Privacy Policy
Privacy Policy and GDPR Compliance
This Personal Data Processing Policy (hereinafter referred to as the "Policy") establishes the rules for the processing of personal data by the Controller listed below in this document in connection with the exercise of its business activity, namely in connection with the operation of the website with an integrated electronic store (e-shop) available at the internet address www.mohha.eu, through which it realizes the purchase and sale of goods.
The Policy is prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as "GDPR") and with Act No. 18/2018 Coll. on the Protection of Personal Data (hereinafter referred to as "APPD").
The purpose of this Policy is to demonstrate that the processing of personal data by the Controller takes place in accordance with the applicable legal regulations, in particular the APPD and the GDPR Regulation.
The Controller is obliged to adopt appropriate technical and organizational measures with regard to the nature, scope, context, and purpose of processing, as well as the risks to the rights and freedoms of data subjects, and to continuously update these measures.
This document is the result of an assessment of processing activities carried out by the Controller for the purpose of fulfilling legal obligations in the field of personal data protection. By introducing standardized measures according to this Policy, the risk of a personal data breach is reduced.
This Policy applies to all natural persons whose personal data are processed in connection with the activity of the Controller. The Policy contains an overview of individual purposes of personal data processing, categories of data subjects, applicable legal bases of processing, as well as information about the rights of data subjects and the method of their exercise.
CONTROLLER:
Business name: KOAN TRADE s.r.o.
Registered office: Cintorínska 1001, 925 32 Veľká Mača
Place of business: Zoltána Kodálya 767, 924 01 Galanta
Legal form: Limited Liability Company
Registration: Commercial Register of the District Court Trnava,
Section: Sro, Insert number: 36551/T
ID No. (IČO): 50 021 826
Contact details of the Controller:
Email: info@mohha.eu
Delivery address: Z.Kodálya 767, 924 01 Galanta
(hereinafter referred to as the "Controller")
Data Protection Officer (DPO)
The Controller has no obligation to appoint a data protection officer according to Art. 37 of the GDPR, and therefore this function is not established.
The contact person who supervises the processing of personal data and is authorized to process requests and provide information regarding the exercise of data subjects' rights can be contacted in writing via email at info@mohha.eu or by mail at KOAN TRADE s.r.o., Z. Kodálya 767, 924 01 Galanta.
The contact person for reporting security incidents can be contacted in writing via email at info@mohha.eu or by mail at KOAN TRADE s.r.o., Z. Kodálya 767, 924 01 Galanta.
GENERAL INFORMATION ON PERSONAL DATA PROCESSING:
The Controller is responsible for the processing of personal data in accordance with the GDPR Regulation, i.e., Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
PERSONAL DATA PROCESSING PRINCIPLES:
The Controller is obliged to comply with the principles of personal data processing according to Art. 5 of the GDPR Regulation, which include in particular:
-
the obligation to process personal data lawfully, fairly, and in a transparent manner,
-
the obligation to collect personal data only for specified, explicitly stated, and legitimate purposes and not further process them in a manner incompatible with these purposes,
-
the obligation to process personal data only to an extent that is adequate, relevant, and necessary in relation to the purpose,
-
the obligation to store personal data in a form permitting identification of data subjects for no longer than is necessary for the purposes of processing,
-
the obligation to ensure the accuracy and updating of personal data; inaccurate data must be corrected or deleted without delay,
-
the obligation to process personal data in a manner that ensures their appropriate security,
-
the obligation to be able to demonstrate compliance with the processing principles at the request of the supervisory authority.
LEGAL GROUNDS FOR PERSONAL DATA PROCESSING:
The processing of personal data by the Controller is lawful only if it is performed based on one of the legal bases established in the GDPR Regulation and in the APPD. The legal bases are in particular:
a) Art. 6 (1) (a) of the GDPR Regulation, or Section 13 (1) (a) of the APPD – consent of the data subject to the processing of personal data for one or more specific purposes.
b) Art. 6 (1) (b) of the GDPR Regulation, or Section 13 (1) (b) of the APPD – processing of personal data is necessary for the performance of a contract to which the data subject is a party, or to perform measures before concluding a contract based on their request.
c) Art. 6 (1) (c) of the GDPR Regulation, or Section 13 (1) (c) of the APPD – processing of personal data is necessary for the fulfillment of a legal obligation that applies to the Controller.
d) Art. 6 (1) (f) of the GDPR Regulation, or Section 13 (1) (f) of the APPD – processing of personal data is necessary for the purposes of the legitimate interests of the Controller or a third party, except for cases where these interests are overridden by the interests or fundamental rights and freedoms of the data subject, in particular if the data subject is a child.
e) Further processing of personal data for the purpose of archiving, scientific or historical research, or for a statistical purpose, if it is in accordance with a specific regulation and if appropriate safeguards for the protection of data subject rights are maintained. This legal basis applies only if the Controller performs such processing.
