Main menu


personal data processing principles


Protection of our customers‘ personal data is our priority. We have drawn up this document – Personal Data Processing Principles – to inform you, our customers, how our company acquire, preserves and processes your personal data in connection with sale of our products and provision of related services. This Hannah brand website is run by Outdoor Concept a.s., however, purchasing our products as well as registering into our loyalty club take place via our partner e-shop run by Rock Point a.s.

Processing of your personal data is necessary to perform our contractual commitments properly. Furthermore, certain legal obligations arise when selling our products, including personal data processing and storing for a certain time.

By means of these Personal Data Processing Principles, we would like to provide you with information on how we collect, process and protect your personal data (see chapters 3-6 below), your rights and how to exercise them (see chapter 7 below).

Personal data is any information concerning an identified or identifiable natural person, particularly our customers and other people whose personal data we are allowed to process.

We recommend that you get acquainted with these Personal Data Processing Principles thoroughly. In case you have any questions, do not hesitate to contact us via the contact details below.


The joint personal data controllers are Rock Point a.s., Vrážská 1507, 153 00 Praha 5 – Radotín, CRN: 26707233, VAT identification number: CZ26707233, Outdoor Concept a.s., Americká 54, 30100 Plzeň, CRN: 29093724, VAT identification number: CZ2909372; Hannah Czech a.s., Americká 54, 30100 Plzeň, CRN: 26383519, VAT identification number: CZ26383519. Hereinafter „the data controller”. All these companies constitute one group.

The data controller appointed a manager of personal data protection to whom you can turn if you have any questions concerning personal data protection. The manager’s contact details are:

Address: Americká 54, 30100 Plzeň

Telephone: (+420) 379 200 602

E-mail address:

Please take into consideration that these contact details might be changed in the future. You can always find current contact details in the latest version of the Personal Data Processing Principles.


We need to know and process your personal data in order to supply you with our goods and provide you with related services. We process personal data especially for the purposes of the conclusion and performance of a contract (including dealings before the conclusion of the contract). Therefore, the lawful basis of such processing is the performance of a contract or our legitimate interest, especially in those cases when the customer is a legal person and we process the personal data of their contact persons.

Sale of goods

We especially process your personal data in order to supply you with goods and to administrate a customer relationship with you. We keep processing some of your data which we have at our disposal after termination of the contract. We specifically do so for following purposes:

  • Sale of goods and related services. We process personal data when selling goods to customers and providing related services. For these purposes, we process the data on the lawful basis of the performance of a contract and/or our legitimate interest. We keep your personal data either for the duration of the contract or for the duration of warranty periods of the goods and periods of limitation unless it is necessary to keep it for a longer period due to other purposes of processing.
  • Payments. Payments at our website are processed through an external payment gateway. It means we only have access to the first 6 and the last 4 digits of the number of your payment card you have used to purchase. We do not process any other data of your payment instruments.
  • Warranty claims. If a customer thinks the contract performance our Company shows any defects, they are entitled to complain about the goods or service in compliance with Return Policy and Terms and Conditions. Settling complaints is a part of performance of the contract between you and our Company and the obligation to settle complaints arises from legislation.
  • Customer support. If you contact us via our contact form, phone or another way, we will keep the personal data you have provided until we deal with your requirement or for the duration necessary to defend ourselves or to exercise our legal claims. However, we do not record your phone calls.
  • Demands for payment. If an invoice for goods you have chosen is past due, we can keep sending you demands for payment until the invoice is paid for.
  • Establishment, exercise and defence of legal claims. After the contract has finished, we can, on the basis of our legitimate interest, keep some of your personal data for the duration of periods of limitation as the processing is necessary to protect our rights or defend legal claims, including collection of sums owed.
  • Accounting and tax documents. Some personal data can be stated in accounting documents (particularly invoices). According to the law (e.g. the VAT law or the accounting law), we are obliged to keep these documents for the period of 10 years, therefore we also archive your personal data stated in the documents in question.

The personal data you provide us with within the contract are processed for the purposes stated above. We process this data in particular:

  • Identification data (particularly name, surname, delivery and invoicing data);
  • Contact details (e-mail address, phone number);
  • Information about performance of the contract (particularly information about delivered goods and provided services, payment history);
  • The first 6 and the last 4 digits of your payment card number.

Customer account and loyalty club

If you decide to create your customer account, we also use your personal data for the purposes of the loyalty club. You become a member after creating a customer account on-line or in a shop.

If you no longer wish to be a member of our loyalty club, please, let us know. We will cancel your customer account and we will not process your personal data for this purpose anymore. However, you will lose the points you have gained within the loyalty programme.

In case you do not log into your customer account for more than 3 years or you do not make another purchase, we will contact you and ask if you would like to keep your customer account open. In case you do not and there is no legal reason for keeping your personal data, we will delete them and you will not be considered our customer any more.

