Privacy Policy
Updated 6 August 2026
At Michael's Treasures, I value your privacy and am committed to protecting your personal data. This Privacy Policy explains how your personal information is collected, used and protected when you contact me through this website, in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR").
1. Data Controller
Michal Sopoliga
IČO: 22533834
Slavíkova 1379/20, 130 00, Prague
michael.treasures1@gmail.com
2. What Data Are Collected
Depending on your enquiry, the following categories of personal data may be collected:
- Contact Information (such as your name, email address and, if provided, your phone number)
- Communication Data (the content of messages and enquiries you send through the contact form or by email)
- Transaction Data (information necessary to complete a purchase or sale, such as billing or shipping details)
- Photographs and Related Metadata (photographs you voluntarily provide, including any metadata contained within the files)
3. How Is Your Data Used
Your personal data are processed only to the extent necessary to respond to your enquiry, provide advice, arrange the purchase or sale of a watch, complete a transaction, and fulfil our legal obligations.
Personal data are never used for marketing purposes without your prior consent.
Where necessary for the provision of our services, certain personal data may be shared with trusted third-party service providers. In particular, information relating to a watch or its owner may be shared with:
Tuloki Watch Service s.r.o.
Jesenského 98/74, 943 01 Štúrovo, Slovakia
Email: renovebytuloki@gmail.com
Such information is shared only where necessary for the inspection, servicing or repair of a watch and only to the extent required for those purposes.
4. Legal Bases for Processing
Personal data are processed only where there is a lawful basis under the General Data Protection Regulation (GDPR). Depending on the circumstances, processing is based on:
- Performance of a Contract — where processing is necessary to respond to an enquiry or to provide the requested services, including the purchase or sale of a watch.
- Legal Obligation — where certain information must be retained to comply with applicable legal, tax or accounting obligations.
- Consent — where explicit consent has been provided, for example for receiving newsletters, marketing communications or for the use of non-essential cookies. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal.
5. Data Retention
Your personal data are kept only as long as necessary for the purposes explained above or as required by law. Where no legal obligation requires longer retention, personal data will be securely deleted or anonymised.
6. Cookies
This website does not currently use analytics, advertising or other non-essential cookies. Only cookies that are strictly necessary for the operation and security of the website may be used.
7. Your Rights
Under the GDPR, data subjects are entitled to exercise the following rights, subject to the conditions and limitations set out in applicable law:
- Right of Access — to obtain confirmation as to whether personal data are being processed and, where that is the case, to access such data.
- Right to Rectification — to request the correction of inaccurate or incomplete personal data.
- Right to Erasure — to request the deletion of personal data where the legal requirements are met.
- Right to Restriction of Processing — to request that the processing of personal data be restricted in certain circumstances.
- Right to Object — to object to the processing of personal data where processing is based on legitimate interests.
- Right to Data Portability — to receive personal data in a structured, commonly used and machine-readable format, where applicable.
- Right to Withdraw Consent — to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before its withdrawal.
- Right to Lodge a Complaint — to lodge a complaint with the competent supervisory authority if it is believed that the processing of personal data infringes applicable data protection laws. In the Czech Republic, the competent supervisory authority is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů — ÚOOÚ), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic.
8. Data Security
Appropriate technical and organisational measures are implemented to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or unauthorised access.
Although reasonable safeguards are maintained, no method of electronic transmission or storage can be guaranteed to be completely secure.
9. International Data Transfers
Where personal data are processed by service providers located outside the European Economic Area (EEA), appropriate safeguards are implemented in accordance with Chapter V of the GDPR, including the use of the European Commission's Standard Contractual Clauses where applicable.
10. Changes to this Privacy Policy
This Privacy Policy may be updated from time to time to reflect changes in applicable legal requirements, business practices or the operation of this website. The latest version will always be published on this page together with the date of the last update.
11. Contact
If you have any questions about this Privacy Policy or your rights, please contact me at: michael.treasures1@gmail.com