Privacy policy
This English translation is provided for convenience. The Czech version is legally binding.
Účinné od: 11. července 2026
Poslední aktualizace: 11. července 2026
This Privacy Policy explains how Essentials Vault processes personal data when you visit https://essentialsvault.eu, make a purchase, communicate with us or receive marketing.
1. Controller and contact details
The personal data controller is:
- HofMark s.r.o., IČO 297 39 560
- registered office Nové sady 988/2, Staré Brno, 602 00 Brno
- privacy email support@essentialsvault.eu
No data protection officer has been appointed.
2. Personal data we process
Depending on how you use the online store, we process in particular:
- identification and contact details (name, address, email, telephone number, billing details);
- order, payment, shipping, return, complaint and communication data;
- customer account and preference data;
- technical and operational data (IP address, device, browser, security logs);
- website usage data and marketing identifiers, only to the extent permitted by your cookie settings;
- review content or other content you provide to us voluntarily.
We do not store full payment card details. The payment service provider processes them.
3. Purposes, legal bases and retention periods
| Purpose | Typical data | Legal basis | Indicative period |
|---|---|---|---|
| Purchase, payment, delivery, account and customer service | contact, order and transaction data | performance of a contract / pre-contractual steps, čl. 6 odst. 1 písm. b) GDPR | for the term of the contract and then usually 3 years for ordinary claims, or longer in the event of a dispute |
| Accounting, taxes and statutory records | billing and transaction data | legal obligation, čl. 6 odst. 1 písm. c) | usually 5 or 10 years depending on the document and applicable law |
| Returns, complaints, fraud and protection of rights | order, communications, evidence and risk indicators | contract, legal obligation and legitimate interest, čl. 6 odst. 1 písm. b), c), f) | for the handling period and then usually 3 years, or until final resolution in the event of a dispute |
| Online store security | IP, device and logs | legitimate interest in security, čl. 6 odst. 1 písm. f) | usually no more than 12 months, and longer only in the event of a security incident or legal claim |
| Offers of our own similar goods to existing customers | email and purchase history | § 7 odst. 3 zákona č. 480/2004 Sb. and legitimate interest, always with a simple opt-out | until you opt out, but no longer than 3 years after the last purchase or relevant activity |
| Newsletter for subscribers | email and proof of consent | consent, čl. 6 odst. 1 písm. a) GDPR and § 7 zákona č. 480/2004 Sb. | until consent is withdrawn or 3 years after the last verifiable activity. Proof of consent is retained for the period necessary to defend a claim |
| Personalisation, measurement and advertising | cookie ID, IP, website behaviour and conversions | consent, čl. 6 odst. 1 písm. a) GDPR. Storage and access to cookies are also governed by electronic communications law | according to the cookie table and until consent is withdrawn |
| Abandoned cart | email, cart contents and activity | marketing consent or the statutory rules for contacting an existing customer. A service message is sent only to the extent necessary for pre-contractual steps | reminder data for no more than 30 days unless another legal basis applies |
| Reviews | name/alias, order and content | consent or legitimate interest in verified reviews, depending on the process | for the publication period and for a reasonable period afterwards for record-keeping |
These periods are maximum time frames. We delete or anonymise data sooner if it is no longer needed. Statutory archiving and protection of specific claims take priority.
4. Marketing
4.1. We send newsletters to people who are not customers only with their active consent. Consent is not a condition of purchase and may be withdrawn at any time using the link in the email or by contacting the controller.
4.2. Subject to statutory conditions, we may send existing customers offers for our own similar goods. A free and simple opt-out must be available when we obtain the contact details and in every message.
4.3. Marketing and analytics cookies do not run before consent. Refusal must not prevent a basic purchase. Consent can be changed through the “Cookie settings” link available on the website.
4.4. If we use personalisation or create advertising audiences, we may profile purchasing and browsing behaviour. We do not make decisions based solely on automated processing that have legal or similarly significant effects unless the customer receives specific information in advance.
5. Recipients and service providers
We disclose data only to the extent necessary, particularly to the following categories of recipients:
- Shopify as the online store and hosting platform;
- payment providers displayed at checkout;
- carriers and collection point networks selected by the customer at checkout;
- Klaviyo for email, automation and customer communications;
- accounting, tax and legal advisers;
- IT, security, support and cloud service providers;
- active analytics and advertising platforms, particularly Google or Meta, only if deployed on the website and the customer has given the relevant cookie consent;
- public authorities where required by law.
The specific recipient depends on the selected payment and shipping methods and the tools currently active. We enter into the required arrangements with processors under čl. 28 GDPR. On request, we will provide more information about recipients relevant to specific processing.
6. Transfers outside the EEA
Some providers may process data outside the European Economic Area, particularly in the USA or Canada. We base transfers on a European Commission adequacy decision, including the EU–US Data Privacy Framework if the recipient is certified, standard contractual clauses or another statutory safeguard. On request, we will provide more information about the safeguard used.
The specific transfer mechanism depends on the provider’s current contracting entity and settings. We will provide more information on request.
7. Cookies
We use:
- necessary cookies for the cart, checkout, security, market selection and cookie preferences. These operate without consent and only to the extent necessary;
- analytics cookies for traffic and performance measurement, only with consent;
- marketing and personalisation cookies for advertising, audiences and personalisation, only with consent.
A detailed cookie table must be generated from the scripts actually deployed and must state at least the name, provider, purpose, duration and category. General text without a cookie inventory is insufficient. Browser settings do not replace the option to refuse cookies in the banner.
8. Data sources
We obtain data directly from you, from your use of the online store, from payment and shipping partners and, where lawful, from advertising or analytics partners. We do not obtain data from public sources for unsolicited marketing.
9. Your rights
You have the right to:
- obtain confirmation and access to your data;
- request correction of inaccurate data;
- request deletion where the conditions are met;
- request restriction of processing;
- receive data in a portable format where processing is based on a contract or consent and carried out by automated means;
- object to processing based on legitimate interest. You may object to direct marketing at any time, after which we will stop it;
- withdraw consent at any time without affecting the lawfulness of prior processing;
- file a complaint with Úřadu pro ochranu osobních údajů, https://uoou.gov.cz, or with the competent supervisory authority in the country of your habitual residence, place of work or place of the alleged GDPR infringement.
Send your request to support@essentialsvault.eu. We will normally respond within one month. We may take reasonable steps to verify your identity. Manifestly unfounded or excessive requests may be handled under čl. 12 odst. 5 GDPR.
10. Requirement to provide data
We need the data marked as mandatory in the order to enter into and perform the contract or comply with the law. Without it, we may be unable to process the order. Marketing consent is voluntary.
11. Security and children
We use appropriate technical and organisational measures, access controls and contractual safeguards for service providers. No system is completely secure.
The online store is not directed at children. We do not knowingly request children’s personal data for marketing. Contact us if you discover that a child has provided data to us without authorisation.
12. Changes
We may update this policy. The current version is always available on this page. We will use a reasonable notification method for a material change. We will not introduce a new purpose requiring consent without obtaining new consent.