Privacy and data processing statement
Updated: 4. November 2024
This Privacy Statement describes how we collect and use information, which may include personal information that you provide to us. As a Data Controller, we take precautions to protect personal information from loss, misuse, unauthorized access, disclosure, alteration or destruction. We have taken appropriate technical and organisational measures to protect the information systems on which your personal data is stored and we contractually require suppliers and service providers to protect your personal data.
This statement also defines:
- how we treat your data
- how you can access and edit them
- who is the Data Controller of your personal data
- who the responsible person is and contact details
- the list or range of recipients and processors to whom your personal data may be disclosed,
- information about the scope of the data we process about you
- the range of purposes for which we may use your personal data
- the range of legal bases for processing
- information about your rights and how you can exercise them.
Contact details of the operator:
Company Name: Compass Europe s.r.o.
Address: Poľná 3, 903 01 Senec
ID: 35 890 495
Name of the statutory representative: Ing. Tibor Mészáros
Contact person’s name: Michal Haverl
Contact: Mobile: +421 910 903 393
email: haverl@compasspools.eu
URL of the web page: www.compassBazény.eu
Definition of basic terms
- Processing of personal data means any operation or set of operations which the Data Controller, Processor or an authorised third party systematically performs on the personal data of the Data Subject; this includes, in particular, the collection of personal data, storage on information carriers, disclosure, alteration or modification, retrieval, use, transmission, dissemination, disclosure, storage, exchange or combination, blocking and destruction of the personal data of the Clients.
- the data subject’s consent is any serious and freely given, specific, informed and unambiguous indication of the data subject’s wishes in the form of a statement or an unambiguous confirmatory act by which the data subject consents to the processing of his or her personal data,
- genetic data are personal data relating to inherited genetic characteristics of a natural person or acquired genetic characteristics of a natural person which provide unique information about the physiology or health of that natural person and which result, in particular, from the analysis of a biological sample of that natural person,
- biometric data are personal data which are the result of specific technical processing of personal data concerning the physical characteristics of a natural person, the physiological characteristics of a natural person or the behavioural characteristics of a natural person and which allow unique identification or confirm the unique identification of that natural person, such as, in particular, facial images or dactyloscopic data,
- health-related data are personal data relating to the physical health or mental health of a natural person, including data relating to the provision of healthcare or healthcare-related services which reveal information about his or her health,
- processing of personal data a processing operation or set of processing operations concerning personal data or sets of personal data, in particular the obtaining, recording, organisation, structuring, storage, alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise, alignment or combination, restriction, erasure, whether or not carried out by automated or non-automated means,
- profiling is any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal characteristics or characteristics relating to a natural person, in particular to analyse or predict the characteristics or Vlastnosti of the data subject relating to his or her performance at work, financial situation, health, personal preferences, interests, reliability, behaviour, location or movements,
- by pseudonymisation, the processing of personal data in such a way that they cannot be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data cannot be attributed to an identified natural person or to an identifiable natural person,
- a logo record is a record of a user’s course of action in an automated information system
- an online identifier is an identifier provided by an application, tool or protocol, in particular an IP address, cookies, login data to online services, radio frequency identification, which may leave traces that can be used, in particular in combination with unique identifiers or other information, to create a profile of the data subject and to identify him or her,
- an information system is any organised collection of personal data which is accessible according to specified criteria, whether the system is centralised, decentralised or distributed on a functional or geographical basis,
- the data subject is any natural person whose personal data are processed,
- a controller is anyone who, alone or jointly with others, determines the purpose and means of processing personal data and processes personal data on his or her own behalf; the controller or the specific requirements for his or her determination may be laid down in a special regulation or an international treaty by which the Slovak Republic is bound, if that regulation or that treaty provides for the purpose and means of processing personal data,
- A processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
- the recipient is anyone to whom the personal data are disclosed, regardless of whether he or she is a third party; a public authority which processes personal data on the basis of a special regulation or an international treaty to which the Slovak Republic is bound in accordance with the rules on the protection of personal data applicable to the purpose for which the personal data are processed shall not be considered a recipient,
- a third party is anyone other than the data subject, controller, processor or other natural person who processes personal data on behalf of the controller or processor,
- the responsible person is a person designated by the controller or processor who performs tasks pursuant to the GDPR and Act No. 18/2018 Coll,
- an establishment, e.g. an establishment resident in a Member State, which has been authorised in writing by the controller or processor pursuant to Article 27 of the GDPR,
- the main establishment is:
- the place of central administration of the controller in the European Union where the controller is a controller with establishments in more than one Member State, except where decisions on the purposes and means of the processing of personal data are taken at another establishment of the controller in the European Union and that other establishment has the power to enforce the implementation of such decisions, in which case the establishment which has taken such decisions shall be deemed to be the main establishment,
- the place of central administration of the processor in the European Union if the processor has establishments in more than one Member State or, if the processor does not have a central administration in the European Union, the establishment of the processor in the European Union where the main processing activities are carried out in the context of the activities of the establishment of the processor, to the extent that the processor is subject to specific obligations under the GDPR and Act No 18/2018 Coll,
- a third country is a non-member country.
