Privacy policy

PRIVACY POLICY

 

Effective date: October 16, 2025

Data Controller (Operator):

Johanka Valášková

OhradnĂ­ 30/903, 140 00 Prague 4, Czech Republic

Business ID (IÄŚ): 14311640

E-mail: info@newcastanets.com

(referred to as “Controller”, “we”, or “us”)


These Privacy Policy rules describe how we collect, use, and protect the personal data of customers, website users at https://newcastanets.shop, and participants in our courses and memberships (collectively referred to as the “Services”).

We take the protection of your personal data seriously and comply with Regulation (EU) 2016/679 (GDPR) and related data protection laws.

 

1. WHO IS THE DATA CONTROLLER AND CONTACT INFORMATION

The controller of your personal data is Johanka Valášková.

For any questions or requests regarding personal data, please contact us at info@newcastanets.com or by post at the address above.


The platform Shopify Inc. (151 O’Connor Street, Ottawa, Canada) provides hosting and technical processing of data.

Shopify acts as a data processor and has entered into a data processing agreement with us based on EU Standard Contractual Clauses (SCCs).

Read more about Shopify’s privacy policy: https://www.shopify.com/legal/privacy

 

2. PERSONAL DATA WE COLLECT

We only collect data necessary to provide our Services, including:

  • Identification and contact details (name, e-mail, address, phone number)
  • Billing and payment details (payment method, transaction data)
  • Order information (purchase history of courses and products)
  • Account information (username, password – stored in encrypted form)
  • Communication with us (emails, messages, social media correspondence)
  • Technical data (IP address, cookies, browser type, visit duration, referral source)
  • Marketing and consent data (newsletter subscription, cookie consent, waiting list participation, etc.)

 

3. HOW WE OBTAIN PERSONAL DATA

We may collect data:

  • directly from you when you make an order or register for a course,
  • when you subscribe to our newsletter or waiting list,
  • automatically when you visit our website (via cookies and analytics tools),
  • from our data processors (Shopify, payment providers such as Shopify Payments, PayPal, or carriers such as DHL, Zásilkovna).

 

4. PURPOSES AND LEGAL BASES FOR PROCESSING

Purpose of Processing

Legal Basis

Contract performance (courses, memberships, castanet orders)

Art. 6(1)(b) GDPR

Fulfilling legal obligations (accounting, tax compliance)

Art. 6(1)(c) GDPR

Legitimate interest (security, website improvement, analytics)

Art. 6(1)(f) GDPR

Marketing and newsletters (based on consent or existing relationship)

Art. 6(1)(a)/(f) GDPR

Processing based on explicit consent (e.g. cookies for ads or measurement)

Art. 6(1)(a) GDPR

You may withdraw your consent at any time by clicking the unsubscribe link in our emails or by contacting us at info@newcastanets.com.

 

5. COOKIES AND ANALYTICS

Our website uses cookies to ensure functionality, measure traffic, and personalize advertising.

We use in particular: Google Analytics, Meta Pixel (Facebook), and Shopify Analytics.


  • Essential cookies: necessary for cart, checkout, and core website functions.
  • Analytics cookies: help us improve website performance and user experience.
  • Marketing cookies: used only with your consent for personalized advertising (e.g., on social networks).

 

You can manage or disable cookies in your browser settings. More information is available in our [cookie banner].

 

6. DATA SHARING AND DISCLOSURE

We share your data only with trusted and verified partners:

  • Shopify Inc. (hosting and e-commerce platform),
  • Payment providers: Shopify Payments, PayPal,
  • Carriers: DHL, Zásilkovna, and others,
  • Accounting and tax advisors,
  • Email marketing tools: SmartEmailing, MailerLite (or equivalent),
  • Advertising and analytics partners: Google, Meta Platforms, YouTube, etc.

 

All data processors are bound by confidentiality and GDPR-compliant data processing agreements ensuring the same level of protection as required by EU law.

 

7. DATA TRANSFER OUTSIDE THE EU

Data is primarily processed within the European Union.

If data is transferred outside the EU (e.g. through Shopify, Google, Meta), such transfers occur under EU Standard Contractual Clauses (SCCs) that guarantee an adequate level of protection.

 

8. DATA RETENTION PERIOD

  • Accounting and contractual data: 10 years (in accordance with tax laws)
  • Membership and account data: for the duration of membership + 1 year after termination
  • Marketing data (newsletter consent): 5 years or until consent is withdrawn
  • Technical and analytics data: according to cookie settings (maximum 26 months)

 

9. YOUR RIGHTS UNDER GDPR

You have the following rights under the GDPR:

  • Right of access and to obtain a copy of your data
  • Right to rectification of inaccurate data
  • Right to erasure (“right to be forgotten”)
  • Right to restriction of processing
  • Right to data portability
  • Right to withdraw consent at any time
  • Right to object to processing (especially to direct marketing)

 

You may exercise your rights by contacting info@newcastanets.com.

We will respond without undue delay, no later than within 30 days.


If you believe your data is being processed unlawfully, you have the right to lodge a complaint with the Office for Personal Data Protection (Úřad pro ochranu osobních údajů):

 www.uoou.cz

 

10. DATA SECURITY

Your personal data is stored in secure systems and accessible only to persons who need it to perform their duties.

We use encrypted connections (HTTPS), secure payment gateways, and internal data protection policies.

Although no transmission over the Internet can be guaranteed to be 100% secure, we take all reasonable technical and organizational measures to protect your data.


11. CHANGES TO THIS POLICY

This policy may be updated from time to time to reflect legal changes or adjustments in our Services.

The latest version is always available at https://newcastanets.shop/privacy-policy.

Significant changes will be communicated via e-mail or upon your next visit to our website.

Â