Privacy policy

Information on the Processing of Personal Data under GDPR

of MARRON RACING s.r.o.
for the online store www.bikerect.cz

Valid and effective from 10 June 2026

1. Personal Data Controller

1.1. The controller of personal data within the meaning of Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council, the General Data Protection Regulation (hereinafter referred to as the "GDPR"), is:

MARRON RACING s.r.o.
registered office: building registration no. 106, 594 01 Velké Meziříčí, Czech Republic
Company ID No.: 278 17 989
VAT ID No.: CZ27817989
registered in the Commercial Register maintained by the Regional Court in Brno, Section C, Insert 85445

hereinafter referred to as the "Controller".

1.2. Contact details of the Controller:

address: building registration no. 106, 594 01 Velké Meziříčí, Czech Republic
e-mail: kolovesak@email.cz
telephone: +420 602 967 090

1.3. The Controller has not appointed a Data Protection Officer, as the Controller is not legally obliged to do so.

1.4. This English version is provided for information and practical use by foreign customers. In the event of any discrepancy between the Czech and English versions, the Czech version shall prevail.

2. When We Process Personal Data

2.1. We process personal data in particular when:

a) you submit an order in the online store at www.bikerect.cz,
b) you contact us by e-mail, telephone or contact form,
c) you provide additional information related to your order, such as the type or size of your bicycle,
d) we communicate with you about product compatibility, delivery, payment, a complaint or withdrawal from the contract,
e) we issue and archive accounting and tax documents,
f) you give consent to receive commercial communications or to the use of optional cookies, where such consent is required.

3. What Personal Data We Process

3.1. We process only personal data that is necessary for a specific purpose. This may include in particular the following categories of data:

a) identification data: name and surname, or company name, Company ID No. and VAT ID No.,
b) contact data: e-mail address, telephone number,
c) billing data: billing address and data necessary for issuing a tax document,
d) delivery data: delivery address and data necessary for handing over the shipment to the carrier,
e) order data: ordered goods, quantity, price, payment method, delivery method and order date,
f) payment data: information about the payment made, variable symbol, amount and payment status; payment card details are processed by the payment gateway provider, not by the Controller,
g) technical data related to the order: bicycle type, bicycle size, information about mudguards, tyres, frame or other information you provide to verify compatibility with the BIKERECT stand,
h) communication data: the content of e-mail, telephone or other communication related to an order, enquiry, complaint or customer support,
i) data related to complaints or withdrawal from the contract: description of the defect, photographs of the defect, order number, invoice number and bank account number for refund,
j) technical website data: IP address, device data, browser data and website behaviour data, if processed through cookies or similar technologies.

4. Purposes and Legal Bases of Processing

4.1. Order Processing and Performance of the Purchase Agreement

We process personal data for the purpose of receiving and processing orders, verifying product compatibility, confirming availability, communicating with the Buyer, arranging payment, delivering goods and fulfilling other rights and obligations arising from the purchase agreement.

The legal basis is the performance of a contract or the implementation of pre-contractual measures under Article 6(1)(b) GDPR.

Providing such data is necessary. Without it, we cannot process the order or deliver the goods.

4.2. Accounting, Taxes and Legal Obligations

We process personal data for the purpose of keeping accounting records, issuing and retaining tax documents, fulfilling tax obligations and complying with other legal obligations.

The legal basis is compliance with a legal obligation under Article 6(1)(c) GDPR.

4.3. Complaints, Withdrawal from the Contract and Customer Support

We process personal data for the purpose of handling complaints, withdrawal from the contract, refunds, customer enquiries and customer support.

The legal basis is the performance of a contract under Article 6(1)(b) GDPR, compliance with a legal obligation under Article 6(1)(c) GDPR and, where applicable, the legitimate interest of the Controller under Article 6(1)(f) GDPR.

4.4. Protection of the Controller's Legal Claims

We may also process personal data for the purpose of protecting our rights, resolving potential disputes, recovering claims and proving compliance with our obligations.

The legal basis is the legitimate interest of the Controller under Article 6(1)(f) GDPR.

4.5. Commercial Communications to Existing Customers

If you purchase from us, we may use your e-mail address to send commercial communications concerning our own similar products or services, provided that you have not refused such use during the order process or later.

The legal basis is the legitimate interest of the Controller under Article 6(1)(f) GDPR in connection with Act No. 480/2004 Coll., on Certain Information Society Services.

Each commercial communication will include a simple and free option to unsubscribe.

4.6. Newsletter and Commercial Communications to Persons Who Are Not Our Customers

If you are not our customer and you subscribe to our newsletter, we process your e-mail address on the basis of your consent.

The legal basis is consent under Article 6(1)(a) GDPR.

You may withdraw your consent at any time, for example by clicking the unsubscribe link in the e-mail or by sending a message to kolovesak@email.cz.

4.7. Cookies, Analytics and Marketing

We may use cookies and similar technologies on the website. Technical cookies are necessary for the proper functioning of the website and the online store.

Analytical, marketing or other optional cookies are used only if you give us your consent through the cookie banner or cookie settings.