- Member State means a State that is a Member State of the European Union or a contracting party to the Agreement on the European Economic Area,
- international organisation means an organisation and its subordinate entities governed by public international law, or any other entity established by or under an agreement between two or more countries
For the purposes of this notice, the data subjects are:
- natural persons with whom we have a contract in the course of our business and who use our services
- representatives of clients, natural persons representing legal persons, natural persons forming the statutory body of a legal person;
- authorised persons of the client, authorised persons of the controller and processors of the controller whose personal data are processed by the controller,
- other natural persons whose personal data is necessary to process
- users of our website;
- natural persons who have entered the premises monitored by our CCTV system.
Personal Data Processing Policy:
When processing the personal data of Data Subjects, the Controller shall, to the greatest extent possible, respect and honour the highest standards of personal data protection, observing in particular the following principles:
- Purpose limitation principle (Article 5(1)(b) GDPR): personal data will only be collected for specified, explicit and legitimate purposes and may not be further processed in a way incompatible with those purposes. SAL shall inform the data subject of the purpose of the processing of the personal data before processing.
- Principle of data minimisation (Article 5(1)(c) GDPR): personal data will be processed in such a way that such processing is proportionate, relevant and limited to the necessary extent given by the purpose for which it is processed.
- Principle of accuracy (Article 5(1)(d) GDPR): personal data will be processed in such a way that they are correct and updated as necessary; measures must be taken to ensure that personal data which are incorrect in relation to the purposes for which they are processed are erased or rectified without undue delay. In order to ensure the principle of accuracy, the following wording should be included in the written consent to the processing of personal data: ‘The data subject shall provide true and up-to-date personal data. In the event of a change in the personal data, the data subject shall immediately notify the controller of the change.”
Next, we follow these procedures:
- Only authorised persons of our company (our employees) and authorised persons of our agents have access to your personal data.
- personal data are processed in accordance with the relevant legislation (in particular in accordance with the Obecné nařízení o ochraně osobních údajů 2018/18 Coll. and the GDPR) in a fair and transparent manner
- when processing personal data, the Controller takes care to protect their rights and fully respects them
- personal data are always processed in a clear and comprehensible manner for a specified purpose by specified means and in a specified manner;
- only those personal data are collected whose processing is compatible with the stated purposes (adequate, relevant and necessary for the fulfilment of those purposes)
- they shall be kept only for the period necessary for the purposes for which they are processed;
- A legal declaration containing the consent of minors under the age of sixteen shall not be valid unless agreed or subsequently approved by the statutory representative of such minors.
The operator is not responsible for the accuracy of the data provided by website visitors or guests.
- The principle of minimum retention (Article 5(1)(e) GDPR): personal data shall be kept in a form which permits identification of the data subject at the latest for as long as is necessary for the purpose for which the personal data are processed.
- Integrity and confidentiality principle (Article 5(1)(f) GDPR): personal data will be processed in a manner that ensures their adequate security, including protection against unauthorised processing of personal data, unlawful processing of personal data, accidental loss of personal data, erasure of personal data or damage to personal data, by means of appropriate technical or organisational measures.
How we collect your personal data
We obtain your personal data in the following ways:
- by completing and submitting the submission form on our website
- electronically, by e-mail
- on the basis of a telephone conversation
- on personal arrival at our offices
- by paper mail
- through another person who has given us your personal data for the purpose of establishing a possible cooperation
Information for employees
Scope of personal data processed
Contact data – first name, surname, permanent address, temporary address, email contact and private and business telephone contact.
Employment data – employment contract, salary schedule, job classification, job description, competences, performance evaluation, records of work trips, attendance, CV (curriculum vitae), entrusted property, access rights to applications, access rights to protected areas, records of access to protected areas.
Personal and family data – marital status, date of birth, family data for tax credits and tax obligations, data on disabled persons, identifiers such as birth number, ID number, driver’s license number.
Payroll information – bank details, annual settlement applications, annual settlements, bonuses, second and third pillar insurance.
