Personal Data Protection and Cookie Notice
Summary: personal data protection
This Privacy Policy page contains complete information on how we process your data, how we use cookies, and what rights you have as a data subject. Protecting our customers’ personal data is a priority for MAN’S SET.
/ Personal data protection policy and information provided by the controller to the data subject when collecting personal data from the data subject, and a cookie notice for the mansset.eu online store /
I. Controller
1.1. The identity and contact details of the Controller are as follows:
- Business name: Dmytro Nykytiuk
- Registered office: Agatova 3460/7F, 84101 Bratislava-Dubravka, Slovenská republika
- Company ID (IČO): 56703538
- Tax ID (DIČ): 3122099057
- Bank account: SK08 1100 0000 0029 4721 2179
- The Seller is not a payer of value added tax (VAT)
1.2. The email and telephone contact details for the Controller are:
- Email: info@mansset.eu
- Phone no.: +421911704726
1.3. Address of the Controller for the delivery of correspondence:
Dmytro Nykytiuk, Tupeho 30, Bratislava 831 01, Slovenská republika
1.4. Pursuant to Article 13(1) and (2) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 May 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter the “Regulation”), and further pursuant to Act No. 18/2018 Coll. on Personal Data Protection and on the Amendment of Certain Acts, as amended, and pursuant to Act No. 452/2021 Coll. on Electronic Communications, as amended, the Controller hereby provides the Data Subject (the Buyer), from whom the Controller (the Seller) obtains personal data relating to them, with the following information, instructions and explanations:
II. References
2.1. This personal data protection policy and information forms part of the General Terms and Conditions published on the Seller’s Website.
2.2. Pursuant to Section 3(1)(n) of Act No. 102/2014 Coll., the Seller informs the consumer that there are no specific relevant codes of conduct to which the Seller has committed to adhere, whereby a code of conduct means an agreement or set of rules defining the conduct of a seller who has undertaken to comply with such a code of conduct in relation to one or more specific business practices or industries, where these are not laid down by law, another legal regulation, or a measure of a public authority, and of the manner in which the consumer may familiarize themselves with them or obtain their text.
III. Personal Data Protection and the Use of Cookies. Notice and Explanation of Cookies, Scripts, and Pixels
3.1. The Controller of the Website provides the following brief explanation of the function of cookies, scripts, and pixels:
3.1.1. Cookies are text files containing a small amount of information that are downloaded to your device when you visit a website. Thanks to this file, the website stores information about your actions and preferences for a certain period of time (such as login name, language, font size, and other display settings), so you do not need to re-enter them the next time you visit the website or browse its individual pages.
A script is a piece of program code used to ensure the correct and interactive function of websites. This code runs on the Controller’s server or on your device.
A pixel is a small, invisible piece of text or image on a website that is used to monitor website traffic. For this purpose, various data is stored via pixels.
Types of Cookies
3.1.2. Cookies are divided into the following categories:
Technical or functional cookies – ensure the proper functioning of the Controller’s Website and its use. These cookies are used without consent.
Statistical cookies – enable the Controller to obtain statistics on the use of its website. These cookies are used only with consent.
Marketing / Advertising cookies – used to create advertising profiles and similar marketing activities. These cookies are used only with consent.
How to Control Cookies
3.2. How to control cookies:
3.2.1. You can control and/or delete cookies at your discretion – see aboutcookies.org for details. You can delete all cookies stored on your computer or other device, and you can set most browsers to prevent them from being stored.
Which Cookies We Use
3.3. The Controller’s Website uses the following cookies:
You can find all cookies used by the Controller at https://www.cookieserve.com/ by entering the Controller’s website address https://mansset.eu
Technical or functional cookies – the information is accessed by the Controller of the Website. Cookie duration: 2 years.
Statistical cookies – the information is accessed by the Controller of the Website. Cookie duration: 2 years.
Marketing and advertising cookies – the information is accessed by the Controller of the Website. Cookie duration: 2 years.
