PRIVACY POLICY
We are a company Testuj.to s.r.o., with registered office at Karolinská 706/3, Karlín, 186 00 Prague 8, ID No.: 07652780 (hereinafter also "we"), which connects manufacturers and sellers of products sold on the market ("Clients") with you, who try, test and evaluate their products. The connection between the two parties takes place on our website https://www.testuj.to/ ("Website"), through which we provide our Services to you.
Capitalized terms have the same meaning as terms used in the Terms and Conditions unless otherwise defined in this Privacy Policy ("Policy").
In this document, you will learn how we process your personal data, why we do so, with whom we share your personal data or what your rights are in relation to the protection of your personal data.
The processing of personal data is governed by Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC ("GDPR").
A. Personal data we process
We process your personal data only to the extent necessary to provide our Services. We obtain your personal data primarily through the User Account that you create through the registration form. We also process your personal data when you want to sign up for product testing. For clarity, we have divided the personal data we process into the following categories:
- Identification datawhich is your name, gender, age, date of birth, additional information about your user account, profile photo.
- Contact detailswhich is your home address, email address and telephone number.
- Social media datawhich are the link to your profile on the social network and the number of your followers on the social network.
- Data related to product testingwhich includes the content of reviews, information about your preferences and experience using products similar to the product you are testing, information about what products you want to test, information about your use of the product you are testing, photos and videos, and other information related to the completion of the logged testing.
- Data related to market researchwhich includes information about the number of people in your household, the amount of household income, the number and gender of children in the household, a description of your interests and favourite leisure activities, information about your occupation at work, information about your lifestyle, etc. All this information is provided voluntarily and is not dependent on the establishment of a relationship.
- Health data and other sensitive datasuch as information about possible pregnancies, information about preferences related to health, sex life or sexual orientation, and other special categories of personal data that may be relevant to ensure testing of specific products.
- Data contained in the communication, i.e. the information you provide in the email communication, contact form, or other information we exchange during the communication.
- Cookies and other technical datawhich is data obtained from technical files and similar tools and technologies that we use for the purposes described below.
B. Purposes of the processing of personal data
We process your personal data as a data controller for the following processing purposes:
Processing of Personal Data in connection with the provision of our Services through the App
B.1 Provision of Services and related information
We primarily process personal data to provide you with our Services in accordance with the Terms and Conditions and to fulfil our obligations to you as a User. This processing includes the use of personal data for the purposes of creating a user account, entering into a contract, communicating in connection with the provision of the Services and entering into a contract, and providing the Services (in particular, arranging product testing) to the extent that it does not interfere with the purposes set out in clause B.2 of this Policy, transmitting information to the company for which the testing is being carried out for the purpose of sending products and arranging any communications in connection with the testing. Our communications with each other may include communications via the Website, email, or SMS messages, as applicable, where we may send you notifications regarding product orders, notifications of upcoming review deadlines, and other communications related to the provision of the Services.
For this purpose, we process your Identification Data, Contact Data, Data from social networks, Data related to product testing, Data contained in communications.
The legal basis for this processing is the performance of the contract between you and us and the necessity to take steps at your request before entering into the contract. The data is processed for the duration of the concluded contract and for the time necessary for the performance of the obligations under such contract.
The provision of the Services may involve products that by their nature may be problematic for certain groups of people, either on the basis of health or current condition. At the same time, other specific information about particular segments may also be relevant to the Clients for whom testing is being conducted. For this reason, we may also require Health Information and other sensitive information as part of the completion of the testing form. These special categories of personal data will be processed on the basis of your explicit consent within the meaning of Article 9(1)(a) GDPR. However, this consent will be mandatory for the provision of the specific Service, as without it, unreasonable harm could arise or the terms of the contractual relationship between us and the Clients for whom we are providing testing could not be fulfilled. Consent is granted for the duration of the provision of the Services or the specific testing.
If you do not comply with the terms and conditions for publishing reviews regarding testing, we may intervene in the text of your review to ensure that the content of the review complies with the law and the contract we have entered into between us.
B.2 Market research, target group identification and marketing
We may also process your data for the purpose of conducting market research, market behaviour and preferences of our Users and for marketing purposes of our Clients, who may send you product offers or other marketing communications based on your consent. In order to more accurately offer the tested products to the right target group and to better prepare and offer the Services to you, we may also use your personal data to distinguish which target group you belong to based on the information you provide. Processing for this purpose may involve automated decision making, including profiling of your personal data.
For this purpose, we process your Identification Data, Contact Data, Social Media Data, Data related to product testing, Data related to market research, Health Data and other sensitive data, Data contained in communications.
The legal basis for this processing is your consent to the processing of this personal data, which you can withdraw at any time. Even if you withdraw your consent, the processing carried out prior to the withdrawal of your consent is lawful. We will process this data for as long as your consent exists, but for a maximum period of 5 years from the date of consent. Data related to market research may subsequently be shared with third parties, in particular our Clients.
B.3 Protecting our rights and legal interests
We may process your data to protect our rights and legal interests. In particular in connection with proceedings before judicial authorities and other public authorities, or in connection with the internal handling of your claims.
