The data controller is 1490 s.r.o., Company ID 05235847, VAT ID CZ05235847, registered office at Sudkův Důl 10, 395 01 Obrataň, Czech Republic (“UTOPIA”, “we” or “us”). Contact: ivo@utopia.direct.
We process identification, contact, billing, delivery, order, payment-status and communication data to enter into and perform purchase contracts, deliver orders, and handle complaints and returns. The legal basis is performance of a contract and pre-contractual steps.
We retain accounting, tax and other mandatory records to comply with legal obligations. We may process communications and necessary technical records for customer support, store security and the establishment, exercise or defence of legal claims, based on the contract or our legitimate interests as applicable.
We send newsletters only where we have valid consent or another lawful basis. We use Shopify to record consent and send the messages. Every marketing message provides an easy way to unsubscribe.
Depending on the customer's choices, Shopify and Shop may also send automated notifications about an abandoned cart, a product being back in stock, a price drop or a product viewed again. Sending is governed by the applicable consent settings, and the notifications can be disabled or unsubscribed from.
Google Analytics 4, Google Ads and Meta Pixel/Conversions API are used to measure traffic, the purchasing journey and advertising, and — only where permitted — to create advertising audiences. Optional analytics and marketing technologies run only after the relevant cookie consent. Consent can be changed or withdrawn through “Cookie settings” in the footer without preventing an ordinary purchase.
We use strictly necessary technologies for the cart, checkout, security and consent choices; analytics and marketing technologies are used only after consent. The current cookie list and durations are shown in the cookie settings. Merely using the website does not constitute consent to optional cookies.
We disclose data only to the extent necessary for a particular purpose. The recipients and service providers typically include:
We disclose data to public authorities only where required by law or necessary to protect legal rights.
Some technology providers may process data outside the EEA. Where applicable, they use a mechanism recognised by the GDPR, such as an adequacy decision, standard contractual clauses, binding corporate rules and any necessary supplementary safeguards. Customer data from the EEA is initially received by Shopify International Limited in Ireland and may then be processed by Shopify affiliates and subprocessors, including in Canada and the United States. Details are provided in the policies of the relevant services; on request, we will provide available information about the transfer mechanism used.
We retain personal data only for as long as necessary for the relevant purpose:
Afterwards, data is deleted or anonymised unless law or the protection of rights requires further retention. Backups are overwritten according to a secure retention cycle and are not used for ordinary processing.
Subject to the GDPR, you may request access, rectification, erasure, restriction and portability, object to processing based on legitimate interests, and withdraw consent. You may complain to the Czech Office for Personal Data Protection, uoou.gov.cz.
We respond without undue delay, generally within one month. GDPR permits an extension in complex cases; if so, we will explain it in time. We may reasonably verify identity before disclosing data.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you. Payment and ecommerce service providers may use automated security and fraud-risk mechanisms under their own terms.
We publish the current version and effective date on this page and provide appropriate notice of material changes. This policy is effective from 7 September 2026.