PERSONAL DATA PROTECTION POLICY

Dear client, Let us inform you that we, Zazu Naturals s.r.o., Reg. No.: 17789010, with its registered office at Tržiště 366/13, Malá Strana, 118 00 Prague 1, as the data controller and processor of personal data (hereinafter referred to as "we" or "our company"), process your personal data in connection with the performance of our business activities. The purpose of this communication is to provide you with information, especially about what personal data we collect, how we handle it, where we obtain it from, for what purposes we use it, who we may disclose it to, where you can get information about your personal data, and what your individual rights are in the field of data protection. When processing personal data, we adhere to legal regulations and process personal data only to the extent provided by specific services and/or processing purposes. Please acquaint yourself with the contents of this communication, and we are open to answering any potential queries at our office via email at info@izazu.cz. We also have a Data Protection Officer available, Ms. Mihaela Grigorova, email: mihaela.grigorova@izazu.com.

I. General Information

Our company must process certain personal data in light of its business activities, especially to deliver the goods you ordered and fulfill related contractual obligations. Without provision of your personal data, we would be unable to deliver our goods to you. We may process your personal data beyond our contractual obligations, such as offering additional products or other contact with you. For this, we need to obtain your consent.

I.2. Personal Data Processing Principles

In processing your personal data, we respect the highest standards of personal data protection and adhere to the following principles: (a) We always process your personal data for a clearly and intelligibly defined purpose, by defined means, in a defined manner, and only for the duration necessary for the purposes of processing; we only process accurate personal data of clients and ensure that their processing corresponds to the defined purposes and is necessary to fulfill these purposes. (b) We protect your personal data as confidential information; therefore, we process clients' personal data in a way that ensures the highest possible security of these data, preventing any unauthorized or accidental access, alteration, destruction, loss, unauthorized transfers, or other unauthorized processing, as well as misuse. (c) We always provide you with clear information about the processing of your personal data and your rights to accurate and complete information about the circumstances of this processing, as well as your other related rights. (d) We have established and adhere to appropriate technical and organizational measures in our company to ensure a level of security corresponding to all possible risks; all persons who come into contact with clients' personal data are obliged to maintain confidentiality of the information obtained in connection with processing of such data.

II. Information on Processing of Personal Data

II.1. Information about the Data Controller

The data controller of your personal data is us, ZAZU NATURALS s.r.o., Reg. No.: 17789010, with its address at Tržiště 366/13, Malá Strana, 118 00 Prague 1, registered in the Commercial Register kept by the Municipal Court in Prague, Section C, Insert 376701.

II.2. Processing Purposes and Legal Basis for Processing

II.2.1. Processing of Personal Data Without Your Consent This usually pertains to situations where you are required to provide certain personal data as a condition for us to provide you with our product/service, or where we are authorized to process your personal data acquired by other means. (a) We are permitted by law to process your personal data without your consent for the following purposes, in particular:

(i) Preventing damage to our company's property;

(ii) Preventing fraudulent actions to which our company may be exposed;

(b) Conclusion of or performance of a contract with you. This relates primarily to the actual realization of a contractual relationship or other contract fulfillment between our company and you. Personal data are necessary, among other things, to enable the contractual relationship to be carried out without unreasonable legal risks, including actions for concluding or changing an agreement with you. (c) Protection of rights and legally protected interests, especially for:

(i) Protecting the rights and legally protected interests of our company, enforcing claims, securing or other assertion of claims, developing and improving services provided;

(ii) Resolving any dispute agenda, in particular for the purposes of managing legal or other disputes.

(d) Our legitimate interests. This refers primarily to situations where there is a contractual/customer relationship between you and our company. II.2.2. Processing of Personal Data With Your Consent This usually concerns situations where you voluntarily consent to us processing your personal data. Based on your consent, our company processes your personal data for the following purposes: (a) Offering additional company products; (b) Offering job opportunities or other contact with you.

II.3. Scope of Clients' Personal Data Being Processed

Our company processes your personal data to the extent necessary to fulfill the aforementioned purposes. We process contact details (contact addresses, phone numbers, email and other similar contact details), identification data (name, surname, date of birth, permanent address, type, number and validity of identification documents; for entrepreneurs also Reg. No. and Tax ID).

II.4. Method of Processing Personal Data

The way our company processes your personal data includes manual and automated processing in our company's information systems and in physical form. Your personal data is primarily processed by the provider of our e-commerce platform and software solutions, based on a written agreement that includes the same guarantees for personal data processing as we ensure ourselves according to our legal obligations.

