⬇ PDF

Privacy Policy (GDPR) and Cookie Policy (EN)

Version: 2026-07-18

The Czech version of this document is decisive. Translations into other languages are for information only.

This privacy policy is issued by HOOKAH GARAGE s.r.o., with registered office at Dobrovského 874/29, 702 00 Ostrava, Czech Republic, Reg. No. (IČO): 08997608 (hereinafter the "Controller"). By means of this document we fulfil our information obligation and clearly inform you about what personal data we collect when you browse and use the website available at www.titaniumcarcare.eu, how we handle it, on what legal bases we process it, to whom we transfer it, and what rights are guaranteed to you as a data subject by Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter only "GDPR") and Act No. 110/2019 Coll., on the processing of personal data.

1. Controller of personal data

  • HOOKAH GARAGE s.r.o.
  • Registered office: Dobrovského 874/29, 702 00 Ostrava, Czech Republic
  • Reg. No. (IČO): 08997608
  • VAT No. (DIČ): CZ08997608
  • Entry in the Commercial Register: Regional Court in Ostrava, Section C, File 81580
  • Controller's contact e-mail: office@titaniumcarcare.eu

2. Scope of processed data

  • Identification data: name, surname, company name, Reg. No., VAT No.
  • Contact data: e-mail, telephone, delivery/billing address.
  • Order data: content of orders, purchase history, payment and delivery information.
  • Communication data: queries, complaints, customer support.
  • Technical data: IP address, device data, access logs, data on consents and document acceptances.
  • Login verification data: one-time code (stored as a cryptographic hash) and the associated verification token, generated when the customer activates e-mail login verification (MFA). This is data processed for a very short time in an unreadable form.

3. Purposes and legal bases

Personal data is processed for the purposes of:

  • Conclusion and performance of the purchase contract under Art. 6(1)(b) GDPR,
  • Fulfilment of the Controller's legal obligations (accounting and tax obligations) under Art. 6(1)(c) GDPR,
  • Protection of the Controller's legitimate interests (in particular for security, fraud prevention and enforcement of claims) under Art. 6(1)(f) GDPR,
  • Direct marketing (sending newsletters) under Art. 6(1)(a) GDPR, where the customer has given consent, or on the basis of our legitimate interest (Art. 6(1)(f) GDPR) where you are our existing customer.
  • E-mail login verification (one-time code) and securing of the user account, on the basis of Art. 6(1)(b) GDPR, or Art. 6(1)(f) GDPR to the extent necessary to protect account security; the customer activates this function voluntarily and may deactivate it at any time in the account settings.

4. Categories of data subjects

  • B2C customers (consumers).
  • B2B customers and their authorised contact persons.
  • Potential customers (lead, newsletter).
  • Website visitors.

5. Recipients of personal data and processors

  • Carriers and logistics partners: Geis CZ s.r.o., GLS Czech Republic s.r.o., Zásilkovna s.r.o. (Packeta) and any other contractual carriers – for the purpose of delivering the shipment the following information is transferred to them: name, delivery address and telephone number of the recipient. The transfer of personal data to carriers for the purpose of delivering the shipment is necessary for the performance of the contract under Art. 6(1)(b) GDPR. Where carriers process personal data for their own operational, complaint or legal purposes, they may act as independent controllers to that extent.
  • Payment service providers: ComGate Payments, a.s. (payment gateway for card, bank transfer and BLIK payments) – personal and payment data is processed in accordance with ComGate's terms and conditions and privacy policy. This provider acts as an independent controller to the extent that it determines the purposes and means of processing for the provision of payment services and for the fulfilment of its legal obligations.
  • Providers of IT infrastructure, hosting, e-mail and support tools: they ensure the operation of the e-shop, ERP system and related services for the Controller; these entities generally act as processors of personal data and process data only to the necessary extent in accordance with the Controller's instructions.
  • Accounting, tax or legal advisors: external specialists providing services to the Controller to the necessary extent. Depending on the nature of the services provided, these persons may act either as processors or as independent controllers of personal data (in particular attorneys and tax advisors).
  • Public authorities: State authorities and institutions (e.g. the tax office) where required by law or by a binding decision of the competent authority.

