Policy**PRINTSTEP s.r.o.
*Effective from: 1 May 2026 Version: 1.
0*## 1. Introductory provisions##
The data controller within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as the “GDPR”) is:
PRINTSTEP s.r.o. Company registration number: 27947807 VAT number: CZ27947807 Registered office: Jičínská 226/17, 130 00 Prague 3, Czech Republic, registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, File 128622 (hereinafter referred to as the “Controller” or “we”)
enquiries – Email: [email protected] (requests from data subjects)
– Telephone: +420 246 082 412 –
Postal address: same as the
Controller’s registered office### 1.3 Data Protection Officer (DPO)
The Controller is not obliged to appoint a Data Protection Officer pursuant to Article 37(1) of the GDPR (as it does not process personal data on a large scale or process special categories of data). All enquiries and requests from data subjects are handled directly by the Controller via the contact details provided above.
This policy applies to the processing of personal data via
:- easybag.com (international online shop)
| Term | Meaning |
|---|---|
| Personal data | Any information relating to an identified or identifiable natural person |
| Data subject | A natural person whose personal data we process (you) |
| Controller | PRINTSTEP s.r.o. — determines the purposes and means of processing |
| Processor | A third party that processes data on the Controller’s instructions (e.g. hosting) |
| Processing | Any operation involving data (collection, storage, use, disclosure, erasure) |
| Consent | A freely given, specific, informed and unambiguous indication of will |
3.1 When visiting the website (automatically)
page- Referrer URL-
Session identifier (session cookie)
account- First name and surname-
Email address-
Telephone number (optional)
Identification details: first name, surname, Company registration number, VAT number (for business customers)
Delivery address-
Order details (goods, quantity, price)
helpdesk- Sender’s email
address- Message content and any attachments-
Any details you provide yourself (telephone number, order number, etc.)
Examples of forms: contact form, feedback form (/references), B2B enquiry form, request for a quote.
Data collected
:- First name and surname-
Email address-
Telephone number (optional)
Email address-
Record of consent given and
any withdrawal thereof- Record of communications sent and your interaction with them (opens, clicks)
See section 7 below.
| Purpose of processing | Data categories | Legal basis | Retention period |
|---|---|---|---|
| Fulfilment of orders and delivery of goods | Identification, contact, address, order details | Performance of a contract (Article 6(1)(b) of the GDPR) | Duration of the contract + 4 years (warranty, complaints) |
| Issuing tax documents and maintaining accounts | Identification, billing | Compliance with a legal obligation (Article 6(1)(c)) — Act No. 235/2004 Coll. on VAT, No. 563/1991 Coll. on Accounting | 10 years from the end of the tax period |
| Operation of a user account | Identification, contact and authentication data | Performance of a contract (Article 6(1)(b)) | Until the account is closed + 1 year |
| Handling of complaints | Identification, contact and order details | Compliance with a legal obligation + performance of a contract | 4 years from the resolution of the complaint |
| Communication with the helpdesk | Contact details, content of communication | Legitimate interests (Article 6(1)(f)) — customer support | 7 years from the last communication |
| Processing of form requests / feedback | Contact details, content, photographs | Legitimate interest (Article 6(1)(f)) — processing of the request | 2 years from the last contact |
| Protection against spam (reCAPTCHA Enterprise) | Technical, behavioural | Legitimate interest (Article 6(1)(f)) — security | 6 m months (stored by Google) |
| Rate-limiting and protection against abuse | IP address, timestamp | Legitimate interest (Article 6(1)(f)) | 1 hour (Redis cache) |
| Sending commercial communications (newsletter) | Email address | Consent (Article 6(1)(a)) or legitimate interest (customer pursuant to Section 7(3) of Act No. 480/2004 Coll.) | Until consent is withdrawn or 5 years of inactivity |
| Ad targeting and remarketing | Online identifiers, behaviour | Consent (Article 6(1)(a)) | As per settings in the cookie bar, max. 13 m months |
| Analytics and website performance measurement | Anonymous/pseudonymous behavioural | Consent (Article 6(1)(a)) — analytical cookies | As per settings, max. 26 m months |
| Defence of legal claims | All relevant | Legitimate interest (Article 6(1)(f)) | For the duration of the limitation period (max. 10 years) |
We transfer your personal data to the following processors, who process it exclusively on our instructions and in accordance with the terms of a Data Processing Agreement (DPA):
| Processor | Purpose | Registered office | Transfer outside the EU |
|---|---|---|---|
| Hetzner Online GmbH | Server hosting, databases, backups | Germany (Falkenstein, Nuremberg) | No (EU) |
| Forpsi (Internet CZ, a.s.) | Backup storage (Object Storage) | Czech Republic | No (EU) |
| Cloudflare, Inc. | CDN, DDoS protection, WAF | USA (registered office); EU edge servers | Yes — guaranteed via Standard Contractual Clauses (SCC) + Data Privacy Framework |
5.2 Payment services
Stripe and GoPay act as independent data controllers for payment transactions. We only pass on to them the data necessary to process the payment; you enter your payment details (card number, CVC) directly with them; we do not store them.
