Privacy policy
This privacy policy (“Policy”) describes how Glamaxx Group s.r.o., having its seat at Krkonošská 1511/5, Vinohrady, 120 00 Prague 2, Czech Republic, Identification number 230 34 670, VAT number CZ23034670, e-mail address info@glamaxx.com, PEC address ge2pjkd, as the commercial company registered under the law of Czech Republic, listed in the commercial register of the Czech Republic held by the Metropolitan court in Prague, under the file number C 420304 (herein after referred to as the “Company”, “we”, “us” or “our”) collects, protects and uses the personally identifiable information (“Personal Data” or “Information”) you (“User”, “you” or “your”) may provide on the www.glamaxx.com website and any of its products or services or products or services of the third parties (collectively, “Website” or “Services”). It also describes the choices available to you regarding our use of your Personal Data and how you can access and update this information. This Policy does not apply to the practices of companies that we do not own or control, or to individuals that we do not employ or manage.
The requirements of this Policy are in addition to, not in substitution of, any other requirements under the applicable data protection laws in particular under Act No. 110/2019 Coll., on processing of Personal Data as amended (“Processing of Personal Data Law” or “PPDL”) and the European Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (“GDPR”) and any other applicable regulations valid and effective in the Czech Republic and at territory of the European Union or territory of the European Economic Area. In case of conflict between the applicable Processing of Personal Data Law and GDPR or any other regulations and the provisions of this Policy, the applicable data protection laws and regulations shall prevail.
This Policy Rules has been drafted on the processing of Personal Data and to clarify what the Company is obliged to do to ensure that individuals Personal Data remains safe and confidential. The aim of this document is to provide Data Subjects with information about the Personal Data which are being collected by the Company, why the Company collect Personal Data, how the Personal Data are being use, from which sources the Personal Data are coming from, what is the purpose of collecting them, to who is the Company permitted to provide the Personal Data, and where Data Subjects can obtain additional information about processing and administration of Personal Data and about its security.
Please note that if you do not agree with the processing of your Personal Data or privacy policy, you cannot use our Services.
Collection of personal Data
We receive and store any information you knowingly provide to us when you create an account, fill in any online forms on the Website. When required this information may include your email address, name, phone number, address, credit card information, bank information, or other Personal Data as completely listed in the list of collected Personal Data attached to this Policy as Appendix No. 1. You can choose not to provide us with certain information, but then you may
not be able to take advantage of some of the Website’s features. Users who are uncertain about what information is mandatory are welcome to contact us.
Collection of non-personal information
When you visit the Website, our servers automatically record information that your browser sends. This data may include information such as your device’s IP address, browser type and version, operating system type and version, language preferences or the webpage you were visiting before you came to our Website, pages of our Website that you visit, the time spent on those pages, information you search for on our Website, access times and dates, and other statistics.
Managing Personal Data
You are able to access, add to, update and delete certain Personal Data about you. The information you can view, update, and delete may change as the Website or Services change. When you update information, however, we may maintain a copy of the unrevised information in our records. Some information may remain in our private records after your deletion of such information from your account. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. We may use any aggregated data derived from or incorporating your Personal Data after you update or delete it, but not in a manner that would identify you personally. Once the retention period expires, Personal Data shall be deleted. Therefore, the right to access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after the expiration of the retention period.
Purposes for Collection of Personal Data
The Company may Process Personal Data for the following purposes, upon instruction of the Data Controller (“Purposes”):
(a) in order to provide Services;
(b) operate, administrate and optimize the Website and diagnose problems with the Website; (c) direct marketing purposes, including third parties so that Company may provide the Data Subject with information about products and services that may be of interest to the Data Subject.
Processing of Personal Data enables the Company to facilitate activity to provide related Services, which include, but are not limited to Services described above in accordance with the General Terms and Conditions. The Company is processing the Personal Data for marketing and statistical purposes as well.
The Website allows you to submit Personal Data according to your will. The submission of Personal Data is on a voluntary basis.
