PRIVACY POLICY

Declaration of KRO Services s.r.o. on the processing of personal data  

This privacy policy statement (“Statement“) describes how personal data is processed at KRO Services s.r.o. (“Company“). This Statement ensures that the processing of personal data complies with generally applicable law, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to as the “Regulation“), so that the rights of data subjects are adequately protected.

The Company builds strong and lasting relationships with its customers, partners and consumers based on mutual trust: ensuring the security and confidentiality of their Personal Data is therefore a priority for the Company. 

The Company is committed to complying with all applicable regulatory and legal provisions governing the protection of Personal Information.

The Company applies a very strict privacy policy to ensure that the personal information of those who use its websites, portals, applications and platforms (our “Site”) is protected:

  • Users remain in control of their data. Data is processed transparently, confidentially and securely.
  • The Company is committed to continuously striving to protect the personal data of its users. 
 

THE PURPOSE OF THIS POLICY

We have developed this Policy to inform you of the conditions under which we collect, process, store and protect your Personal Data on our sites and as part of the services provided by the Company (the “Services”). This Policy applies to all users, including users who use the Site and Services without being registered or signed up for a particular service or account (collectively, “Users”). 

Please read this Policy carefully to familiarize yourself with the categories of Personal Data that is collected and processed, how we use that Personal Data, and with whom we are likely to share it. This Policy also describes your rights and how you can contact us to exercise those rights or ask us any questions about the protection of your Personal Data.

These principles may be amended, supplemented or updated, in particular in the light of possible legal and regulatory developments, case law or further technical developments. However, your Personal Data will always be processed in accordance with the legislation in force at the time of data collection, unless a binding legal regulation provides otherwise and it is necessary to apply it retroactively.

THE IDENTITY AND CONTACT DETAILS OF THE CONTROLLER

The personal data controller is KRO services s.r.o., ID No.: 093 80 884, V jirchářích 150/8, Prague 1 – Nové Město, 110 00, registered with the Municipal Court in Prague, Section C, Insert 334316.

COLLECTION AND SOURCE OF PERSONAL DATA

We will most likely collect your Personal Data directly (in particular through the data collection forms on our Site) or indirectly through our Service providers.

THE TYPES OF PERSONAL DATA WE COLLECT AND USE

We may specifically collect and process the following types of Personal Data:

  • information you provide when you fill out forms on the Site (for example, for employment or rental interest, marketing purposes, etc.);
  • information you provide for the purposes of authentication or verification of your age when purchasing age-restricted goods;
  • information that you provide in order to process an order or provide a service, including booking a table on the premises;
  • information relating to your purchases, such as products, quantities, price, billing and delivery address, including information about your health, only if you voluntarily agree to this, for example if you report specific food allergies after placing an order;
  • transaction data, such as payment information and credit/debit card information, which is passed directly to third parties who process your requests; 
  • information provided through “posts”, comments or other content you post on the Site, information from you if you use the chat feature on our Site; 
  • information you provide for the purposes of managing your application and, where applicable, for the recruitment process (e.g.: CV, information on education, work experience, awards, diplomas, certificates, certifications, languages spoken, expected salary, etc.);
  • your preferences about receiving marketing materials from us and third parties and your communication preferences.
 

The personal data marked with an asterisk in the data collection forms is mandatory as it is necessary for the processing of all orders placed. Without this mandatory information, these transactions cannot be processed. 

THE PURPOSES FOR WHICH WE USE YOUR PERSONAL DATA

A. Answer to your questions

If you contact us, your personal data will be used for the purpose of answering your questions and providing you with relevant information. We process your personal data on the basis of the consent you give by providing this data.We process information such as your name, contact details, communications with us, questions you have asked and any other personal data that is necessary to respond to your enquiries.

B. Development and improvement of products or services

We process your personal data in order to evaluate, analyse and improve our products and services for our customers. We use your personal data to analyse customer behaviour and to make appropriate adjustments to our products and services. When you use our website or applications, or enter or search for information through these platforms, we also process your personal data to generate analytical reports. We use your personal data to analyse customer behaviour and to make adjustments to our products and services to improve them. This includes analysing how often you read our newsletters, how often you visit our websites and apps, which links you click on and which products and services you purchase through our websites and apps. We may obtain additional data from public sources to supplement our database used for the above purposes.

