Personal Data Protection
This policy describes how SENTORA ONE s.r.o. handles the personal data of visitors and customers of the store https://sentora.one, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation, „GDPR“) and Act No. 110/2019 Coll., on the Processing of Personal Data.
1. Data controller
- Controller: SENTORA ONE s.r.o.
- Company reg. no. (IČO): 29850746
- Registered office: Barákova 561/79, Božkov, 326 00 Plzeň
- Contact for personal data matters: info@sentora.one
A data protection officer has not been appointed: neither the scope nor the nature of the processing requires one.
2. What data we process, why and on what basis
a) Handling the order and performing the contract
- Data: name and surname, delivery address, e-mail, phone, order content, payment data (not card numbers) and delivery data.
- Legal basis: performance of the contract (Art. 6(1)(b) GDPR); the subsequent retention of documents fulfils a legal obligation (Art. 6(1)(c) GDPR).
- Period: for the duration of handling the order and the warranty periods; invoices and other accounting records for 5 years from the end of the accounting period to which they relate (Section 31 of Czech Act No. 563/1991 Coll., on Accounting), or longer where the time limit for assessing tax requires it (Czech Act No. 280/2009 Coll., the Tax Code).
- Providing the data is a contractual requirement: without it the order cannot be processed.
b) Customer account
- Data: e-mail, password (stored exclusively as a secure hash, scrypt), name, order history, favourite products, basket content; when signing in via Google, the identifier and e-mail of the Google account.
- Legal basis: performance of the contract (maintaining the account at your request).
- Period: until the account is cancelled; thereafter anonymisation or erasure, unless a legal obligation prevents it.
c) Newsletter
- Data: e-mail, date and source of the consent given.
- Legal basis: consent (Art. 6(1)(a) GDPR), given by actively subscribing.
- Period: until the consent is withdrawn: you can unsubscribe at any time via the link in every commercial e-mail; thereafter we no longer process the e-mail for this purpose.
d) Commercial communications to customers (legitimate interest)
- We may send customers communications relating to similar goods (including reminders of an unfinished order) to their e-mail on the basis of a legitimate interest (recital 47 GDPR, Section 7(3) of Act No. 480/2004 Coll.). You can object to this processing at any time free of charge: an unsubscribe link is in every such e-mail.
e) Contact form and communication
- Data: name, e-mail, possibly phone and the content of the message.
- Legal basis: legitimate interest in handling your query (Art. 6(1)(f) GDPR); for queries relating to a contract, performance of the contract.
- Period: for the duration of handling and a reasonable period thereafter (usually 1 year).
f) Product reviews
- Data: chosen name, e-mail, content of the review.
- Legal basis: legitimate interest (transparent evaluation of the offer); we publish reviews after approval.
- For the “like” voting on reviews, the browser stores a randomly generated identifier (localStorage) so that each visitor can vote only once. The identifier contains no personal data and cannot be linked to a specific person.
g) Cookies and traffic measurement
We always use necessary cookies (running the store: sign-in, basket, storing your consent choice). We activate analytical and marketing cookies only with your consent given in the cookie bar; consent can be changed at any time in the website footer („Cookie settings“). Google tools (Tag Manager, Analytics, Google Ads), Microsoft Clarity and Meta load on the page only after you consent to the category they belong to; until then the website does not run them at all and sends them no data. Withdrawing consent stops them from running again. A detailed overview, including validity periods, is contained in the Cookie Policy.
We measure website traffic with our own cookieless solution: to distinguish unique visits, the server stores only a salted fingerprint (hash) of the IP address and browser that changes every day. The fingerprint cannot be converted back into an IP address, cannot be linked across days, and no personal data is stored in the process. The legal basis is our legitimate interest in a basic overview of traffic (Art. 6(1)(f) GDPR).
We additionally use Vercel Web Analytics, provided by our hosting provider Vercel Inc., which is likewise cookieless and stores nothing in your browser. A visit is distinguished only by a fingerprint (hash) derived from the incoming request, which is discarded after 24 hours, and we only look at aggregate figures (pages viewed, traffic source, device type, country). Before sending, we strip every parameter from page addresses except advertising campaign tags (utm). The legal basis is likewise our legitimate interest (Art. 6(1)(f) GDPR).
3. Recipients and processors
We pass on data only to the extent necessary for the given purpose to the following categories of recipients:
- Stripe Payments Europe, Limited: processing of online payments (an independent controller for the payment transaction),
- Zásilkovna s.r.o. (Packeta) and its partner carriers: delivery of consignments (name, address, phone, e-mail),
- Vercel Inc.: hosting and operation of the website, and aggregate cookieless traffic and site speed measurement (Vercel Web Analytics, Vercel Speed Insights),
- MongoDB, Inc. (Atlas): database infrastructure,
- Google Ireland Limited: signing in with a Google account (only if you choose it); when consent to analytical/marketing cookies is given, also Google tools (Tag Manager, Analytics, Google Ads),
- Microsoft Ireland Operations Limited: Microsoft Clarity (anonymised session replays and heatmaps), only with consent to analytical cookies,
- Meta Platforms Ireland Limited: conversion measurement and ad targeting on Facebook and Instagram, only with consent to marketing cookies. To match a purchase to an ad we transmit your e-mail and phone number solely as an irreversible hash (SHA-256), never in readable form,
- Váš Hosting s.r.o. (Czech Republic): e-mail mailboxes and the sending of transactional and commercial e-mails,
- accounting and tax advisers, legal representatives and public authorities, where required by law.
We have concluded data processing agreements with the processors in accordance with Art. 28 GDPR. Some providers may process data outside the EU/EEA as well (in particular the USA); in such a case the transfer is based on a Commission adequacy decision (the EU-U.S. Data Privacy Framework) or on standard contractual clauses.
4. Your rights
- Right of access: confirmation of whether we process data and a copy of the data (Art. 15),
- Right to rectification of inaccurate data or completion of incomplete data (Art. 16),
- Right to erasure („to be forgotten“), unless a legal obligation or another overriding ground prevents it (Art. 17),
- Right to restriction of processing (Art. 18),
- Right to portability of data processed on the basis of a contract or consent (Art. 20),
- Right to object to processing on the basis of a legitimate interest, including direct marketing: following an objection to direct marketing we always cease it (Art. 21),
- Right to withdraw consent at any time, without affecting the lawfulness of the earlier processing.
You can exercise your rights at info@sentora.one. We will respond without undue delay, at the latest within one month (in complex cases the deadline may be extended by a further two months, we would inform you of this). Submission is free of charge; in the case of manifestly unfounded or excessive requests we may charge a reasonable fee or refuse the request.
You also have the right to lodge a complaint with the supervisory authority: the Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Praha 7, uoou.gov.cz.
5. Automated decision-making and profiling
We do not carry out any automated decision-making or profiling that would have legal or similarly significant effects for you.
6. Security
We protect data with technical and organisational measures: all communication is encrypted (HTTPS/TLS), passwords are stored exclusively as secure hashes, access to the systems is controlled and limited to necessary persons. We have no access to payment card data: it is processed exclusively by the Stripe payment gateway.
7. Changes to this policy
We may update the policy, for example when providers or the legal framework change. The current wording is always available on this page; we will inform registered customers of any substantial changes.
This policy takes effect on 15 September 2026.
