Privacy

Policy**PRINTSTEP s.r.o.

*Effective from: 1 May 2026 Version: 1.

0*## 1. Introductory provisions##

1.1 Data Controller

The data controller within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as the “GDPR”) is:

PRINTSTEP s.r.o. Company registration number: 27947807 VAT number: CZ27947807 Registered office: Jičínská 226/17, 130 00 Prague 3, Czech Republic, registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, File 128622 (hereinafter referred to as the “Controller” or “we”)

1.2 Contact details for data protection

enquiries – Email: [email protected] (requests from data subjects)

– Telephone: +420 246 082 412 –

Postal address: same as the

Controller’s registered office### 1.3 Data Protection Officer (DPO)

The Controller is not obliged to appoint a Data Protection Officer pursuant to Article 37(1) of the GDPR (as it does not process personal data on a large scale or process special categories of data). All enquiries and requests from data subjects are handled directly by the Controller via the contact details provided above.

1.4 Web interfaces to which the policy applies

This policy applies to the processing of personal data via

:- easybag.com (international online shop)

  • taskahned.cz and taskahned.sk (local online shops in the Czech Republic and Slovakia)
  • any other domains of the Controller listed in the statement of processing activities##
  • Definitions
TermMeaning
Personal dataAny information relating to an identified or identifiable natural person
Data subjectA natural person whose personal data we process (you)
ControllerPRINTSTEP s.r.o. — determines the purposes and means of processing
ProcessorA third party that processes data on the Controller’s instructions (e.g. hosting)
ProcessingAny operation involving data (collection, storage, use, disclosure, erasure)
ConsentA freely given, specific, informed and unambiguous indication of will
##
  • What personal data do we collect###

3.1 When visiting the website (automatically)

  • IP address and approximate geolocation (at city level)
  • Browser type and version, operating system-
Date and time of visit, pages visited, time spent on the

page- Referrer URL-

Session identifier (session cookie)

  • Data collected by Google reCAPTCHA Enterprise (see Article 8)

3.2 Upon registration and maintenance of a user

account- First name and surname-

Email address-

Telephone number (optional)

  • Password (stored only in hashed form — bcrypt)

3.3 When ordering goods-

Identification details: first name, surname, Company registration number, VAT number (for business customers)

  • Contact details: telephone number, email
address- Billing address-

Delivery address-

Order details (goods, quantity, price)

  • We do not accept or store payment details (these are processed by Stripe / GoPay as separate data controllers — see Article 5)

3.4 When communicating with the

helpdesk- Sender’s email

address- Message content and any attachments-

Any details you provide yourself (telephone number, order number, etc.)

  • Conversation records (internal tickets, operator notes)

3.5 When filling in forms (contact, feedback, enquiry)

Examples of forms: contact form, feedback form (/references), B2B enquiry form, request for a quote.

Data collected

:- First name and surname-

Email address-

Telephone number (optional)

  • Order number (optional)
  • Content of the message / enquiry-
Rating (1–5 stars, for the feedback form only)
  • Any attached photographs (max. 5 MB, JPG/PNG/WebP/PDF only)
  • Technical data: IP address, user-agent, timestamp (audit trail)

3.6 When subscribing to the newsletter and marketing communications-

Email address-

Record of consent given and

any withdrawal thereof- Record of communications sent and your interaction with them (opens, clicks)

3.7 Cookies and similar technologies

See section 7 below.

Purpose of processingData categoriesLegal basisRetention period
Fulfilment of orders and delivery of goodsIdentification, contact, address, order detailsPerformance of a contract (Article 6(1)(b) of the GDPR)Duration of the contract + 4 years (warranty, complaints)
Issuing tax documents and maintaining accountsIdentification, billingCompliance with a legal obligation (Article 6(1)(c)) — Act No. 235/2004 Coll. on VAT, No. 563/1991 Coll. on Accounting10 years from the end of the tax period
Operation of a user accountIdentification, contact and authentication dataPerformance of a contract (Article 6(1)(b))Until the account is closed + 1 year
Handling of complaintsIdentification, contact and order detailsCompliance with a legal obligation + performance of a contract4 years from the resolution of the complaint
Communication with the helpdeskContact details, content of communicationLegitimate interests (Article 6(1)(f)) — customer support7 years from the last communication
Processing of form requests / feedbackContact details, content, photographsLegitimate interest (Article 6(1)(f)) — processing of the request2 years from the last contact
Protection against spam (reCAPTCHA Enterprise)Technical, behaviouralLegitimate interest (Article 6(1)(f)) — security6 m months (stored by Google)
Rate-limiting and protection against abuseIP address, timestampLegitimate interest (Article 6(1)(f))1 hour (Redis cache)
Sending commercial communications (newsletter)Email addressConsent (Article 6(1)(a)) or legitimate interest (customer pursuant to Section 7(3) of Act No. 480/2004 Coll.)Until consent is withdrawn or 5 years of inactivity
Ad targeting and remarketingOnline identifiers, behaviourConsent (Article 6(1)(a))As per settings in the cookie bar, max. 13 m months
Analytics and website performance measurementAnonymous/pseudonymous behaviouralConsent (Article 6(1)(a)) — analytical cookiesAs per settings, max. 26 m months
Defence of legal claimsAll relevantLegitimate interest (Article 6(1)(f))For the duration of the limitation period (max. 10 years)
##
  • Recipients of personal data (processors)