Purposes:
the controller processes the personal data of employees for several purposes only to the extent necessary and for the purpose in question:
- The purpose of the labour-law agenda is to record personal data of the company’s employees and employees performing work on the basis of an agreement on work performed outside the employment relationship (contract workers) for the purpose of registration in the social and health insurance company, processing payroll, creating labour-law documentation, for correspondence, recording of education and knowledge for the purpose of verifying the qualifications for tenders, enabling the use of company benefits.
- Personal data for the purpose of protecting the health, property and property rights of the company, its employees, business partners and visitors is used to control access to premises and applications within the minimized scope of contact data Records of incoming and outgoing mail in postal relations with employees within the necessary scope of contact data.
Legal Basis:
The processing of personal data must be carried out on one of the following legal bases:
- the data subject has consented to the processing of his or her personal data for one or more specific purposes;
- the processing is necessary for the performance of a contract to which the data subject is a party or to carry out pre-contractual measures at the request of the data subject;
- the processing of personal data is necessary pursuant to a special regulation or an international treaty by which the Slovak Republic is bound (§ 13 (1) (c) of the GDPR)
- processing is necessary to protect the vital interests of the data subject or another natural person;
- the processing is necessary for the performance of a task carried out in the public interest
- the processing is necessary for the purposes of the legitimate interests pursued by the controller, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, in particular where the data subject is a child.
Data storage:
employees’ personal data is not transferred to third countries, it is exclusively located in the European Union.
Retention:
personal data is retained for the duration of the purposes, which generally means for the duration of the employment relationship, unless the legislation of the Slovak Republic requires longer retention periods of personal data, for example for pension provision.
Sharing of personal data (Recipients, processors, third parties)
The difference between the Controller and the Processor is that the Controller determines to the Processor the purpose of the processing of personal data. Not vice versa.
Our company acts primarily as an Operator, e.g. in relation to its employees. For our own operation, we also use cooperation with Intermediaries who carry out professional activities (e.g. accounting and personnel management, occupational health and safety, IT support, etc.). However, as an Operator, we do not also act as an Intermediary.
At the same time, we as the Operator are also obliged to cooperate with Third Parties, which may be governmental, police, regulatory authorities. Other Third Parties are e.g.: social insurance company, health insurance company, post office, bank, leasing company. We also use third parties to support us in the provision of services and to help provide, operate and manage internal IT systems. These include, for example, information Technologie providers, providers of cloud-based software as a service, identity management, website hosting and management, data analytics, data backup, security and retention services. The servers that power and facilitate the cloud infrastructure are located in secure data centers around the world, and personal data can be stored in any of them.
Employees’ personal data is further handled by intermediaries and 3rd parties according to the table below:
Information for jobseekers
The controller processes personal data of job applicants
Scope of personal data processed:
Contact details – first name, last name, permanent address, temporary address, email contact and telephone contact.
Job details – CV – overview of professional career, knowledge and experience, declaration of integrity for some positions, references.
Salary information – required income
Purposes:
the Controller processes personal data of job applicants for the purpose of:
- Recruitment of new employees by selecting from among candidates through an assessment of their professional qualifications and assessment of their suitability for the performance of the required job (especially in technical and professional positions)
- Records of incoming and outgoing mail in postal relations with applicants within the necessary range of contact details.
- The personal data of job seekers are handled exclusively by employees of the Controller who are instructed on their duties in relation to the personal data of the data subjects and do not provide them to any recipients, intermediaries or third parties.
Legal basis
We process applicants’ data only for the purpose and within the framework of the selection procedure in accordance with the legal regulations. The processing of candidates’ data is carried out for the purpose of fulfilling our contractual obligations and pre-contractual measures in the context of the selection procedure in accordance with Article 6(1)(b) GDPR and Article 6(1)(f) GDPR, respectively Article 13(1)(a) and (f) of Act No. 18/2018 on the Protection of Personal Data, as amended.
The personal data of job applicants are therefore processed by the Controller on the legal basis of the pre-contractual relationship between the future employer and the candidate, for the assessment of the candidate’s suitability for the performance of the job position to be filled.
Saving data
The personal data of job seekers are not transferred to third countries, they are exclusively located in the European Union.
Retention
Personal data is retained only for the duration of the purpose.
It is a condition of the selection procedure that the applicant provides us with the requested data. In the case of the online form, the required data is visibly marked; in other cases, this is clear from the descriptions. This group of data includes in particular information about the person concerned, the correspondence address and contact details, the supporting documents for the selection procedure (e.g. covering letter, CV and relevant certificates). In addition, applicants may also provide us with other information on a voluntary basis.