We process your data for these purposes based on our legitimate interest to improve our products and services. We process your contact details such as address and email address, personal data such as name and date of birth, payment details and your correspondence with our company. In addition, we process personal data that you have entered on our website or that has been generated when using our website, and technical data from your device, such as your IP address, the pages you have visited on our website, information about your clicks and pages viewed, and the length of your visit to our website.

If you choose to participate in our surveys, we may ask you to provide us with personal information such as your address, email address, name and date of birth. We may also use the personal information that you provide to us as part of the survey for these purposes.

C. Customer, employee, supplier or business partner evaluation and acceptance

If you contact us, we will process your personal data for the purpose of confirming and verifying your identity and also for the purpose of evaluating and verifying the possibility of further cooperation. Our company will also process your personal data for administrative purposes, such as verification and comparison with data available in public registers of state and supervisory authorities. For this purpose:

– we process personal data as it is necessary for the conclusion of a contract between you and our company. Our company cannot conclude contracts without obtaining the necessary information;

– we process your contact information such as your address and email address, personal data such as your name and date of birth, information about payment transactions, and details of your correspondence with our company.

D. Conclusion and performance of the contract

If you have purchased a product or service from us as a customer, or if you work with us as a supplier, business partner or employee, we process your personal data for administrative purposes such as invoicing and making payments. We also use your personal data for the purposes of delivering, receiving and administering our or your products and services. 

Our company will also process your personal data for other services, including the provision of reservations. For this purpose:

– we process personal data because it is necessary to make the requested reservation or to conclude a contract between you and our company. Our company cannot fulfil booking requests or enter into contracts without obtaining the requested information,

– we also process your contact details in some cases, such as your address and email address, personal data such as your name and date of birth, payment information and details of your correspondence with our company.

E. Relationship Management and Marketing

We use the information stored in our customer database to send you relevant offers and newsletters, as well as for the purposes of providing you with customer services, including making reservations, managing your account and loyalty program, and sending you updates. We also use your personal data to develop, implement and analyse marketing surveys and marketing strategies. For these purposes – sending newsletters and/or marketing and other communications between us – we process your personal data on the basis of your consent or legitimate interest. 

We process your contact information such as your address and email address, personal information such as your name, communication preferences, payment information, order history and correspondence with our company.

F. Business activities and internal management

Your personal data is processed in the context of the conduct and organisation of our business activities. This includes general management, order management and management of our assets. Our company also processes your personal data for internal management purposes. We conduct audits, investigations, business checks and manage and use lists of customers, suppliers and business partners. We also process your personal data for financial administration and accounting, archiving and insurance purposes, legal and business consultation and dispute resolution. To this end:
– We process personal data based on our legitimate interest to maintain and develop our business activities
– We process your contact details such as your address and email address, personal data such as your name, payment information, order and payment history, correspondence with our company and data generated during the performance of a contract between you and our company.

H. Use of our website and applications

If you use our website, we process technical data that is necessary to enable you to use the functions of our website and to enable our webmasters to manage and improve its operation. If you enter personal data on our website, such as your product preferences or location to receive information or features, our company will process this data in order to provide you with the requested information or features. We also process your personal data to enable you to store your information (such as preferences and products) in your save list and to be able to share this information with others according to the sharing settings on your device. We process personal data based on our legitimate interest to create and provide a technically correct website and to improve its functionality. We process personal data that you enter on the website or that is generated when you use our company’s website and technical data from your device, such as your IP address, the web browser you use, the pages you visit on our website, information about your clicks and page views, and the length of your visit to our website.

I. Allowing you to contact us

Our company is active on social media such as Facebook, X (formerly Twitter), LinkedIn, TikTok, YouTube and Instagram. If you contact us through these channels, we process your personal data in order to answer your questions and respond to your messages. When you use the “Contact” function on our website or app, you can contact us through various communication channels such as email addresses or forms on the website to provide us with feedback and suggestions for improvement, among other things. For this purpose:
– We process personal data based on our legitimate interest in order to respond to your inquiries in appropriate ways and to link you to our social media pages
– We process the communication channels you have chosen to communicate with us and the personal data you have provided to our company. This includes your username, name, address, email address and the personal data provided in your message. In addition, when you use links to third party websites or applications, cookies may also be placed on your device by the relevant third party.

