Sortiment
Metal Metal
Wood Wood
Concrete, asphalt, mineral substrates Concrete, asphalt, mineral substrates
Plastic, glass, ceramics Plastic, glass, ceramics
Walls Walls
Facades Facades
Sprays Sprays
Thinners, hardeners, cleaners, technical fluids Thinners, hardeners, cleaners, technical fluids
Tinting systems
Colorlak Dekor Colorlak Dekor
Colorlak Profi Colorlak Profi
Colorlak Pta Colorlak Pta

GDPR and COOKIES

Privacy Policy of COLORLAK, a. s. 

Article 1

Introductory Provisions

 

(1)  COLORLAK, a. s., ID No.: 49444964, with its registered office at Tovární 1076, 686 03 Staré Město, registered in the Commercial Register maintained by the Regional Court in Brno under file number B 1112 (hereinafter referred to as “COLORLAK”), hereby fulfills its information obligation pursuant to the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council, the General Data Protection Regulation (hereinafter referred to as the “GDPR”), Directive 2002/58/EC of the European Parliament and of the Council on privacy and electronic communications, Act No. 110/2019 Coll., on the processing of personal data, as amended, Act No. 127/2005 Coll., on electronic communications, as amended, and other relevant legal regulations.

 

(2)  COLORLAK makes this statement on behalf of the COLORLAK, a.s. group; where this document refers to COLORLAK, it also includes all companies belonging to the group. This document applies to all companies forming the group, specifically:

 

a)  COLORLAK, a.s., 

b)  COLORLAK SK, s.r.o.,

c)  COLORLAK POLSKA, Sp. z o.o.

 

(3)  The purpose of this document is to provide visitors to the COLORLAK Company’s website with complete, specific, and understandable information regarding the scope, purpose, and manner in which COLORLAK processes their personal data in connection with their access to and use of the website. 


(4)  For the purposes of this document, a data subject means any natural person who visits or otherwise uses the website https://www.colorlak.cz/ (hereinafter referred to as the “User”).

 

(5)  For the purposes of this document, “personal data” means any information about the User that is collected in connection with their visit to and use of the COLORLAK website (hereinafter referred to as “Personal Data”).

 

(6)  For the purposes of this document, “Controller” means a natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data and is responsible for such processing and its protection (hereinafter referred to as the “Controller”).

 

(7)  For the purposes of this document, “Recipient” means a natural or legal person, public authority, agency, or other body to whom personal data is disclosed, whether a third party or not (hereinafter referred to as the “Recipient”). Public authorities to which personal data may be disclosed pursuant to applicable laws are not considered Recipients. Public authorities handle Personal Data in accordance with applicable data protection rules to the extent and for the purposes defined by applicable laws.

(8)  “Processing of personal data” means any handling of personal data obtained in connection with access to and use of the COLORLAK website, whether automated through technologies on the website or by other means. Processing includes any operation or set of operations performed on such data, such as, in particular, collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

 

 

Article 2

Data Controller

 

(1)  The data controller processing Personal Data collected through visits to the website is COLORLAK, a. s., ID No.: 49444964, with its registered office at Tovární 1076, 686 03 Staré Město, registered in the Commercial Register maintained by the Regional Court in Brno under file number B 1112.

 

(2)  Contact details of the Controller:

a)  email: gdpr@colorlak.cz

b)  hotline: 800 145 555

c)  phone: +420 572 527 111

d)  mailing address: Tovární 1076, 686 03 Staré Město, Czech Republic

 

(3)  In the event of any questions, comments, complaints, or requests regarding the processing of Personal Data, you may contact the Controller using the contact information provided above.

(4)  The Controller is responsible for ensuring that the processing of Personal Data complies with applicable laws. The Controller ensures that Personal Data is processed lawfully and transparently, that it is protected against unauthorized access, loss, or misuse, and that Users’ rights are respected.

