Privacy Policy
I. General Provisions
1. The controller of personal data within the meaning of Art. 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as "GDPR") is:
- Online store: www.healthygarden.shop (hereinafter referred to as: "HealthyGarden e-shop")
- Operator: Nico distribution s.r.o.
- Company ID (IČO): 096 27 014
- VAT ID (DIČ): CZ09627014
- Registered office: Lannova 2061/8, Nové Město, 110 00 Praha 1 (CZ)
- File No.: C 339223, registered with the Municipal Court in Prague
(hereinafter referred to as the "controller").
2. Contact details of the controller for all matters relating to HealthyGarden:
- Email: info@healthygarden.shop
- Phone: +420 737 410 600
3. Personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
4. The controller has not appointed a Data Protection Officer.
II. Sources and Categories of Processed Personal Data
1. The controller processes personal data that you have provided through HealthyGarden, or personal data that the controller has obtained in connection with the fulfilment of your order.
2. The controller processes your identification and contact details and the data necessary for the performance of the contract.
III. Legal Basis and Purpose of the Processing of Personal Data
1. The legal basis for the processing of personal data is:
- the performance of the contract between you and the controller pursuant to Art. 6(1)(b) GDPR,
- the controller's legitimate interest in providing direct marketing (in particular for sending commercial communications and newsletters) pursuant to Art. 6(1)(f) GDPR,
- your consent to processing for the purposes of direct marketing (in particular for sending commercial communications and newsletters from HealthyGarden) pursuant to Art. 6(1)(a) GDPR in conjunction with Section 7(2) of Act No. 480/2004 Coll., on Certain Information Society Services, where no order for goods or services has been made.
2. The purpose of the processing of personal data is:
- processing your order and exercising the rights and obligations arising from the contractual relationship between you and the controller; when placing an order, the personal data necessary for successful order processing (name and address, contact details) are required. The provision of personal data is a necessary requirement for the conclusion and performance of the contract – without the provision of personal data, it is not possible to conclude the contract or for it to be performed by the controller,
- sending commercial communications and carrying out other HealthyGarden marketing activities.
3. The controller does not carry out any automated individual decision-making within the meaning of Art. 22 GDPR.
IV. Data Retention Period
1. The controller retains personal data:
- for the period necessary to exercise the rights and obligations arising from the contractual relationship between you and HealthyGarden and to assert claims arising from that contractual relationship (for a period of 15 years from the termination of the contractual relationship).
2. Upon expiry of the data retention period, the controller shall delete the personal data.
V. Recipients of Personal Data (Sub-processors of the Controller)
1. The recipients of personal data are persons:
- involved in the delivery of goods/services or the processing of payments under the contract,
- ensuring the operation of the e-shop and other services in connection with the operation of the HealthyGarden e-shop,
- providing marketing services.
2. The controller does not intend to transfer personal data to a third country (outside the EU) or to an international organisation.
VI. Cookies
Our website uses cookies to improve your browsing experience. Cookies are small text files stored in your browser. Below you will find a detailed overview of all the cookies we use.
Necessary Cookies
These cookies are necessary for the basic functionality of the website and are stored automatically. They cannot be disabled.