| Processor | Purpose | Registered office |
|---|---|---|
| Stripe Payments Europe, Ltd. | Card payment processing | Ireland |
| GoPay s.r.o. | Payment processing (cards, bank transfers, e-wallets) | Czech Republic |
5.3 Delivery of goods
We only provide the carrier with the data necessary for delivery (name, address, telephone number, email). Carriers are independent data controllers in relation to this data.
| Carrier | Registered office |
|---|---|
| PPL CZ s.r.o. | Czech Republic |
| GLS | Czech Republic |
| Direct Parcel Distribution CZ s.r.o. (DPD) | Czech Republic |
| GEIS | Czech Republic |
5.4 Communication services
| Processor | Purpose | Registered office |
|---|---|---|
| PRINTSTEP s.r.o. — internal SMTP server (Postal) | Sending transactional emails | Hetzner DE (own infrastructure) |
| Google Ireland Limited | Google Workspace (Controller’s internal emails) | Ireland |
5.5 Security and anti-spam services
| Processor | Purpose | Registered office | Transfer outside the EU |
|---|---|---|---|
| Google Ireland Limited / Google LLC | reCAPTCHA Enterprise — form protection against spam (see Article 8) | Ireland / USA | Yes — SCCs + Data Privacy Framework |
Note: For administrator authentication, the Controller uses its own self-hosted installation of the open-source software Logto on its own servers (Hetzner). Administrators’ data is processed exclusively by the Controller on its own infrastructure — there is therefore no external processor for authentication services.
| Processor | Purpose | Registered office | Note |
|---|---|---|---|
| DeepL SE | Translation of website texts | Germany | No (EU) |
| Anthropic PBC | Claude AI — translation of the user interface | USA | Only technical website text, no customer PII |
5.7 Analytics and marketing (with consent only)
| Processor | Purpose | Registered office |
|---|---|---|
| Google Ireland Limited | Google Analytics 4, Google Tag Manager (GTM) | Ireland |
| Meta Platforms Ireland Limited | Facebook Pixel | Ireland |
Note: GTM itself does not store personal data, but serves as a container for triggering other tagging scripts (GA4, Pixel, etc.). Specific processing takes place within the individual connected services.
We transfer accounting records to an external accountancy firm for the purposes of bookkeeping and tax consultancy (a statutory obligation under Act No. 563/1991 Coll. on Accounting).
We will provide the current list of external accountancy partners on request at
[email protected].## 6. Transfer of personal data to third countries
Some of our data processors are based outside the European Economic Area (EEA) or process data there, particularly in the USA. In such cases, we apply the following safeguards
:- Standard Contractual Clauses (SCCs) approved by the European
Commission- Data Privacy Framework (DPF) — for processors certified under the EU-US Data Privacy Framework-
Data Processing Agreements (DPAs) with each processor-
Transfer Impact Assessment (TIA — Transfer Impact Assessment) in accordance with the judgment of the Court of Justice of the EU in Case C-311/18 (Schrems II)
. Specific processors outside the EEA are listed in the table in Article 5.