DECLARATION:
We declare that as the Controller of your personal data, we fulfill all legal obligations required by the applicable legislation, in particular according to the APPD and the GDPR Regulation, and therefore that:
-
we will process your personal data only based on a valid legal ground in accordance with the GDPR Regulation and the APPD mentioned above,
-
we will proceed in accordance with the principles of personal data processing according to Art. 5 of the GDPR Regulation, which are stated in this Policy,
-
we hereby fulfill the information obligation according to Art. 13 of the GDPR Regulation towards data subjects,
-
we will enable you and we will support you in exercising and fulfilling your rights according to the APPD and the GDPR Regulation.
FULFILLMENT OF THE INFORMATION OBLIGATION TOWARDS DATA SUBJECTS:
Fulfillment of the information obligation towards data subjects is carried out in accordance with Article 13 of the GDPR Regulation, which regulates the obligations of the Controller when obtaining personal data directly from the data subject. Specific information according to Art. 13 of the GDPR Regulation is provided to data subjects through this Policy. Detailed information is provided for individual purposes of personal data processing and in the appendices linked to these purposes. The Controller processes personal data for specific and separately defined purposes of processing, which are divided by categories of data subjects and are stated in the following part of the document.
PURPOSES OF PERSONAL DATA PROCESSING
I. Information for website and e-shop visitors and users
-
Operation, management, and security of the website and e-shop
-
Use of cookies
-
Processing of personal data through a contact form
-
Communication with the Controller through electronic communication channels
II. Information for e-shop customers – consumers (B2C)
-
Order form
-
Purchase of goods and customer support through the e-shop
-
Price and product inquiry
-
Economic and accounting agenda
-
Reporting a defect in goods or services (complaint)
-
Withdrawal from the purchase contract by the consumer
III. Information for e-shop customers – business entities (B2B)
-
Order form
-
Purchase of goods and customer support through the e-shop
-
Price and product inquiry
-
Economic and accounting agenda
-
Exercise of rights from liability for defects according to the Commercial Code
-
Exercise and processing of data subjects' rights
V. Information for business partners – suppliers and their employees or representatives
-
Communication and management of contractual relations
-
Economic and accounting agenda
SECURITY AND PROTECTION OF PERSONAL DATA:
The Controller has adopted all appropriate technical and organizational measures, the aim of which is to ensure the protection of processed personal data from unauthorized access, change, destruction, loss, or other unauthorized processing. These measures are designed with regard to the character, scope, context, and purpose of processing, as well as risks for the rights and freedoms of data subjects. The Controller is simultaneously obliged to notify serious security incidents to the supervisory authority in accordance with Article 33 of the GDPR without undue delay.
YOUR RIGHTS IN CONNECTION WITH PERSONAL DATA PROTECTION:
Method and form of response:
Responses to requests and information are provided in the same form in which the request was submitted (in writing, electronically, or orally), unless the data subject has requested a different method. Oral provision of information may be conditioned by proving the identity of the data subject. If the Controller has legitimate doubts about the identity of the natural person submitting the request, they are entitled to ask for the provision of additional information necessary to verify their identity, and this exclusively to the extent necessary for the protection of personal data. For the reason of ensuring the protection of personal data, in cases where the disclosure of personal data occurs, it is generally more appropriate to process requests in writing by registered mail to avoid unauthorized disclosure of data to a third party.
Deadline for processing the request:
In the sense of Section 29 (3) of the APPD, the deadline for processing the requests of data subjects is one month from the delivery of the request. The deadline may be extended in justified cases with regard to the complexity and number of requests by a further two months, even repeatedly. The data subject must be informed about every such extension along with the reasons for the extension of the deadline. As an objective reason for the extension of the deadline, according to the law, one can consider, for example, a situation where the employer requests from the data subject the supplementation of some information to assess and process their request, while the supplementation of the required information will not be processed immediately. Likewise, the occurrence of security incidents that have paralyzed the employer's information systems for a certain time, etc.
