SDI Gifts

Privacy Policy

Information about how SDI Gifts s.r.o. processes personal data for enquiries, quotations, orders, production, delivery, invoicing, and business communication.

Controller

SDI gifts s.r.o.

Controller of personal data processed for B2B corporate gifts, branded merchandise, promotional products, and custom production. Registered in the Commercial Register maintained by the Municipal Court in Prague, file no. C 247957.

Registered office
Křemenáčová 90/6
Pitkovice
104 00 Praha 10
Czech Republic
Company ID / IČ
04461223
VAT ID / DIČ
CZ04461223

1. Controller and contact details

  1. 1.1The controller of personal data is SDI gifts s.r.o., with its registered office at Křemenáčová 90/6, Pitkovice, 104 00 Praha 10, Czech Republic, Company ID / IČ: 04461223, VAT ID / DIČ: CZ04461223.
  2. 1.2The Controller can be contacted regarding personal data protection at info@sdigifts.eu or by phone at +420 773 047 945.
  3. 1.3The Controller has not appointed a data protection officer, as the Controller is not required to do so under applicable data protection law.
  4. 1.4This Privacy Policy explains how the Controller processes personal data in connection with enquiries, quotations, orders, production, delivery, invoicing, complaints, business communication, and use of the website www.sdigifts.eu.
  5. 1.5This Privacy Policy applies mainly to business customers, client representatives, supplier representatives, delivery contacts, and other persons communicating with the Controller in a business context.

2. Personal data we process

  1. 2.1The Controller may process identification and contact data, including name, surname, email address, phone number, delivery address, billing address, company name, job position or role, and business contact details.
  2. 2.2The Controller may process company and billing data, including Company ID / IČ, VAT ID / DIČ, invoicing details, payment status, order references, accounting records, and tax documents.
  3. 2.3The Controller may process order and project data, including product selection, quantities, prices, branding method, delivery requirements, production requirements, delivery deadlines, communication history, quotation details, order confirmations, proforma invoices, invoices, and complaint records.
  4. 2.4The Controller may process files and materials provided for quotation, artwork preparation, production, approval, or delivery, including logos, artwork, designs, print files, mockups, product photos, packaging files, visual references, and delivery documents.
  5. 2.5Logos, artwork, designs, and similar business materials are often not personal data by themselves. However, they may contain personal data if they include a person’s name, image, signature, contact details, or other information relating to an identifiable person.
  6. 2.6The Controller may process delivery and fulfilment data, including delivery address, contact person, phone number, delivery instructions, shipment information, tracking information, customs information, and proof of delivery where relevant.
  7. 2.7The website does not use analytics, marketing, advertising, or tracking cookies. Basic technical data such as IP address, browser information, server logs, and security logs may be processed by the hosting provider or website systems where necessary for website operation, security, troubleshooting, and protection against misuse.
  8. 2.8The Controller may also receive personal data from the Buyer, the Buyer’s employees or representatives, sales agents, suppliers, couriers, production partners, or other business contacts, especially where such data is needed for communication, quotation, order processing, production, delivery, complaint handling, accounting, or legal compliance.
  9. 2.9Where the Buyer or another business contact provides personal data relating to another person, such as an employee, representative, delivery contact, event contact, or recipient, the Buyer or business contact should ensure that it is authorised to provide such data and, where required, that the relevant person is informed about the processing described in this Privacy Policy.