3.3.1. Cookies made available to third parties:
Google Analytics, Google ADS: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Írsko. For more information on privacy protection, see https://support.google.com/analytics/topic/2919631?hl=sk&ref_topic=1008008
Facebook Pixels: Facebook Ireland Ltd. 4 Grand Canal Square, Grand Canal Harbour Dublin 2, Írsko. For more information on privacy protection, see https://www.facebook.com/about/privacy/
IV. Personal Data Processed
4.1. On its website, the Controller processes the following personal data: first name, surname, place of residence, email address, home telephone number, mobile telephone number, billing address, delivery address, data obtained from cookies, and IP addresses.
V. Contact Details of the Person Responsible for Personal Data Protection Oversight
5.1. The Controller has appointed a data protection officer in accordance with Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. Contact:
- Email: info@mansset.eu
- Phone no.: +421951097300
5.2. The Controller is also the Seller within the meaning of that term as defined in the General Terms and Conditions of this website.
VI. Purposes of Processing the Data Subject’s Personal Data and the Data Retention Period
6.1. The purposes of processing the Data Subject’s personal data are, in particular:
6.1.1. recording, creating, and processing contracts and client data for the purpose of concluding contracts with third parties.
6.1.2. processing accounting documents and documents related to the Controller’s business activities.
6.1.3. compliance with legal regulations relating to the archiving of documents and records, e.g. under Act No. 431/2002 Coll. on Accounting, as amended, and other relevant regulations.
6.1.4. the Controller’s activities in connection with fulfilling a request, order, contract, or similar instrument of the Data Subject.
6.1.5. newsletter, marketing, and similar advertising activities of the Controller, where the Data Subject has given the Controller consent to marketing and similar advertising activities.
6.2. The Controller retains the Data Subject’s personal data only for the period strictly necessary for the purposes of performing the contract and its subsequent archiving in accordance with the statutory periods imposed on the Controller by law. Where the Data Subject has consented to receiving promotional emails and similar offers, the Data Subject’s personal data is processed for these purposes until the Data Subject withdraws their consent, but for no longer than 10 years.
VII. Legal Basis for Processing the Data Subject’s Personal Data
7.1. Where the Controller carries out processing of personal data based on the consent of the Data Subject, such processing will commence only after the Data Subject has given the relevant consent.
7.2. Where the Controller processes the Data Subject’s personal data for the purpose of negotiating pre-contractual relations and concluding and performing the purchase contract, and the related delivery of goods, products, or services, the Data Subject is obliged to provide personal data for the proper performance of the purchase contract; otherwise, performance cannot be ensured. Personal data for this purpose is processed without the consent of the data subject.
VIII. Recipients or Categories of Recipients of Personal Data
8.1. The recipients of the Data Subject’s personal data will be, or may at least be, the following:
8.1.1. the statutory bodies of the Controller or their members.
8.1.2. persons performing work activities in an employment relationship or similar arrangement for the Controller.
Categories of Data Recipients
8.1.3. the Controller’s business representatives and other persons cooperating with the Controller in carrying out the Controller’s tasks. For the purposes of this document, all natural persons performing dependent work for the Controller on the basis of an employment contract or agreements on work performed outside an employment relationship shall be considered employees of the Controller.
8.1.4. Recipients of the Data Subject’s personal data will also include the Controller’s associates, business partners, suppliers, and contractual partners, in particular: an accounting company, a company providing services related to software development and maintenance, a company providing legal services to the Controller, a company providing consulting to the Controller, companies ensuring the transport and delivery of products to buyers and third parties, marketing companies, companies operating social networks, and companies providing payment gateways and other payment methods.
8.1.5. Recipients of personal data will also include courts, law enforcement authorities, the tax authority, and other state authorities, where so provided by law. Personal data will be provided by the Controller to such authorities and state institutions on the basis of, and in accordance with, the legal regulations of the Slovak Republic.