The Company shall only Process Personal Data to the extent that is relevant for the Purposes. Given that no Sensitive Data is required to achieve any of the Purposes of the Company will not Process Sensitive Data and Company invites anyone using its Services to refrain from sharing with
Company any Sensitive Data about themselves or other individuals and to refrain from sharing any other Personal Data which are not necessarily complying with the Purposes stated herein.
The Company may offer functionality from third parties by redirecting you to the third-party's website. While visiting the third-party site, your privacy choices and the data you share with the third party will be subject to the third party's privacy policy, and not subject to Company’s Policy.
The Source of Personal Data and the Consent to collect
We receive most of the Personal Data that we process directly from you. Sometimes we also receive your Personal Data from third parties, e.g. from social networks you use.
You consent herewith your clear, informed and duly intended consent to collect and process your Personal Data indicated herein by the Company under the conditions set out herein by the fact of starting using the Website.
You have the right to withdrawal the consent to collect and process your Personal Data pursuant to the previous article of this Privacy Policy at any moment.
Use and processing of collected information
Any of the information we collect from you may be used to personalize your experience; improve our Website; improve customer Services and respond to queries and emails of our customers; send notification emails such as password reminders, updates, etc; run and operate our Website and Services. Non-Personal Information collected is used only to identify potential cases of abuse and establish statistical information regarding Website usage. This statistical information is not otherwise aggregated in such a way that would identify any particular user of the system.
We may process Personal Data related to you if one of the following applies: (i) You have given their consent for one or more specific purposes. Note that under some legislation we may be allowed to process information until you object to such processing (by opting out), without having to rely on consent or any other of the following legal bases below. This, however, does not apply, whenever the processing of Personal Data is subject to European data protection law; (ii) Provision of information is necessary for the performance of an agreement with you and/or for any pre contractual obligations thereof; (ii) Processing is necessary for compliance with a legal obligation to which you are subject; (iv) Processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in us; (v) Processing is necessary for the purposes of the legitimate interests pursued by us or by a third party. In any case, we will be happy to clarify the specific legal basis that applies to the processing, and whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
We only process Personal Data for the period that is necessary for the purpose for which we are processing it. Assuming you do not delete your profile or terminate your contractual relationship with us, we have been processing your personal data for 5 years. When we find that your Personal Data is no longer necessary for any of the purposes for which it was processed, we discard it.
Information on the processing of personal data
Pursuant to Article 13 of the GDPR, the Company provides the following information:
(1) Identity and contact details of the data controllers
The data controllers of the Personal Data collected through the Website, each within the limits of the processing actually carried out, are the following:
Glamaxx Group s.r.o, having its seat at Krkonošská 1511/5, Vinohrady, 120 00 Prague 2, Czech Republic, Identification number 230 34 670, VAT number CZ23034670, e-mail address info@glamaxx.com, PEC address ge2pjkd, as the commercial company registered under the law of Czech Republic, listed in the commercial register of the Czech Republic held by the Metropolitan court in Prague, under the file number C 420304;
(2) Type of personal data processed
No registration is required to access the Website. However, there are sections that require registration or the use of a username and password (e.g., to register for the Website), or services for the use of which you must provide your information (e.g., to contact us, subscribe to the newsletter, etc.).
Moreover, in order to allow a normal and efficient navigation and fruition of the Website, the Company will collect some personal data of Users related to the connection and navigation within the Website. With reference to data related to navigation within the Website collected through the use of "cookies" see also point “Cookies” below regarding Profiling Tools.
Where necessary, the companies will obtain the specific consent of the User to the relevant use of the data.
