PRIVACY NOTICE
Version 1.0 | Effective from August 26, 2026
1. Data controller
The controller of personal data is TIENS (Czech Republic) s.r.o., Company ID No. 27397556, VAT ID No. CZ27397556, with its registered office at Slezská 2526/113, 130 00 Prague 3, Czech Republic (“TIENS”, “we” or the “Controller”).
Contact point for privacy questions and the exercise of data-protection rights: office@tiens.cz, telephone +420 724 175 888, postal address Slezská 2526/113, 130 00 Prague 3.
2. Who this Notice applies to
This Notice applies in particular to visitors to tiens.cz, customers using the Czech B2C environment, users of customer accounts, persons contacting support, recipients of marketing communications and participants in events, training sessions and competitions. It applies to independent distributors to the extent stated below; their contractual relationship may be supplemented by a separate privacy notice.
3. What data we process, why and for how long
We process only data that is proportionate to the relevant purpose. The retention period will always be shortened where the data is no longer required and there is no other legal ground for continued retention.
| Activity | Typical data | Purpose | Legal basis | Retention | |
| Website operation and security | IP address, technical logs, device, security events | Secure operation, diagnostics, prevention of misuse | Legitimate interests; strictly necessary technologies | As long as required for operation and security, usually days to months | |
| Order, payment and delivery | Name, contact details, address, order, price, payment and delivery data | Contract conclusion and performance, delivery, support | Performance of a contract | For the contractual relationship and then for statutory and limitation periods | |
| Customer account | Identification and contact data, login, order history, settings | Account administration and security | Contract; legitimate interests in security | For the life of the account and a necessary period after closure | |
| Accounting and tax | Billing data, orders, payments, tax documents | Accounting, tax and record-keeping duties | Legal obligation | For statutory retention periods; tax documents generally 10 years | |
| Withdrawal, complaints and disputes | Identity, order, defect details, photographs, communications | Handling statutory rights and protecting legal claims | Contract, legal obligation, legitimate interests | For the case and then for the period in which claims may be asserted | |
| Enquiries and support | Name, e-mail, telephone, message, order or distributor number | Responding to and handling a request | Pre-contractual steps, contract or legitimate interests | For handling and a reasonable follow-up period based on the enquiry | |
| Newsletter - consent | E-mail, possibly name, consent and opt-out records | Offers and news | Consent | Until withdrawal; evidence of consent as long as needed to demonstrate compliance | |
| Offers to existing customers | E-mail, necessary purchase history, opt-out record | Offers of our own similar products or services | Legitimate interests together with the statutory direct-marketing regime | Until opt-out or the statutory conditions cease to apply | |
| Website analytics and marketing | Online identifiers, events, device, approximate location | Usage and campaign measurement, marketing personalisation | Consent | By technology and consent validity; see Cookie Policy | |
| Events, training and competitions | Contact details, registration, participation, possibly photo or video | Organisation, communications, rules and documentation | Contract/rules; consent where required for promotional use of likeness | By purpose, rules and limitation periods | |
| Independent distributors | ID, contact and contract data, sponsor/structure, orders, performance, commissions, payments, training and compliance data | Contract, network and reward administration, support, accounting, fraud prevention | Contract, legal obligation, legitimate interests | For the relationship and then for accounting, tax and limitation periods |
4. Sources of personal data
• directly from you when you order, register, contact us, attend an event or give consent;
• from use of the website and applications where this is permitted by the legal basis and your cookie settings;
• from payment, delivery and other service providers to the extent required for a transaction or incident;
• for distributors, also from the TIENS distribution system and structure and from order, performance, reward and sponsorship records;
• from public sources only where proportionate to the purpose and legally permitted.
5. Health data and other sensitive data
We do not require information about your health for ordinary sales. Do not send diagnoses, medical reports or other sensitive health information through general contact forms unless it is necessary for a specific request.
If TIENS specifically collects or publishes a testimonial, case study or other material containing health information identifying a person, we will use an appropriate legal basis under Article 9 GDPR. Where the basis is explicit consent, it will be specific, informed, demonstrable and revocable.
6. Recipients and processors
We disclose data only to the extent necessary. Recipients may include hosting, IT and e-commerce platform providers, payment services, carriers, accounting, tax and legal advisers, CRM and e-mailing providers, analytics and advertising platforms activated according to your consent, TIENS Group companies where necessary for the relevant purpose, and public authorities where required by law.
The current website environment may include in particular the Bitrix/Bitrix24 platform, TIENS global CRM and form services, and Weglot translation solutions. Specific technologies that store or read data on your device are described in the Cookie Policy.
7. Transfers of personal data outside the EEA
Some service providers or TIENS Group companies may operate outside the European Economic Area (the “EEA”). Transfers take place only where GDPR requirements are met, in particular on the basis of a European Commission adequacy decision or appropriate safeguards, typically the European Commission’s Standard Contractual Clauses. We also apply supplementary technical and organisational measures where required by the risk.
For recipients in the United States, an adequacy decision may be relied upon only where the relevant recipient participates in the EU-U.S. Data Privacy Framework. For ordinary transfers to other countries without an adequacy decision, we use appropriate contractual and security safeguards. Information about the safeguards used may be requested at office@tiens.cz; confidential and security-sensitive parts will remain protected.
8. Marketing communications
We send newsletters to persons who are not our customers on the basis of consent. Subject to Czech law, we may send existing customers offers for our own similar products or services where they could easily refuse such use when their contact details were collected and in every subsequent message.
Every marketing communication identifies the actual sender and provides an easy and free means of unsubscribing. We respect an opt-out without undue delay. We may retain a minimal suppression record so that the contact is not inadvertently returned to an active mailing list.
9. Automated decision-making and profiling
With your consent, analytics or marketing tools may create segments for measurement and communications. TIENS does not, without separate lawful use, make decisions based solely on automated processing that produce legal effects or similarly significantly affect you. If such processing is introduced, you will receive specific information about its logic, significance and expected consequences.
10. Your rights
Subject to the conditions of the GDPR, you have in particular the right:
• to information about and access to your personal data;
• to rectify inaccurate data and complete incomplete data;
• to erasure where the statutory conditions are met;
• to restriction of processing;
• to object to processing based on legitimate interests; you may object to direct marketing at any time;
• to data portability where the statutory conditions are met;
• to withdraw consent at any time without affecting the lawfulness of processing before withdrawal;
• not to be subject, where the statutory conditions apply, to a decision based solely on automated processing that has legal or similarly significant effects;
• to lodge a complaint with the supervisory authority.
11. How to exercise your rights and lodge a complaint
You may send a request to office@tiens.cz or to TIENS at its registered office. For security reasons, we may take proportionate steps to verify your identity. We will respond within the time limits laid down by the GDPR.
The supervisory authority is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 727/27, 170 00 Prague 7, e-mail filing office posta@uoou.gov.cz, data box qkbaa2n.
Current contact information is available on the Office for Personal Data Protection website.
12. Data security
We apply technical and organisational measures appropriate to the nature of the data and the risk, including access management, account protection, logging, backups, system updates, supplier management, training of relevant persons and procedures for handling security incidents.
13. Children
The online shop and distribution programme are not primarily intended for children. If we discover that we have obtained a child’s personal data without an appropriate legal basis, we will take proportionate steps to remedy the situation. For events or promotional content involving children, we assess the correct legal basis and any requirement for consent from a legal representative in advance.
14. Changes to this Notice
We may update this Notice when services, providers or legal requirements change. The current version will always be identified by a version number and effective date. This version is effective from August 26, 2026.