6. Transfers outside the EEA

Personal data may exceptionally be transferred outside the European Economic Area (EEA), in particular if one of the service providers used stores or makes data accessible from a third country. In such a case the Controller will ensure that the transfer takes place only in accordance with Chapter V of the GDPR, in particular on the basis of an adequacy decision or standard contractual clauses.

7. Retention period

  • Data for contract performance (orders, delivery and billing data): for the duration of the contractual relationship and for a further 4 years after its termination for the protection of legal claims (taking into account the limitation period under § 629 of Act No. 89/2012 Coll., the Civil Code (hereinafter only "CC"), increased by a time reserve for any disputes arising in the future).
  • Accounting and tax documents (invoices, tax documents): 10 years from the end of the tax period in which the obligation to issue them arose (Act No. 563/1991 Coll., on accounting; Act No. 235/2004 Coll., on VAT).
  • Marketing consents (newsletter): until consent is withdrawn; records of consent are retained for 3 years after withdrawal as evidence of the lawfulness of processing.
  • Audit data on acceptance of terms (in particular B2B): 5 years from the termination of the contractual relationship, or for the period necessary to fulfil legal obligations.
  • Technical logs and security records: a maximum of 12 months from their creation, unless the law provides otherwise.
  • Login verification codes (e-mail MFA): the one-time code is stored solely as an irreversible cryptographic hash and is valid for no more than 10 minutes; after expiry it is automatically invalidated. The hash of the code and the verification token are automatically and permanently deleted by a periodic job no later than 20 minutes after generation, regardless of whether the code was used.
  • Deleted customer/account records (B2C and B2B): if a legal retention obligation persists (in particular accounting/tax agenda or protection of legal claims), the record is first pseudonymised (soft delete) and hidden from ordinary operational listings; identification data is permanently removed (anonymised) only after the relevant statutory retention period has expired.

8. Rights of data subjects

Data subjects have the following rights:

  • Right of access to personal data.
  • Right to rectification of inaccurate data.
  • Right to erasure, where the conditions of the GDPR are met.
  • If immediate full erasure conflicts with a legal obligation (e.g. accounting/tax), processing is restricted to the necessary minimum and identifiers are anonymised until the end of the statutory retention period.
  • Right to restriction of processing.
  • Right to data portability.
  • Right to object to processing.
  • Right to object to the processing of personal data for direct marketing purposes.
  • Right to lodge a complaint with the Office for Personal Data Protection (Czech Republic).

8a. Withdrawal of marketing consent

  • You may withdraw your consent to receiving marketing communications (newsletter) at any time, in particular via the unsubscribe link in the e-mail or by request to the Controller's contact e-mail.
  • Withdrawal of consent is free of charge and effective for the future; it does not affect the lawfulness of processing prior to withdrawal.
  • Withdrawal of marketing consent does not affect the sending of transactional messages necessary for the performance of the contract (e.g. order confirmation, billing and status e-mails).

9. Cookies and online identifiers

  • The website uses exclusively technical (necessary and functional) cookies, which are necessary to ensure the proper and secure operation of the e-shop (e.g. keeping the user logged in, operation of the shopping cart, language settings or protection against CSRF attacks). These cookies are stored on the basis of the Controller's legitimate interest under Art. 6(1)(f) GDPR and do not require your prior consent. No third-party analytical, statistical or marketing cookies (used to track traffic or personalise advertising) are deployed on the website. Details are provided below in the separate "Cookie Policy" section.

10. Data security

  • Technical and organisational measures: The Controller declares that it has adopted all appropriate technical and organisational measures to ensure maximum security of personal data. These measures include in particular strict management of access rights, logging of system access, regular data backups and encryption of data transfers (including the mandatory use of the secure HTTPS protocol on the website). Access to the data is limited to authorised persons who necessarily need it to perform work or contractual tasks. These persons are trained and bound by a statutory or contractual obligation of confidentiality.
  • With those partners who, in providing services, act as processors of personal data (within the meaning of Art. 28 GDPR), the Controller has concluded written data processing agreements (DPAs). These agreements bind the processors to implement equally strict technical and organisational measures as those applied by the Controller itself. In the event of a security incident that may jeopardise the rights and freedoms of natural persons, the Controller will, without undue delay and no later than within 72 hours, report the incident to the Office for Personal Data Protection (Art. 33 GDPR). If the incident represents a high risk, the affected persons are also informed without undue delay (Art. 34 GDPR).