J. Monitoring and control

We monitor our processes to verify compliance with our guidelines and regulations. In the course of doing so, we may access and review your personal information. For this purpose:
– We may process your personal information based on our legitimate interest to monitor our internal processes and compliance with the law
– We may gain access to personal information stored on our systems and may be reviewed for compliance purposes. Personal information that we have access to and that is reviewed will not be retained for the purpose of the review, except where we need it to further investigate possible non-compliance 
– We do not retain your personal information for this purpose unless it is linked to a potential data breach. In this case, we will retain your relevant personal data until the investigation or proceedings are completed.

K. Protecting health, safety and ensuring integrity

At our company, we value your health, safety, security and integrity. We process your personal data to ensure the protection of our employees, customers, suppliers and business partners. As part of this, we verify your authorization to access our premises and may perform a check of your personal data against records available in public registers of government and supervisory authorities. We also process your personal data to ensure the protection of our company’s assets and those of our employees and customers. To this end:
– We may process your personal information based on our legitimate interest to monitor our internal processes and compliance with the law
– We process your contact details such as your address and email address, personal data such as your name and date of birth, order and payment history and your history of visits to our premises.

TRANSMISSION OF PERSONAL DATA

The security and confidentiality of your Personal Data is very important to us. For this reason, we restrict access to your Personal Data to our employees or external collaborators only to the extent necessary to process your orders or provide the requested Services. We ensure that those authorised to process Personal Data are committed to maintaining the confidentiality of such data or comply with the relevant legal obligation of confidentiality.

We will not disclose your personal data to third parties. However, we may share your Personal Data with entities within the Company’s group: 

  • KRO Kitchen s.r.o., ID No.: 07555504, with registered office at Moskevská 43/30, Vršovice, 101 00 Praha 10. 
  • Alma Bio s.r.o., ID No.: 17874114, with registered office at V jirchářích 150/8, Nové Město, 110 00 Prague 1.
  • Alma Wines s.r.o., ID No.: 17492441, with registered office at V jirchářích 150/8, Nové Město, 110 00 Prague 1.
 

Your personal data may also be transferred to external collaborators and suppliers who help us process your orders and deliver the services you request:

  • suppliers of transport services: Messenger a.s., ID No.: 27575896, with registered office at Libínská 3127/1, 15000 Praha 5 – Smíchov; Zásilkovna s.r.o., ID No.: 28408306, with registered office at Českomoravská 2408/1a, 190 00 Praha 9; Liftago, a.s., ID No.: 24278777, with registered office at Rohanské nábřeží 678/25, Karlín, 186 00 Praha 8
  • supplier of the e-mailing platform: Mailchimp c/o The Rocket Science Group, LLC, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, MOSS No. EU372008134
  • supplier of the CRM platform: Cortex, a.s., ID No.: 47125616, with registered office at U Elektry 974/1c, Praha 9, 190 00, and its related provider of the Septim POS system: ASW Systems a.s., ID No.: 28211189, with registered office at K Hájům 2671/8, Stodůlky, 155 00 Praha 5
  • supplier of the Resdiary reservation system: Access UK Ltd, The Armstrong Building, 10 Oakwood Drive, Loughborough, LE11 3QF, VAT Number: GB108221356
  • software providers: Solidpixels – Breezy, s.r.o., ID No.: 277 33 823, with registered office at Plzeňská 157, 150 00 Praha 5; Shoptet, a.s., ID No.: 28935675, Dvořeckého 628/8, 169 00 Praha 6.
 

In addition, we may share your Personal Data (i) if we are required to do so by law or legal process, (ii) in response to a request by public authorities or other officials, or (iii) if we believe that disclosure is necessary or appropriate to prevent physical harm or financial loss or in connection with an investigation relating to suspected or proven illegal activity.

SENSITIVE PERSONAL DATA

In general, we do not collect sensitive Personal Information through our website. “Sensitive Personal Data” means any information relating to an individual’s racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health information or information relating to an individual’s sex life or sexual orientation. This definition also includes Personal Information relating to criminal convictions and offences.

COOKIES

To make the Company’s website work as efficiently as possible and to make your visit to this website as enjoyable as possible, we use cookies. These small information files allow the website to store and subsequently use certain information about visitors’ preferences. Cookies make it possible for the site to “remember” visitors when they visit again, allowing us to provide a more personalised and better service.

