Skip to main content
Legal

Privacy Policy

Last updated: 2026-04-24

1. Data controller

FF wholesale s.r.o., company ID (IČO): 21066752, VAT ID (DIČ): CZ21066752, registered at Korunní 1295/55, 120 00 Prague 2 — Vinohrady, Czech Republic, is the data controller under Regulation (EU) 2016/679 (GDPR).

Contact: filip@ffwholesale.cz, +420 773 251 106.

2. What data we process

  • Registration and contact data (for portal clients): name, email, phone, company, VAT/CRN — to maintain your account and billing.
  • Inquiry form data (/stock-pricing): name, company, email, phone, business type, preferences — to send you a quote.
  • Warranty claim data (/warranty): IMEI, invoice number, fault description, contact — to process your claim.
  • RMA form data (/rma): company, contact email, invoice number, and per device unit the IMEI and fault description — to process a claim or return.
  • Device buyback data (in-store purchase contract): full name, date of birth, permanent address, and the type, number and issuing authority/country of the identity document, plus the device description and purchase price. We are legally required to obtain and keep this seller identification under Section 31 of the Czech Trade Licensing Act (No. 455/1991 Coll.) and the AML Act (No. 253/2008 Coll.).
  • First-party visit measurement (visit_sessions): a random session token, traffic source, landing page and referrer. It contains no name, email or IP address, is independent of Google Analytics and of cookie consent, and is used only to measure traffic sources. Admin and client-portal visits are not recorded.
  • Site usage data (only with consent): anonymised Google Analytics 4 data — see Cookie Policy.

3. Purpose and legal basis

PurposeLegal basisRetention
Contract (portal, invoices)Art. 6(1)(b) GDPRDuration of contract + 10 years (statutory)
Business communication (lead)Art. 6(1)(f) legitimate interest2 years from last contact
Warranty / RMA claim handlingArt. 6(1)(b) + (c)4 years from claim date
Device buyback record (private sellers)Art. 6(1)(c) — Sec. 31 Trade Licensing Act, AML (253/2008)As required by law (typically up to 10 years)
First-party visit measurementArt. 6(1)(f) legitimate interestPseudonymous, for as long as needed for traffic analysis
Analytics (GA4)Art. 6(1)(a) consent14 months (GA4 default)

4. Data recipients (processors)

  • Fakturoid s.r.o. (invoicing) — Czech Republic
  • Google Ireland Ltd. (Google Analytics 4) — EU, with transfer to US under standard contractual clauses (SCC). Only active with analytics consent.
  • Meta Platforms Ireland Ltd. (Meta Pixel + Conversions API for Facebook/Instagram ads) — EU, with transfer to US under SCC. Only active with marketing consent. Server-side Conversions API sends hashed contact data (email, phone) to improve conversion attribution — again, only with consent.
  • Exon.io (Exon s.r.o.) — hosting and IT infrastructure, Czech Republic
  • Telegram Messenger Inc. — notifications (only metadata: lead name, company, email for internal alerts)

5. Transfer to third countries

Google Analytics and Meta Pixel / Conversions API transfer pseudonymised (resp. hashed) data to the US. Transfer is secured by standard contractual clauses (SCC), EU-US Data Privacy Framework (DPF) membership of Meta and Google, and technical measures (GA4 IP anonymisation, SHA-256 hashing of PII for Meta CAPI, Consent Mode v2).

6. Automated decision-making and profiling

We do not process personal data in an automated way that would have legal effects on you (no automatic credit decisions, no AI lead scoring).

7. Your rights

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16)
  • Right to erasure — "right to be forgotten" (Art. 17)
  • Right to restriction of processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object (Art. 21)
  • Right to withdraw consent (without affecting lawfulness before withdrawal)
  • Right to lodge a complaint with the supervisory authority — Czech DPA (uoou.gov.cz)

8. Security

We use HTTPS (TLS 1.3), hashed user passwords (bcrypt 12 rounds), HttpOnly + Secure cookies, rate limiting, anti-spam filtering, regular backups, and restricted access to processing systems.

9. GDPR contact

For any request or complaint, contact filip@ffwholesale.cz. We will respond within 30 days.

Related: Cookie Policy.