Here is an example of the type of information that is collected through the Website: Identifying data: first name, last name, address, etc;
(a) Contact data: residential address, e-mail address, telephone number;
(b) Connection data: IP address, device number/ID, data about your Internet connection and service provider, the equipment you use to access websites, your browsing history, and other technical and usage details;
(c) Interest and preference data: data about your purchases (e.g., number, value, and types of purchases), products placed in your shopping cart, etc;
(d) Transactional data: credit card number, tax code, VAT, etc;
(3) Optional provision of Personal Data
Some of the Personal Data requested on the Website, such as first and last name, telephone number and e-mail address, may be marked as "mandatory" [e.g., indicated with an (*)] as they are necessary to access the Website services you wish to use (e.g., if you place an order). Failure to provide the data marked as "mandatory" will result in the companies being unable to provide the requested service (for example, if the User does not provide his/her e-mail address, the Company will not be able to proceed with sending the newsletter). Failure to provide data marked as "optional" will have no consequences. Users are required to indicate on the Website only the personal data that concerns them. If personal data of third parties are indicated, Users must expressly declare and acknowledge that they have obtained the consent of third parties for the processing of the corresponding personal data by the companies, or other data controllers.
(4) Purpose and legal basis of processing
Users' data are collected and processed for purposes strictly related to the use, management and updating of the Website, the services offered within it and its presentation to Users. The specific purposes of data use are detailed in this paragraph.
(a) Website registration
Users' Personal Data will be processed by the Company to enable registration on the Website, proceed to the creation of a personal account and ensure access to areas and any benefits reserved for members (e.g. make purchases faster, check purchase history, etc.).
Users' e-mail address may also be used to send any communication related to how to use the Site's features (e.g., confirmation of registration, invitation to renew credentials, etc.).
The processing of data for this purpose does not require the consent of the Users, as is necessary for the performance of a contract between the Users and the Company (relevant articles of the PPDL).
(b) E-commerce
When you make a purchase on the Website, your Personal Data will be processed by the Company to complete the sales process and executing the contract in place between the parties (e.g. managing and processing payment, completing the delivery and/or return process, etc.);
To fulfill legal obligations (e.g., in tax matters, accounting for billing, bookkeeping and accounting records) inherent in the contract with concluded with the User;
Handle any services closely related to the sale (e.g., requesting information about products, using customer service, sending order confirmation, etc.);
Protect the rights arising from the contract with concluded with the User, including through agents, in or out of court.
The processing of data for this purpose does not require the consent of the Users, as it is necessary for the execution of the sale and purchase contract concluded with the User and the execution of pre-contractual measures adopted at the request of the User himself, as well as to properly fulfill the legal obligations to which the Company is subject (relevant articles of the PPDL) and - in case of disputes - for the pursuit of the legitimate interest of the Company in the protection of its rights (relevant articles of the PPDL).
(c) ContactUs
Data provided by filling out the "Contact Us" form or by using the contact services (via e mail, fax, telephone or paper mail) will be processed by the Company to respond appropriately to User reports and/or requests for information.
The processing of data for this purpose does not require the consent of the Users, as it is necessary for the execution of the contract of sale and purchase concluded with the User or the execution of pre-contractual measures taken at the request of the User (relevant articles of the PPDL).
Furthermore, subject to the collection of appropriate and specific consent, Users' data will be processed by Company for:
(d) Marketing
Allow subscription to update services on promotions, sales and initiatives - through the use of automated and non-automated means, such as newsletters, e-mail, telephone contact, text messages, instant messages, posts, communications and posts on social networks, etc. -, related to the Company.
In the case of subscription to the "Newsletter", the User will receive only commercial communications on the e-mail address indicated during registration.
Where the User has consented to preference analysis, communications may be tailored based on the interests and additional available information about the individual User (e.g., indicating only active promotions in the region to which the individual belongs).
The processing of data for this purpose requires the consent of the Users (relevant articles of the PPDL).
(e) Preference analysis
Analyze your data (including, where available, your browsing data) to learn about your purchasing preferences and tastes and enable the Company to improve its commercial offerings accordingly and personalize its communications.
The processing of data for this purpose requires the consent of the Users (relevant articles of the PPDL).
(f) Geolocation ("Store Locator" feature)
The Company may detect your location through the use of special geolocation cookies in order to show the User accessing the "Store Locator".