8.1.6. List of third parties – processors and recipients who process the Data Subject’s personal data:
Specific Processors and Recipients
General Logistics Systems Slovakia s.r.o., Budča 1039, 962 33 Budča, Slovenská republika – third party providing transport services
Packeta Slovakia s. r. o., with registered office at Kopčianska 3338/82A, 851 01 Bratislava, Company ID (IČO): 48136999 – third party providing transport services
STRIPE PAYMENTS EUROPE, LIMITED, C/O A & L Goodbody, Ifsc, North Wall Quay, Dublin, D01 H104, Írsko – third party providing the payment gateway
PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24, Boulevard Royal, 2449, LUXEMBOURG, Luxembursko – third party providing the payment gateway
Heureka Shopping s.r.o., Karolinská 650/1, 186 00 Praha 8 – Karlín, ČR, Company ID (IČO): 02387727 – third party monitoring satisfaction with the operation of the website and ensuring the functioning of the Overené zákazníkmi (Verified by Customers) service
Other Service Providers
8.2. The Controller of the online store determines purchase satisfaction through email questionnaires as part of the Overené zákazníkmi (Verified by Customers) program, in which the Controller’s online store participates. The Controller sends such a questionnaire to the Data Subject – the Buyer – every time the Data Subject – the Buyer – makes a purchase from the Controller’s online store, unless, pursuant to Act No. 452/2021 Coll., as amended, the Data Subject – the Buyer – has objected to receiving electronic mail for direct marketing purposes.
The Controller processes personal data for the purpose of sending questionnaires within the Overené zákazníkmi program on the basis of the Controller’s legitimate interest, which consists in ascertaining the satisfaction of the Data Subject – the Buyer – with the purchase made through the Seller’s online store.
For sending questionnaires, evaluating the feedback of the Data Subject – the Buyer, and analysing market position, the Controller uses a data processor, namely the operator of the Heureka.sk portal. For these purposes, the Controller may transmit information about the goods purchased and the email address of the Data Subject – the Buyer. When sending the email questionnaires, the personal data of the Data Subject – the Buyer – is not transmitted to any third party for its own purposes.
The Data Subject – the Buyer – may object at any time to receiving email questionnaires within the Overené zákazníkmi program by declining further questionnaires using the link in the questionnaire email. In the event of such an objection by the Data Subject – the Buyer, the Controller will no longer send questionnaires to the Data Subject – the Buyer.
IX. Information on the Provision of Personal Data to Third Countries and the Period of Their Retention:
9.1. Not applicable. The Controller does not transfer personal data of individuals to third countries.
X. Notice of the Existence of the Data Subject’s Relevant Rights:
10.1. The Data Subject has, among others, the following rights, whereby:
10.1.1. Point 10.1 is without prejudice to the other rights of Data Subjects.
Right of Access to Data
10.1.2. The Data Subject’s right of access to data under Article 15 of the Regulation, the content of which is:
- the right to obtain confirmation from the Controller as to whether the Data Subject’s personal data is being processed and, if so, to what extent. Where personal data is being processed, the Data Subject also has the right to learn its content and to request from the Controller information on the reasons for its processing, in particular information on: the purpose of the processing, the categories of personal data concerned, the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations, the envisaged period for which the personal data will be stored or, if not possible, the criteria used to determine that period, the existence of the right to request from the Controller rectification or erasure of personal data concerning the Data Subject or restriction of processing, and the existence of the right to object to such processing, the right to lodge a complaint with a supervisory authority, where the personal data were not collected from the Data Subject, any available information as to their source, the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) of the Regulation and, in such cases, at least meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the Data Subject, and information on the appropriate safeguards pursuant to Article 46 of the Regulation relating to the transfer of personal data, where personal data are transferred to a third country or an international organisation.
10.1.3. the right to obtain a copy of the personal data undergoing processing, provided that the right to obtain such a copy must not adversely affect the rights and freedoms of others.
Right to Rectification and Erasure of Data
10.1.4. the Data Subject’s right to rectification under Article 16 of the Regulation, the content of which is the right to have the Controller rectify, without undue delay, inaccurate personal data concerning the Data Subject; the right to have incomplete personal data of the Data Subject completed, including by means of providing a supplementary statement by the Data Subject; the Data Subject’s right to erasure of personal data (the so-called “right to be forgotten”) under Article 17 of the Regulation, the content of which is:
10.1.5. the right to obtain from the Controller the erasure, without undue delay, of personal data concerning the Data Subject, where one of the following grounds applies:
- the personal data are no longer necessary for the purposes for which they were collected or otherwise processed; the Data Subject withdraws the consent on which the processing is based, provided that there is no other legal ground for the processing; the Data Subject objects to the processing of personal data pursuant to Article 21(1) of the Regulation and there are no overriding legitimate grounds for the processing, or the Data Subject objects to the processing of personal data pursuant to Article 21(2) of the Regulation; the personal data have been unlawfully processed; the personal data must be erased for compliance with a legal obligation under European Union law or the law of the Member State to which the Controller is subject; the personal data were collected in connection with the offer of information society services referred to in Article 8(1) of the Regulation;
10.1.6. the right to have the Controller, who has made the Data Subject’s personal data public, take reasonable steps, including technical measures, having regard to available technology and the cost of implementation, to inform other controllers processing the personal data that the Data Subject has requested the erasure of any links to, or copies or replications of, such personal data; provided that the right to erasure of personal data with the content of the rights under Article 17(1) and (2) of the Regulation does not arise to the extent that processing of the personal data is necessary:
Exceptions to the Right to Erasure
10.1.7. for exercising the right to freedom of expression and information.
