Privacy Policy
Privacy Policy
We are P2D2 s.r.o., with registered office at Korunní 2569/108, Vinohrady, 101 00 Prague 10, Czech Republic, Company ID: 06801781, registered in the Commercial Register maintained by the Municipal Court in Prague, file no. C 378682. We operate the online store www.beviro.com.
Our contact details:
E-mail: info@beviro.com Phone: +420 775 688 565
To sell our products and run our website, we process certain personal data. The processing of personal data is governed mainly by Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data ("GDPR") and by Czech Act No. 110/2019 Coll., on the Processing of Personal Data. We have not appointed a Data Protection Officer.
I. How we process personal data
A. When you shop with us
If you place an order, we process the details you enter: first and last name, email, phone number, delivery and billing address, details of your purchase and payment, and for business customers, company ID and VAT number. If you return goods, we also process the bank account number you give us.
Why? To perform the contract: deliver your goods, accept payment, keep you updated on your order and handle any withdrawal from the contract or complaint. We also process the data to meet our legal obligations, mainly for accounting and tax purposes.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (compliance with a legal obligation).
How long? For the duration of the limitation periods for contractual claims, usually 4 years from delivery. Tax documents are kept for 10 years from the end of the tax period in which the transaction took place.
B. When you contact us
If you email us, message us on social media or call us, we process your contact details and the content of the communication.
Why? To reply to you and resolve your question or request.
Legal basis: Art. 6(1)(b) GDPR if the communication relates to a contract or negotiations about one, otherwise Art. 6(1)(f) GDPR, our legitimate interest in answering your query.
How long? Up to 12 months from our last communication, unless it leads to a purchase or cooperation.
C. Customer account
If you create a customer account, we process the details you enter when registering and in your profile (name, email, password in encrypted form, delivery addresses) and your order history.
Why? To run the account you created: store your details for faster checkout and show your order history.
Legal basis: Art. 6(1)(b) GDPR, as maintaining the account is a service we agreed to provide at your request.
How long? For as long as the account exists. You can close your account at any time; we may close accounts that have been inactive for more than 2 years. Order data is then kept as described in point A.
D. Newsletters (commercial communications)
If you have bought from us, we may email you news and offers of products similar to those you purchased, unless you opted out when ordering. This is permitted by Art. 13(2) of Directive 2002/58/EC, as implemented in Section 7(3) of Czech Act No. 480/2004 Coll., on Certain Information Society Services, and by our legitimate interest under Art. 6(1)(f) GDPR. You can unsubscribe at any time with one click in the footer of every email.
If you subscribed without making a purchase, we send you the newsletter based on your consent under Art. 6(1)(a) GDPR. Consent is voluntary and can be withdrawn at any time.
How long? Until you unsubscribe, object or withdraw your consent, but no longer than 3 years from your last order or from giving consent.
If you are under the age at which you can consent to information society services in your country (between 13 and 16, depending on the EU Member State), consent may only be given by your parent or legal guardian.
E. Reviews
After a purchase, we may email you asking you to review the product you bought. We do so based on our legitimate interest under Art. 6(1)(f) GDPR and Section 7(3) of Act No. 480/2004 Coll.; you can object to these emails at any time.
If you write a review and we publish it as a customer review, we check against our order records that it comes from a person who actually bought the product. Consumer protection law requires us to take reasonable steps to verify reviews presented as genuine, so this processing is based on Art. 6(1)(c) GDPR (compliance with a legal obligation).
How long? Data linked to a review is processed for as long as the review is published.
F. Visiting our website (cookies and analytics)
When you visit our website, we process technical data: IP address, browser and device type, and how you use the site. Details about cookies are in Section V.
1. Introductory provisions
1.1 What is personal data?
Personal data means any information that identifies or can identify a specific natural person. In particular (but not limited to) personal data are:
Identifying information such as name, surname, identification number, tax identification number, gender;
contact details, such as home address, telephone number, email address;
other data, such as information obtained through cookies, IP address (network identifier) including browser type, device and operating system, time and number of accesses to the web interface and other similar information
1.2 What guides our handling of personal data?
Within the meaning of the General Data Protection Regulation (Regulation (EU) 2016/679, hereinafter also referred to as "GDPR"), the Controller is the controller of your personal data, i.e. it collects, stores and uses (and otherwise processes) your personal data for the performance of its business activities (the individual purposes for which the personal data is processed are further defined below), which consists in particular in the provision of consulting services in the field of the use of medicinal herbs, including the organisation of professional seminars and educational or social events.
