Data Protection
I personally value every piece of personal data you entrust to me. Therefore, I always handle this data in a way that does not betray your trust. Please read how I take care of your personal data.
1. Data Controller
The data controller is SC Media s.r.o., with its registered office at Soukenická 877/9, 702 00 Ostrava – Moravská Ostrava, ID No.: 21458871, entered in the Commercial Register maintained by the Regional Court in Ostrava, Section C, Insert 95756 (hereinafter referred to as the “Controller”).
Controller’s contact details:
E-mail: stacycruzreal@gmail.com
Telephone: +420 607 711 189
2. What personal data do we process and why?
We process personal data that you provide to us in connection with the use of our services (purchase of audiovisual content, registration, communication with us) or that we obtain automatically during your visit to our e-shop.
2.1. Purchase and registration
-
Identification data: Name, surname, e-mail address, billing address, delivery address (if different), telephone number. [source: 7] We need this data to process your order, deliver the content, issue an invoice, and potentially communicate regarding the order. [source: 8] Legal basis: performance of a contract (Article 6(1)(b) GDPR).
-
Payment data: Bank account number, payment card details (if paying by card). We process this data to execute the payment. Legal basis: performance of a contract (Article 6(1)(b) GDPR). Note: Payment card data processing is usually handled by a third-party payment gateway. Ensure you have a data processing agreement with the payment gateway provider.
-
Data about purchased content: Information about which audiovisual content you have purchased. We process this data for the performance of the contract and for potential claims handling. Legal basis: performance of a contract (Article 6(1)(b) GDPR) and legitimate interest (Article 6(1)(f) GDPR) in the case of handling complaints.
-
Optional data: If you register, you may provide us with additional data (e.g., date of birth) used for offer personalisation. Legal basis: your consent (Article 6(1)(a) GDPR).
-
Age: Given that our e-shop offers content with sexual themes intended exclusively for adults, we perform verification of your majority (reaching the age of 18). This verification is necessary to fulfil our legal obligations and legitimate interests in protecting minors from inappropriate content and to enable access to our services. Age verification takes place in two steps:
-
Before entering the website: We process your confirmation (declaration) that you are 18 years of age or older. This processing is necessary for compliance with a legal obligation (Article 6(1)(c) GDPR) arising from regulations for the protection of children and youth (e.g., Act No. 40/1995 Coll., on the Regulation of Advertising, and other relevant regulations) and for the purposes of our legitimate interests (Article 6(1)(f) GDPR) in protecting minors.
-
When registering a user account: We again process your confirmation (declaration) that you are 18 years of age or older. This processing is necessary for:
-
Compliance with a legal obligation (Article 6(1)(c) GDPR): Even within a registered account, we fulfil legal obligations regarding the protection of minors.
-
Performance of a contract (Article 6(1)(b) GDPR): Verification of your majority is a condition for concluding and performing the contract for the provision of our services (enabling the purchase and access to purchased content in your account). Without this confirmation, we cannot allow you to register and subsequently use the services.
-
Legitimate interest (Article 6(1)(f) GDPR): Our legitimate interest lies in ensuring that our services are used only by authorised persons (over 18 years old) and in the ability to demonstrate compliance with legal regulations. Information confirming you have reached the age of 18 is therefore processed for the purposes of enabling entry to the website, creating and maintaining your user account, enabling the purchase and access to purchased content, and for fulfilling our legal obligations and protecting our rights.
2.2. Communication with customers
-
E-mail, telephone, contact form: If you contact us, we process your contact details and the content of the communication to handle your request. Legal basis: legitimate interest (Article 6(1)(f) GDPR).
-
Sending commercial communications (newsletter): If you have given us your consent, we will send you commercial communications with news and offers via e-mail. Legal basis: your consent (Article 6(1)(a) GDPR). You can withdraw your consent at any time.
