Privacy and cookies
Effective from 8 August 2026
1. Who is the data controller?
The data controller is Stexaco s.r.o., Company ID No. 06356826, with its registered office at Na Štěpnici 1253, 665 01 Rosice, Czech Republic (“Stexaco”, “we” or “us”).
You can contact us about personal data protection at info@stexaco.cz or at the address above.
2. What data do we process and why?
Website access and security
When you visit the website, technical systems may process your IP address, the date and time of the request, the requested URL, browser and device information, and technical error or security logs. We use this information to operate and secure the website, diagnose faults and protect the website and user accounts. The legal basis is our legitimate interest in operating a secure and reliable website.
Contact form and ordinary communication
We process your email address, the subject and content of your message, and any information you choose to provide. We use it to handle your question or enquiry and subsequent communication. The legal basis is taking steps at your request before entering into a contract or, where applicable, our legitimate interest in handling business communication. The contact form content is not stored in the theme database; the form sends it by email.
Registration and customer account
When you register and manage an account, we process the contact person's name, email address and telephone number, details of the represented company, company and VAT identification numbers, billing and delivery addresses, technical activation and login data, and securely stored authentication data. We do not know your password in readable form; WordPress stores only its cryptographic hash.
We use this information to verify registration, create and secure the account, pre-fill orders and communicate with the customer. The legal bases are taking steps before entering into a contract, performing a contractual relationship and our legitimate interest in securing the customer portal.
We may obtain company details from the public ARES register. The company identification number entered by you is sent to ARES from our server; the result may be cached in WordPress for 24 hours to reduce repeated queries.
Orders
We process the identification and contact details of the customer and its contact person, billing and delivery addresses, customer reference, note and ordered product data. Submitting the form creates a web copy, an internal email, an email copy for the customer and an XML file for our internal order processing. The temporary XML file is deleted after the delivery attempt.
We use this information to receive, check, confirm and process an order, maintain related communication and protect legal claims. The legal bases are taking steps before entering into a contract, performing a contract, our legitimate interests and, for data required by accounting or tax rules, compliance with legal obligations.
Deleting the web copy of an order does not delete emails already sent or a record that may have been created in our internal system.
3. Where do we obtain the data?
We obtain data directly from you, from the company you represent, from communications and orders and, for company identification data, from the public ARES register.
4. Who may receive the data?
Access is limited to people who need the data to operate the website, communicate and process orders. Where necessary, our contracted hosting, email, backup and IT service providers and providers of our accounting or internal systems may process the data. We may also disclose data to public authorities where required by law.
The current website does not transmit data to Google Maps, Apple Maps or linked partner websites before you choose to follow an external link. Further processing after opening such a link is governed by the destination service.
5. Transfers outside the European Economic Area
The current website does not load analytics or marketing services and its web fonts are hosted directly on our website. If any of our operational providers processes data outside the European Economic Area, we will ensure appropriate safeguards under the GDPR and provide information about them on request.
6. How long do we retain the data?
We retain personal data only for as long as needed for its purpose:
- technical and security logs for the period necessary to operate the service and investigate incidents under the hosting and security settings;
– kontaktní zprávy a související komunikaci do vyřízení požadavku a dále po dobu potřebnou pro navazující obchodní komunikaci a ochranu právních nároků;
– neaktivovaná registrace má aktivační odkaz platný 24 hodin a po jeho vypršení je záznam určen k technickému odstranění;
– údaje zákaznického účtu po dobu existence účtu a obchodního vztahu a dále po dobu potřebnou ke splnění právních povinností a ochraně právních nároků;
– objednávky, e-maily a související interní záznamy po dobu zpracování obchodního případu a následně po dobu stanovenou účetními, daňovými a dalšími právními předpisy nebo potřebnou k ochraně právních nároků;
– údaje uložené pouze v prohlížeči podle části 7 níže.
The exact period may vary according to the nature of the transaction, a legal obligation or an ongoing dispute. When the purpose no longer applies, we securely delete or anonymise the data unless the law requires us to retain it.
7. Cookies and browser storage
The website in its current form does not use analytics or marketing cookies. We therefore do not display a consent cookie banner. We use only technical means needed for login, security and functions requested by the user.
| Name or pattern | When used | Purpose | Duration |
|---|---|---|---|
wordpress_logged_in_[hash] | only after login | maintains the authenticated customer session | browser session; if “Remember me” is selected, for the period configured in WordPress |
wordpress_sec_[hash] or wordpress_[hash] | only after login | securely authenticates the logged-in user | the same as the authenticated session |
wordpress_test_cookie | may be set on the standard WordPress login or password-reset page | tests whether the browser accepts cookies | browser session |
stexacoB2B.orderDraft.* in sessionStorage | after an actual change to a new order while logged in | restores the draft and recognises the form just submitted in the current tab | up to 24 hours after the last change; it also ends with the tab session |
The draft in `sessionStorage` may contain contact and delivery details, the customer reference, note and order lines. It is not stored on the server and is not continuously synchronised between separate tabs. It is also removed when the form is cleared, the order is successfully submitted or the user logs out. The browser may remove technical data sooner.
You can remove or block cookies and website data in your browser settings. Blocking technical cookies will prevent login to the customer portal and some functions may not work correctly.
8. Automated decision-making
The website described here does not carry out automated individual decision-making or profiling that produces legal or similarly significant effects for you.
9. Your rights
Subject to the conditions of the GDPR, you may request access to, correction or erasure of your personal data, restriction of processing and data portability. You may object to processing based on legitimate interests. If any processing is based on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing.
We may reasonably verify your identity when handling a request and will respond within the statutory time limit. You also have the right to lodge a complaint with the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, at uoou.gov.cz.
10. Changes to this document
We may update this document when the website, services used or legal requirements change. The current version is always published on this page with its effective date.