 

 

Article 3

Personal Data

 

(1) In connection with visiting and using the website, certain technical and operational data necessary to ensure the proper functioning, security, and optimization of the website are automatically recorded. This data may be used to identify and resolve technical issues, provide services, improve the user experience, compile anonymous statistical reports, and respond to inquiries.

 

(2) In connection with visiting and using the website, the following categories of personal data may be processed:

a)  Identification and contact information

-    email address.

 

b)  User behavior data

-    the URL of the website from which the User arrived at the website,

-    pages visited and content viewed,

-    the order of pages visited (navigation path),

-    time spent on the website,

-    clicks on links or buttons,

-    navigation on the website,

-    preference settings,

-    frequency of visits,

-    use of the search field on the website,

-    text of the query submitted by the User.


c)  Technical data

-    IP address,

-    date and time of website access,

-    server response code,

-    amount of data transferred,

-    web browser type and version,

-    operating system type and version,

-    device type (computer, mobile phone, tablet),

-    screen resolution,

-    browser language settings,

-    approximate location.

 

d)  Security data

-    server access logs,

-    login attempt logs,

-    server error logs,

-    request metadata.

 

(3) In connection with the operation of the website, data provided by third parties may also be processed, in particular by providers of analytics, advertising, marketing, or login services.

 

 

Article 4

Purpose of Processing and Legal Basis 

 

(1) Personal data collected in connection with the visit and use of this website is processed only to the extent necessary and always for clearly defined purposes. Data may be processed in particular for the following purposes:

a)  ensuring the operation, functionality, and security of the website so that it remains accessible and protected against misuse, 

b)  handling requests, inquiries, suggestions, or complaints submitted through the website, 

c)  measuring website traffic and evaluating website performance for the purpose of improvement, 

d)  tailoring website content to Users’ needs and preferences, 

e)  marketing, including sending commercial communications and displaying advertisements, provided consent has been granted, 

f)   compliance with legal obligations established by law, 

g)  creation of internal reports and statistics to improve services and ensure effective management of operations, 

h)  protection of the Controller’s legitimate interests, in particular the protection of rights and property, ensuring the security of services, and the effective functioning of the website.

 

(2) Data is always processed in accordance with applicable laws and only for the time necessary to achieve the stated purposes. Personal data is processed based on the legitimate interest of COLORLAK, based on the User’s consent, to fulfill the Controller’s legal obligations, and, where necessary, also for the performance of a contract or measures taken prior to its conclusion.


(3) Personal data collected in connection with visits to and use of the website is processed primarily on the basis of the Controller’s legitimate interest in ensuring the operation, security, and functionality of the website. In such cases, the User’s consent is not required; it is sufficient to inform the User about the processing and its purpose.

 

(4) The Controller’s legitimate interest consists primarily in ensuring the security and functionality of the website and the effective management and development of its services. The processing of Personal Data is necessary to protect these interests and is proportionate, given that it does not exceed the normal expectations of website Users and does not unduly interfere with their rights and freedoms.

 

(5) Consent to the processing of personal data is given voluntarily by the User via an interactive element upon their first visit to the Controller’s website. Consent may be withdrawn at any time in the same manner in which it was given, or via the Controller’s contact details specified in Article 2, paragraph (2) of this document.


Article 5

Sharing and Disclosure of Data

 

(1) Personal data may be disclosed or transferred to third parties only if the User consents to such disclosure or transfer. 

 

(2) Without the User’s consent, Personal Data may be disclosed or transferred to third parties only to the extent necessary and always in accordance with applicable laws. Data may be shared with other companies within the Controller’s group, such as subsidiaries, if necessary for the administration and operation of the website or for internal administrative purposes. Furthermore, Personal Data may be disclosed to external service providers, in particular providers of hosting, cloud storage, email services, and analytical and technical services. Data may also be disclosed to public authorities or other entities if required by law or if necessary to protect the Controller’s rights.

 

 

Article 6

Retention Period

 

(1) Personal data is retained only for the period necessary to fulfill the purposes for which it was collected and in accordance with applicable laws. Data processed on the basis of consent is retained until the User revokes their consent. 