2.3. Automatically collected data (cookies and log files)
When you visit our e-shop, we may automatically collect certain information, such as your IP address, browser type, operating system, visited pages, time spent on pages, and other technical data. This data serves to:
-
Ensure e-shop functionality: Necessary cookies. Legal basis: legitimate interest (Article 6(1)(f) GDPR).
-
Analyse website traffic and improve services: Analytical cookies. Legal basis: legitimate interest (Article 6(1)(f) GDPR), if data anonymisation is ensured, otherwise consent (Article 6(1)(a) GDPR).
-
Personalise content and advertising: Marketing cookies. Legal basis: consent (Article 6(1)(a) GDPR).
Detailed information about cookies and their setting options can be found in the separate document “Information on the use of cookies” https://stacycruz.live/cookies/.
3. Sensitive personal data
Processing of sensitive personal data about purchased erotic content: When you purchase erotic content on our e-shop, we process information about the specific content you have purchased. [source: 38] This information may indirectly reveal information about your sex life or sexual orientation and is therefore considered a special category of personal data (sensitive personal data) within the meaning of Art. [source: 39] 9 of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).
Purpose of processing: We process this sensitive personal data solely for the following purposes:
-
Managing your user account: Enabling access to purchased content in your user account. This includes displaying purchase history and the possibility of re-downloading or viewing the purchased content.
-
Processing your order: Ensuring the proper handling of your order, including invoicing, delivery (in the case of physical goods), and potential claims handling.
-
Improving our offer: We may use information about the content you purchased in an anonymised and aggregated form to improve our offer and recommendations for other customers. This information will be completely stripped of any identifiers.
Legal basis for processing: The processing of this sensitive personal data is necessary for:
-
Performance of a contract (Article 6(1)(b) GDPR): Processing is necessary to fulfil the contract for the purchase of erotic content that you conclude with us. Without processing this data, we could not provide you with access to the purchased content and process your order.
-
Explicit consent (Article 9(2)(a) GDPR): We also ask for your explicit consent to the processing of this sensitive data for the purposes stated above. You can withdraw this consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
4. Who may we transfer your personal data to?
We may transfer your personal data to third parties (processors) who help us operate the e-shop and provide services. These mainly include:
-
Providers of technical infrastructure and software solutions:
-
Automattic Inc. (USA): Operator of WordPress.com and WooCommerce.
-
Hostinger International Ltd. (Lithuania): Hosting provider.
-
Providers of payment services:
-
Automattic Inc. / WooPayments (in cooperation with Stripe Inc. and others): Processing online payments.
-
You enter your payment details directly into the secure interface of the payment gateway.
-
Providers of delivery and transport services:
-
Česká pošta, PPL, Zásilkovna, DHL (to the extent necessary for delivery – name, address, telephone, e-mail).
-
Providers of accounting and tax services:
-
Zuzana Tkáčová, ID No.: 17737362.
-
Providers of IT and marketing services:
-
Google LLC (Google Analytics, Google Tag Manager)
-
Meta Platforms, Inc. (Meta Pixel)
-
Microsoft Corporation (Clarity)
-
Public authorities:
-
In cases stipulated by law (e.g., Police of the Czech Republic, Tax Office, etc.).
We have concluded data processing agreements (DPAs) with processors, which oblige them to protect personal data in accordance with GDPR.
Transfer of personal data to third countries
Within the scope of using certain services (Automattic, Stripe, Google, Meta, Microsoft), your personal data may be transferred to countries outside the EU/EEA, particularly to the USA. Such transfers only occur if an adequate level of protection is ensured, primarily through Standard Contractual Clauses (SCCs) approved by the European Commission and potential supplementary measures. We recommend that you also familiarise yourself with the privacy policies of these providers:
-
Automattic Privacy Policy: https://automattic.com/privacy/
-
Stripe Privacy Policy: https://stripe.com/privacy (Potentially add links to Google, Meta, Microsoft policies here)
5. How long do we retain your personal data?
We retain your personal data for the period strictly necessary to achieve the purpose for which it was collected, or for the period stipulated by legal regulations.