By participating in the selection procedure for the specific position presented, we do not ask candidates for their consent to the processing of personal data, as the purpose is to seek formal contractual cooperation and therefore the legal basis is the pre-contractual relationship.
Where special categories of personal data within the meaning of Article 9(1) are requested from a candidate in the context of a selection procedure, they shall be processed in accordance with Article 9(2)(a) (e.g. health data). These data are required only if they are necessary for the performance of the job in question.
Candidates can send us their details via the online form on our website, where available. The data is sent in encrypted form as far as we are technically able. Applicants may also send us their data by e-mail. However, we would like to point out that e-mail communications are not encrypted as such and the sender is responsible for their encryption. We can therefore assume no responsibility for the transmission of data between the sender and our server. For this reason, we recommend that you rather use the online form or the option of sending by post. In addition to the online form and e-mail communication, there is also the alternative of conventional postal delivery.
The data provided by applicants may be further processed by us for the purpose of organising the employment relationship in the event of a successful application for a given position. We will use the legal basis of a specific regulation.
Otherwise, if the applicant is unsuccessful in the selection procedure, we will proceed to delete the data or ask for his/her consent to the storage of personal data. The applicant’s data will also be deleted if the applicant withdraws his/her application, which is his/her right at all times.
We proceed to deletion, except in the case of a legitimate objection by the applicant, after the expiry of the purpose of the processing. We only retain the data to answer any additional questions about the selection procedure and to fulfil our obligations under the Equal Opportunities Act. Where applicable, receipts relating to any billing of travel expenses will be archived in accordance with tax law.
Scope of personal data processed:
Contact details – first name, last name, place of residence, email and telephone working contact.
Purposes:
the controller processes personal data about customers for the purposes of pre-contractual and contractual relations and direct marketing only to the extent necessary for these purposes.
Legal basis
The personal data of customers are processed by the Controller on the legal basis of contractual and pre-contractual relations (order, work contract), special regulation (obligation to deal with complaints) and legitimate interest (marketing).
Data storage
The personal data of customers and customer employees are not transferred to third countries, they are exclusively located in the European Union.
Retention
Personal data are retained for the duration of the purpose, which generally means for the duration of the contractual relationship, unless the legislation of the Slovak Republic requires longer periods of archiving personal data, for example for archiving accounting documents.
We process the data of our members, supporters, prospects of our products and services, customers or other persons on the basis of Article 6(1)(b) GDPR insofar as we fulfil our contractual obligations towards them or offer them our products and services or are in an existing business relationship with them (e.g. towards members) or are themselves recipients of their services or support. Otherwise, we process data of data subjects in accordance with Article 6(1)(f) of the GDPR on the basis of our legitimate interests, e.g. when it comes to administrative tasks or public relations.
The data processed in this way, the manner, scope, purpose and necessity of the processing shall be determined in accordance with the relevant contractual relationship. This includes, in particular, basic personal identification data (e.g. names, addresses, etc.) as well as contact data (e.g. e-mail addresses, telephone numbers, etc.), contractual data (e.g. services used, content and information reported, names of contact persons) and, in the case of paid services and products, payment data (e.g. bank connections, payment history, etc.).
We delete this data when its storage is no longer necessary for the performance of our statutory and commercial obligations. We determine this based on the nature of the tasks and contractual relationships involved. In the case of data processing relating to business obligations, we retain the data in question for as long as it may still be relevant for the performance of the business obligations as well as in connection with warranty or other comparable obligations. We review the necessity of data retention every three years, otherwise the statutory retention periods apply.
Scope of personal data processed
Contact details – first name, last name, employer’s address, work email and work phone contact, bank details.
Purposes
The controller processes personal data of suppliers and employees of suppliers for the purposes of pre-contractual and contractual relations only to the extent necessary for these purposes.
Saving data
The personal data of suppliers and employees of suppliers are not transferred to third countries, they are exclusively located in the European Union.
Retention
Personal data are retained for the duration of the purpose, which generally means for the duration of the contractual relationship, unless the legislation of the Slovak Republic requires longer periods of archiving personal data, for example for archiving accounting documents.
Legal basis
Personal data of suppliers and employees of suppliers are processed by the Controller on the legal basis of contractual and pre-contractual relations.
