Information page for the order request portal

Privacy and personal data policy

This policy explains how the operator of the Mega Mart portal processes personal data during registration, login, account management, catalog use, and order requests. It follows Regulation (EU) 2016/679 (GDPR), Czech Act No. 110/2019 Coll., and related law. Last updated: 13 July 2026.

1. Controller and contact

The data controller is the operator of the Mega Mart order portal, business location Libušská 319, Prague 4 – Libuš, 142 00, Czech Republic (“Mega Mart”, “we”, or the “controller”).

For privacy matters and GDPR requests, contact info@megamart.cz or +420 792 397 143.

2. Who and what this policy covers

This policy applies to website visitors, retail customers, approved B2B customers and their authorized contacts, access applicants, and people who contact us about products, orders, or support.

3. Personal data we process

  • identity and business data: name, company, IČO, VAT number, role, or relationship to an account,
  • contact and login data: phone, email, approved contacts, OTP delivery/verification data, access status, and login sessions,
  • location and delivery data: store labels, saved and default locations, one-time address, and requested date,
  • order data: products, quantities, displayed prices, notes, request number, status, and order history,
  • account usage data: favorites, cart, language, and customer preferences,
  • communications, access requests, support, and requests to change contacts or locations,
  • technical and security data: IP address, device/browser, timestamps, session identifiers, login attempts, lockouts, and security events.

4. Sources of data

  • directly from you when you register, log in, order, manage an account, or communicate with us,
  • from the company or person who names you as an authorized account contact,
  • from existing Mega Mart customer records and lists supplied by a customer or administrator,
  • from public business registers when verifying an IČO and company information,
  • automatically through necessary cookies, browser storage, and security logs.

5. Purposes and lawful bases

  • account creation and management, phone/IČO verification, SMS login, catalog access, and handling order requests – contract performance or pre-contract steps under Article 6(1)(b) GDPR,
  • B2B relationship management, contacts, locations, favorites, and support – contract performance and our legitimate interest in efficient customer service,
  • verification against public registers – legitimate interests in data accuracy, fraud prevention, and protecting non-public prices,
  • portal security, abuse prevention, audits, incident response, and legal claims – legitimate interests in service security and protecting rights,
  • accounting, tax, statutory records, and lawful authority requests – compliance with a legal obligation under Article 6(1)(c) GDPR,
  • marketing, if introduced – only under an appropriate lawful basis; consent may be withdrawn and direct marketing objected to at any time.

6. Required information

Fields marked as required are necessary to provide the requested service. Without phone and verification data we may be unable to grant secure B2B access; without contact and order details we cannot process a request. Optional notes and alternative contacts are not required.

7. Retention

Specific periods depend on purpose, scope, sensitivity, risk, limitation periods, and legal duties. Data needed to establish, exercise, or defend legal claims may be retained for the duration of the relevant claim or proceeding.

  • active account data is kept for the business relationship and afterward only as needed to protect rights, resolve requests, and meet legal duties,
  • order, accounting, and tax records are kept for statutory periods; selected records may commonly need to be retained for up to 10 years,
  • an SMS OTP usually expires after 10 minutes; related security metadata is retained only as needed to prevent abuse and investigate incidents,
  • access requests, communications, and security records are reviewed and deleted or anonymized when no longer needed,
  • favorites and preferences are kept until removed, the account is closed, or they are no longer needed for the service.

8. Recipients and processors

Access is limited to authorized Mega Mart personnel and necessary suppliers: hosting/CDN (Vercel), database and storage (Supabase), SMS verification (BulkGate), email and transactional messaging (Zoho Mail and Resend), IT support, and where needed carriers, accountants, or legal advisers.

Suppliers process data under contractual terms and controller instructions. We may disclose data to a public authority where legally required. We do not sell personal data.

9. Transfers outside the EEA

Some technology suppliers may involve infrastructure or subprocessors outside the European Economic Area. Transfers are then based on an adequacy decision, the EU–US Data Privacy Framework, Standard Contractual Clauses under Article 46 GDPR, or another valid safeguard. Details of the applicable safeguard may be requested at info@megamart.cz.

10. Cookies and browser storage

The portal uses necessary cookies and browser storage for login, session security, cart, order completion, language, and customer preferences. These technologies are required for core functions.

We currently do not use behavioral advertising cookies or marketing profiling. If consent-based analytics or marketing cookies are introduced, they will not activate before consent and users will be able to change or withdraw their choice.

11. Automated decision-making

We do not make decisions based solely on automated processing that produce legal or similarly significant effects. Security rules may temporarily restrict login after repeated failed attempts; access and exceptions can be reviewed by an administrator.

12. Your rights

Send requests to info@megamart.cz. We may reasonably verify identity. We respond without undue delay, normally within one month; GDPR permits an extension for complex requests, in which case we will notify you.

  • confirmation, access, and a copy of your personal data,
  • correction of inaccurate data and completion of incomplete data,
  • erasure or restriction where GDPR conditions are met,
  • data portability in a structured format where the right applies,
  • objection to legitimate-interest processing and at any time to direct marketing,
  • withdrawal of consent for the future where processing relies on consent,
  • a complaint to the Czech Data Protection Authority, Pplk. Sochora 27, 170 00 Prague 7, www.uoou.gov.cz.

13. Data security

We use technical and organizational safeguards appropriate to risk, including access controls, user verification, encrypted transmission, separated administrator permissions, security logs, and supplier-backed backups. No system can guarantee absolute security; report suspected account misuse promptly.

14. Minors and regulated goods

The portal and catalog areas containing regulated goods are not intended for anyone under 18. If we learn that a minor provided data without a valid basis, we will take reasonable steps to delete it.

15. Changes to this policy

We may update this policy when the portal, suppliers, or legal requirements change. The current version is always published on this page, and material changes will be communicated in an appropriate way.