-
Order data: For the duration of the contractual relationship and further for the period stipulated by law for archiving (especially according to the Accounting Act – 5 years, the VAT Act – 10 years for tax documents) and limitation periods for potential disputes.
-
Data for sending commercial communications: Until consent is withdrawn or an objection is raised.
-
Communication data: For the period necessary to handle the request and any subsequent limitation periods.
-
Cookie data: According to cookie settings (see Cookie Policy).
-
Age verification data:
-
Confirmation before entry (without registration): For the duration of the session or a short period in log files (e.g., several days/weeks).
-
[source: 62] Confirmation during registration: For the entire duration of the user account’s existence.
-
After account deletion: To a limited extent (record of confirmation) for the duration of the limitation period (generally 3 years, possibly longer according to GDPR specifics). Note: The retention of other data associated with the account (e.g., invoices) is governed by its own deadlines (see above).
6. Method of processing personal data
We process your personal data in accordance with applicable legal regulations, especially GDPR and Czech laws. We pay attention to its protection and security. Processing takes place both manually and automatically in our electronic systems (customer database, accounting system, e-shop platform WordPress/WooCommerce) as well as in paper form.
-
Data security: We have adopted and maintain appropriate technical and organisational measures against unauthorised access, alteration, destruction, loss, unauthorised transfers, and other misuse.
-
Access to data: Access is granted only to authorised employees or authorised processors to the necessary extent, bound by confidentiality.
-
Automated decision-making and profiling: We do not perform any automated decision-making or profiling with legal or similarly significant effects for you.
-
During processing, we respect the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality.
7. Cookie Policy
A cookie is a small data file (text file) that is stored in your device’s browser when you visit a site and collects information (e.g., language preference, login details). [source: 71] We use our own cookies as well as third-party cookies (from other domains) for the purposes of functionality, analysis, advertising, and promotion. [source: 72] If you do not wish to accept cookies, you can manage them (delete, block) in your internet browser settings or use private/incognito mode. [source: 73] Help can be found in your browser’s documentation:
We describe the policy for processing cookie files in detail here: https://stacycruz.live/cookies/
8. What are your rights?
You have the right to know how we handle your data. You can contact us at any time if you require:
-
Obtaining a copy (access to) personal data: We will send you an overview of the data we hold about you (Right of access).
-
Rectification of personal data: Let us know what needs to be corrected (Right to rectification).
-
Erasure of personal data (‘right to be forgotten’): If you do not wish for further processing, we will arrange for erasure (within the limits of legal obligations) (Right to erasure).
-
Restriction of processing of your personal data: We will mark data whose processing is to be restricted (Right to restriction of processing).
-
Withdrawal of consent: If processing is based on consent, you can withdraw it at any time.
-
Portability of personal data: Upon request, we will provide your data in a structured, machine-readable format (Right to data portability).
-
To object to processing (pursuant to Art. 21 GDPR): If we process data based on legitimate interest, you can object (Right to object).
-
To lodge a complaint with a supervisory authority: This is the Office for Personal Data Protection (www.uoou.cz). However, we believe that any potential discrepancies can be resolved directly with you.
To exercise your rights, please contact us at: e-mail: stacycruzreal@gmail.com or telephone number: +420 607 711 189.
9. References to Legislation
We always proceed in accordance with applicable legislation:
-
Constitutional basis:
-
Council of Europe Convention No. [source: 83] 108
-
Article 8 of the Charter of Fundamental Rights of the EU
-
Article 16 of the Treaty on the Functioning of the European Union
-
Articles 7, 10(3) and 13 of the Charter of Fundamental Rights and Freedoms (Czech)
-
General regulations:
-
Act No. 89/2012 Coll., Civil Code
-
Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR)
-
Act No. 110/2019 Coll., on Personal Data Processing
-
Act No. 480/2004 Coll., on Certain Information Society Services
10. Final Provisions
These privacy principles may be updated from time to time. The current version is always available on our e-shop.
Last updated: 20 March 2025