3. Purposes and legal bases

  1. 3.1The Controller processes personal data to respond to enquiries, prepare quotations, communicate with customers, discuss product options, prepare artwork, and take steps before concluding a contract. Where the data subject is a party to the contract or potential contract, the legal basis is taking steps before entering into a contract. Where the data subject acts as a representative, employee, contact person, agent, or other business contact of a company or organisation, the legal basis is the Controller’s legitimate interest in normal B2B communication and business development.
  2. 3.2The Controller processes personal data to accept and perform orders, produce or source Goods, arrange branding, coordinate suppliers, organise delivery, provide order documents, handle complaints, and provide customer support. Where the data subject is a party to the contract, the legal basis is performance of a contract. Where the data subject acts on behalf of a company or organisation, the legal basis is the Controller’s legitimate interest in performing the contract with that company or organisation and maintaining related business communication.
  3. 3.3The Controller processes billing, accounting, tax, and invoicing data to comply with legal obligations under accounting, tax, VAT, and related laws. The legal basis is compliance with legal obligations.
  4. 3.4The Controller processes communication history, order records, project files, artwork, logos, and production documentation for repeat orders, quality control, customer support, claim handling, prevention of disputes, and protection of legal claims. The legal basis is the Controller’s legitimate interest in efficient B2B service, continuity of projects, and protection of rights.
  5. 3.5The Controller may process personal data to protect the website, email systems, business records, and IT infrastructure against misuse, spam, fraud, unauthorised access, security incidents, and technical problems. The legal basis is the Controller’s legitimate interest in security and business protection.
  6. 3.6The Controller may use completed product photos, client identity, client logos, or project visuals publicly on the website, in public case studies, advertising, or social media only where the client has approved such use. If such materials contain personal data, the Controller processes such personal data only where a valid legal basis under applicable data protection law applies.
  7. 3.7The Controller does not use personal data for automated decision-making, including profiling, that would produce legal effects concerning a data subject or similarly significantly affect a data subject.
  8. 3.8Providing personal data is generally voluntary. However, some personal data may be necessary to respond to an enquiry, prepare a quotation, conclude or perform a contract, produce or deliver Goods, issue invoices, handle complaints, comply with legal obligations, or protect legal claims. If necessary personal data is not provided, the Controller may be unable to provide a quotation, accept or perform an order, arrange delivery, issue required documents, or respond properly to a request.

4. Contact form and email communication

  1. 4.1When a person submits the contact form on the website, the submitted information is sent through the website’s PHP form to the Controller’s email address info@sdigifts.eu.
  2. 4.2Contact form submissions are not intentionally stored in a separate website database or website admin panel. They are stored in the Controller’s email mailbox and processed as business email communication.
  3. 4.3The Controller uses website hosting and email-related service providers, including Hostinger. Such providers may process technical data and email data where necessary to provide hosting, email transmission, security, and related technical services.
  4. 4.4The Controller does not operate a newsletter and does not use contact form data for newsletter subscription.
  5. 4.5The Controller asks users not to send unnecessary personal data, sensitive personal data, or confidential third-party data unless such information is necessary for the enquiry, quotation, order, production, delivery, or legal compliance.

5. Quotations, orders, production, and delivery

  1. 5.1For quotations and orders, the Controller may process personal data and business materials needed to prepare the offer, confirm specifications, prepare artwork, produce or customise Goods, source Goods, arrange packaging, and coordinate delivery.
  2. 5.2If the Buyer provides logos, designs, artwork, product photos, brand manuals, print files, or similar files, the Controller uses them only for quotation, artwork preparation, production, approval, repeat orders, quality control, claim handling, or related business purposes.
  3. 5.3If Goods are shipped directly from a supplier or production partner to the customer, the Controller may share necessary delivery data with the relevant supplier or production partner, including delivery contact details, address, phone number, order reference, delivery instructions, and shipment information.
  4. 5.4The Controller may share necessary delivery data with delivery companies such as DHL, TNT/FedEx, DPD, or similar logistics providers in order to arrange shipment, tracking, customs processing, delivery, and proof of delivery.
  5. 5.5The Controller does not sell personal data and does not provide personal data to third parties for their independent marketing purposes.