For this purpose, we process your Identification Data, Contact Data, Data from social networks, Data related to product testing, Data contained in communications.
The legal basis for this processing is our legitimate interest in the protection of our rights. The data is processed until a maximum of 10 years after the termination of the concluded contract (or longer in the event of a dispute), or for a maximum of 5 years after the collection of personal data if no contract has been concluded.
On the basis of the consent given in section B.1. of this Policy for the purpose of using Health Data and other sensitive data, we may also use these special categories of personal data to protect our own legal claims, in particular in situations where inaccurate data would be provided and harm would occur, both on our side and on the side of the Client.
B.4 Compliance with legal obligations
We may also process your personal data in order to comply with our legal obligations, particularly in the areas of accounting and tax. This may be the case if we receive payments from you that you may be obliged to pay if you fail to comply with your obligations under the terms and conditions.
For this purpose, we process your Identification Data, Contact Data, Data from social networks, Data related to product testing, Data contained in communications.
The legal basis for this processing is the performance of our legal obligations. The data is processed for the period of time required by law, for example in the field of taxation for up to 10 years.
B.5 Sending commercial communications
We may also use your personal information to send you offers related to our Services and our company. We will send you commercial communications provided that you do not consent to such communications. That is, you may choose not to receive commercial communications before completing your user account registration.
For this purpose, we process your Identification Data and Contact Data (email address).
The legal basis for this processing is our legitimate interest, which is direct marketing. We will process your personal data until you opt-out of receiving commercial communications from us, which you can do in each individual email. Opting out is deemed to be an objection in relation to direct marketing.
B.6 Ensuring communication
Through our Website you can contact us via chat, use the contact email, fill in one of the forms available on the Website, etc. Subsequently, communication between you and us may take place. In this case, we will process your personal data for the purpose of ensuring mutual communication.
For this purpose, we process your Identification Data, Contact Data, Data contained in communications.
The legal basis is our legitimate interest, which is to ensure communication with you. The personal data is stored for the time necessary for the processing of mutual communication or, if a contractual relationship is established, for the duration of the contractual relationship.
Cookies
B.7 Website operation and security (necessary)
We also process your personal data for the purpose of the basic functioning and operation of the Website, its stability and security, to improve the user experience, for the internal functioning of the Website, your identification as a user when using the User Account and during your repeated visits to the Website.
For this purpose, we process cookies and other technical data that may be stored on your device with which you access the Website and your User Account.
The legal basis for this processing is our legitimate interest in the proper functioning and safe operation of our Website. The data is generally processed for the duration of your visit to the Website, but at most for a period of 1 year from the date of collection.
B.8 Website traffic and usage analysis (analytics)
We process your personal data to understand how visitors use our Website. As part of this, we may track traffic to the Website, your user behaviour on the Website, optimise the Website and generally make your visit to the Website smoother and more user-friendly.
We process cookies and other technical data for this purpose.
The legal basis for the processing of cookies and other technical data is your consent given via the cookie bar. Personal data is processed until your consent is withdrawn, but in any case for a maximum of 1 year after your visit to the Website. In the course of this processing, your personal data may also be passed on to third parties, in particular providers of analytical tools and cookies.
B.9 Promotion Website (marketing)
With your consent, we may process cookie data for this purpose to help us get to know you better and to better target advertising (marketing cookies). In this case, your personal data may be passed on to third parties.
The legal basis for the processing is therefore your consent given via the cookie bar. Personal data is processed until your consent is withdrawn, but in any case for a maximum of 1 year after your visit to the Website.
C. Sharing of personal data
We process the above personal data as so-called data controllers. Thus, we determine the purposes and means of processing. We are the ones who decide what personal data we require from you within the User Account.
In some cases, however, we process your personal data as so-called personal data processors. This occurs in particular when processing Data related to product testing. In such cases, the scope of the processed data and the reason for processing it is determined by our Clients, for whom we carry out the testing in cooperation with you. Therefore, in cases where one of our Clients is the data controller, this Client will inform you about the processing of your data. You can also exercise your rights under the GDPR against them in such a case.
We may also use third parties to process personal data to help us provide our Services or in some situations we may be required to share personal data. These third parties act as so-called recipients of personal data. Specifically, they are:
- Clients (providers of tested products), in particular for the purpose of sending products for the purpose of providing the Service;
- providers of systems that send emails, text messages and commercial communications;
- provider of the SMS alerting tool;
- the provider of the SMS phone number verification tool;
- a system provider that provides us with a marketing management, sales support and customer care application;
- providers of accounting and tax-related services;
- translation service providers;
- cloud storage and infrastructure providers;
- providers of cookies and tools used for marketing purposes and to analyse traffic and user behaviour within the website;
- the company that mediates our communication with you and other users of our services;
- Amazon Web Services, Inc., which provides us with cloud services. This company is registered with the Data Privacy Framework under its parent company Amazon.com, Inc;
- Microsoft Ireland Operations Limited, providing cloud storage services and analytics tools. If personal data is shared with Microsoft Corporation, that company is registered with the Data Privacy Framework;
- Google Ireland Limited, which provides us with analytics tools. If personal data is shared with Google LLC, it is registered with the Data Privacy Framework;
- Mixpanel, Inc., which provides us with a product analysis tool. This company is registered with the Data Privacy Framework.
