Privacy policy

This English translation is provided for convenience. The Czech version is legally binding.

Účinné od: 11. července 2026
Poslední aktualizace: 11. července 2026

This Privacy Policy explains how Essentials Vault processes personal data when you visit https://essentialsvault.eu, make a purchase, communicate with us or receive marketing.

1. Controller and contact details

The personal data controller is:

  • HofMark s.r.o., IČO 297 39 560
  • registered office Nové sady 988/2, Staré Brno, 602 00 Brno
  • privacy email support@essentialsvault.eu

No data protection officer has been appointed.

2. Personal data we process

Depending on how you use the online store, we process in particular:

  • identification and contact details (name, address, email, telephone number, billing details);
  • order, payment, shipping, return, complaint and communication data;
  • customer account and preference data;
  • technical and operational data (IP address, device, browser, security logs);
  • website usage data and marketing identifiers, only to the extent permitted by your cookie settings;
  • review content or other content you provide to us voluntarily.

We do not store full payment card details. The payment service provider processes them.

3. Purposes, legal bases and retention periods

Purpose Typical data Legal basis Indicative period
Purchase, payment, delivery, account and customer service contact, order and transaction data performance of a contract / pre-contractual steps, čl. 6 odst. 1 písm. b) GDPR for the term of the contract and then usually 3 years for ordinary claims, or longer in the event of a dispute
Accounting, taxes and statutory records billing and transaction data legal obligation, čl. 6 odst. 1 písm. c) usually 5 or 10 years depending on the document and applicable law
Returns, complaints, fraud and protection of rights order, communications, evidence and risk indicators contract, legal obligation and legitimate interest, čl. 6 odst. 1 písm. b), c), f) for the handling period and then usually 3 years, or until final resolution in the event of a dispute
Online store security IP, device and logs legitimate interest in security, čl. 6 odst. 1 písm. f) usually no more than 12 months, and longer only in the event of a security incident or legal claim
Offers of our own similar goods to existing customers email and purchase history § 7 odst. 3 zákona č. 480/2004 Sb. and legitimate interest, always with a simple opt-out until you opt out, but no longer than 3 years after the last purchase or relevant activity
Newsletter for subscribers email and proof of consent consent, čl. 6 odst. 1 písm. a) GDPR and § 7 zákona č. 480/2004 Sb. until consent is withdrawn or 3 years after the last verifiable activity. Proof of consent is retained for the period necessary to defend a claim
Personalisation, measurement and advertising cookie ID, IP, website behaviour and conversions consent, čl. 6 odst. 1 písm. a) GDPR. Storage and access to cookies are also governed by electronic communications law according to the cookie table and until consent is withdrawn
Abandoned cart email, cart contents and activity marketing consent or the statutory rules for contacting an existing customer. A service message is sent only to the extent necessary for pre-contractual steps reminder data for no more than 30 days unless another legal basis applies
Reviews name/alias, order and content consent or legitimate interest in verified reviews, depending on the process for the publication period and for a reasonable period afterwards for record-keeping

These periods are maximum time frames. We delete or anonymise data sooner if it is no longer needed. Statutory archiving and protection of specific claims take priority.

4. Marketing

4.1. We send newsletters to people who are not customers only with their active consent. Consent is not a condition of purchase and may be withdrawn at any time using the link in the email or by contacting the controller.

4.2. Subject to statutory conditions, we may send existing customers offers for our own similar goods. A free and simple opt-out must be available when we obtain the contact details and in every message.

4.3. Marketing and analytics cookies do not run before consent. Refusal must not prevent a basic purchase. Consent can be changed through the “Cookie settings” link available on the website.

4.4. If we use personalisation or create advertising audiences, we may profile purchasing and browsing behaviour. We do not make decisions based solely on automated processing that have legal or similarly significant effects unless the customer receives specific information in advance.

5. Recipients and service providers

We disclose data only to the extent necessary, particularly to the following categories of recipients:

  • Shopify as the online store and hosting platform;
  • payment providers displayed at checkout;
  • carriers and collection point networks selected by the customer at checkout;
  • Klaviyo for email, automation and customer communications;
  • accounting, tax and legal advisers;
  • IT, security, support and cloud service providers;
  • active analytics and advertising platforms, particularly Google or Meta, only if deployed on the website and the customer has given the relevant cookie consent;
  • public authorities where required by law.

The specific recipient depends on the selected payment and shipping methods and the tools currently active. We enter into the required arrangements with processors under čl. 28 GDPR. On request, we will provide more information about recipients relevant to specific processing.

6. Transfers outside the EEA

Some providers may process data outside the European Economic Area, particularly in the USA or Canada. We base transfers on a European Commission adequacy decision, including the EU–US Data Privacy Framework if the recipient is certified, standard contractual clauses or another statutory safeguard. On request, we will provide more information about the safeguard used.

The specific transfer mechanism depends on the provider’s current contracting entity and settings. We will provide more information on request.

7. Cookies

We use:

  1. necessary cookies for the cart, checkout, security, market selection and cookie preferences. These operate without consent and only to the extent necessary;
  2. analytics cookies for traffic and performance measurement, only with consent;
  3. marketing and personalisation cookies for advertising, audiences and personalisation, only with consent.

A detailed cookie table must be generated from the scripts actually deployed and must state at least the name, provider, purpose, duration and category. General text without a cookie inventory is insufficient. Browser settings do not replace the option to refuse cookies in the banner.

8. Data sources

We obtain data directly from you, from your use of the online store, from payment and shipping partners and, where lawful, from advertising or analytics partners. We do not obtain data from public sources for unsolicited marketing.

9. Your rights

You have the right to:

  • obtain confirmation and access to your data;
  • request correction of inaccurate data;
  • request deletion where the conditions are met;
  • request restriction of processing;
  • receive data in a portable format where processing is based on a contract or consent and carried out by automated means;
  • object to processing based on legitimate interest. You may object to direct marketing at any time, after which we will stop it;
  • withdraw consent at any time without affecting the lawfulness of prior processing;
  • file a complaint with Úřadu pro ochranu osobních údajů, https://uoou.gov.cz, or with the competent supervisory authority in the country of your habitual residence, place of work or place of the alleged GDPR infringement.

Send your request to support@essentialsvault.eu. We will normally respond within one month. We may take reasonable steps to verify your identity. Manifestly unfounded or excessive requests may be handled under čl. 12 odst. 5 GDPR.

10. Requirement to provide data

We need the data marked as mandatory in the order to enter into and perform the contract or comply with the law. Without it, we may be unable to process the order. Marketing consent is voluntary.

11. Security and children

We use appropriate technical and organisational measures, access controls and contractual safeguards for service providers. No system is completely secure.

The online store is not directed at children. We do not knowingly request children’s personal data for marketing. Contact us if you discover that a child has provided data to us without authorisation.

12. Changes

We may update this policy. The current version is always available on this page. We will use a reasonable notification method for a material change. We will not introduce a new purpose requiring consent without obtaining new consent.