure, confidential and is only used for authorised purposes.
15.3 International Technology Providers
Some of our technology providers may process personal data from outside the EEA.
Where that happens, we follow Chapter V GDPR and apply the safeguards described in Section 16 (International Transfers).
15.4 Legal Disclosure
We may disclose personal data where we reasonably believe it’s necessary to:
- comply with applicable laws or legal obligations;
- respond to lawful requests from competent authorities;
- protect the rights, property or safety of ODETTA s.r.o., our customers or other individuals;
- investigate suspected fraud, security incidents or unlawful activities;
- establish, exercise or defend legal claims; or
- protect the integrity and security of the E-shop.
15.5 Business Transactions
If ODETTA s.r.o. goes through a merger, acquisition, restructuring, asset transfer or similar transaction, personal data may transfer to the successor entity, to the extent the law allows.
Any such recipient stays bound by confidentiality obligations and applicable data protection law.
15.6 Data Minimisation
Whenever we share personal data with third parties, we apply data minimisation.
Only what a specific disclosure actually needs gets shared.
We don’t authorise recipients to use personal data for purposes incompatible with this Privacy Policy.
Annex 1 – Main Service Providers
For transparency, the table below lists the main categories of service providers we currently use to run the E-shop. This list may change as our services evolve.
| Provider | Purpose |
|---|---|
| Stripe | Payment processing |
| PayPal | Payment processing |
| Vercel | E-shop hosting |
| Railway | Backend infrastructure |
| Cloudflare | Security, CDN and performance |
| Cloudinary | Image hosting and optimisation |
| Sanity | Content management system (CMS) |
| Resend | Transactional e-mail delivery |
| FHB Group, s.r.o. (Fulfillment by FHB) | Order fulfilment, warehousing, and delivery/returns handling |
| E-shop analytics and related services (where applicable) | |
| Meta | Marketing and advertising services (where applicable and subject to consent) |
| TikTok | Marketing and advertising services (where applicable and subject to consent) |
Note: our specific providers may change over time. If we replace one with another offering substantially equivalent services, this Privacy Policy still applies without needing immediate amendment, as long as the processing stays consistent with the purposes described here and with applicable law.
16. International Transfers of Personal Data
As a Slovak company, ODETTA s.r.o. processes most personal data within the European Economic Area (“EEA”).
But because we use certain technology, cloud, payment, communication and analytics providers, some personal data may be transferred to, accessed from, or processed in countries outside the EEA.
Wherever that happens, we make sure it follows Chapter V GDPR and that your personal data gets an appropriate level of protection.
16.1 When International Transfers May Occur
International transfers can happen, for example, where:
- a service provider stores data outside the EEA;
- technical support is provided from outside the EEA;
- cloud infrastructure involves international processing;
- communication services operate through global networks;
- analytics or marketing platforms process information outside the EEA; or
- international payment processing requires the transfer of limited transaction-related information.
Not every international provider results in data actually leaving the EEA - it depends on the specific service and the provider’s infrastructure.
16.2 Safeguards for International Transfers
Where personal data leaves the EEA, we rely on one or more GDPR-recognised safeguards, including:
- an adequacy decision adopted by the European Commission;
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- other transfer mechanisms recognised under Chapter V of the GDPR; or
- a derogation expressly permitted under Article 49 GDPR, where applicable.
Before engaging a provider that might involve international transfers, we assess the processing involved and put in place appropriate contractual, organisational and technical safeguards where needed.
16.3 Additional Protective Measures
Where appropriate, we may add supplementary safeguards to protect personal data transferred outside the EEA - for example:
Depending on the circumstances, these measures may include:
- encryption during transmission and storage;
- access controls;
- authentication procedures;
- pseudonymisation where appropriate;
- contractual confidentiality obligations;
- regular security assessments; and
- careful selection and monitoring of service providers.
The specific safeguards we apply vary depending on the processing and the provider involved.
16.4 Transfers to Countries Covered by an Adequacy Decision
Where personal data goes to a country the European Commission has recognised as offering an adequate level of protection, the transfer relies on that adequacy decision under Article 45 GDPR.
16.5 Transfers Based on Standard Contractual Clauses
Where no adequacy decision applies, we may rely on Standard Contractual Clauses adopted by the European Commission, together with any supplementary measures the processing calls for.
16.6 Your Rights
You can ask us for more information about the safeguards applied to international transfers of your personal data.
Where the law permits it, we may share a summary of the relevant safeguards, while protecting confidential business information and our providers’ security.
16.7 Future Changes
International data transfer mechanisms may evolve due to changes in legislation, regulatory guidance or decisions of competent courts and supervisory authorities.
Where necessary, we will update our transfer mechanisms and this Privacy Policy to ensure continued compliance with applicable data protection legislation.