7.1 What are cookies
? Cookies are small text files stored by your browser when you visit a website. They are used to remember preferences, for authentication and to measure website traffic.
| Category | Purpose | Legal basis | Retention period | Examples |
|---|---|---|---|---|
| Essential | Website functionality (shopping basket, login, language) | Legitimate interest (Article 6(1)(f)) — the website does not function without them | Session-based or up to 1 year | session, cart, locale |
| Security | Protection against spam and attacks (reCAPTCHA) | Legitimate interest (Art. 6(1)(f)) | 6 m months | _GRECAPTCHA |
| Functional | Remembering preferences (theme, region) | Consent (Art. 6(1)(a)) | Max. 1 year | theme, region |
| Analytical | Traffic measurement, A/B testing | Consent (Art. 6(1)(a)) | Max. 26 m months | _ga, _gid |
| Marketing | Ad targeting, remarketing | Consent (Art. 6(1)(a)) | Max. 13 m months | _fbp, _gcl_au |
7.3 Managing cookie
consent A cookie banner will appear on your first visit. You can change or withdraw your
consent at any time:- By clicking on the ‘Cookie settings’ link in the website
footer- In your browser settings (by deleting or blocking cookies)
Withdrawing your consent does not affect the lawfulness of processing carried out prior to the withdrawal of consent.
To protect our forms against automated abuse (bots, spam), we use the Google reCAPTCHA Enterprise service provided by Google Ireland Limited (registered office: Gordon House, Barrow Street, Dublin 4, Ireland).
?- The device’s IP
address- User-agent (browser and operating system type)
Purpose: To detect and block automated (bot) form submissions; to protect against spam and fraud
.- Legal basis: The legitimate interest of the Controller and the user in the security of web forms and the integrity of communications (Article 6(1)(f) of the GDPR).
– PRINTSTEP s.r.o. — Data Controller –
Google Ireland Limited / Google LLC — Data Processor –
A Data Processing Agreement (DPA) containing the European Commission’s Standard Contractual Clauses (SCCs) has been concluded between the parties.
– Controller (PRINTSTEP): Risk scores are stored for up to 30 days (after which they are aggregated into anonymous statistics)
.- Google: Raw data is retained for a maximum of 6 m months in accordance with its own retention rules (Google Privacy Policy).
Google Ireland processes data primarily within the EU, but may transfer it to its parent company, Google LLC, in the USA. Such transfers are protected by Standard Contractual Clauses (SCCs) and certification under the Data Privacy Framework (DPF).
Terms and Policies By using our forms, you agree to
:- Google’s
Terms of Service- Google’s Privacy Policy## 9
. Your rights under the GDPR
As a data subject, you have the following rights vis-à-vis the Controller:
You may request confirmation from us as to whether we are processing your personal data and, if so, you have the right to obtain a copy of it.
If your data is inaccurate or incomplete, you have the right to have it rectified or completed without undue delay.
You have the right to request the erasure of your data if
:- The data is no longer necessary for the purpose for which it was collected
processing- The data has been processed unlawfully
Exceptions: We cannot erase data that we are required by law to retain (invoices — 10 years), or data necessary for the defence of legal claims (for a maximum period until the limitation period expires).
In certain situations (e.g. verification of accuracy, raising an objection), you have the right to request that we temporarily cease processing your data.
If we process your data on the basis of a legitimate interest, you have the right to object to this at any time. We will cease processing your data unless we can demonstrate compelling legitimate grounds for the processing which override your interests.
In the case of direct marketing, you may object at any time — you do not need to give a reason — and we will immediately stop processing your data for this purpose.
Where we process data on the basis of consent or the performance of a contract, by automated means, you have the right to receive your data in a structured, commonly used and machine-readable format (JSON / CSV).
If you have given us your consent (e.g. to receive a newsletter), you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
We do not use automated decision-making with legal consequences. The reCAPTCHA risk scoring system merely determines whether a form is displayed — it does not affect your rights or obligations.
your rights You may submit your request
:- By email: [email protected]
We will process your request without undue delay, no later than 1 m months from receipt. In justified cases, this period may be extended by a further 2 m months — we will inform you of this.
To verify your identity, we may ask you for additional information (particularly if the request was not sent from an email address registered with us).