We transfer your personal data to the following processors, who process it exclusively on our instructions and in accordance with the terms of a Data Processing Agreement (DPA):

5.1 Hosting and infrastructure

ProcessorPurposeRegistered officeTransfer outside the EU
Hetzner Online GmbHServer hosting, databases, backupsGermany (Falkenstein, Nuremberg)No (EU)
Forpsi (Internet CZ, a.s.)Backup storage (Object Storage)Czech RepublicNo (EU)
Cloudflare, Inc.CDN, DDoS protection, WAFUSA (registered office); EU edge serversYes — guaranteed via Standard Contractual Clauses (SCC) + Data Privacy Framework
###

5.2 Payment services

Stripe and GoPay act as independent data controllers for payment transactions. We only pass on to them the data necessary to process the payment; you enter your payment details (card number, CVC) directly with them; we do not store them.

ProcessorPurposeRegistered office
Stripe Payments Europe, Ltd.Card payment processingIreland
GoPay s.r.o.Payment processing (cards, bank transfers, e-wallets)Czech Republic
###

5.3 Delivery of goods

We only provide the carrier with the data necessary for delivery (name, address, telephone number, email). Carriers are independent data controllers in relation to this data.

CarrierRegistered office
PPL CZ s.r.o.Czech Republic
GLSCzech Republic
Direct Parcel Distribution CZ s.r.o. (DPD)Czech Republic
GEISCzech Republic
###

5.4 Communication services

ProcessorPurposeRegistered office
PRINTSTEP s.r.o. — internal SMTP server (Postal)Sending transactional emailsHetzner DE (own infrastructure)
Google Ireland LimitedGoogle Workspace (Controller’s internal emails)Ireland
###

5.5 Security and anti-spam services

ProcessorPurposeRegistered officeTransfer outside the EU
Google Ireland Limited / Google LLCreCAPTCHA Enterprise — form protection against spam (see Article 8)Ireland / USAYes — SCCs + Data Privacy Framework

Note: For administrator authentication, the Controller uses its own self-hosted installation of the open-source software Logto on its own servers (Hetzner). Administrators’ data is processed exclusively by the Controller on its own infrastructure — there is therefore no external processor for authentication services.

5.6 Localisation and translation services

ProcessorPurposeRegistered officeNote
DeepL SETranslation of website textsGermanyNo (EU)
Anthropic PBCClaude AI — translation of the user interfaceUSAOnly technical website text, no customer PII
###

5.7 Analytics and marketing (with consent only)

ProcessorPurposeRegistered office
Google Ireland LimitedGoogle Analytics 4, Google Tag Manager (GTM)Ireland
Meta Platforms Ireland LimitedFacebook PixelIreland

Note: GTM itself does not store personal data, but serves as a container for triggering other tagging scripts (GA4, Pixel, etc.). Specific processing takes place within the individual connected services.

5.8 External accounting services

We transfer accounting records to an external accountancy firm for the purposes of bookkeeping and tax consultancy (a statutory obligation under Act No. 563/1991 Coll. on Accounting).

We will provide the current list of external accountancy partners on request at

[email protected].## 6. Transfer of personal data to third countries

Some of our data processors are based outside the European Economic Area (EEA) or process data there, particularly in the USA. In such cases, we apply the following safeguards

:- Standard Contractual Clauses (SCCs) approved by the European

Commission- Data Privacy Framework (DPF) — for processors certified under the EU-US Data Privacy Framework-

Data Processing Agreements (DPAs) with each processor-

Transfer Impact Assessment (TIA — Transfer Impact Assessment) in accordance with the judgment of the Court of Justice of the EU in Case C-311/18 (Schrems II)

. Specific processors outside the EEA are listed in the table in Article 5.

7. Cookies and similar technologies###

7.1 What are cookies

? Cookies are small text files stored by your browser when you visit a website. They are used to remember preferences, for authentication and to measure website traffic.