| Name | Description | Duration |
|---|---|---|
| ADD_TO_CART | Used by Google Tag Manager | 1 year |
| GUEST-VIEW | Stores the order ID that guests use to check order status | 1 year |
| LOGIN_REDIRECT | Stores the destination page that was loading before the customer was redirected to the login page | 1 year |
| MAGE-MESSAGES | Tracks error messages and other notifications displayed to the user | 1 year |
| MAGE-TRANSLATION-STORAGE | Stores translated content at the customer's request | 1 year |
| MAGE-TRANSLATION-FILE-VERSION | Tracks the version of translations in local storage | 1 year |
| PRODUCT_DATA_STORAGE | Stores product data configuration related to recently viewed/compared products | 1 year |
| RECENTLY_COMPARED_PRODUCT | Stores the IDs of recently compared products | 1 year |
| RECENTLY_COMPARED_PRODUCT_PREVIOUS | Stores the IDs of previously compared products for easy navigation | 1 year |
| RECENTLY_VIEWED_PRODUCT | Stores the IDs of recently viewed products for easy navigation | 1 year |
| RECENTLY_VIEWED_PRODUCT_PREVIOUS | Stores the IDs of previously viewed products for easy navigation | 1 year |
| STF | Records the time messages are sent by the SendFriend module | 1 year |
| X-MAGENTO-VARY | Improves performance when using Varnish to cache static content | 1 year |
| FORM_KEY | A security measure protecting form submissions against CSRF attacks | 1 year |
| MAGE-CACHE-SESSID | Triggers the clearing of the local cache | 1 year |
| MAGE-CACHE-STORAGE | Local storage of visitor-specific content enabling e-commerce features | 1 year |
| MAGE-CACHE-STORAGE-SECTION-INVALIDATION | Forces the local storage of specific content sections that should be invalidated | 1 year |
| PERSISTENT_SHOPPING_CART | Stores the persistent cart key used to restore an anonymous customer's cart | 1 year |
| PRIVATE_CONTENT_VERSION | Prevents pages containing customer content from being cached on the server | 1 year |
| SECTION_DATA_IDS | Stores customer-specific information related to actions initiated by the customer | 1 year |
| STORE | Tracks the specific store view/language setting selected by the customer | 1 year |
| AGE_POPUP | Stores age verification settings | 1 year |
Marketing Cookies
These cookies are used to track visitors across different websites for marketing purposes. They are stored only with your consent.
| Name | Description | Duration |
|---|---|---|
| CUSTOMER_SEGMENT_IDS | Stores your customer segment ID | 1 year |
| EXTERNAL_NO_CACHE | Indicates whether caching is enabled or disabled | 1 year |
| FRONTEND | Your session ID on the server | 1 year |
| LAST_CATEGORY | The last category you visited | 1 year |
| LAST_PRODUCT | The last product you viewed | 1 year |
| NEWMESSAGE | Indicates whether a new message has been received | 1 year |
| NO_CACHE | Indicates whether the use of cache is permitted | 1 year |
Functional Cookies
These cookies enable enhanced functionality and personalisation on the website.
| Name | Description | Duration |
|---|---|---|
| MG_DNT | Allows data collection to be limited if you have your own cookie consent management code | 1 year |
| USER_ALLOWED_SAVE_COOKIE | Used for cookie restriction mode | 1 year |
| AUTHENTICATION_FLAG | Indicates whether the customer is logged in or logged out | 1 year |
| DATASERVICES_CUSTOMER_ID | Identifies the logged-in customer | 1 year |
| DATASERVICES_CUSTOMER_GROUP | Indicates the customer group (stored as a SHA-1 checksum) | 1 year |
| DATASERVICES_CART_ID | Identifies the customer's actions with the cart | 1 year |
| DATASERVICES_PRODUCT_CONTEXT | Identifies the customer's interactions with products | 1 year |
VII. Customer Rights
1. Under the conditions set out in the GDPR, you have:
- the right of access to personal data pursuant to Art. 15 GDPR,
- the right to rectification of personal data pursuant to Art. 16 GDPR and, where applicable, the right to restriction of processing pursuant to Art. 18 GDPR,
- the right to erasure of personal data pursuant to Art. 17 GDPR,
- the right to object to processing pursuant to Art. 21 GDPR,
- the right to data portability pursuant to Art. 20 GDPR,
- the right to withdraw consent to processing in writing or electronically to the address or email of the controller stated in Article I of this Privacy Policy.
2. You also have the right to lodge a complaint with the Office for Personal Data Protection if you believe that your right to the protection of personal data has been violated.
VIII. Privacy Protection and Security Measures
1. The controller declares that it has adopted all appropriate technical and organisational measures to secure personal data.
2. The controller has adopted technical measures to secure data storage systems and the storage of personal data in paper form.
3. The controller declares that only authorised persons have access to personal data.
IX. Final Provisions
1. By submitting an order via the online order form on HealthyGarden, you confirm that you have familiarised yourself with this Privacy Policy and that you accept it in full.
2. You agree to this Privacy Policy by ticking the relevant box in the online form. By ticking the consent box, you confirm that you have familiarised yourself with the terms of the Privacy Policy and accept them.
3. The controller is entitled to amend this Privacy Policy. A new version of the Privacy Policy will be published on the website and will also be sent to you at the email address you provided to the controller.
These terms take effect on 19 November 2025.
