- Personal Data Processing Principles
- Controller: Controller of the personal data is Bestsport, a.s., with registered seat at Prague 9, Českomoravská 2345/17, 190 00 Prague, ID No.: 24214795, registered in the Commercial Register administered by the Municipal Court in Prague, Section B, File No. 17875 (hereinafter referred to only as the “Bestsport, a.s.” or also “Controller”). The controller operates so-called O2 arena (building No. 2345/17, Libeň cadastral area), so-called O2 universum (buildings without number, on the plot No. 3343/32, Libeň cadastral area) and the so-called Parking House (building No. 2422, Libeň cadastral area) (O2 arena, O2 universum, and Park House are jointly referred to as the “Buildings”).
- Data Protection Officer: The Data Protection Officer can be contacted by e-mail at firstname.lastname@example.org
- Legality: Personal data is collected and processed by the controller in accordance with the legal regulations governing the area of personal data protection, in particular Act No. 101/2000 Coll., on the Personal Data Protection, as amended (hereinafter referred to only as the “Act”), Act No. 480/2004 on some services of the information society, and Directive (EC) No. 2016/679 of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to only as the “GDPR”).
- Personal Data: The controller collects personal data communicated to it directly by the data subject, either on the basis of a consent or in connection with conclusion of a contract between the data subject and the controller, the personal data obtained through the CCTV system in the Buildings and their surroundings, and personal data obtained during visit to the Buildings. The personal data provided this way usually comprises name, surname, e-mail address, contact details (telephone, mobile phone, address, contact address), personal identification card number, photographs for input into the system in case of repeated access to any of the Buildings, photographs or other image record of the data subject in case of camera recordings, and – in case of any purchase by the data subject – also the information about such purchase (in particular, the type of goods / service, price, quantity) (hereinafter referred to also as the “personal data”).
- Purpose of Personal Data Processing Personal data is processed by the controller for the following purposes and based on the following titles:
- if an e-mail address for sending a newsletter is entered at the controller’s website, the purpose of the personal data processing is to send marketing communication and news relating to the controller's business, subject to the consent with such processing; the purpose may in this case include also sending operational and informative messages regarding O2 arena operation (e.g., information on security measures during events, etc.); the e-mail address is voluntarily provided the data subject for this purpose and the consent does not represent a prerequisite for providing any service or sale of the controller’s goods.
- in case of purchase of goods/services of the controller, the purpose consists in contract performance, and/or communication of operating and other information regarding the purchased goods / services required for use of the goods / service, on the basis of concluded contract; the purpose can in this case also include distribution of operating and information messages regarding the operation of O2 arena (e.g., information on security measures during events, etc.); the purpose can also include the internal needs of Bestsport, a.s., mainly for the protection of rights and legitimate interests of Bestsport, a.s., for the production of statistics and analyzes, improvement and increasing the quality of services, and/or their adaptation for analyses of business opportunities, etc.; In case of purchase of goods / services, the personal data provision is a prerequisite for conclusion of a valid contract – the contract cannot be concluded without such information; in case of purchase of goods / services of the controller, the personal data is also processed for the purpose of newsletter (marketing communications) distribution; the data subject can object to the controller at any time free of charge against the personal data processing for direct marketing purposes performed without a consent, by written notice sent by e-mail to email@example.com or firstname.lastname@example.org or in writing to the address of the controller’s registered office.
- in case of granting consent with personal data processing by the controller at the web site of the controller’s ticket operator (a company selling tickets for events held in O2 arena's Buildings or at O2 universum), the purpose of the personal data processing is to send marketing communication and news relating to the controller's business, subject to the consent with such processing; the purpose may in this case include also sending operational and informative messages regarding O2 arena operation (e.g., information on security measures during events, etc.), statistic evaluation of visitors of the events taking place in O2 arena’s Buildings or at O2 universum, and other analytical evaluation for the controller’s purposes; the personal data is voluntarily provided the data subject for this purpose and the consent does not represent a prerequisite for providing any service or sale of the controller’s or third party’s goods.
- in case of monitoring the premises (Buildings) and the vicinity of the premises (Buildings) of the controller, the purpose is to protect the property, safety, and other protected interests of the controller, controller’s employees, and other persons located at these places; the CCTV recordings are kept for 21 days from the date of recording (information regarding camera recordings is provided separately); provision of such personal data is a prerequisite for entry into the Buildings and its surroundings and the reason for this are the legitimate interests of the controller;
- in case of live screen transmissions, the purpose is to provide the services to customers during selected events – direct transmission from the auditorium to the large screens inside the hall, serving for performance, such as entertainment during breaks, etc.; the provision of such personal data is the prerequisite for entry into O2 arena Building or into O2 universum and the reason are the legitimate interests of the controller;
- in case of a visit to O2 arena or O2 universum through the staff reception (i.e., to visit one of the Buildings outside events) without use of a ticket, the purpose consists in property protection, safety, and other protected interests of the controller; the provision of such personal data is the prerequisite for entry into O2 arena Building or to O2 universum building and the reason are the legitimate interests of the controller - access to said Buildings can be declined without provision of such data;
- in case of creating recordings from events, the purpose is the legitimate interest of the controller as event organizer to artistic performance recording and its further commercial utilization; in this case, the information about event recording is displayed for the particular event on its website (www.o2arena.cz or www.o2universum.cz); provision of such personal data is the prerequisite for entry into O2 arena Building or O2 universum in order to view such event and thus for conclusion of agreement about sale of ticket for such event.