17. Data Retention
17.1 Standard Retention Periods
The table below sets out our standard retention periods. They may be extended where the law requires it or where needed to establish, exercise or defend legal claims.
| Category of Personal Data | Retention Period |
|---|---|
| Customer Account information | Until the Customer Account is deleted, and thereafter only for as long as necessary to comply with legal obligations or resolve disputes. |
| Orders and purchase records | For the period required under applicable accounting, tax and consumer protection legislation. |
| Accounting and tax documents | 10 years from the end of the accounting period to which the document relates, as required under Act No. 431/2002 Coll. on Accounting and Act No. 222/2004 Coll. on Value Added Tax. |
| Payment transaction records | For the period necessary to process the transaction and comply with applicable legal obligations. |
| Delivery information | Until delivery has been completed and for any additional period necessary to resolve complaints, returns or legal claims. |
| Customer support correspondence | For as long as reasonably necessary to resolve the enquiry and any related legal matters. |
| Complaint and warranty documentation | For the duration of the complaint or warranty procedure and any statutory retention period thereafter. |
| Newsletter subscription records | Until consent is withdrawn or another lawful basis no longer exists. |
| Records demonstrating consent | For the period necessary to demonstrate compliance with applicable legal requirements. |
| Technical logs and security records | For the period necessary to maintain security, investigate incidents and protect the E-shop. |
| Analytics information | In accordance with the retention settings applicable to the relevant analytics service and your cookie preferences. |
| Marketing preferences | Until updated, withdrawn or no longer required for compliance purposes. |
We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, to comply with our legal obligations, to resolve disputes and to establish, exercise or defend legal claims.
- In setting a retention period, we consider:
- the nature and sensitivity of the Personal Data;
- our contractual obligations;
- applicable legal and regulatory requirements;
- statutory limitation periods;
- the need to protect our legitimate business interests; and
- recommendations and guidance issued by competent supervisory authorities.
Once the retention period ends and no other lawful basis applies, we securely delete, anonymise or otherwise dispose of the data using appropriate measures.
17.2 Legal Obligations
Some categories of personal data must be kept longer where the law requires it, in particular:
This may include, in particular:
- accounting records;
- tax documentation;
- documentation relating to consumer rights;
- records required for fraud prevention;
- information necessary for legal proceedings;
- documentation required by competent public authorities.
Where the law requires us to retain data, we only delete it once the statutory retention period has expired.
17.3 Legal Claims
Where personal data is relevant to establishing, exercising or defending legal claims, we may keep it until the relevant limitation period expires and any related proceedings conclude.
17.4 Deletion and Anonymisation
Once personal data is no longer needed, we will:
- securely delete it;
- irreversibly anonymise it; or
- otherwise dispose of it using appropriate technical and organisational measures.
How we delete it depends on the type of data, the storage medium, and legal requirements.
17.5 Review of Retention Periods
We periodically review our retention practices to make sure we’re not keeping data longer than necessary.
Retention periods may change as legislation, regulatory guidance or our own operations evolve.
18. Your Rights Under the GDPR
The GDPR gives you a number of rights over your personal data. We want you to be able to exercise them simply, transparently and effectively.
Exercising your rights is generally free. But where a request is manifestly unfounded, excessive or repetitive, we may charge a reasonable fee or decline to act, as Article 12 GDPR allows.
18.1 Right of Access
You can ask us to confirm whether we process your personal data.
If we do, you can request access to it, along with information such as:
- the purposes of processing;
- the categories of Personal Data concerned;
- the recipients or categories of recipients;
- the envisaged retention period or the criteria used to determine it;
- your rights under the GDPR;
- the source of the Personal Data where it was not collected directly from you;
- information regarding international transfers, where applicable; and
- information about automated decision-making where required by law.
You can also request a copy of the personal data being processed.
18.2 Right to Rectification
You can ask us to correct inaccurate or incomplete personal data without undue delay.
Where possible, you can also update certain data directly through your Customer Account.
18.3 Right to Erasure ("Right to be Forgotten")
You can ask us to delete your personal data where one of the grounds in Article 17 GDPR applies.
This right isn’t absolute.
We may keep processing some data where retention is necessary - for example:
- to comply with legal obligations;
- to establish, exercise or defend legal claims;
- to exercise the right of freedom of expression and information;
- for reasons of public interest recognised by applicable law; or
- where another exception under Article 17 GDPR applies.
Under certain circumstances, you may request that we temporarily restrict the processing of your Personal Data.
While restricted, we generally just store the data, unless further processing is allowed under the GDPR.
18.5 Right to Data Portability
Where processing rests on your consent or on performing a contract, and is carried out by automated means, you can ask to receive the personal data you gave us in a structured, commonly used, machine-readable format.
