Privacy Policy
of TUČI s.r.o.
for the online store gear.outspacegame.com
Effective from August 23, 2026
I. Data Controller
The controller of personal data is:
TUČI s.r.o.
Company ID: 04455614
VAT ID: CZ04455614
registered office: Smetanova 633/51, 602 00 Brno, Česká republika
E-mail:
gear@outspacegame.com
hereinafter referred to as the “Controller”.
II. Personal Data We Process
The Controller processes only personal data necessary for the operation of the online store, order fulfilment and compliance with related obligations.
This includes in particular:
- first name and surname,
- e-mail address,
- telephone number,
- billing and, where applicable, delivery details,
- details of the selected pickup point or parcel locker,
- information about orders and purchased products,
- information about the price and payment status,
- information necessary for issuing accounting and tax documents,
- information relating to complaints, returns and customer communication,
- technical data necessary for the operation and security of the online store.
When paying by payment card, the Controller does not process or store complete payment card details. Such information is processed by the payment service provider.
III. Purposes and Legal Bases of Processing
1. Order Fulfilment and Performance of the Purchase Contract
Personal data is processed for the purpose of receiving and processing orders, receiving payment, manufacturing ordered products, delivering goods, communicating with customers and handling withdrawals from contracts or complaints.
The legal basis for this processing is Article 6(1)(b) of the GDPR – processing necessary for the performance of a contract or in order to take steps at the request of the data subject prior to entering into a contract.
2. Compliance with Legal Obligations
The Controller processes and retains certain personal data because this is required by applicable legislation, in particular accounting and tax regulations.
The legal basis is Article 6(1)(c) of the GDPR – compliance with a legal obligation to which the Controller is subject.
3. Protection of the Controller's Rights and Legitimate Interests
The Controller may, to the extent necessary, retain and process information required to protect its rights, maintain records of completed transactions, prevent fraudulent conduct, secure the online store and establish, exercise or defend legal claims.
The legal basis is Article 6(1)(f) of the GDPR – the legitimate interests of the Controller.
IV. Provision of Personal Data
The provision of information necessary to conclude and perform a purchase contract is a contractual requirement.
Without the provision of information necessary to process the order, it is not possible to accept, process, pay for or deliver the order.
The customer is not required to provide any other information that is not necessary for the relevant purpose.
V. Recipients of Personal Data
The Controller discloses personal data to third parties only to the extent necessary to fulfil the relevant purpose.
Personal data may in particular be disclosed to:
- payment service and payment gateway providers,
- carriers responsible for delivering orders,
- operators of pickup points and parcel lockers where necessary for delivery,
- hosting and technical service providers,
- accounting and tax service providers,
- other service providers necessary for the operation of the online store,
- public authorities where required by applicable law.
Such recipients receive only the information necessary to perform their specific tasks.
VI. Payment Services
Payments made through the online store may be processed by an external payment service provider.
The payment service provider may receive information necessary to identify and process the payment, including the order amount, currency, order number, contact details and technical information required to process and secure the payment.
Payment card details are entered by the customer directly into the secure environment of the payment service provider, and the Controller does not store complete payment card details.
The payment service provider may perform its own transaction security and risk assessments as part of payment processing.
VII. Delivery
For the purpose of delivering an order, the Controller provides the selected carrier with the information necessary to deliver the shipment.
This includes in particular:
- the recipient's first name and surname,
- telephone number,
- e-mail address,
- the selected delivery location, pickup point or parcel locker,
- information necessary to identify the shipment.
VIII. Retention Period
Personal data is retained only for as long as necessary for the purpose for which it was collected or for the period required by applicable law.
Information relating to an order may be retained after performance of the contract for the period necessary to protect the Controller's rights and resolve potential legal claims.
Information contained in accounting and tax documents is retained for the period prescribed by applicable legislation. Tax documents subject to Czech VAT legislation are retained for 10 years from the end of the tax period in which the relevant taxable supply took place.
Once there is no longer a legal basis for processing, personal data will be deleted, anonymised or retained only where its continued retention is required by applicable law.
IX. Transfers Outside the European Economic Area
Some technical or payment service providers may process personal data outside the European Economic Area in connection with the provision of their services.
Where such a transfer takes place, it must be carried out in accordance with the GDPR, in particular on the basis of an adequacy decision of the European Commission or using appropriate safeguards under the GDPR.
X. Rights of Data Subjects
Subject to the conditions set out in the GDPR, data subjects have in particular the right to:
- request access to their personal data,
- request rectification of inaccurate or incomplete personal data,
- request erasure of personal data where the legal conditions are met,
- request restriction of processing,
- object to processing based on legitimate interests,
- request data portability where the relevant legal conditions are met.
These rights may be exercised by contacting: gear@outspacegame.com.
Individual rights are not absolute and may only be exercised under the conditions established by applicable legislation. For example, the Controller is not required to erase information that it is legally required to retain or that is necessary for the establishment, exercise or defence of legal claims.
XI. Right to Lodge a Complaint
If a data subject believes that the processing of their personal data infringes applicable data protection legislation, they have the right to lodge a complaint with the supervisory authority:
Office for Personal Data Protection
Pplk. Sochora 27
170 00 Prague 7
Czech Republic
Website:
https://uoou.gov.cz/
XII. Security of Personal Data
The Controller implements appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, loss, destruction or other misuse.
Access to personal data is limited to persons who require such access in order to perform their employment, contractual or legal duties.
XIII. Cookies
Information regarding the storage and use of cookies is provided separately in the Cookie Policy and, where applicable, through the cookie consent management tool available on the website.
XIV. Final Provisions
This Privacy Policy may be updated from time to time to reflect changes in the way personal data is processed, the services used or applicable legislation.
The current version of this Privacy Policy is always available on gear.outspacegame.com.