10.1.8. for compliance with a legal obligation which requires processing under European Union law or the law of the Member State to which the Controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.
10.1.9. for reasons of public interest in the area of public health, in accordance with Article 9(2)(h) and (i) of the Regulation, as well as Article 9(3) of the Regulation.
10.1.10. for archiving purposes in the public interest, for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the Regulation, insofar as the right referred to in Article 17(1) of the Regulation is likely to render impossible or seriously impair the achievement of the objectives of such processing; or for the establishment, exercise, or defence of legal claims;
Right to Restriction of Processing and Data Portability
10.1.11. the Data Subject’s right to restriction of processing under Article 18 of the Regulation, the content of which is:
10.1.12. the right to have the Controller restrict the processing of personal data in any of the following cases: the accuracy of the personal data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the personal data; the processing is unlawful and the Data Subject opposes the erasure of the personal data and requests the restriction of their use instead; the Controller no longer needs the personal data for the purposes of processing, but they are required by the Data Subject for the establishment, exercise, or defence of legal claims; the Data Subject has objected to processing pursuant to Article 21(1) of the Regulation, pending verification whether the legitimate grounds of the Controller override those of the Data Subject;
10.1.13. the right that, where processing of personal data has been restricted, such personal data shall, with the exception of storage, be processed only with the Data Subject’s consent, or for the establishment, exercise, or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State;
10.1.14. the right to be informed in advance of the lifting of the restriction on processing of personal data;
Notification Obligation and Data Portability
10.1.15. the Data Subject’s right to have the notification obligation towards recipients fulfilled under Article 19 of the Regulation, the content of which is: the right to have the Controller notify each recipient to whom personal data have been disclosed of any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16, Article 17(1), and Article 18 of the Regulation, unless this proves impossible or involves disproportionate effort; the right to have the Controller inform the Data Subject about those recipients if the Data Subject so requests;
10.1.16. the Data Subject’s right to data portability under Article 20 of the Regulation, the content of which is: the right to receive the personal data concerning the Data Subject which they have provided to the Controller, in a structured, commonly used, and machine-readable format, and the right to transmit that data to another controller without hindrance from the Controller, where:
- a/ the processing is based on the Data Subject’s consent pursuant to Article 6(1)(a) of the Regulation or Article 9(2)(a) of the Regulation, or on a contract pursuant to Article 6(1)(b) of the Regulation, and at the same time
- b/ the processing is carried out by automated means, and at the same time:
Data Portability and the Right to Object
10.1.17. the right to obtain personal data in a structured, commonly used, and machine-readable format and the right to transmit that data to another controller without hindrance from the Controller, provided that this does not adversely affect the rights and freedoms of others;
10.1.18. the right to have personal data transmitted directly from one controller to another, where technically feasible;
10.1.19. the Data Subject’s right to object under Article 21 of the Regulation, the content of which is:
Right to Object to Processing
10.1.20. the right to object at any time, on grounds relating to the Data Subject’s particular situation, to the processing of personal data concerning them which is carried out on the basis of Article 6(1)(e) or (f) of the Regulation, including profiling based on those provisions of the Regulation;
10.1.21. where the Data Subject exercises the right to object at any time, on grounds relating to their particular situation, to the processing of personal data concerning them which is carried out on the basis of Article 6(1)(e) or (f) of the Regulation, including profiling based on those provisions of the Regulation, the right that the Controller shall no longer process the Data Subject’s personal data unless the Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the Data Subject, or grounds for the establishment, exercise, or defence of legal claims
10.1.22. the right to object at any time to the processing of personal data concerning the Data Subject for the purposes of direct marketing, including profiling to the extent that it is related to direct marketing; where the Data Subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes;
10.1.23. in connection with the use of information society services, the right to exercise the right to object to the processing of personal data by automated means using technical specifications;