We process the data of our members, supporters, prospects of our products and services, customers or other persons on the basis of Article 6(1)(b) GDPR insofar as we fulfil our contractual obligations towards them or offer them our products and services or are in an existing business relationship with them (e.g. towards members) or are themselves recipients of their services or support. Otherwise, we process data of data subjects in accordance with Article 6(1)(f) of the GDPR on the basis of our legitimate interests, e.g. when it comes to administrative tasks or public relations.
The data processed in this way, the manner, scope, purpose and necessity of the processing shall be determined in accordance with the relevant contractual relationship. This includes, in particular, basic personal identification data (e.g. names, addresses, etc.) as well as contact data (e.g. e-mail addresses, telephone numbers, etc.), contractual data (e.g. services used, content and information reported, names of contact persons) and, in the case of paid services and products, payment data (e.g. bank connections, payment history, etc.).
We delete this data when its storage is no longer necessary for the performance of our statutory and commercial obligations. We determine this based on the nature of the tasks and contractual relationships involved. In the case of data processing relating to business obligations, we retain the data in question for as long as they may still be relevant for the performance of the business obligations as well as in connection with warranty or other comparable obligations. We review the necessity of data retention every three years, otherwise the statutory retention periods apply.
The Operator’s website may contain links that are not operated by the Operator and are provided there for the information of visitors only. The Operator has no influence on the content and security of websites operated by partner companies and is therefore not responsible for them. Before you provide any data on that website, please review the data protection statement and data management guidelines of those websites you visit.
Use of automated processing of your personal data
Automated processing is the processing of personal data where automated information systems, such as IT applications, software, etc., are used exclusively. We would like to inform you that we do not use so-called profiling, i.e. automated processing, in the provision of our services.
Data Protection Impact Assessment (Article 35 GDPR)
In particular, a data protection impact assessment is required in cases where:
- a systematic and extensive evaluation of personal aspects relating to natural persons based on automated processing, including profiling, and on which decisions having legal effects concerning or having a similarly significant impact on the natural person are based;
- large-scale processing of special categories of data pursuant to Article 9(1) or of personal data relating to criminal convictions and offences pursuant to Article 10; or
- systematic monitoring of publicly accessible places on a large scale.
Our processing activities do not involve the cases mentioned above or similar cases and therefore it is not necessary to carry out a data protection impact assessment.
Given our processing activities, the type of processing, the technologies used, the nature, scope, context and purposes of the processing, this processing will not lead to a high risk to the rights and freedoms of natural persons, therefore the controller is not obliged to carry out an impact assessment of the planned processing operations on the protection of personal data prior to the processing.
Where there is a real, risky and dangerous situation, the purpose of protecting property against burglary, theft or vandalism may constitute a legitimate interest for carrying out monitoring. The legitimate interest must therefore actually exist and be a current issue (i.e. not fictitious or speculative).
As an Operator, we have taken advantage of this opportunity and we monitor our operations with a camera system for the above purpose and on a legal basis in accordance with the GDPR and internal guidelines. The proportionality test carried out has assessed the risks and intensity of interference with the rights and freedoms of the data subject as negligible.
Administration, accounting, organisation, contact management
We process data in the context of the administration and organisation of our company, bookkeeping and compliance with legal obligations such as archiving. In these areas, we process the same data as in connection with the performance of our contractual obligations. The legal basis for the data processing in question is Article 6(1)(c) GDPR, Article 6(1)(f) GDPR. The data subjects in this case are customers, those interested in our products and services, business partners and visitors to our website.
The purpose of the processing and our legitimate interest lies in administration, accounting, corporate organisation, data archiving, i.e. tasks that serve to maintain our business activities, perform our tasks and provide our services. The principles of erasure of processed data related to the tasks listed above are the same as those related to the performance of contractual obligations and contractual communications.
We transfer or transmit data to the financial administration, financial advisors (e.g. tax advisors or economic analysts) as well as to other providers of billing and payment services.
Furthermore, we store data about suppliers, promoters and other business partners for the purpose of e.g. contacting them at a later date on the basis of our business and economic interests. We store this data, which mostly relates to the activities of our company, on a long-term basis as a matter of principle.
Registering for a user account
Users can create a user account on our website. As part of the registration process, the required data is visibly marked. We process the entered data in accordance with Article 6(1)(b) GDPR for the purpose of providing the user account service. The processed data primarily includes login data (name, password, but also e-mail address). The data entered as part of the registration process is used for the purpose of managing and setting up the user account.
Users may be notified by email of changes relevant to the use of their user account (e.g. technical changes). At the moment of cancellation of the user account, all related data will be deleted, unless it is subject to a statutory retention period. The user is responsible for the retention of his/her data in the event of cancellation of the account before the termination of the contractual relationship. Our company is entitled to irreversibly delete all user data stored during the duration of the contractual relationship.