In addition to this, we may share your personal data with certain third parties as data controllers for the purpose of "Fulfilling Legal Obligations" where we are obliged to do so under applicable legislation (in particular, administrative authorities, police authorities and judicial authorities). Similarly, we may be obliged to share your data with persons (e.g. providers of products tested) who claim to have been harmed by your conduct.
Where we share your personal data with controllers and processors in third countries (outside the EEA), we only do so where there is a decision by the European Commission that a particular country outside the EEA provides an adequate level of data protection, including where controllers or processors have adopted additional data protection measures such as Binding Corporate Rules (BCRs) or Standard Contractual Clauses (SCCs).
D. Your rights in processing and the possibility of exercising them
Just as we have rights and obligations when processing your personal data, you have certain rights when processing your personal data as set out in the following paragraphs. You have the right to (i) request access to your personal data; (ii) withdraw your consent; (iii) request rectification of your personal data; (iv) request erasure of your personal data; (v) request restriction of the processing of your personal data; (vi) request portability of your personal data; (vii) object to the processing of your personal data; or (viii) lodge a complaint with the relevant supervisory authority.
For all issues related to the processing of your personal data, whether it is a question, exercise of rights, sending a complaint to us, etc., you can contact us via chat on the Website or by email at testovani@testuj.to.
Your request will be processed without undue delay, at most within 1 month. In exceptional cases, in particular due to the complexity of your request, we are entitled to extend this period by a further 2 months. We will, of course, always inform you of any such extension and the reason for it.
You also have the right to lodge a complaint with the supervisory authority as described below.
D.1 Right of access
You have the right to obtain confirmation from us as to whether or not we are processing your personal data.
If we process your personal data, you also have the right to request access to information about the purpose and scope of the processing, the recipients of the data, the duration of the processing, the right to rectification, erasure, restriction of processing and objection to processing, the right to lodge a complaint with a supervisory authority and the sources of personal data (this information is already provided in this document).
You can also ask us for a copy of the personal data we process. We provide the first copy free of charge; further copies may be subject to a fee. The scope of the data provided may be limited so as not to interfere with the rights and freedoms of others.
D.2 Right to withdraw consent
You have the right to withdraw your consent to the processing of personal data at any time. However, the withdrawal of consent does not affect the lawfulness of the processing prior to the withdrawal of such consent, nor does it lead to the termination of the processing of personal data that has already been anonymised. In the event that consent is withdrawn within the meaning of purpose B.1. of this Policy, this may result in you not being able to participate in the testing for which you have signed up.
D.3 Right to repair
You have the right to request us to correct inaccurate personal data concerning you. Depending on the purpose of the processing, you may also have the right to have incomplete personal data completed, including by providing an additional declaration.
D.4 Right to erasure (right to be forgotten)
You have the right to request the deletion of your personal data in cases where:
- We no longer need your personal data for the purposes for which it was collected or processed;
- you withdraw the consent on the basis of which the personal data was processed and there is no further reason for processing it:
- you object to processing and there are no other overriding reasons for processing, or you object to processing for direct marketing purposes;
- personal data is processed in violation of the law.
However, you cannot exercise this right where the processing is necessary for compliance with our legal obligations or tasks entrusted to us in the public interest or for the establishment, exercise or defence of legal claims.
D.5 Right to restriction of processing
You have the right to request restriction of the processing of your personal data in cases where:
- you contest the accuracy of your personal data; in this case, you may request a restriction of processing until the accuracy of the personal data has been verified;
- the processing is in breach of the law and instead of erasure you request a restriction of the processing of personal data;
- We no longer need your personal data for the purposes for which it was collected or processed, but you require it for the establishment, exercise or defence of legal claims;
- you have objected to the processing of your personal data; in this case, you may request a restriction of processing until it is verified that our legitimate interests prevail.
D.6 Right to portability
You have the right to obtain a copy of your personal data that we process by automated means on the basis of your consent or for the performance of a contract. We will transmit this data in a commonly used and machine-readable format to you or to a controller designated by you, if technically feasible. The scope of the data provided may be limited so as not to interfere with the rights and freedoms of others.
D.7 Right to object
You have the right to object to the processing of your personal data that we process on the basis of our legitimate interest. We will stop processing your data if there are no other overriding reasons for processing or if the processing is not necessary for the establishment, exercise or defence of legal claims or if you object to processing for direct marketing purposes.
E. Right to lodge a complaint
In addition to the possibility of exercising your rights with our company, you can also file a complaint with the relevant supervisory authority, which is the Office for Personal Data Protection located at Pplk. Sochora 27, 170 00 Prague 7.
F. Changes to this processing information
This Policy is effective as of July 30, 2024 We may change this Processing Information from time to time, so please check it regularly. We will post any changes to this document on our Website.