The legal basis for technical cookies is the legitimate interest of the Controller in ensuring the functionality of the website under Article 6(1)(f) GDPR. The legal basis for optional cookies is consent under Article 6(1)(a) GDPR.

You may change or withdraw your cookie consent at any time in the cookie settings on the website, if this option is available.

5. Retention Period of Personal Data

5.1. We retain personal data only for as long as necessary for the relevant purpose.

5.2. Data related to an order and the purchase agreement is retained for the period necessary to process the order, deliver the goods, exercise rights arising from defective performance and protect legal claims.

5.3. Data contained in accounting and tax documents is retained for the period required by legal regulations, generally for 10 years from the end of the relevant tax period.

5.4. Data related to a complaint is retained for the period necessary to handle the complaint and subsequently for the period necessary to protect legal claims.

5.5. If you only contact us with an enquiry and no contract is concluded, we retain your data for the period necessary to deal with the enquiry, generally no longer than 1 year from the last communication, unless there is another legal reason for longer retention.

5.6. Data processed on the basis of consent is retained for the duration of the consent, but no longer than until the consent is withdrawn.

5.7. After the relevant retention period expires, we delete or anonymise personal data, or retain it only to the extent required by legal regulations or the protection of our legal claims.

6. To Whom We Disclose Personal Data

6.1. We disclose personal data only to the necessary extent and only to persons or entities that need the data to provide a specific service or comply with a legal obligation.

6.2. Recipients or processors of personal data may include in particular:

a) the provider of the online store and website solution: Webnode AG,
b) carriers and delivery companies, especially DPD or other carriers selected for shipment delivery,
c) payment service providers and payment gateway providers, if you choose payment by card or another online payment method,
d) banks, if you choose payment by bank transfer or if we refund your payment,
e) providers of invoicing, accounting and economic systems,
f) external accountants or tax advisors,
g) providers of IT services, hosting, security and technical support,
h) providers of analytical and marketing tools, if such tools are used on the website and the required consent has been granted,
i) public authorities, if we are required to do so by law.

6.3. We do not sell personal data to third parties and we do not publish personal data.

6.4. If personal data is transferred outside the European Economic Area, such transfer takes place only in accordance with the GDPR, in particular on the basis of an adequacy decision of the European Commission, standard contractual clauses or another appropriate legal mechanism.

7. Webnode and Technical Operation of the Online Store

7.1. The online store www.bikerect.cz is operated through the Webnode platform.

7.2. Webnode, as the provider of the technical solution, may process personal data stored within the online store, in particular data from orders, forms and website operation, in accordance with contractual and statutory personal data protection rules.

7.3. Details of data processing by the Webnode platform are governed by Webnode's documentation and contractual terms.

8. Automated Decision-Making and Profiling

8.1. We do not use automated individual decision-making that would have legal effects concerning you or similarly significantly affect you.

8.2. If we use analytical or marketing tools, they may be used for basic evaluation of website traffic, advertising performance or visitor interests. Such processing takes place only to the extent permitted by law and according to cookie settings.

9. Your Rights

9.1. In connection with the processing of personal data, you have the following rights under the conditions set out in the GDPR:

a) the right of access to personal data,
b) the right to rectification of inaccurate or incomplete personal data,
c) the right to erasure of personal data if there is no longer a legal reason for further processing,
d) the right to restriction of processing,
e) the right to data portability,
f) the right to object to processing based on legitimate interest,
g) the right to object to processing for direct marketing purposes,
h) the right to withdraw consent if the processing is based on consent,
i) the right to lodge a complaint with a supervisory authority.

9.2. If you object to processing for direct marketing purposes, we will no longer process your personal data for that purpose.

9.3. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

9.4. You may exercise your rights by e-mail at kolovesak@email.cz or in writing at the Controller's address:

MARRON RACING s.r.o.
building registration no. 106
594 01 Velké Meziříčí
Czech Republic

9.5. The supervisory authority is:

Office for Personal Data Protection
Pplk. Sochora 27
170 00 Prague 7
Czech Republic
website: www.uoou.cz

10. Security of Personal Data

10.1. The Controller has adopted appropriate technical and organisational measures to protect personal data against unauthorised access, misuse, loss, destruction or damage.

10.2. Access to personal data is granted only to persons who need such access to perform their work or contractual duties and who are bound by a duty of confidentiality.

10.3. The website uses secure data transmission through the HTTPS protocol, provided that this function is active within the website solution.

10.4. Personal data is protected in particular by restricted access rights, the use of passwords, technical security of devices and appropriate management of user access.

11. Order Form and Confirmation of Acknowledgement

11.1. By submitting an order, you confirm that you have read this Privacy Policy.

11.2. This confirmation does not constitute consent to the processing of personal data for the purpose of processing the order. The processing of data necessary for the order is carried out mainly for the performance of the contract and compliance with legal obligations.

11.3. Separate consent may be required only for purposes where consent is the legal basis, for example for sending newsletters to persons who are not customers or for the use of optional analytical and marketing cookies.

12. Changes to This Privacy Policy

12.1. The Controller is entitled to amend or supplement this Privacy Policy.

12.2. The current version of this Privacy Policy will always be published on the website www.bikerect.cz.

12.3. This version of the Privacy Policy becomes effective on 10 June 2026.