 

(2) Upon expiration of the retention period, the data is securely deleted or anonymized, unless there is another legal basis for its continued retention.

 

Article 7

Security Measures

 

(1) The controller has implemented appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing, loss, destruction, or damage. Only authorized persons have access to the data, and only to the extent necessary. Data is transmitted and stored securely, and access to it is protected by technical means such as encryption and secure communication channels. The controller also ensures regular updates and checks of systems and training for employees who handle personal data. The measures taken correspond to the risks of processing and are regularly evaluated and updated.

 

Article 8

Cookies

 

(1) Cookies are small data files that are stored on the User’s device when visiting a website and that subsequently allow the website to recognize the device upon a return visit. They are used primarily to store information about the User’s settings and preferences, to ensure the proper functioning of the website, to improve its functionality and user experience, to measure traffic, and to tailor content or advertising based on the User’s behavior (hereinafter “Cookies”).


(2) The website may use various types of cookies, which differ according to their purpose and duration of storage:

a)  Technically necessary cookies are those that are essential for the proper functioning of the website and enable, for example, navigation between pages, access to secure areas, or the storage of settings necessary to provide services that the User has explicitly requested. User consent is not required for these cookies.

b)  Preference cookies are used to remember the User’s individual settings, such as the selected language, page layout, or other options that enhance user comfort.

c)  Analytical (statistical) cookies allow us to track User behavior on the website to determine how the site is used and to improve it.

d)  Marketing cookies are used to record User visits and activity on the website so that targeted advertising tailored to the User’s interests can be displayed.


(3) Technically necessary cookies are stored based on the Controller’s legitimate interest, while all other cookies are stored and processed only based on the User’s prior consent. 


(4) Consent to the storage and use of cookies that are not technically necessary for the functioning of the website is voluntarily granted by the User via an interactive feature upon their first visit to the website.

 

(5) The User may manage their consent to the use of cookies that are not technically necessary for the functioning of the website at any time. Consent may be revoked, modified, or re-granted via a link available on the website or through the user’s web browser settings. Revocation of consent does not affect the lawfulness of processing that took place prior to such revocation.

 

(6) If a website user does not consent to the storage of cookies on their device, they are entitled to block their storage and use via their web browser settings according to the procedure below:

a)  Google Chrome

To delete cookies in Google Chrome, open Chrome on your computer, click the More options icon (three dots) in the top-right corner, and select Settings. In the left-hand menu, select Privacy and Security, click on Third-party cookies, then on View all site data and permissions, select Clear all data, and confirm the action by clicking the Clear button.

To disable cookies in Google Chrome, open Settings, select Privacy and Security from the left-hand menu, click on Cookies and other site data, and choose either “Block all cookies” or “Block third-party cookies.”

b)  Safari

To clear cookies in Safari on your iPhone or iPad, go to Settings > Safari, tap Clear History and Data, and confirm the action. This will also clear your browsing history and cache. To clear cookies and cache but keep your history in Safari on an iPhone or iPad, go to Settings > Safari > Advanced > Website Data, tap Clear All Website Data, and confirm the action.

To clear cookies in Safari on a MacBook, open Safari and make sure it’s active. In the menu bar in the upper-left corner, click Safari > Preferences; in the Preferences window, go to the Privacy tab, click Manage Website Data, select the data for a specific website from the list that appears, and click Remove, or choose Remove All.

To block cookies in Safari on an iPhone or iPad, go to Settings > Safari > Advanced and turn on the Block All Cookies option.


c)  Internet Explorer 

To disable cookies in Internet Explorer, open the Tools menu, select Internet Options, go to the Privacy tab, move the slider all the way to the top, and click OK to save the change.