7.2 Categories of cookies used on the website

CategoryPurposeLegal basisRetention periodExamples
EssentialWebsite functionality (shopping basket, login, language)Legitimate interest (Article 6(1)(f)) — the website does not function without themSession-based or up to 1 yearsession, cart, locale
SecurityProtection against spam and attacks (reCAPTCHA)Legitimate interest (Art. 6(1)(f))6 m months_GRECAPTCHA
FunctionalRemembering preferences (theme, region)Consent (Art. 6(1)(a))Max. 1 yeartheme, region
AnalyticalTraffic measurement, A/B testingConsent (Art. 6(1)(a))Max. 26 m months_ga, _gid
MarketingAd targeting, remarketingConsent (Art. 6(1)(a))Max. 13 m months_fbp, _gcl_au
###

7.3 Managing cookie

consent A cookie banner will appear on your first visit. You can change or withdraw your

consent at any time:- By clicking on the ‘Cookie settings’ link in the website

footer- In your browser settings (by deleting or blocking cookies)

Withdrawing your consent does not affect the lawfulness of processing carried out prior to the withdrawal of consent.

8. Google reCAPTCHA Enterprise — specific information

To protect our forms against automated abuse (bots, spam), we use the Google reCAPTCHA Enterprise service provided by Google Ireland Limited (registered office: Gordon House, Barrow Street, Dublin 4, Ireland).

8.1 What data does reCAPTCHA collect

?- The device’s IP

address- User-agent (browser and operating system type)

  • Google cookies on the google.com
domain- Date, time and duration of interaction with the form
  • Mouse movements, clicks, screen touches (anonymised behavioural data)
  • Browser fingerprint (resolution, plug-ins, fonts, language)
  • Data you have entered into the form (used for context — not for ad targeting)

Purpose: To detect and block automated (bot) form submissions; to protect against spam and fraud

.- Legal basis: The legitimate interest of the Controller and the user in the security of web forms and the integrity of communications (Article 6(1)(f) of the GDPR).

8.3 Status of the contracting parties

– PRINTSTEP s.r.o. — Data Controller –

Google Ireland Limited / Google LLC — Data Processor –

A Data Processing Agreement (DPA) containing the European Commission’s Standard Contractual Clauses (SCCs) has been concluded between the parties.

8.4 Retention period

– Controller (PRINTSTEP): Risk scores are stored for up to 30 days (after which they are aggregated into anonymous statistics)

.- Google: Raw data is retained for a maximum of 6 m months in accordance with its own retention rules (Google Privacy Policy).

8.5 Transfer to third countries

Google Ireland processes data primarily within the EU, but may transfer it to its parent company, Google LLC, in the USA. Such transfers are protected by Standard Contractual Clauses (SCCs) and certification under the Data Privacy Framework (DPF).

8.6 Google’s

Terms and Policies By using our forms, you agree to

:- Google’s

Terms of Service- Google’s Privacy Policy## 9

. Your rights under the GDPR

As a data subject, you have the following rights vis-à-vis the Controller:

9.1 Right of access (Article 15 of the GDPR)

You may request confirmation from us as to whether we are processing your personal data and, if so, you have the right to obtain a copy of it.

9.2 Right to rectification (Article 16 of the GDPR)

If your data is inaccurate or incomplete, you have the right to have it rectified or completed without undue delay.

9.3 Right to erasure / ‘right to be forgotten’ (Article 17 of the GDPR)

You have the right to request the erasure of your data if

:- The data is no longer necessary for the purpose for which it was collected

  • You withdraw your consent and there is no other legal basis-
You lodge a legitimate objection to the

processing- The data has been processed unlawfully

Exceptions: We cannot erase data that we are required by law to retain (invoices — 10 years), or data necessary for the defence of legal claims (for a maximum period until the limitation period expires).

9.4 Right to restriction of processing (Article 18 of the GDPR)

In certain situations (e.g. verification of accuracy, raising an objection), you have the right to request that we temporarily cease processing your data.

9.5 Right to object (Article 21 of the GDPR)

If we process your data on the basis of a legitimate interest, you have the right to object to this at any time. We will cease processing your data unless we can demonstrate compelling legitimate grounds for the processing which override your interests.

In the case of direct marketing, you may object at any time — you do not need to give a reason — and we will immediately stop processing your data for this purpose.

9.6 Right to data portability (Article 20 of the GDPR)

Where we process data on the basis of consent or the performance of a contract, by automated means, you have the right to receive your data in a structured, commonly used and machine-readable format (JSON / CSV).

9.7 Right to withdraw consent (Article 7(3) of the GDPR)

If you have given us your consent (e.g. to receive a newsletter), you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.

9.8 Right not to be subject to automated decision-making (Article 22 of the GDPR)

We do not use automated decision-making with legal consequences. The reCAPTCHA risk scoring system merely determines whether a form is displayed — it does not affect your rights or obligations.