We store the IP address used and the timestamp of the actions performed when using the registration and login functions as well as during the use of the account itself. The storage is based on our legitimate interests as well as the interests of the user to protect against misuse and any unauthorised use. In principle, we do not disclose this data to third parties, except where this is necessary for the exercise of our claims or where we are bound to do so by statutory provisions pursuant to Article 6 (1) (c) GDPR. The IP addresses used will be anonymised or deleted after a period of seven days at the latest.
Establishing contact with commercial intent
In the event of contact with our company, e.g. via a contact form, email, telephone or social media, we process the user’s data for the purpose of processing the request in question and processing it in accordance with Article 6(1)(b) of the GDPR (performance of the contract). The user’s data may be stored in an internal database. We delete the request when its storage is no longer necessary. We check the justification for retention every two years, otherwise the statutory retention periods apply.
In the following lines, we would like to inform you about the content of our Novinkyletters as well as about subscribing to them, sending them and the process of statistical evaluation, but also about the possibilities of resistance.
Double opt-in and opt-in: Subscribing to our Novinkyletters is done as part of the so-called Double opt-in process. This means that when you subscribe, you will receive an email asking you to confirm your decision. This is a necessary security measure to prevent strangers from using your address to subscribe. Each Novinkyletter subscription is logged so that it can be additionally proven that this process has been carried out in accordance with the law. The logging includes the storage of the time stamp of the subscription and the confirmation of the subscription as well as the IP address used. Any changes to your data with the provider of the advertising service in question will also be logged.
Login details: to subscribe to the Novinkyletter, simply enter your email address. The optional data is your name, which you can enter to allow us to choose the correct form of address.
The sending of Novinkyletters and the related measurements and statistics are carried out on the basis of the recipient’s consent pursuant to Article 6(1)(a) of the GDPR and Article 7 of the GDPR and Article 7(2)(3) of the Unfair Competitive Practices Act, respectively. If the consent of the recipient is not required, we carry out the sending of Novinkyletters on the basis of our legitimate interests in direct marketing pursuant to Article 6(1)(f) of the GDPR and §4(6) of the GDPR respectively Act No. 22/2004 Coll. on Electronic Commerce where the operator may not deliver commercial communication information by electronic mail unless the recipient of the service has requested it in advance, also according to §3 paragraph 7 of Act No. 147/2001 Coll. on Advertising, advertising may not be disseminated by automatic telephone dialling system, telefax and electronic mail without the prior consent of their user, i.e. without the consent of the recipient of the advertisement, and §62 paragraph 2 of the 351/2011 Coll. on Electronic Communications, where for the purpose of direct marketing it is allowed to call or use electronic mail only with the prior consent of the recipient. The consent granted must be demonstrable and may be revoked at any time. An exception is provided for in Section 62(3) of Act No. 351/2011 Coll., according to which the prior consent of the recipient of the electronic mail is not required if the direct marketing is for the direct marketing of the own similar goods and services of a person whose contact information for the delivery of electronic mail you have obtained in connection with the sale of goods or services.
By subscribing to our Novinkyletters as a potential client without a prior legal relationship with us, you therefore consent to receiving them and to the process described below.
By subscribing to our Novinkyletters as our contractual client, we do not require your consent, as the legal basis is our Legitimate Interest to inform you about products and services that are related to a product or service that you have purchased from us in the past.
The registration process is based on our legitimate interests according to Article 6(1)(f) GDPR (legitimate interest). Our interest is to develop a customer-oriented and secure Novinkyletter system that serves our business interests as well as the needs of our users and allows us to additionally demonstrate the user’s consent.
Cancellation / revocation of Novinkyletters: you have the right to cancel the receipt of our Novinkyletters at any time, i.e. to withdraw your consent. You will find a link to unsubscribe at the end of each Novinkyletter. We have the right to retain stored Email addresses for three years based on our legitimate interest for the purpose of proving you have not given your consent. They will be deleted after this period. The processing of data stored in this way is limited to the defence of our legitimate claims. An individual request for deletion may be made at any time, provided that the applicant provides proof of the former consent.
We process Novinkyletters on the following legal bases:
Hosting and emailing
In this context, our company or our hosting service providers process the identification, contact, content, contractual, user, metadata and communication data of our customers, those interested in our products and services and visitors to our website on the basis of our legitimate interests in the efficient and secure provision of online services pursuant to Article 6(1)(f) GDPR or Article 28 GDPR (conclusion of a contract for the mediation of personal data processing).