Transparent information about the introduction and amount of fees:
For processing requests and providing information, the Controller is entitled to require fees from the applicant associated with it. Requests of the data subject and information are primarily processed, or provided, free of charge. A reasonable fee taking into account administrative costs can be required for the second and further copies of documents with which the employer fulfills the request of the data subject. Likewise, a fee can also be introduced for administrative costs for processing a request that is clearly unfounded or inappropriate, especially due to its repetitive nature. The clear unfoundedness or inappropriateness of the request is demonstrated by the Controller. The repetitive nature of a request is one that concerns the same personal data as well as the same exercised right. Therefore, a request submitted, for example, for the right of access to personal data, and then a request submitted for the right to erase those data whose processing was found based on the request for the right of access, does not have a repetitive nature.
Appropriate measures for exercising the data subject's rights and measures facilitating the exercise of their rights:
The Controller reserves the right to process requests online, if they consider this option most appropriate.
List of rights that the legal regulation in the field of personal data protection grants to data subjects:
This list of rights is applicable, and the data subject may exercise these rights with the Controller only upon fulfillment of the legal conditions, which are further specified in the text.
1. Right of access
The data subject has the right to obtain from the Controller confirmation as to whether or not personal data concerning them are being processed, and where that is the case, they have the right to obtain access to those personal data and the information stated in the information obligation. The Controller shall provide a copy of the personal data undergoing processing. For any further copies requested by the data subject, the Controller may charge a reasonable fee corresponding to administrative costs. If the data subject made the request by electronic means, the information shall be provided in a commonly used electronic form, unless the data subject has requested otherwise. The exercised right to obtain a copy of personal data must not have adverse consequences on the rights and freedoms of others.
2. Right to rectification
The data subject has the right for the Controller to rectify inaccurate personal data concerning them without undue delay. With regard to the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.
3. Right to erasure (right to be forgotten)
The Controller is obliged to erase personal data without undue delay if the data subject has exercised the right to erasure, and if: a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed, b) the data subject withdraws consent according to Section 13 (1) (a) or Section 16 (2) (a), on the basis of which the processing of personal data is carried out, and there is no other legal basis for the processing of personal data, c) the data subject objects to the processing of personal data according to Section 27 (1) and there are no overriding legitimate grounds for the processing of personal data or the data subject objects to the processing of personal data according to Section 27 (2), d) the personal data have been unlawfully processed, e) the reason for erasure is the fulfillment of an obligation according to this Act, a specific regulation, or an international treaty by which the Slovak Republic is bound, or f) the personal data were collected in connection with the offer of information society services according to Section 15 (1).
The Controller is not obliged to erase processed personal data about the data subject in the case that the processing of personal data is necessary: a) for exercising the right of freedom of expression or the right to information, b) for the fulfillment of an obligation according to this Act, a specific regulation, or an international treaty by which the Slovak Republic is bound, or for the fulfillment of a task carried out in the public interest or in the exercise of official authority vested in the Controller, c) for reasons of public interest in the area of public health in accordance with Section 16 (2) (h) to (j), d) for archiving purposes, for a scientific purpose, for the purpose of historical research, or for a statistical purpose according to Section 78 (8), if it is likely that the right according to paragraph 1 will render impossible or seriously impair the achievement of the objectives of such processing, e) for the establishment, exercise, or defense of legal claims.
4. Right to restriction of processing
The data subject has the right for the Controller to restrict processing where one of the following cases applies: a) the accuracy of the personal data is contested by the data subject, for a period enabling the Controller to verify the accuracy of the personal data; b) the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead; c) the Controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise, or defense of legal claims; d) the data subject has objected to processing, pending the verification whether the legitimate grounds of the Controller override those of the data subject.
5. Right to portability
The data subject has the right to receive the personal data concerning them, which they have provided to the Controller, in a structured, commonly used, and machine-readable format and has the right to transmit those data to another Controller without hindrance from the Controller to whom the personal data have been provided. The data subject, in exercising their right to data portability according to paragraph 1, has the right to have the personal data transmitted directly from one Controller to another Controller, where technically feasible. The right stated in paragraph 1 must not have adverse consequences on the rights and freedoms of others.