If you are not satisfied with the way your request has been handled or if you believe we are in breach of the GDPR, you have the right to lodge a complaint with the supervisory authority:
Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7 Tel.: +420 234 665 111 Email: [email protected] Website:
www.uoou.cz## 10. Security of personal data
We have implemented the following technical and organisational measures:
Encryption in transit: TLS 1.3 for all communication between users, servers and processors-
Encryption at rest: AES-256 on the database storage, encrypted backups-
Password hashing: bcrypt with a high work factor-
Private storage: Form files (avatars, attachments) stored in private storage with UUID names (URLs cannot be guessed) and ACL controls-
Regular backups: Daily automatic backups to two independent off-site locations (Hetzner Storage Box + Forpsi Object Storage), retention period of 14 days
– Web Application Firewall (WAF): Cloudflare with protection against the OWASP Top 10 –
Rate limiting: Protection of forms and APIs against abuse
– DDoS protection: Cloudflare
– Anti-spam: Google reCAPTCHA Enterprise
– Honeypot fields: Hidden detection of automated submissions
– Self-hosted authentication: Logto on our own servers (no transfer of authentication data to third parties)
– Data minimisation principle: We collect only the data necessary for the specific purpose
– Access restriction principle: Only authorised persons have access to personal data (Logto SSO + role-based access control)
– Confidentiality agreements with employees and external collaborators
– Data Processing Agreements (DPAs) with all data processors
– Audit log: Record of accesses and changes to sensitive data
– Regular security reviews — at least once a
year### 10.3 Procedure in the event of a security incident
In the event of a personal data breach that could result in a high risk to the rights and freedoms of natural persons
:- We will report the incident to the supervisory authority (ÚOOÚ) within 72 hours- We will inform the data
subjects concerned without undue delay- We will document the incident and the measures
taken## 11. Cookies — overview of specific cookies
| Cookie name | Domain | Purpose | Duration | Category |
|---|---|---|---|---|
| easybag_session | easybag.com | Identification of logged-in session | Session | Strictly necessary |
| easybag_cart | easybag.com | Shopping basket contents | 30 days | Strictly necessary |
| locale | easybag.com | Selected website language | 1 year | Strictly necessary |
| region | easybag.com | Selected region (CZ/SK/EU) | 1 year | Functional |
| cookie_consent | easybag.com | Record of consent to cookies | 1 year | Essential |
| _GRECAPTCHA | google.com | Google reCAPTCHA Enterprise | 6 m months | Security |
| _ga, _ga_* | easybag.com | Google Analytics 4 — traffic measurement | 13 m months | Analytical (consent) |
| _gid | easybag.com | Google Analytics — daily identifier | 24 hours | Analytical (consent) |
| _gcl_au | easybag.com | Google Ads conversions (via GTM) | 90 days | Marketing (consent) |
| _fbp | easybag.com | Facebook Pixel | 3 m months | Marketing (consent) |
Note: The specific list of active cookies may vary depending on your consent and the current configuration of the website. You can find the current status in the cookie settings in the website footer.
data Our website and services are not primarily intended for persons under the age of 16. We do not knowingly collect personal data from children under the age of 16 without verifiable consent from a legal guardian. If we discover that we have collected a child’s data without consent, we will delete it immediately.
This policy may be updated from time to time. The current version is always available on the Controller’s website. We will notify you of any significant
changes:- By email — if you have an active account with us or are a newsletter
subscriber- Via a banner on the website — at least 30 days before the change
takes effect Version history:
| Version | Effective from | Main changes |
|---|---|---|
| 1.0 | 1 May 2026 | First published version (includes reCAPTCHA Enterprise disclosure) |
This Policy is governed by the laws of the Czech Republic, in particular
:- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR)
services- Act No. 89/2012 Coll., the Civil Code-
Act No. 235/2004 Coll., on value
added tax- Act No. 563/1991 Coll., on Accounting
In the event of any discrepancy between the English (or any other foreign-language) version of this policy and the Czech version, the Czech version shall prevail.
This policy is effective from 1 May 2026 and supersedes all previous versions.
PRINTSTEP s.r.o. Prague, Czech Republic