- Source of personal data: Source of personal data is:
- the data subject (whether directly through communication to the controller or their activities at social network profiles managed by the controller or through cookies if allowed by the data subject);
- the camera system recording the premises of Bestsport, a.s. (Buildings) and the vicinity of Bestsport’s premises (Buildings)
- the cameras inside the buildings of Bestsport, a.s., scanning the auditorium, but always without recording,
- the cameras of Bestsport, a.s. as the event organizer when recording an event taking place at O2 arena or O2 universum,
- public registers of entrepreneurs (commercial register, trade register, VAT register, land registry database, and other professional publicly available registers).
- Consent with e-mail address recording. If the personal data is processed on the groundwork of consent given by the data subject in electronic form - by e-mail address provision at the controller’s website, it is necessary to enter the e-mail address in relevant field, tick the consent, confirm the acquaintance with this policy in the appropriate box, and confirm in the received e-mail message that the e-mail address was entered by the authorized person. If the specified e-mail address is not confirmed via the provided link, the entered e-mail address is not registered in the controller's database or otherwise processed.
- Correctness of personal data: By entering and providing personal data to the controller (e.g., at www.o2arena.cz / www.o2universum.cz website when buying goods or services, etc.), the personal data provider confirms the right to provide such personal data as well as its correctness and completeness.
- Processors: The controller may assign processing of personal data, incl. distribution of commercial messages on behalf of Bestsport, a.s. to external entities, which provide the controller with administrative or professional and/or technical support, or which carry out marketing, business or other specific activity (hereinafter referred to as the “Processors”); these external entities are contractually bound to comply with the principles of personal data processing in accordance with GDPR and other applicable legal regulations in the same way as Bestsport, a.s.
- Third party access: Personal data may also be disclosed by the controller to public authorities for reasons stipulated by law and, to the extent necessary, also to other entities for the protection of the controller’s rights (e.g., courts, law enforcement authorities, etc.).
- Processing time: Personal data is processed by the controller
- for a maximum of 10 years from subscribing to newsletters and thus granting the consent with personal data processing, respectively, until the data subject withdraws its consent or becomes the customer of Bestsport, a.s.;
- for a period determined with regard to the purpose of personal data processing, to the extent necessary, in case the personal data is processed under a title other than consent (in particular, for the time to claim rights under the liability for defects or warranty for goods or services purchased from the controller (usually two years), for the period of exercise of the controller’s rights towards its debtors (usually three years), retention of tax documents for the administration of taxes (usually ten years), etc.;
- for the period specified in the granted consent,
- for the period of 21 calendar days in case of camera recording monitoring the premises of the controller (Buildings) or the vicinity of the controller's premises (Buildings), see a separate information regarding the camera recordings,
- for an indefinite period of time, in case of Bestsport event recording where Bestsport acts as event organizer.
After the expiration of the authorized processing period, such as the termination of this service or on request in justified cases, the controller will discontinue processing of such personal data and any personal data stored by the controller or the processor will be disposed of in accordance with applicable law.
- Form of processing and security: Provided data is processed by the controller both automatically and manually with the possibility of its mechanical processing, safely, in accordance with the technical and security mechanisms that ensure the maximal possible protection of the processed data (especially against unauthorized access or transmission, against loss or destruction or other misuse).
- Type of processing: Personal data will be processed in particular by collecting, sorting, recording, organizing, structuring, storing, adapting, altering, searching, viewing, will be used, accessed (including accessing by transmission), distributed, combined, limited, destroyed, deleted, etc.
- Automated decision making: The controller does not perform automated decision making, including profiling, which would have legal effects for the data subject or have a significant impact on the data subject. Automated processing with profiling elements is done only when newsletters (marketing communication) are sent on the groundwork of a previous purchase of goods / services from the controller or controller’s ticket operator, only to the extent of sending such newsletters regarding similar products of the controller that the data subject purchased from the controller or ticket operator.
- Consent withdrawal: The given consent can be withdrawn at any time, with effects for the future. The consent withdrawal can be done in writing by sending a written consent withdrawal notice to Bestsport, a.s., Českomoravská 2345/17, 190 00 Prague or by sending an e-mail to email@example.com or firstname.lastname@example.org In case of newsletter (marketing communication), the instructions regarding consent withdrawal is given directly in the newsletter.
- Information about the data subject's rights. Data subjects have the following rights:
- Right of access to personal data: The data subject has the right to request information as to what personal data on the subject is processed by the controller. Such request is made in writing by post to Bestsport, a.s., Českomoravská 2345/17, 190 00 Prague, or by e-mail email@example.com. The controller may request the right to reimbursement for any costs associated with providing this information only in accordance with the GDPR. Upon request, the controller will provide copies of the processed personal data in accordance with the GDPR. This right to obtain a copy must not adversely affect the rights and freedoms of other persons.