To delete cookies in Internet Explorer, open the Tools menu, select Security, click Delete Browsing History, check the Cookies and website data box, and confirm by clicking the Delete button. Save the change by clicking OK.


d)  Firefox

To disable cookies in Firefox, click on Firefox in the main menu, open the Options menu, go to the Privacy section, uncheck the "Allow sites to set cookies" option in the Cookies section, and confirm the settings.

To delete cookies in Firefox, click the three horizontal buttons in the top-right corner of the window and select Settings. In the left menu, select Privacy & Security, go to the Cookies and Site Data section, and click the Clear Data button. In the pop-up window, check the Cookies and Site Data option (you can also check Cached Web Content if you want to free up more space) and confirm the action by clicking the Clear button.


e)  Opera 

To delete cookies in the Opera browser, click the Opera logo in the upper-left corner and select Settings. In the left menu, select Privacy and Security, then in the Privacy section, click Clear browsing data. In the window that opens, select a time range, check the box for Cookies and other site data, and confirm by clicking the Clear data button.

To disable cookies in the Opera browser, open it, go to Privacy and Security in the left menu, click on Cookies and other site data in the Privacy section, and select one of the options: “Block third-party cookies” or “Block all cookies.”


f)   Other browsers

To disable and delete cookies in other browsers, use the help section of the respective browser or contact its manufacturer.

 

(7) Failure to consent to the use of cookies that are not technically necessary for the website’s operation does not affect the website’s basic functionality or availability. However, it may limit certain features, particularly those used to personalize content, remember preferences, analyze traffic, or display targeted advertising.

 

(8) COLORLAK uses Google Analytics on its website to analyze website usage and optimize content; Users’ IP addresses are anonymized before being transmitted to Google’s servers. Google does not associate this data with other information, and Users can block data collection by adjusting their browser settings. COLORLAK also uses related Google advertising features, including demographic reports, remarketing, and ad targeting via Google Ads, which can be managed in Google Account settings.

 

(9) The COLORLAK website also features third-party social plugins that allow Users to share website content with others and interact on social networks. These include, in particular, plugins for Facebook, YouTube, Instagram, LinkedIn, and Twitter (hereinafter “Social Plugins”). Social plugins are not managed by the Controller, who therefore bears no responsibility for the processing of Personal Data carried out by these third parties, nor for their functionality or any damages that may arise from their use. When loading and using Social Plugins, the website User’s data may be transmitted directly to the social network operator and further processed in accordance with its own privacy policy.


Article 9

User Rights

(1) Under applicable law, the user has the right to know how their personal data is used and to influence its processing. To this end, the user has the following rights in particular:

a)  the right of access to personal data,

b)  the right to have inaccurate or incomplete data corrected or supplemented,

c)  the right to erasure of personal data,

d)  the right to restriction of processing,

e)  the right to data portability to another controller,

f)   the right to object to processing,

g)  the right to withdraw consent at any time if processing is based on consent,

h)  the right to lodge a complaint with a supervisory authority.

 

(2) The competent supervisory authority is the Office for Personal Data Protection

a)  Address: Pplk. Sochora 27, 170 00 Prague 7

b)  Phone: +420 234 665 111

c)  Email: posta@uoou.cz

d)  Data box: qkbaa2n

e)  Website: www.uoou.cz

 

(3) The User also has the right to contact the Controller at any time with a question, comment, or request regarding the processing of personal data. The Controller is obligated to respond to such inquiries without undue delay. The response is provided in writing or electronically, depending on how the request was submitted, unless the User requests another form.

 

 

Article 10

Final Provisions

(1) This Privacy Policy is effective as of February 18, 2026, and is available for visitors to the Controller’s website to review at any time.

 

(2) The Controller reserves the right to unilaterally amend or supplement this statement at any time. The new version of the statement will always be published on the Controller’s website and becomes effective on the date of its publication.

 

(3) This statement is governed by applicable laws, in particular the GDPR and the laws of the Czech Republic.

 

(4) If you have any questions or concerns regarding this statement, please contact us using the contact information provided earlier in this document.

In Staré Město on February 18, 2026