Privacy Policy

This page explains what personal data we collect when you visit this shop or buy from us, why we process it, who receives it and what you can do about it. It is the information required by Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (GDPR).

The controller — the company that decides what happens to your data — is Golf Brothers, s.r.o. Its full identification is in section 7, and you can write to us at any time at info@golfbrothers.eu.

1. What data we process and where it comes from

Most of the data comes from you. Some is generated automatically when you use the shop.

  • Order and contract data: first and last name, billing address, delivery address (including a parcel shop or pickup point if you choose one), e-mail address, telephone number for the carrier's delivery notifications, the items ordered, the price, the payment method and the payment status, invoices, delivery notes and returns.
  • Account data if you register: e-mail address, password (stored only as a cryptographic hash), your order history and saved addresses.
  • Business customer data: company name, company registration number and VAT identification number.
  • Communication data: the content of e-mails you send us and of our replies, contact form messages, and complaint and return requests.
  • Technical data: IP address, date and time of the request, the pages requested, referrer, browser and device type, and cookie or similar identifiers. See the Cookie Policy.
  • Marketing data: your e-mail address if you subscribe to our newsletter, and whether you opened it or clicked a link in it.

We do not process special categories of personal data, and we do not knowingly collect data about children.

2. Why we process it and on what legal basis

PurposeLegal basis
Concluding and performing your purchase contract: processing the order, payment, delivery, account administration, returns, withdrawal and complaintsArticle 6(1)(b) GDPR — performance of a contract
Issuing and keeping invoices and accounting records, VAT reporting, product safety and consumer protection dutiesArticle 6(1)(c) GDPR — legal obligation
Fraud prevention, securing the shop, dealing with abusive orders, IT logs and backupsArticle 6(1)(f) GDPR — our legitimate interest in a secure and functioning shop
Sending information about similar goods to customers by e-mail, and asking for a review of a purchaseArticle 6(1)(f) GDPR — legitimate interest in direct marketing to existing customers; you can object at any time with one click
Newsletter for people who are not customers, analytics and marketing cookiesArticle 6(1)(a) GDPR — your consent, which you may withdraw at any time
Establishing, exercising or defending legal claimsArticle 6(1)(f) GDPR — legitimate interest

Where processing rests on consent, withdrawing it is as easy as giving it and does not affect the lawfulness of what we did before you withdrew it.

Providing the data needed for an order is a contractual requirement: without a name, an address, an e-mail address and payment data we cannot conclude or perform the contract.

3. Who receives your data

We pass on only what a recipient needs, and only for the purposes above:

  • Carriers: GLS and UPS receive your name, delivery address, telephone number and e-mail address so that they can deliver and notify you.
  • Payment service providers: GoPay s.r.o. (cards, Apple Pay, Google Pay) and PayPal. Card data is entered directly on the payment provider's page — we never see or store your full card number. Our bank receives payment data for transfers and refunds.
  • IT and hosting providers who operate our servers, e-mail and backups, and who work for us as processors under Article 28 GDPR.
  • Our accountants and tax advisers, and where necessary auditors and lawyers.
  • Our e-mail sending provider for order and shipping notifications and for the newsletter.
  • Analytics providers where you consented — see the Cookie Policy.
  • Public authorities where we are obliged by law to disclose data.

We do not sell personal data and we do not pass it to third parties for their own marketing.

4. Transfers outside the European Union

Your order, payment, delivery, invoicing and support data is processed inside the European Union and the European Economic Area.

Some analytics and marketing tools that only run with your consent are operated by providers established in the United States. Where such a transfer takes place, it is covered by the European Commission's adequacy decision for the EU-US Data Privacy Framework, or by the Standard Contractual Clauses adopted by the Commission together with additional technical safeguards. If you do not consent to analytics and marketing cookies, no such transfer takes place.

5. How long we keep it

  • Order and contract data: for the duration of the contract and then for the period of the statutory limitation of claims, and in any case as long as the tax and accounting rules require — invoices and accounting records for 10 years from the end of the accounting period.
  • Account data: until you delete the account or ask us to; an inactive account is deleted after 3 years without a login.
  • Complaint, return and withdrawal records: 4 years from the closure of the case.
  • Newsletter data: until you unsubscribe, plus a record of the unsubscribe so that we do not write to you again.
  • Server logs: a maximum of 12 months.
  • Cookies: for the periods given in the Cookie Policy.

6. Automated decision-making

We do not use automated decision-making or profiling that produces legal effects for you or similarly significantly affects you. Payment providers may run automated fraud checks as part of their own service; if a payment is refused on that basis you can always choose another payment method or contact us.

7. Who is responsible for your data

The controller of your personal data is:

  • Golf Brothers, s.r.o. — a limited liability company incorporated under the law of the Czech Republic
  • Registered seat: Oldrichovice 934, 739 61 Trinec, Czech Republic
  • Registered in the Czech commercial register kept by the Regional Court in Ostrava, Section C, Insert 41766
  • Company registration number: 27790690, EU VAT identification number: CZ27790690
  • E-mail: info@golfbrothers.eu

We are established in the European Union, so no representative under Article 27 GDPR is required. We have not appointed a data protection officer, because we are not obliged to; data protection questions go to the e-mail address above and are handled by the management. We answer on working days.

8. Your rights

Under the GDPR you have the right to:

  • access your data and receive a copy (Article 15);
  • rectification of inaccurate or incomplete data (Article 16);
  • erasure — "the right to be forgotten" — where the conditions are met (Article 17);
  • restriction of processing (Article 18);
  • data portability — to receive the data you gave us in a structured, commonly used, machine-readable format, or have it sent to another controller (Article 20);
  • object at any time to processing based on our legitimate interest, and unconditionally to direct marketing (Article 21);
  • withdraw consent at any time (Article 7(3)).

Write to info@golfbrothers.eu or to our postal address. We reply within one month; if a request is complex we may extend that by two further months and will tell you why. Exercising these rights is free of charge.

9. Complaining to a supervisory authority

If you think we handle your data unlawfully, you may complain to a data protection supervisory authority — in the Member State where you live or work, where the alleged infringement took place, or to our lead authority.

Our lead supervisory authority is:

  • the Czech data protection authority — the Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, www.uoou.gov.cz

You may equally address the authority in your own country, for example the CNIL in France, the AEPD in Spain, the Garante per la protezione dei dati personali in Italy, the Autoriteit Persoonsgegevens in the Netherlands, Integritetsskyddsmyndigheten (IMY) in Sweden, UODO in Poland, the federal or state authority in Germany, or the Data Protection Commission in Ireland. The full list of national authorities is published by the European Data Protection Board.

10. Changes to this policy

We update this policy when our processing changes or the law does. The version published here is always the current one. This version is effective from 3 August 2026.