For the purposes stated above, i.e. to operate a loyalty club, we use this personal data in particular:

  • Identification data (particularly name, surname, delivery and invoicing data);
  • Contact details (e-mail address, phone number);
  • Information about points gained within the loyalty programme;

Marketing communication

Based on you consent, we can use your personal data to send you marketing offers and other business messages, particularly to send news about our goods and services and other business messages related to our goods and services. These are particularly the news and offers which might be relevant based on your previous purchases and selected preferences. We might also send other messages related to your purchase (e.g. an assembly manual) or reminders of purchases which have not been completed. We will send you news and other messages via your contact details. The lawful basis of such processing is your consent which is consensual, can be withdrawn at any time and which you grant to us when registering your customer account. For this purpose, we process the data for the duration of the consent validity or until you withdraw your consent. If you do so, we will immediately stop processing your personal data for the purposes of sending marketing messages.

We can also contact you (a current customer) without your consent to a limited extent, to offer our products or services related to a product or services you have already purchased. In this case, we only process your personal data to limited extent which is necessary to send a relevant offer. The lawful basis of such processing is our legitimate interest to keep our customers informed about similar products and services we offer. If you express your disagreement or object to such processing, it will be stopped immediately.

For the purposes stated above and to be able to send you relevant marketing messages, we use this personal data in particular:

  • Identification data (particularly name, surname);
  • Contact details (e-mail address, delivery address);
  • Information about goods and services we have supplied you with;
  • Information about your selected preferences

We can organize consumer’s competitions within a selling season. In case you enrol for a competition, we will process your personal data in order to enable you to attend and for the purpose of evaluation, including data which is essential for the competition (e.g. information about purchases, answers to knowledge-based questions, etc…) Processing of your data when organizing competitions is done based on your consent which you have granted by enrolling for a competition. You can withdraw your consent to participate in competitions at any time and unsubscribe from a competition and we will stop processing your data.

For these purposes, we use this personal data in particular:

  • Identification data (particularly name, surname);
  • Contact details (e-mail address, delivery address);
  • Date of birth (if it is relevant to a competition);

Traffic to the website analysis

We use cookies to make using our website as easy as possible. They are small data files saved into your computer‘s hard-drive. We use cookies to get better understanding of how our website is used and to optimize it. Cookies can tell us, for example, whether you have already visited our website or whether you are a new customer.

If you don’t want to receive cookies, you can go to the settings of your browser and delete them from your computer, block them or browse in private, using an incognito window (which means all the cookies will be deleted once you close it). To get more detailed information, see the help/support section of your browser concerning cookies:

Google Chrome


Microsoft Edge a Microsoft Internet Explorer


Detailed description of cookie categories


Basic cookies are necessary to our website to perform properly. These cookies enable website navigation and use of the features you have required, such as access to secured areas of the website, your shopping cart content, user login, etc. Without these cookies, we would not be able to provide services which enable running this website.

This category contains these cookies:

Identification of your visit (session)

Identification of the shopping cart


Performance-related cookies gather anonymous information about the way visitors use our website. These cookies show the interaction between visitors and our website as they provide us with data for the aggregate analysis of our business activities – information about visited areas, time spent at the website or occurrence of potential problems, e.g. error messages. This information helps usimprove our website performance. These cookies cannot gather information about user activity at other websites.

This category contains these cookies:

Identifier for Google Analytics (more information)

Identifier for Hotjar™ Analytics Tool (more information)


These cookies enable to improve website efficiency and comfort and make different functions accessible. For example, you can set language preferences in functional cookies.

This category contains these cookies:

Information about granting / denying consent to process cookies for targeted advertising

Information about setting a level of consent to cookies processing


These cookies are used for advertising which is relevant to users and their interests. They can also be used for saving and measuring efficiency of the campaign which a visitor has come across when visiting a particular website, which enables to communicate better with potential advertiser. Our company uses this type of cookies for the purpose of marketing (you can choose to allow using these cookies when visiting our website for the first time). With your consent granted, we will use the information we have gathered to analyse your behaviour at our website and to display specific advertising for some of our products. We believe this function is beneficial for you as we are going to display only the advertisements or content which correspond to your interests.

This category contains these cookies:

Google targeted advertising (Adwords, DoubleClick, Analytics) (more information)

Facebook targeted advertising (more information)

Seznam targeted advertising (more information)

PROFILing And AUTOMATed processing

We do profiling and automated processing in our campaigns only for the purposes of targeted offer of our goods and services – we want to offer you only those which are relevant to you, not to bother you with useless things. We do not use profiling or automated processing for the purposes of automated decision-making which would impose any legal effects on you or concern you in any significant way.


We have introduced and we follow necessary and adequate technical measures, inner checks and processes of data security in compliance with the best business practice corresponding with potential risk to you as the data subject. We also take in consideration the condition of technological development to protect your personal data from accidental loss, damage, changes and unauthorized release or access. These measures particularly involve the measures to ensure physical security, employee training programs, regular backups, processes for data recovery and incident controls, software protection of the devices where personal data is stored, etc. 