The principle of cookies is based on storing so-called identifiers, which are small information tokens, in the visitors’ browser. It is important to stress that this information is not used to identify the individuals who have visited the site. On the contrary, their primary purpose is to track users’ movement around the site, to determine their preferred location and language, in order to provide the most relevant content when they visit the site. The use of cookies can be managed within the cookie bar on our website (you can change or withdraw your consent at any time here) or within your internet browser. 

Functional, analytical and marketing cookies are set on our website. 

  • Functional cookies – They provide the basic functionality of the site, the site cannot function without them.
  • Analytical cookies – They count website traffic and, by collecting anonymous statistics, allow the operator to better understand its visitors and thus continuously improve the site.
  • Marketing cookies – They collect information to better tailor advertising to your interests, both on and off this website.
 

We use cookies on the following websites: 

  1. krokitchen.cz
  2. almaprague.cz
  3. almawines.cz
  4. almawines.shop
  5. almawines.store
  6. krukarta.cz
 

YOUR RIGHTS

The Company is committed to ensuring that your rights are protected under applicable laws. Below you will find a table summarising your various rights: 

Right of access and rectification You may request a copy of your Personal Data that we hold about you. You also have the right to request the correction of inaccurate Personal Data or the completion of incomplete Personal Data. 
Right to erasure

Your right to be forgotten entitles you to request the erasure of your Personal Data if:

  1. the data is no longer needed for the purposes for which it was collected;
  1. you decide to withdraw your consent;
  1. you object to the processing of your Personal Data;
  1. your Personal Data has been processed unlawfully;
  1. there is a legal obligation to delete your personal data;
  1. deletion is necessary to ensure compliance with applicable law.
Right to restriction of processing

You may request that the processing of your Personal Data be restricted where:

  1. you deny the accuracy of your Personal Data;
  1. the Company no longer needs your Personal Data for the relevant processing purposes;
  1. you object to processing on legitimate grounds;
  1. the processing of your Personal Data is unlawful and you prefer to restrict its use rather than delete it.
Right to data portability

Alternatively, you may request the portability of your Personal Data that you have provided to the Company in a structured, commonly used and machine-readable format, and you have the right to transfer that data to another Controller, without the Company preventing it, if:

  1. the processing of your Personal Data is based on consent or contract; and
  1. this processing is carried out by automatic means.

You also have the right to request the transfer of your Personal Data to a third party of your choice (if technically feasible).

Right to object to processing You have the right to object (i.e. exercise your right to opt-out) to the processing of your Personal Data (in particular in relation to profiling or marketing communications). If we process your Personal Data on the basis of your consent, you have the right to withdraw your consent at any time.
Right to be excluded from automated decision-making You have the right not to be subject to decision-making based solely on automated processing, including profiling, which has legal consequences for you or significantly affects you.
Right to lodge a complaint

You can file a Complaint at your place of work or at the place of the alleged violation, regardless of whether you have suffered harm.

You also have the right to complain to the courts.

   

You can exercise any of the above rights or contact us with any questions or concerns about data protection at any time by sending an email to gdpr@krukarta.cz.

SECURITY 

We implement all possible technical and organisational security measures to ensure the security and confidentiality of the processing of your Personal Data.

To this end, we take all necessary measures, given the nature of the Personal Data and the risks associated with its processing, to maintain the security of the data and, in particular, to prevent its distortion, damage or unauthorised access by third parties (physical protection of the premises, authentication procedures using personal, secure access via identifiers and confidential passwords, recording of connections, encryption of certain data, etc.).

However, you also have a responsibility to ensure the security and confidentiality of your Personal Information, so we urge you to remain vigilant, especially when using an open system such as the Internet.

LINKS TO OTHER SITES 

Occasionally we provide links to other platforms for practical and informational purposes. These platforms operate independently of our Site and we have no control over them. These platforms have their own privacy policies or terms of use, which we encourage you to review. We assume no responsibility for the content of these platforms or for the products and services that may be offered on them or for their other uses.

UPDATES TO OUR ONLINE PRIVACY POLICY

We may update or change this policy as necessary. In this case, the changes will not become effective until 30 business days after the date of the change. To be notified of any changes, please check this page from time to time.

HOW TO CONTACT US

If you have any questions or comments about this Policy, please contact us at the following email address: gdpr@krukarta.cz.