If we proceed to use cookies, prior consent of users will be required depending on the purpose of the cookie. There are different types of cookies that an operator may use on its website.
AboveCookies that do not require consent:
- Cookies used solely for the purpose of transmitting communications, such as those that allow the processing of requests from a web server across a group of devices instead of directing them to a single device (load balancing).
- Cookies strictly necessary to provide an online service that the person has explicitly requested, e.g. user input cookies (when you ask users to fill in an online form or when your customers buy products on your website for their shopping baskets) or authentication cookies (to authenticate users when they log in to your website to use online services, e.g. to access a bank account).
Cookies that require consent:
Some cookies require user consent before you can use them to collect data. This means that cookies cannot be set when a website is first opened. A cookie can only be set and the information collected through it used by the operator after the user’s consent has been obtained. These include:
- persistent cookies for social plug-ins (e.g. those used for behavioural advertising, analytics or market research),
- third-party cookies used for behavioural advertising.
We process the following cookies on our website:
Google Tag Manager
Google Tag Manager is a tool that allows us to manage website tags, so that we can link our online services to Google marketing services such as Google Analytics. The Tag Manager itself implements the tags used and therefore does not process any user data. For the processing of personal data within Google services, we refer you to the following source. Usage Guidelines: www.google.com/intl/de/tagmanager/use-policy
On the basis of our legitimate interests, i.e. our interest in the analysis, optimisation and cost-effective operation of our online services within the meaning of Article 6(1)(f) of the GDPR, we use Google Analytics, a web analytics service from Google LLC (Google). Google uses cookies. The information about the use of the online services collected by means of cookies is generally transmitted to a Google server in the USA and stored there. Google is certified under the Privacy shield agreement, thereby guaranteeing compliance with the European privacy principles:
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active)
At our request, Google will process this information for the purpose of evaluating the use of our online services, compiling reports on the activities of these online services and providing other services related to the use of our online services and website. In doing so, pseudonymised user profiles of our users may be created from the processed data. We only use Google Analytics with IP address anonymisation activated. This means that the shortening of users’ IP addresses takes place within the EU member states or within the EEA states. Only in exceptional cases are complete IP addresses transmitted to Google’s servers in the USA and shortened there. IP addresses from the user’s browser are not linked by Google to other data.
Users can prevent the storage of cookies by setting their browser appropriately. In addition, they have the option to prevent Google from analysing and processing the data from the cookies relating to the use of our online services. Simply download and install the following plugin in your browser:
tools.google.com/dlpage/gaoptout
For more information about Google’s data processing and your options for setting your browser and opting out, please see Google’s privacy statement: policies.google.com/technologies/ads
As well as in Google’s ad settings: adssettings.google.com/authenticated
Users’ personal data will be deleted or anonymised after a period of 14 months.
Google Universal Analytics
Within Google Analytics, we use the Universal Analytics feature, which allows us to analyse user behaviour based on the pseudonymised identity of the user. In this way, it is possible to create pseudonymised user profiles using information from different devices (so-called cross device tracking).
Create focus groups using Google Analytics
We use Google Analytics to ensure that only users who have expressed an interest in our online services or who meet certain characteristics (e.g. interest in certain topics or products) are shown ads for our services by Google and its partners. These characteristics are determined using information about the websites visited and are communicated to Google in the context of remarketing or Google Analytics Audiences. With remarketing audiences, we also want to ensure that our company’s advertising matches the potential interests of users. Based on our legitimate interests, i.e. interests in the analysis, optimisation and economic operation of our online services within the meaning of Article 6(1)(f) GDPR, we use the services of the company:
Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (Google).
Google is certified by the Privacy shield agreement, guaranteeing compliance with the privacy principles in force in Europe:
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
We use the online marketing function Google AdWords to place our own advertising within the Google network (e.g. in search results, in videos, on websites, etc.). This is to ensure that our advertising is shown to users who might be interested in it. This allows us to display advertising on and within our online services in a more targeted way, so that it is only relevant to the potential interests of users. For example, if a user is shown advertisements for products that they have expressed interest in on another site, this is known as remarketing. For this purpose, a special Google code is activated when our website and other websites on which the Google advertising network operates are loaded, and so-called remarketing tags (invisible graphics/codes, also known as Web beacons) are incorporated into the content of the page. These are used to store a cookie (thumbnail file) on the device in question. This file stores information about which pages the user has visited, what content they are interested in and what offers they have clicked on. It also contains technical information about the browser and operating system, the referring site, the time of the page visit, as well as other data related to the use of the online service.