The processing of data for this purpose requires the consent of Users (relevant articles of the PPDL). The User gives consent to such geolocation when he/she activates the eventual appropriate store search functionality and/or (ii) when he/she authorizes the Website from a mobile device to detect his/her location.
It is understood that failure to provide consent for purposes (d), ( e ) and (f) shall in no way affect the possibility of registering on the Website, making a purchase or contacting the Company for any type of complaint or information.
Information transfer and storage
Depending on your location, data transfers may involve transferring and storing your information in a country other than your own. You are entitled to learn about the legal basis of information transfers to a country outside the European Union or to any international organization governed by public international law or set up by two or more countries, such as the UN, and about the security measures taken by us to safeguard your information. If any such transfer takes place,you can find out more by checking the relevant sections of this document or inquire with us using the information provided in the contact section.
Personal Data processed pursuant hereof may further be provided to authorized state authorities, institutions or other entities when the conditions specified by legal regulation are met. Should it be necessary to fulfill the purpose of processing Personal Data necessary for the performance of Company legal obligations or its contractual obligations, should this be necessary to protect Company’s legitimate interests, or should it follow from Services users consent, Company may transfer Personal Data to external suppliers, who support Company in providing its Services.
The rights of users
You may exercise certain rights regarding your information processed by us. In particular, you have the right to do the following: (i) you have the right to withdraw consent where you have previously given your consent to the processing of your information; (ii) you have the right to object to the processing of your information if the processing is carried out on a legal basis other than consent; (iii) you have the right to learn if information is being processed by us, obtain disclosure regarding certain aspects of the processing and obtain a copy of the information undergoing processing; (iv) you have the right to verify the accuracy of your information and ask for it to be updated or corrected; (v) you have the right, under certain circumstances, to restrict the processing of your information, in which case, we will not process your information for any purpose other than storing it; (vi) you have the right, under certain circumstances, to obtain the erasure of your Personal Data from us; (vii) you have the right to receive your information in a structured, commonly used and machine readable format and, if technically feasible, to have it transmitted to another controller without any hindrance. This provision is applicable provided that your information is processed by automated means and that the processing is based on your consent, on a contract which you are part of or on pre-contractual obligations thereof.
You may also object to the processing of your Personal Data or request the portability of the data. However, please note that the Company does not always have to comply with your cancellation, limitation, objection or portability request. Case-by-case reviews of the Company’s legal obligations and exemptions from these rights will be made.
You have the right to lodge a complaint to the competent Personal Data Protection Office which is official state authority authorized to act in the Personal Data matters denominated as Úřad na ochranu osobních údajů, with official seat at Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, phone: +420 234 665 111 (operator), e-mail: posta@uoou.cz if you deem that Company is Processing your Personal Data in violation of any applicable data protection laws and regulations valid and effective in Czech Republic. However, the Company strongly encourages you to contact us via e-mail address info@glamaxx.com for any complaints or queries prior to lodging any complaints to the competent supervisory authority.
Marketing communications and Newsletters
We may also use your Personal Data, among other purposes, to send you commercial messages regarding our Services, both electronically and via SMS. We may use this data for these communications unless you (the addressee) have declined this option.
You have the right to decline receiving commercial messages at any time. You may do so via email, info@glamaxx.com, through your profile, by following the link in a commercial message, or by sending a message to any of the contacts listed in these rules for the processing of personal data. You can do so also by filling out our contact questionnaire on the Website.
Not every message that we send you is a commercial message. We also use your contact information to communicate with you, e.g. when sending out information on changes to the General Terms and Conditions or these rules for the processing of Personal Data.
The right to object to processing
Where Personal Data is processed for a public interest, in the exercise of an official authority vested in us or for the purposes of the legitimate interests pursued by us, you may object to such processing by providing a ground related to your particular situation to justify the objection. You must know that, however, should your Personal Data be processed for direct marketing purposes, you can object to that processing at any time without providing any justification. To learn, whether we are processing Personal Data for direct marketing purposes, you may refer to the relevant sections of this document.
