Privacy Policy

Effective Date: 11 May 2026

Data Controller

Elizaveta Ermakova, OSVČ
Vysočanská 237/101, Praha 9 – Střížkov, 190 00, Czech Republic
IČO: 24342203

Email: toxmetics@gmail.com

The Website toxmetics.com (the “Website”) is operated by Elizaveta Ermakova, self-employed professional (OSVČ).

Toxmetics is an independent educational and professional community project focused on cosmetics safety assessment, product formulation and manufacturing consulting, and education in cosmetics and household chemistry. The Website is used to share professional information, provide consultations, and offer future online courses.

This Privacy Policy explains how personal data is collected and processed when you use the Website.

1. Personal Data We Collect

We only collect personal data that you voluntarily provide or that is necessary for communication and basic website operation.

a) Data you provide directly

When you contact us or use a contact or order form, we may collect:

  • Name and surname

  • Email address

  • Telephone number (if provided)

  • Billing information (if required for invoicing), such as name, address, and IČO for business customers

b) Data collected automatically

When you visit the Website, basic technical data may be processed by our hosting provider for security and functionality purposes, such as:

  • IP address

  • Browser type and version

  • Device information

  • Pages visited

2. How We Use Personal Data

We use personal data only for the following purposes:

  • Responding to inquiries and communication

  • Providing information about services and future courses

  • Processing orders and issuing invoices

  • Maintaining website functionality and security

  • Fulfilling legal obligations (e.g. accounting and tax requirements)

3. Legal Basis for Processing

We process personal data based on:

  • Consent (e.g. when you contact us voluntarily)

  • Contract performance (e.g. purchase of a course or service)

  • Legal obligations (e.g. accounting and tax laws)

  • Legitimate interests (e.g. website security and basic operation)

4. Data Sharing

We do not sell or rent personal data.

Personal data may be shared only with:

  • Website hosting provider: Hostinger International Ltd.

  • Accounting or tax service providers (if applicable)

  • Public authorities, if required by law

5. Data Retention

We keep personal data only for as long as necessary:

  • Contact inquiries: up to 12 months

  • Invoice and accounting data: as required by Czech law (typically 5–10 years)

  • Technical logs: according to hosting provider retention policies

6. Cookies

The Website may use basic cookies necessary for functionality provided by the hosting platform.

If analytics or marketing cookies are introduced in the future, users will be informed and consent will be requested in accordance with applicable law.

7. Your Rights (GDPR)

You have the right to:

  • Access your personal data

  • Rectify inaccurate data

  • Request deletion of your data

  • Restrict processing

  • Object to processing

  • Request data portability

To exercise these rights, contact us at:
toxmetics@gmail.com

8. Data Security

We take reasonable technical and organizational measures to protect personal data. However, no online system is completely secure.

9. Third-Party Services

We use third-party services necessary for website operation, including:

  • Hostinger International Ltd. (website hosting)

Additional services may be added in the future (e.g. analytics or course delivery tools), and this policy will be updated accordingly.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The latest version will always be available on this Website.

11. Accuracy of Information

We make reasonable efforts to ensure that the information provided in this Privacy Policy is accurate and up to date. However, we do not guarantee that the content is free from errors or omissions.

To the extent permitted by applicable law, we are not liable for any minor inaccuracies or typographical errors in this Privacy Policy. This does not affect your statutory rights under GDPR or other applicable data protection laws.