6. Recipients of personal data

  1. 6.1Personal data may be shared with suppliers, manufacturers, branding partners, production partners, packaging partners, and fulfilment partners where necessary for quotation, production, customisation, packaging, delivery, quality control, or complaint handling.
  2. 6.2Personal data may be shared with courier companies, freight forwarders, customs brokers, postal operators, and logistics providers where necessary for delivery, tracking, customs clearance, proof of delivery, or transport-related claims.
  3. 6.3Personal data may be processed by hosting, email, IT, cloud storage, and software providers used by the Controller, including website hosting, email transmission, email storage, file storage, backup, security, and technical support providers.
  4. 6.4Clients may send files through email, Google Drive, Dropbox, file-transfer tools, or similar services. The Controller may download, store, and process such files locally or, where needed, through cloud storage for project, production, repeat order, customer support, complaint handling, or related business purposes.
  5. 6.5Personal data may be shared with accountants, tax advisers, legal advisers, auditors, insurers, debt collection providers, courts, public authorities, tax authorities, or supervisory authorities where necessary for legal obligations, legal claims, accounting, tax compliance, or protection of rights.
  6. 6.6Where a recipient acts as a processor on behalf of the Controller, the Controller uses appropriate contractual arrangements where required by applicable data protection law. Where a recipient acts as an independent controller, such as a courier company processing shipment data under its own legal obligations, that recipient is responsible for its own processing of personal data.

7. International transfers

  1. 7.1The Controller primarily processes personal data within the European Union and the European Economic Area.
  2. 7.2In some cases, personal data or project materials may be transferred outside the European Union or the European Economic Area, especially where a supplier, production partner, courier, platform, or customer-related delivery destination is located outside the EU/EEA.
  3. 7.3Such transfers are made only where necessary for quotation, production, delivery, supplier coordination, customer instructions, legal compliance, or protection of rights.
  4. 7.4Where required by applicable data protection law, the Controller relies on appropriate safeguards or lawful transfer mechanisms for international transfers, such as an adequacy decision, Standard Contractual Clauses, a derogation for specific situations, or another lawful transfer mechanism.
  5. 7.5The Buyer should inform the Controller before order confirmation if the Buyer requires specific restrictions on suppliers, production countries, delivery destinations, file sharing, or international transfers.

8. Retention of personal data

  1. 8.1The Controller keeps personal data only for as long as reasonably necessary for the purposes for which it was collected, or for as long as required by law, contract, legitimate business interests, or protection of legal claims.
  2. 8.2Unsuccessful enquiries are not intentionally entered into a separate customer database or project register. They may remain in the Controller’s email mailbox for a reasonable period needed for business communication, follow-up, spam prevention, legal protection, or email system administration. In practice, this period may depend on the nature of the enquiry, expected follow-up, limitation periods, spam or security needs, and mailbox administration.
  3. 8.3Order records, project communication, quotations, confirmations, delivery records, complaint records, and related business documents may be kept for the duration of the business relationship and afterwards where necessary for repeat orders, customer support, accounting, tax, warranty, complaint handling, limitation periods, or legal claims.
  4. 8.4Invoices, accounting records, tax documents, and VAT-related documents are kept for the statutory retention periods required by Czech law, generally for at least 10 years where applicable.
  5. 8.5Project files, artwork, logos, designs, mockups, print files, production references, and product visuals may be kept while there is an active or reasonably expected business relationship, and where reasonably necessary for repeat orders, reorders, quality control, customer support, complaint handling, legal claims, or protection of legitimate business interests.
  6. 8.6The Buyer may request deletion of project files, artwork, logos, or related materials. The Controller will comply where continued retention is no longer necessary and no legal obligation, contractual need, legitimate interest, or legal claim requires further storage.
  7. 8.7Public portfolio materials are used only with client approval or another valid legal basis. If such materials contain personal data and the relevant processing is based on consent, the data subject may withdraw consent at any time. If client approval for public portfolio use is withdrawn, the Controller will stop future public use where reasonably possible, without affecting lawful use that occurred before withdrawal.
  8. 8.8Technical server logs and website security logs are kept only for a limited period necessary for website operation, troubleshooting, security, and protection against misuse, unless longer retention is needed for investigation or legal protection.