- Right to correction: The data subject may request the controller to correct any inaccurate or incomplete personal data regarding the data subject that they process.
- Right to deletion: The data subject may request the controller to delete the personal data of the data subject if one of the following situations occurs:
- personal data are no longer needed for the purposes for which it was collected or otherwise processed;
- the data subject has withdrawn its consent, based on which the personal data of the data subject was processed and there is no further legal reason for processing of such data;
- the data subject has objected against being the subject of a decision making based on the automated processing of the data subject's personal data and there are no overriding legitimate reasons for such processing, or the data subject has objected to the processing of personal data of the data subject for direct marketing purposes;
- personal data of the data subject has been processed unlawfully;
- personal data of the data subject must be erased in order to comply with a legal obligation stipulated by laws of the European Union or the Member State to which the controller is subject;
- personal data of the data subject was collected exclusively in connection with offer of information society services.
- Right to limit the processing: The data subject may request the controller to limit processing of personal data of the data subject if one of the following situations occurs:
- the data subject has denied the accuracy of the data subject's personal data, for the time necessary for the controller to verify the accuracy of the personal data;
- processing of the data subject’s personal data is unlawful, but the data subject refuses deletion of such data and instead requests that its limited use;
- the controller no longer needs such personal data for processing purposes, however, the data subject requires it for identification, exercise, or defending any legal claims;
- the data subject has raised an objection to data subject’s personal data processing under Article 21 (1) of the GDPR, until it is verified whether the legitimate reasons of the controller outweigh the legitimate reasons of the data subject.
- Right to data portability: In case of personal data processing based on a consent or contract and processed in an automated manner, the data subject has the right to obtain the personal data relating to the data subject, which was previously provided to the controller by the data subject, and the right to pass on such data to another controller in a structured, machine readable format, provided that this right must not adversely affect the rights and freedoms of other persons.
- Right to object: The data subject may at any time object to the controller against the data subject’s personal data processing performed on the groundwork of the controller’s legitimate interest and for the purposes of direct marketing carried out on the groundwork of the controller’s legitimate interest.
- Right to be informed: The data subject has the right to be informed by the controller in the event of a breach of security of the data subject's personal data, which is likely to result in a high risk to the rights and freedoms of natural persons, including the data subject.
- Right in relation to automated processing: The data subject has the right not to be the subject of a decision based exclusively on automated processing, including profiling, which has a legal effect on the data subject or otherwise significantly affects the data subject.
- Change of personal data: In case the personal data is changed, the data subject is obliged to notify the controller of such change in the situations specified in the particular regulation, otherwise the due and correct processing of the provided personal data cannot be guaranteed.
- Place of rights exercise. All rights (appeals, objections, etc.) may be exercised by the data subject
- in writing by post at the controller’s address: Bestsport, a.s., Českomoravská 2345/17, 190 00 Prague;
- personally at the controller's address: Bestsport, a.s., Českomoravská 2345/17, 190 00 Prague;
- by sending an e-mail to firstname.lastname@example.org or email@example.com;
- electronically in the form at https://www.o2arena.cz/cz/kontakt/ (Personal Data category);
The data subject may also file a complaint with the Personal Data Protection Authority, Pplk. Sochora 727/27, 170 00 Prague 7-Holešovice, firstname.lastname@example.org
- Recipients: Personal data may be provided to the following recipients:
- Controller’s processors - provider of security and organizational services, event organizers, ticket operator, media service provider (especially media campaigner), web service provider (especially hosting), service providers and IT system support providers for the controller’s or processors’ systems.
- Law enforcement bodies;
- Other public authorities in the case of a legitimate request or due to statutory obligations of the controller or relevant Processor;
- Camera Systems
Surroundings and the building of the O2 arena (building No. 2345/17, c.a. Libeň), surroundings and the building of the O2 universum (building without number, on parcel No. 3343/32, c.a. Libeň), and the surrounding area and the building of the Park House (building No. 2422, c.a. Libeň) are monitored constantly by a CCTV recorder for the purpose of protecting the property, life and health of persons, operation of all mentioned buildings, and ensuring order and organization of events with connection to the O2 arena / O2 universum premises. An entry made from this camera system is stored for 21 calendar days from the time of recording, unless there is no legitimate reason for a longer retention period (e.g. a request from law enforcement authorities). The record is further provided at the request of data subjects, unless this request would interfere with the rights of other data subjects and law enforcement agencies, or upon a legitimate request of other public administration authority, if appropriate.
The data subjects are informed about the monitoring of this camera system through the information tables at the recording site, where contact to the administrator is given. The administrator of the personal data processed in this way is Bestsport, a.s., Company ID: 24214795. Further information about the camera system can be found at the email@example.com e-mail address.
What are cookies?
Cookies are small data files that make this website remember your actions and settings you have made, so you do not need to enter these data repeatedly.
If you have any questions or concerns about cookies while using the site, please contact firstname.lastname@example.org