Personal data recipients

The personal data we process for the purposes stated above can be shared with third parties which secure some services related to providing our services, e.g. administrative support, providing software tools, etc. These are personal data processors. In particular, we can share your personal data:

  • with other companies related to Rock Point a.s. in order to provide administrative support when providing services and to provide some shared services and other processing activities. We give this data particularly to Outdoor Concept a.s. which is a part of the group (see Joint controller)
  • with companies whose tools we use particularly in on-line services in order to be able to offer you products tailored to your needs. The companies are:







  • with companies providing goods delivery, as Česká pošta and PPL
  • with external companies arranging service and maintenance of our products. These are primarily manufacturers or suppliers of these products with whom we have customer supplier relationships.

We are obliged to make this data available to public authorities up to the necessary extent on the basis of law or other legal acts if they refer to us when exercising their powers and they ask us to provide information which can contain your personal data.

External auditors, tax advisors or lawyers can access some of your personal data on rare occasions, e.g. if it is necessary to collect or book sums owed or to protect our legitimate interests or an insurance company in case of insured events.

Processing safeguards

We have made contracts about data processing with data processors. These contracts ensure at least the same level of your personal data security as these Personal Data Processing Principles.


In compliance with the law, you have the right to require information about the ways your personal data is processed and the right to have the data we keep about you – data subject corrected. In certain cases, you have the right to require deleting your personal data, to access your personal data or to transfer your personal data (for example to transfer it to a different service provider). In some cases, you have the right to raise objections and the right to require restriction of your personal data processing. In case you have provided us with your consent to process your personal data, you can withdraw it at any time. Individual rights and ways how to exercise them are described below.

Exercising your rights

If you exercise any of your rights according to this article or the effective law, each recipient who has been provided with the data according to Chapter 4 of these Personal Data Processing Principles will be informed about the measures which have been taken or erasing your personal data or processing restriction, in compliance with your requirement, in case such notification is feasible and does not require inadequate effort.

If you wish to exercise your rights and/or receive relevant information, you can do so via contact details listed in Chapter 2 of these Personal Data Processing Principles.

If you exercise your rights, we might ask you to provide some additional personal data which you have already provided before. Providing this data is necessary to confirm that the requirement has really been sent by you. We will reply within one month after receiving your request, however, in some difficult cases we reserve the right to extend this period by two more months.


Rectification of your personal data

According to the law, you have the right to rectify your personal data which you share with us. You can rectify your personal data yourself when you log into your customer account at

Erasing your personal data

You can ask us to erase your personal data at any time. If you contact us with such a request, we will immediately erase all your personal data we have at our disposal in case we don’t need it to perform contractual or legal obligations anymore or to protect our legitimate interests described above.

Consent withdrawal

You can withdraw your consent to process your personal data at any time and without giving reasons. In that case, we will immediately erase your personal data and ensure our data processors do the same.

Please, be aware that withdrawing your consent doesn’t influence the lawfulness of any processing which had been done before you withdrew your consent. 

Disclosure and portability of your personal data

You have the right to require information whether we process your personal data and to what extent. You also have the right to require us to disclose your personal data and other personal details you have provided us with to you.

If you require transfer of your personal data which we process on the basis of the contract performance and/or your consent, you can ask us to transfer it directly to a third party (a different data controller) which you state in your application, supposing this request doesn’t have a negative effect on rights and freedoms of other persons and is technically feasible.


Right to object

In case we process your personal data on the basis of our legitimate interest (e.g. when we process personal data of you as a contact person of our customer) you have the right to object to such processing at any time, concerning your particular situation. If we fail to prove legitimate grounds for processing which would override your interests or rights and freedoms or to prove this data is necessary to establishment, exercise and defence of our legal claims, we will not process the data any longer and erase it immediately.

If we process your personal data for direct marketing purposes on the basis of our legitimate interest and you object to processing of your personal data for such marketing, we will immediately stop processing your personal data for this purpose.

Processing restriction

If you ask us to restrict your personal data processing, e.g. when you question accuracy, lawfulness or our need to process your personal data, we restrict processing of your personal data to a strict minimum (storage). However, we might continue processing it for establishment, exercise and defence of legal claims or to protect the rights of other legal and natural persons or other limited reasons specified by valid laws. If the restriction is cancelled and we continue processing your personal data, we will inform you of this fact immediately.


Complaint with ÚOOÚ (Úřad pro ochranu osobních údajů – Personal Data Protection Office)

You have the right to file a complaint concerning our processing of your personal data with Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7. Office website:



We might continuously amend or update these Personal Data Processing Principles. Any changes to these Personal Data Processing Principles come into force on the effective date and after they have been published at the following link:

We will inform you of any significant changes via e-mail before the effective date when the changes come into force.

These Personal Data Processing Principles come into force on 25th May 2018.