9. Security

  1. 9.1The Controller takes reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, disclosure, or destruction.
  2. 9.2Personal data may be stored in email systems, local files, business records, accounting documents, cloud storage, and project folders used for business operations.
  3. 9.3Access to personal data and project materials is limited to persons and partners who need such access for enquiry handling, quotation, production, delivery, accounting, technical support, legal compliance, or protection of rights.
  4. 9.4No method of electronic communication, email transmission, cloud storage, or internet-based processing is completely secure. The Controller therefore recommends that Buyers avoid sending unnecessary personal data or sensitive personal data unless required for the project.
  5. 9.5If a personal data breach occurs, the Controller will assess the risk and, where required by applicable law, notify the competent supervisory authority or affected persons.

10. Cookies and tracking

  1. 10.1The website does not use analytics, marketing, advertising, remarketing, profiling, or tracking cookies.
  2. 10.2The website does not use Google Analytics, Google Tag Manager, Meta Pixel, LinkedIn Insight Tag, Hotjar, Microsoft Clarity, newsletter tracking, or similar marketing or analytics tools.
  3. 10.3The website does not display a cookie consent banner because it does not use non-essential cookies requiring consent.
  4. 10.4Strictly necessary technical cookies, local technical storage, server logs, or similar technical tools may be used only where necessary for website functionality, security, fraud prevention, form protection, hosting, or troubleshooting.
  5. 10.5The website may contain links to third-party websites or services. If a third-party website or service is opened by the user, that third party may process personal data according to its own privacy policy, cookie policy, and technical settings. The Controller is not responsible for the privacy practices, content, or technical settings of third-party websites or services.

11. Rights of data subjects

  1. 11.1Where the conditions under applicable data protection law are met, data subjects have the right to request access to their personal data.
  2. 11.2Data subjects have the right to request correction of inaccurate or incomplete personal data.
  3. 11.3Data subjects have the right to request deletion of personal data where continued processing is no longer necessary and no legal obligation, contractual need, legitimate interest, or legal claim requires further retention.
  4. 11.4Data subjects have the right to request restriction of processing in cases provided by applicable law.
  5. 11.5Data subjects have the right to object to processing based on legitimate interests, including processing for certain business communication, project retention, or legal protection purposes.
  6. 11.6Data subjects have the right to data portability where processing is based on consent or contract and carried out by automated means.
  7. 11.7Where processing of personal data is based on consent, the data subject may withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing before withdrawal.
  8. 11.8Data subjects also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of their habitual residence, place of work, or place of the alleged infringement. In the Czech Republic, the supervisory authority is the Office for Personal Data Protection / Úřad pro ochranu osobních údajů, Pplk. Sochora 727/27, Holešovice, 170 00 Praha 7, Czech Republic, www.uoou.gov.cz.

12. How to exercise your rights

  1. 12.1Requests concerning personal data can be sent to info@sdigifts.eu.
  2. 12.2The request should identify the person making the request and describe what right is being exercised or what information is requested.
  3. 12.3The Controller may request additional information where necessary to verify identity, clarify the request, protect personal data, or prevent unauthorised disclosure.
  4. 12.4The Controller will respond to requests without undue delay and at the latest within one month after receiving the request. This period may be extended by up to two further months where necessary, taking into account the complexity and number of requests. In such case, the Controller will inform the data subject of the extension and the reasons for it within one month after receiving the request.
  5. 12.5If a request concerns personal data processed by a courier, supplier, platform, or other independent controller, the Controller may direct the person to the relevant recipient where appropriate.

13. Changes to this Privacy Policy

  1. 13.1The Controller may update this Privacy Policy from time to time to reflect changes in legal requirements, business processes, website functionality, suppliers, delivery methods, or data processing practices.
  2. 13.2The version published on the website is the current version applicable to website visitors and business contacts, unless a separate written agreement states otherwise.