10.1.24. the right to object, on grounds relating to the Data Subject’s particular situation, to the processing of personal data concerning the Data Subject where the personal data are processed for scientific or historical research purposes or for statistical purposes pursuant to Article 89(1) of the Regulation, except where the processing is necessary for the performance of a task carried out for reasons of public interest;
Automated Individual Decision-Making
10.1.25. the Data Subject’s right related to automated individual decision-making under Article 22 of the Regulation, the content of which is:
10.1.26. the right not to be subject to a decision based solely on automated processing of personal data, including profiling, which produces legal effects concerning the Data Subject or similarly significantly affects them, except in the cases referred to in Article 22(2) of the Regulation [i.e. except where the decision: (a) is necessary for entering into, or the performance of, a contract between the Data Subject and the Controller,
10.1.27. permitted by European Union law or the law of the Member State to which the Controller is subject, which also lays down suitable measures to safeguard the rights, freedoms, and legitimate interests of the Data Subject, or (c) based on the explicit consent of the Data Subject.
XI. Notice of the Data Subject’s Right to Withdraw Consent to the Processing of Personal Data:
11.1. The Data Subject is entitled to withdraw their consent to the processing of personal data at any time, without affecting the lawfulness of processing based on consent given before its withdrawal.
The Data Subject is entitled to withdraw their consent to the processing of personal data at any time – in whole or only in part. A partial withdrawal of consent to the processing of personal data may relate to a particular type of processing operation / processing operations, whereby the lawfulness of the processing of personal data in respect of the remaining processing operations shall remain unaffected. A partial withdrawal of consent to the processing of personal data may relate to a particular specific purpose of processing personal data / particular specific purposes of processing personal data, whereby the lawfulness of the processing of personal data for the other purposes shall remain unaffected.
The Data Subject may exercise the right to withdraw consent to the processing of personal data in written form, sent to the Controller’s address registered as its seat in the Commercial Register at the time of withdrawal of consent to the processing of personal data, or in electronic form by electronic means (by sending an email to the Controller’s email address stated in the identification of the Controller in this document).
XII. Notice of the Data Subject’s Right to Lodge a Complaint with a Supervisory Authority:
12.1. The Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement, if they consider that the processing of personal data concerning them infringes the Regulation, all without prejudice to any other administrative or judicial remedy.
The Data Subject has the right to be informed by the supervisory authority to which the complaint was lodged, as the complainant, of the progress and outcome of the complaint, including the possibility of lodging a judicial remedy pursuant to Article 78 of the Regulation.
12.2. The supervisory authority in the Slovak Republic is the Slovak Data Protection Authority (Úrad na ochranu osobných údajov Slovenskej republiky), Hraničná 12, 820 07 Bratislava 27, Slovenská republika. Phone contact: +421 /2 3231 3214, Email: statny.dozor@pdp.gov.sk,
XIII. Information Related to Automated Decision-Making, Including Profiling:
13.1. Since the Controller does not process the Data Subject’s personal data in the form of automated decision-making, including profiling, as referred to in Article 22(1) and (4) of the Regulation, the Controller is not required to provide the information under Article 13(2)(f) of the Regulation, i.e. information on automated decision-making, including profiling, and on the logic involved, as well as the significance and envisaged consequences of such processing for the Data Subject. Not applicable.
XIV. Final Provisions
14.1. This Personal Data Protection Policy and Cookie Notice form an integral part of the General Terms and Conditions and the Complaints Procedure. The documents – the General Terms and Conditions and the Complaints Procedure for this website – are published on the domain of the Seller’s website.
14.2. This Privacy Policy enters into force and effect upon its publication on the Seller’s website on 05.08.2023
Updates to the Privacy Policy Page
We may update the Privacy Policy and Cookie Notice document from time to time, for example when legal regulations change. You will always find the current version on this page. If you have any questions about the processing of your data, please contact us at info@mansset.eu or via the Contact page. Protecting your personal data is a priority for us – we process only the data we absolutely need.