II.5. Recipients of Personal Data

Your personal data are accessible to persons involved in the delivery of goods ordered by you and fulfilling associated duties of our company. With your consent, we may disclose your personal data to third parties for the purpose of providing products and services in compliance with the consent. Additionally, your personal data may be transferred to third parties involved in processing clients' personal data in our company or they may have access to such personal data for other reasons in accordance with the law. Information typically flows to: (a) Providers of accounting services; (b) Processors providing us with server, web, cloud, and IT services. Before any transfer of your personal data to a third party, we always conclude a written agreement with this party regulating the processing of personal data to include the same guarantees for personal data processing as we ensure ourselves according to our legal obligations.

II.6. Transfer of Personal Data Abroad

Your personal data are processed in the territory of the Czech Republic and are not transferred to countries outside the European Union.

II.7. Duration of Personal Data Processing

Our company processes clients' personal data only for the period necessary with regard to the purposes of their processing. We regularly assess whether there is still a need to process certain personal data required for a specific purpose. If we find that they are no longer needed for any purposes for which they have been collected or otherwise processed, we dispose of the data. However, internally, we have already evaluated the usual data usability period for certain processing purposes, after the expiration of which we carefully assess the need to continue processing the relevant personal data for that purpose. In this context, it also applies that personal data processed for the following purposes: (a) Fulfillment of a purchase contract, we process for three years; (b) Offering additional products and services with your consent, for three years.

II.8. Right to Withdraw Consent

In this communication, we have elucidated the reasons why we need your personal data and the circumstances under which we may process them only with your consent. You are not obliged to grant your consent to the processing of your personal data, and at the same time, you are entitled to withdraw this consent. We remind you that we are authorized to process certain personal data for specific purposes even without your consent. If you withdraw your consent in such a case, we will cease processing the relevant personal data for purposes requiring that specific consent, but we may still be authorized, or even obliged, to continue processing the same personal data for other purposes. If you wish to withdraw your consent regarding the processing of personal data, please contact us at our office at Tržiště 366/13, Malá Strana, 118 00 Prague 1 or via email at info@izazu.cz.

II.9. Sources of Personal Data

We primarily acquire clients' personal data from: (a) Clients themselves; (b) Publicly available sources (public registers, records, or lists); (c) Potential candidates interested in working with us; (d) Our own activities, specifically processing and evaluating other personal data of clients.

II.10. Your Rights in Connection With the Processing of Your Personal Data

You can exercise all your rights at our office at Tržiště 366/13, Malá Strana, 118 00 Prague 1 or via email at info@izazu.cz. Furthermore, you can lodge a complaint with the supervisory authority, the Office for Personal Data Protection (www.uoou.cz). II.10.1. Right of Access means you can request confirmation from us at any time as to whether personal data concerning you is being processed, and if so, for what purposes, to what extent, to whom it is disclosed, how long we will process it, whether you have the right to rectification, erasure, restriction of processing, or to object, where we obtained the personal data, if there is automated decision-making based on your personal data, including any profiling. You also have the right to obtain a copy of your personal data, with the first provision provided free of charge, and for subsequent requests, we may require a reasonable charge for administrative costs. II.10.2. Right to Rectification means you can ask us at any time to correct or supplement your personal data if they are inaccurate or incomplete. II.10.3. Right to Erasure means we must erase your personal data if (i) it is no longer necessary for the purposes for which it was collected or otherwise processed, (ii) the processing is unlawful, (iii) you object to the processing and there are no overriding legitimate grounds for the processing, or (iv) we are legally required to do so. II.10.4. Right to Restriction of Processing means we must restrict the processing of your personal data until we resolve any disputed issues relating to the processing of your personal data, so that we may only have them stored and possibly use them for the purpose of determining, enforcing, or defending legal claims. II.10.5. Right to Object means you can object to the processing of your personal data that we process for direct marketing purposes or based on legitimate interest. If you object to processing for direct marketing purposes, your personal data will no longer be processed for those purposes.

III. Final Provisions

III.1. This communication is issued for an indefinite period and takes effect on 01/01/2024. III.2. We may change this communication at any time by issuing a new complete version; its current version is published on our company's website and is also available at our office. III.3. Unless expressly stated otherwise, all information provided here also relates to the processing of personal data of potential clients, i.e., individuals with whom we have not yet entered into a contractual relationship but with whom we have already been in contact. The information provided here also applies in a reasonable extent to the processing of personal data of other individuals with whom our company is directly in contact, even though we do not have a contractual relationship with them (e.g., representatives of legal entities).