11. Automated decision-making

  • The Controller does not normally carry out decision-making based solely on automated processing that would have legal effects for data subjects, unless expressly stated otherwise.

11a. Protection of children's data

  • The e-shop services are not intended for persons under 16 years of age. The Controller does not knowingly collect personal data of children under 16. If you have reason to believe that we have received such data by mistake, please contact us at office@titaniumcarcare.eu and we will delete the data without undue delay.

12. Contact point and changes to the policy

  • Please send queries and requests regarding the protection of personal data to: office@titaniumcarcare.eu.
  • The Controller may reasonably update this policy; the current version is published in the eShop.

Cookie Policy (EN)

This cookie policy supplements the main Privacy Policy of HOOKAH GARAGE s.r.o. and explains in detail how we work with these files on our website www.titaniumcarcare.eu. On our e-shop we use exclusively technical and functional cookies that are necessary to ensure basic operation (e.g. for the functioning of the shopping cart, keeping you logged in or protection against cyberattacks). Because we do not deploy any marketing or advertising cookies to track users, we do not use a cookie pop-up banner. However, in accordance with legislation, we transparently inform you below about the specific files we store on your device.

1. What are cookies?

Cookies are small text files that are stored on your device (computer, tablet, mobile phone) when you visit a website. Cookies allow websites to remember your preferences, keep you logged in or collect anonymous statistics about traffic.

2. What cookies do we use?

2.1 Necessary cookies

These cookies are required for the basic functioning of the e-shop. Without them it would not be possible to make purchases or log in to an account. They cannot be disabled.

Name Purpose Validity period
sessionid Maintaining the login session Session / 2 weeks
csrftoken Protection of forms against CSRF attacks 1 year

2.2 Functional cookies

These cookies remember your choices (language, currency) and improve usability.

Name Purpose Validity period
django_language Storing the selected language 1 year

2.3 Payment technical cookies

When paying by card or bank transfer we use the ComGate payment gateway. ComGate may store its own technical cookies necessary for the secure processing of the payment. These cookies fall under the privacy terms of ComGate (comgate.eu), which is responsible for them.

3. Third-party cookies

Third-party technologies (payment gateway) may be present on the site. These third parties may set their own cookies in accordance with their terms. We do not have full control over third-party cookies.

Third-party providers and their policies:

  • ComGate Payments, a.s. – payment processing; comgate.eu/cs/ochrana-soukromi

4. Legal basis for processing

We process all of the above cookies (necessary, functional and payment technical cookies) on the basis of our legitimate interest under Art. 6(1)(f) GDPR. Without these files it would be technically impossible to ensure the proper, secure and functional operation of the e-shop (in particular it would not be possible to complete the purchase process, keep you logged in or securely make a payment). The storage of these cookies is fully in accordance with § 89(3) of Act No. 127/2005 Coll., on electronic communications, and therefore we do not require your prior consent for their use.

5. How to manage or disable cookies?

Cookies can be managed directly in your browser:

  • Google Chrome: Settings → Privacy and security → Cookies and site data
  • Mozilla Firefox: Options → Privacy & Security → Cookies and Site Data
  • Safari: Preferences → Privacy
  • Microsoft Edge: Settings → Privacy, search and services → Cookies

Please note that disabling necessary cookies may render the e-shop non-functional (you will not be able to make purchases or log in).

6. Contact

If you have any questions about cookie processing, please contact us at: office@titaniumcarcare.eu

Controller of personal data:

HOOKAH GARAGE s.r.o.

Dobrovského 874/29, 702 00 Ostrava, Czech Republic

Reg. No. (IČO): 08997608 | VAT No. (DIČ): CZ08997608

The current wording is effective from the version stated in the document header.