This Personal Data Processing Policy applies to (i) the processing of personal data by the Controller during your use of the www.be-viro.com website (the "Website"), (ii) the processing of personal data by the Controller during communication with you by email or telephone, (iii) the processing of personal data by the Controller during the course of a business relationship with clients and suppliers, (iv) the processing of personal data in the performance of the Controller's legal obligations, and (v) the processing of personal data that is necessary for the purposes of protecting the Controller's legitimate interests.
The Personal Data Processing Policy describes the purposes of personal data processing and the methods of processing, informs about the individual categories of personal data processed, their potential recipients, the retention period of personal data and your rights in relation to the protection of personal data.
II. Who has access to your data
Your data stays with us. However, we are helped by companies that have access to data because they handle part of our operations:
- the e-commerce platform and hosting provider Simplia, s.r.o.,
- the carrier General Logistics Systems Czech Republic s.r.o. (GLS), to which we pass the data needed for delivery,
- the payment gateway operator ComGate Payments, a.s.; card details are processed solely by the payment gateway and we have no access to them,
- the email marketing provider ECOMAIL.CZ, s.r.o.,
- the provider of a tool for collecting email contacts and personalising website content (pop-ups), Mailocator s.r.o., Company ID: 06534597,
- providers of accounting and tax services,
- Google Ireland Ltd., provider of Google Analytics and Google Ads, under the terms available at https://policies.google.com/technologies/cookies?hl=en,
- Meta Platforms Ireland Ltd., provider of Facebook and Instagram, under the terms available at https://www.facebook.com/policy/cookies/,
- Microsoft Ireland Operations Ltd., provider of Microsoft Clarity, under the terms available at https://privacy.microsoft.com/en-us/privacystatement,
- public authorities, where required by law.
This list may change over time; we will provide up-to-date information on request using the contact details above.
III. Transfers outside the EU
We process data primarily within the European Union. Providers of analytics and marketing tools (Google, Meta, Microsoft) may transfer data to the USA; such transfers are based on the European Commission's adequacy decision (EU-U.S. Data Privacy Framework) or on standard contractual clauses under Art. 46 GDPR.
IV. Your rights
In connection with the processing of your personal data, you have the following rights:
- right of access: you can ask what data we process about you and request a copy,
- right to rectification: we will correct inaccurate data and complete incomplete data,
- right to erasure: we will delete your data in cases set out by law; we cannot delete data to the extent we are legally required to process it,
- right to restriction of processing in cases set out by law,
- right to data portability: we will provide data processed on the basis of a contract or consent in a machine-readable format,
- right to object to processing based on legitimate interest; we will always comply immediately with an objection to direct marketing,
- right to withdraw consent at any time, for commercial communications most easily via the unsubscribe link in every email.
You can exercise your rights using the contact details at the top of this policy. We will respond without undue delay and within one month at the latest.
If you believe we are not handling your data properly, you have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State where you live, work or where the alleged infringement took place. Our lead supervisory authority is the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, www.uoou.gov.cz. You can also turn to the courts. We would appreciate it if you contacted us first, though, as most issues can be resolved directly.
V. Cookies
Cookies are small files that a website stores in your browser. We use the following categories:
- Strictly necessary: enable basic website functions such as your shopping cart, logging in to your account or completing checkout. The website cannot work without them, and no consent is required for them.
- Analytics: help us understand how you use the website and improve it (Google Analytics, Microsoft Clarity). We only store them with your consent.
- Marketing and personalisation: allow us to show relevant ads and measure their performance (Meta Pixel, Google Ads) and to personalise website content, such as displaying pop-up offers (Mailocator). We only store them with your consent.
You give your consent through the cookie banner when you visit the website, where you can choose "Accept all" or "Necessary only". You can change your choice at any time: simply delete the cookies for www.beviro.com in your browser, and the banner will appear again on your next visit so you can choose differently. We are also happy to help you withdraw consent via the contact details at the top of this policy. An overview of cookie categories and the tools that use them is given above in this section; we will provide details about specific cookies on request. You can use the website without giving consent, although some features may not be available.
VI. Security and changes to this policy
To protect personal data, we use appropriate technical and organisational measures, in particular encrypted communication (HTTPS), access control and contractual obligations of processors under Art. 28 GDPR. Only authorised persons have access to the data.
We may update this policy, in particular when legislation or the tools we use change. The current version is always available on this page.
This policy is valid and effective from 18 September 2026 and replaces the previous version of 25 May 2018.