Where technically feasible, you can also ask us to send that data directly to another controller.
18.6 Right to Object
Where we process personal data based on our legitimate interests under Article 6(1)(f) GDPR, you can object on grounds relating to your particular situation.
Where we process data for direct marketing, you can object at any time.
If you object to direct marketing, we’ll stop processing your data for that purpose without undue delay.
18.7 Right to Withdraw Consent
Where processing relies on your consent, you can withdraw it at any time.
Withdrawing consent doesn’t affect the lawfulness of processing before the withdrawal.
18.8 Rights Relating to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects on you - unless an Article 22 GDPR exception applies.
As of this Privacy Policy’s date, ODETTA s.r.o. doesn’t carry out automated decision-making with legal or similarly significant effects on customers.
18.9 How to Exercise Your Rights
You can exercise your rights at any time by contacting us using the details in this Privacy Policy.
To protect your data’s privacy and security, we may ask for additional information to verify your identity before we act on your request.
We aim to respond without undue delay, and in any case within one month, unless the GDPR allows a longer period due to the request’s complexity or volume.
If we extend the response period, we’ll tell you why within the legal time limits.
18.10 Lodging a Complaint
If you believe our processing of your personal data breaches applicable law, you can lodge a complaint with the competent supervisory authority.
For ODETTA s.r.o., that’s:
Úrad na ochranu osobných údajov Slovenskej republikyHraničná 12820 07 Bratislava 27Slovak Republic
E-shop: https://dataprotection.gov.sk
You also have the right to seek judicial remedies where the law provides for them.
19. Data Security
ODETTA s.r.o. is committed to protecting Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
We apply technical and organisational measures appropriate to the risks involved, taking into account the nature, scope, context and purpose of processing, and the likelihood and severity of any risk to people’s rights and freedoms.
Depending on the nature of the processing, our security measures may include:
- access controls based on the principle of least privilege;
- authentication and password protection;
- secure hosting infrastructure;
- firewall and network security measures;
- monitoring and logging of security events;
- regular software updates and security patches;
- backup and disaster recovery procedures;
- confidentiality obligations for authorised personnel; and
- periodic review of security procedures and organisational safeguards.
The specific measures we apply may evolve as technology, legal requirements and cybersecurity risks change.
19.2 Confidentiality
Access to personal data is limited to people who need it to do their job or provide services on ODETTA s.r.o.’s behalf.
Everyone authorised to process personal data is bound by confidentiality obligations.
19.3 Personal Data Breaches
If a personal data breach occurs, we take appropriate steps to contain, investigate and remediate it.
Where the law requires it, we notify the competent supervisory authority and, where necessary, affected individuals within the GDPR’s time limits.
19.4 No Absolute Security
Despite our safeguards, no method of electronic transmission or storage can be guaranteed completely secure.
So while we use commercially reasonable measures to protect your data, we can’t guarantee absolute security.
20. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- changes in applicable legislation;
- guidance issued by supervisory authorities;
- court decisions;
- changes to our services;
- implementation of new technologies;
- changes to our business operations; or
- other circumstances affecting the processing of Personal Data.
Where changes are significant, we’ll take appropriate steps to let you know, through the E-shop or other suitable means, where the law requires it.
The updated Privacy Policy takes effect on the date shown at the start of the document.
We’d encourage you to check back periodically to stay informed about how we process and protect your data.
21. Contact Information
If you have questions about this Privacy Policy, the processing of your personal data, or want to exercise your GDPR rights, contact us at:
ODETTA s.r.o.Registered Office: Karola Adlera 1932/1, 841 02 Bratislava – Dúbravka, Slovak RepublicCompany ID (IČO): 57 553 157VAT ID (IČ DPH): SK2122824264Tax ID (DIČ): 2122824264Registered in the Commercial Register of the Municipal Court Bratislava III, Section: Sro, Insert No. 198549/B
E-mail: a.belkina@tk-fashion.com
E-shop: https://www.tk-fashion.com
As of this Privacy Policy’s date, ODETTA s.r.o. has not designated a Data Protection Officer under Article 37 GDPR, since it isn’t required to.
If that changes, the DPO’s contact details will be published on the E-shop and this Privacy Policy updated accordingly.
22. Final Provisions
This Privacy Policy is governed by Slovak law and directly applicable EU legislation, including the GDPR.
Where mandatory consumer protection or data protection law of another EU Member State applies to a specific processing activity, that mandatory law remains unaffected.
If any provision of this Privacy Policy is or becomes invalid, unlawful or unenforceable, the rest remain in full effect.
This Privacy Policy is part of the information ODETTA s.r.o. provides about processing personal data in connection with operating the E-shop and its services.
If you have legal or policy-related questions, please contact us using the details provided on the Contact page.