9.9 How to exercise

your rights You may submit your request

:- By email: [email protected]

  • By post: to the Controller’s registered office (see section 1.1)

We will process your request without undue delay, no later than 1 m months from receipt. In justified cases, this period may be extended by a further 2 m months — we will inform you of this.

To verify your identity, we may ask you for additional information (particularly if the request was not sent from an email address registered with us).

9.10 Right to lodge a complaint

If you are not satisfied with the way your request has been handled or if you believe we are in breach of the GDPR, you have the right to lodge a complaint with the supervisory authority:

Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7 Tel.: +420 234 665 111 Email: [email protected] Website:

www.uoou.cz## 10. Security of personal data

We have implemented the following technical and organisational measures:

10.1 Technical measures-

Encryption in transit: TLS 1.3 for all communication between users, servers and processors-

Encryption at rest: AES-256 on the database storage, encrypted backups-

Password hashing: bcrypt with a high work factor-

Private storage: Form files (avatars, attachments) stored in private storage with UUID names (URLs cannot be guessed) and ACL controls-

Regular backups: Daily automatic backups to two independent off-site locations (Hetzner Storage Box + Forpsi Object Storage), retention period of 14 days

– Web Application Firewall (WAF): Cloudflare with protection against the OWASP Top 10 –

Rate limiting: Protection of forms and APIs against abuse

– DDoS protection: Cloudflare

– Anti-spam: Google reCAPTCHA Enterprise

– Honeypot fields: Hidden detection of automated submissions

– Self-hosted authentication: Logto on our own servers (no transfer of authentication data to third parties)

10.2 Organisational measures

– Data minimisation principle: We collect only the data necessary for the specific purpose

– Access restriction principle: Only authorised persons have access to personal data (Logto SSO + role-based access control)

– Confidentiality agreements with employees and external collaborators

– Data Processing Agreements (DPAs) with all data processors

– Audit log: Record of accesses and changes to sensitive data

– Regular security reviews — at least once a

year### 10.3 Procedure in the event of a security incident

In the event of a personal data breach that could result in a high risk to the rights and freedoms of natural persons

:- We will report the incident to the supervisory authority (ÚOOÚ) within 72 hours- We will inform the data

subjects concerned without undue delay- We will document the incident and the measures

taken## 11. Cookies — overview of specific cookies

Cookie nameDomainPurposeDurationCategory
easybag_sessioneasybag.comIdentification of logged-in sessionSessionStrictly necessary
easybag_carteasybag.comShopping basket contents30 daysStrictly necessary
localeeasybag.comSelected website language1 yearStrictly necessary
regioneasybag.comSelected region (CZ/SK/EU)1 yearFunctional
cookie_consenteasybag.comRecord of consent to cookies1 yearEssential
_GRECAPTCHAgoogle.comGoogle reCAPTCHA Enterprise6 m monthsSecurity
_ga, _ga_*easybag.comGoogle Analytics 4 — traffic measurement13 m monthsAnalytical (consent)
_gideasybag.comGoogle Analytics — daily identifier24 hoursAnalytical (consent)
_gcl_aueasybag.comGoogle Ads conversions (via GTM)90 daysMarketing (consent)
_fbpeasybag.comFacebook Pixel3 m monthsMarketing (consent)

Note: The specific list of active cookies may vary depending on your consent and the current configuration of the website. You can find the current status in the cookie settings in the website footer.

12. Processing of children’s

data Our website and services are not primarily intended for persons under the age of 16. We do not knowingly collect personal data from children under the age of 16 without verifiable consent from a legal guardian. If we discover that we have collected a child’s data without consent, we will delete it immediately.

13. Changes to the Privacy Policy

This policy may be updated from time to time. The current version is always available on the Controller’s website. We will notify you of any significant

changes:- By email — if you have an active account with us or are a newsletter

subscriber- Via a banner on the website — at least 30 days before the change

takes effect Version history:

VersionEffective fromMain changes
1.01 May 2026First published version (includes reCAPTCHA Enterprise disclosure)
##
  • Final provisions

This Policy is governed by the laws of the Czech Republic, in particular

:- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR)

  • Act No. 110/2019 Coll., on the processing of personal data-
Act No. 480/2004 Coll., on certain information society

services- Act No. 89/2012 Coll., the Civil Code-

Act No. 235/2004 Coll., on value

added tax- Act No. 563/1991 Coll., on Accounting

In the event of any discrepancy between the English (or any other foreign-language) version of this policy and the Czech version, the Czech version shall prevail.

This policy is effective from 1 May 2026 and supersedes all previous versions.

PRINTSTEP s.r.o. Prague, Czech Republic