6. Right to object to the processing of personal data
The data subject has the right to object, on grounds relating to their particular situation, to the processing of personal data concerning them which is performed based on Article 6 (1) (e) or (f), including objecting to profiling based on those provisions. If personal data are processed for direct marketing purposes, the data subject has the right to object at any time to the processing of personal data concerning them for such marketing, which includes profiling to the extent that it is related to such direct marketing. The Controller may no longer process the personal data unless they demonstrate compelling legitimate grounds for the processing of personal data which override the rights or interests of the data subject, or grounds for the establishment, exercise, or defense of legal claims. If the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.
7. Right to the ineffectiveness of automated individual decision-making including profiling
The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. Paragraph 1 shall not apply if the decision: a) is necessary for entering into, or performance of, a contract between the data subject and the Controller, b) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the rights and freedoms and legitimate interests of the data subject, or c) is based on the data subject's explicit consent.
8. Right to withdraw consent to the processing of personal data
If the Controller processes personal data about the data subject only on the legal basis of consent, they are obliged to ensure for data subjects the right to withdraw their consent at any time, in the same simple form as the consent was provided. If the Controller processes personal data on a legal basis other than the consent of the data subject, this person does not have the right to withdraw consent, as it was not even provided.
9. Right to lodge a complaint with a supervisory authority
The data subject has the right to lodge a complaint or a petition to initiate proceedings with a supervisory authority – the Office for Personal Data Protection of the Slovak Republic, Park One Building, Námestie 1. mája 18, 811 06 Bratislava, tel. no.: +421 /2/ 3231 3214, e-mail: statny.dozor@pdp.gov.sk, web: https://dataprotection.gov.sk – if they believe that in the processing of their personal data, rights in the field of personal data protection have been violated.
In the case of submitting a petition in electronic form, the submission must fulfill the requirements according to Section 19 (1) of Act No. 71/1967 Coll. on Administrative Proceedings (Administrative Procedure Code).
The data subject may exercise all rights according to the GDPR Regulation and the APPD, while the scope of applicable rights depends on the specific purpose and legal basis of processing. The Controller shall assess each request individually. A detailed assignment of specific rights to individual legal bases of processing is stated in the Matrix of Legal Bases and Rights of Data Subjects, which forms an integral part of this Policy.
You can exercise your right at any time, namely in written form or electronically by delivering a request to the stated contact details:
First and last name: Andrej Máthé Kováč
Email: info@mohha.eu
Delivery address: Z. Kodálya 767, 924 01 Galanta
CONFIDENTIALITY:
The Controller wishes to assure data subjects that all persons involved in the processing of personal data on their behalf or upon their instruction – including collaborators, contractual partners, and authorized persons – are obliged to maintain confidentiality about personal data, the disclosure of which could endanger their security. This obligation of confidentiality continues even after the termination of the legal or other authorized relationship with the Controller. Without the explicit consent of the data subject, their personal data will not be provided to a third party.
This personal data processing policy replaces the previous version and is valid in the current wording from 02.03.2026.
Cookies policy
WHAT ARE COOKIES?
As is common practice with almost all professional websites, our website uses cookies. Cookies are tiny files that are downloaded to your device to improve your experience. This document provides information on what cookies we use, how we use them, and what your options are regarding their management. For more general information on cookies, see the Wikipedia article on HTTP Cookies.
TYPES OF COOKIES:
We classify cookies according to:
Timeframe:
-
Session cookies – stored only temporarily and deleted after the browser is closed.
-
Persistent cookies – remain stored until you delete them or until your browser deletes them based on the set expiration date.
Entity:
-
First-party cookies – created by the operator of this website.
-
Third-party cookies – created by an external entity (e.g., an analytical service provider).
Legal Basis:
-
Cookies for which consent is not required – e.g., technical (essential) cookies.
-
Cookies for which consent is required – e.g., analytical, functional, and marketing cookies.
THE PERSONAL DATA CONTROLLER IS:
Business Name: KOAN TRADE s.r.o.
Registered Office: Cintorínska 1001, 925 32 Veľká Mača
Establishment: Zoltána Kodálya 767, 924 01 Galanta
Legal Form: Limited Liability Company
Registration: Commercial Register of the District Court Trnava, Section: Sro, Insert number: 36551/T
ID (IČO): 50 021 826
VAT ID (IČ DPH): SK2120148272
Contact Details of the Controller:
-
Email: info@mohha.eu
-
Delivery Address: Z. Kodálya 767, 924 01 Galanta
WHAT COOKIES DO WE USE ON OUR WEBSITE?