How to exercise these rights
Any requests to exercise User rights can be directed to the Company through the contact details provided in this document. These requests can be exercised free of charge and will be addressed by the Company as early as possible and always within one month.
Privacy of children
We do not knowingly collect any Personal Data from children under the age of 13. If you are under the age of 13, please do not submit any Personal Data through our Website or Service. We encourage parents and legal guardians to monitor their children’s Internet usage and to help enforce this Policy by instructing their children never to provide Personal Data through our Website or Service without their permission. If you have reason to believe that a child under the age of 13 has provided Personal Data to us through our Website or Service, please contact us.
Cookies
The Website uses “cookies” to help personalize your online experience. A cookie is a text file that is placed on your hard disk by a web page server. Cookies cannot be used to run programs or deliver viruses to your computer. Cookies are uniquely assigned to you and can only be read by a web server in the domain that issued the cookie to you. We may use cookies to collect, store, and
track information for statistical purposes to operate our Website and Services. You have the ability to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. If you choose to decline cookies, you will not be able to use and experience the features of the Website and Services.
Information security
We secure information you provide on computer servers in a controlled, secure environment, protected from unauthorized access, use, or disclosure. We maintain reasonable administrative, technical, and physical safeguards to protect against unauthorized access, use, modification, and disclosure of Personal Data in its control and custody. However, no data transmission over the Internet or wireless network can be guaranteed. Therefore, while we strive to protect your Personal Data, you acknowledge that (i) there are security and privacy limitations of the Internet which are beyond our control; (ii) the security, integrity, and privacy of any and all information and data exchanged between you and our Website cannot be guaranteed; and (iii) any such information and data may be viewed or tampered with in transit by a third-party, despite best efforts.
Data breach
In the event we become aware that the security of the Website has been compromised or users Personal Data has been disclosed to unrelated third-parties as a result of external activity, including, but not limited to, security attacks or fraud, we reserve the right to take reasonably appropriate measures, including, but not limited to, investigation and reporting, as well as notification to and cooperation with law enforcement authorities. In the event of a data breach, we will make reasonable and legally necessary efforts to notify affected individuals if we believe that there is a reasonable risk of harm to the user as a result of the breach or if notice is otherwise required by law. When we do we will send you an email. All measures are governed by the relevant internal regulations of the Company.
The Company confirms that in case of breach of safety of Personal Data shall act without any delay and inform Personal Data Protection Office immediately but no later than in 72 hours upon such a breach of safety of Personal Data.
Legal disclosure
We will disclose any information we collect, use or receive if required or permitted by law, such as to comply with a subpoena, or similar legal process, and when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request. In the event we go through a business transition, such as a merger or acquisition by another company, or sale of all or a portion of its assets, your user account and personal data will likely be among the assets transferred.
If it is appropriate to achieve any of the Purposes Company may share the Personal Data with the following categories of recipients:
(a) The Company will disclose Personal Data with Website or Services users.
(b) The Company may share Personal Data with a subsidiary or parent company.
(c) The Company may also share the Personal Data with external providers of IT related services which might be necessary to be able to provide its Services.
Changes and amendments
We reserve the right to modify this Policy relating to the Website or Services at any time, effective upon posting of an updated version of this Policy on the Website. When we do we will revise the updated date at the bottom of this page. Continued use of the Website after any such changes shall constitute your consent to such changes.
Acceptance of this Policy
You acknowledge that you have read this Policy and agree to all its terms and conditions. By using the Website or its Services you agree to be bound by this Policy. If you do not agree to abide bythe terms of this Policy, you are not authorized to use or access the Website and its Services.
Contacting us
Should you have any questions regarding the processing of your Personal Data, please contact us using email: info@glamaxx.com.
This document was last updated on 2nd October 2025
Appendix No. : The complete list of the Personal Data which may be collected under this Policy.
(a) Name, Last name
(b) Academic title, Education achieved
(c) Permanent address, Contact address
(d) Country of citizenship
(e) Date and place of birth, Birth number
(f) Phone number, E-mail address
(h) IP Address
(i) Credit card information, Bank information.