STRICTLY NECESSARY COOKIES are cookies without which our website would not function properly; they are automatically placed on the Data Subject's device and cannot be switched off. These cookies do not store any personally identifiable information and cannot identify the user; they are used solely to guarantee the correct display of the website.
On our website, we use the following necessary cookies: (Cookie Name / Description / Legal Basis / Category of Data Subjects / Retention Period / Provider / Transfer to Third Countries)
FUNCTIONAL COOKIES improve the functionality of the website and provide a better user experience. These cookies allow the site to remember information that changes the way the site behaves or looks, such as your preferred language, time zone, or the region you are in. They are essential for the proper functioning of certain parts of the website, such as forms or access to secure areas. Without these cookies, some services or website functions may not work properly. Functional cookies do not record personally identifiable information and serve as a basis for better and more personalized functionality.
On our website, we use the following functional cookies: (Cookie Name / Description / Legal Basis / Category of Data Subjects / Retention Period / Provider / Transfer to Third Countries)
ANALYTICAL COOKIES are used to collect information about how visitors use the website. This data includes the number of visitors, where they came from, what pages they visited, and how long they stayed on them. This information helps the operator understand user behavior, optimize the content and functionality of the website, and ensure it is as visitor-friendly as possible. To process analytical data, we use the Google Analytics service operated by Google LLC, located at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The collected cookies are subsequently processed by Google in accordance with the privacy policy available at: https://www.google.com/intl/cs/policies/privacy/#nosharing
On our website, we use the following analytical cookies: (Cookie Name / Description / Legal Basis / Category of Data Subjects / Retention Period / Provider / Transfer to Third Countries)
TARGETING COOKIES are used to optimize website traffic and limit the rate of requests. These cookies may be linked to Google Analytics, which helps the operator monitor site performance and ensure proper functionality.
On our website, we use the following targeting cookies: (Cookie Name / Description / Legal Basis / Category of Data Subjects / Retention Period / Provider / Transfer to Third Countries)
WHY WE USE COOKIES
We use cookies for a variety of reasons detailed in this document. Unfortunately, in most cases, there are no industry standard options for disabling cookies without completely disabling the functionality and features they add to this site. It is recommended that you leave on all cookies if you are not sure whether you need them or not, in case they are used to provide a service that you use.
DISABLING COOKIES
You can prevent the setting of cookies by adjusting the settings on your browser. For more information on how to manage or disable cookies, see your browser's Help section. Detailed instructions are also available on the website www.aboutcookies.org. Please be aware that disabling cookies will affect the functionality of this and many other websites that you visit. Disabling cookies will usually result in also disabling certain functionality and features of this site.
YOUR RIGHTS IN RELATION TO PERSONAL DATA
Regarding your personal data, you have the following rights:
-
Right to information: You have the right to know why your personal data is needed, what will happen to it, and how long it will be retained.
-
Right of access: You have the right to request access to your personal data that we process about you.
-
Right to rectification: You have the right to request that your personal data be supplemented or corrected whenever it is inaccurate or incomplete.
-
Right to erasure (Right to be forgotten): You have the right to request the erasure of your personal data if its processing is no longer necessary.
-
Right to restriction of processing: You have the right to request that the processing of your data be restricted under certain circumstances.
-
Right to data portability: You have the right to obtain your personal data and transfer it to another controller.
-
Right to object: You can object to the processing of your personal data based on the legitimate interest of the controller.
You may exercise these rights to the extent that they apply to you under applicable laws, such as the General Data Protection Regulation (GDPR).
WHERE CAN YOU CONTACT US?
If you wish to exercise these rights or have any comments, questions, or requests regarding the use of cookies on our website, you can contact us in writing or electronically using the following contact details:
Email: info@mohha.eu Delivery Address: Z. Kodálya 767, 924 01 Galanta
We welcome your questions and suggestions.
If you have a complaint about how we handle your personal data, you can contact the relevant supervisory authority: Office for Personal Data Protection of the Slovak Republic (www.dataprotection.gov.sk).
FINAL PROVISIONS
The Controller reserves the right to change these terms at any time. The current version of the terms will be published on our website. We recommend checking these terms regularly to stay informed about any changes.