Other comparable technologies may be used instead of cookies.
We also receive a so-called conversion cookie. The information collected by cookies enables Google to compile conversion statistics for us. However, we only get an anonymised number of how many users in total clicked on our advertisement and thus jumped to the page marked with the so-called conversion-tracking-tag. However, we don’t get any information that can be used to identify specific users. Within the Google advertising network, user data is processed in a pseudonymised form, i.e. Google does not store and process e.g. names or e-mail addresses of users, but relevant data from cookies within pseudonymous user profiles. This means that, from Google’s perspective, it is not the data of a specific person that is processed and displayed, but that of the owner of the cookie, regardless of who this owner is. This does not apply if the user grants Google the express right to process his or her data without a pseudonymisation process. The information collected about the user is transmitted to Google and stored on its servers in the USA.
For more information about Google’s data processing and your browser settings and opt-out options, please refer to Google’s privacy statement: policies.google.com/technologies/ads, as well as Google’s ad settings: adssettings.google.com/authenticated
Facebook Pixel, Custom Audiences and Facebook Conversionk
As part of our online services and on the basis of and for the purpose of our legitimate interests in analysing, optimising and economically operating our online services, we use the Facebook Pixel function of the social network Facebook operated by the company:
Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA,
or, in the case of the EU:
Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter referred to as Facebook).
Facebook is Privacy Shield certified, which guarantees compliance with the European Privacy Shield Principles.
https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active
The Facebook Pixel allows Facebook to identify visitors to our online services as a target group for displaying advertising (so-called Facebook ads). For this reason, we use the Facebook Pixel feature to ensure that the Facebook ads paid for by us are only shown to Facebook users who have expressed an interest in our online services or who meet certain characteristics based on the pages they visit (e.g. interest in certain topics/products). We provide this information to Facebook in the context of so-called Custom Audiences.
With Facebook Pixels, we also try to ensure that our Facebook ads are relevant to users’ potential interests and do not appear distracting. This feature also allows us to evaluate the usefulness of Facebook advertising for statistical and market-analytical purposes. Thanks to the so-called conversion rate, we are able to determine whether a user clicked on our Facebook ad and went to our company’s website. The processing of data by Facebook is governed by the company’s Data Use Directive. For general information on the display of Facebook advertising, please also refer to the aforementioned directive: www.facebook.com/policy. For more information on the Facebook Pixel function and how it works, please refer to the Help section of the Facebook website:
www.facebook.com/business/help/651294705016616.
You have the right to object to the collection of your data by Facebook Pixel and the processing of your data in the context of the display of ads on Facebook. If you wish to set what types of ads you will be shown on Facebook, please go to the following page set up by Facebook and follow the instructions on how to set up your ad display: www.facebook.com/settings.
The settings are not platform-specific, i.e. they apply whether you’re using a desktop or mobile device. The storage of cookies, which are used for statistical and advertising purposes, can be prevented by deactivating them via the advertising initiative’s social media page: http://optout.networkadvertising.org/
Alternatively, via the US website: http://www.aboutads.info/choices
or the European site: http://www.youronlinechoices.com/uk/your-ad-choices
Online presence in social media
We present our company online on social networks and platforms and in this way we actively communicate with customers, prospects and users and inform them about our services. When using individual social networks and platforms, the terms and conditions and personal data processing policies of the respective operator apply. Unless our privacy statement states otherwise, we process the data of users who interact with our company on social networks and platforms (e.g. contribute to our online presentations or send us messages).
In accordance with Article 17 of the GDPR and Article 18 of the GDPR, we proceed to the deletion of the data processed by us or to the restriction of their processing. Unless otherwise stated in this privacy statement, we proceed to delete the stored data as soon as the reason for which it was stored no longer exists and no statutory provisions on data retention obligations prevent its deletion.
If the data are not deleted because their retention is required for another legitimate reason, their processing will be restricted, i.e. the data will be blocked and their processing for another purpose will not be permitted. This applies, for example, to data whose retention is prescribed by commercial or tax law.
Some examples where the data subject’s right to erasure is limited by a specific provision:
Act No 431/2002 Coll. on Accounting, as amended, defines different retention periods for individual accounting records. The financial statements, statements of selected data from the financial statements and the annual report shall be retained for ten years following the year to which they relate. Furthermore, Act No 395/2002 Coll. on archives and registers and on the amendment of certain acts (hereinafter referred to as the Act on archives and registers), as amended by Act No 515/2003 Coll., must also be complied with. Accounting documents, account books, lists of account books, lists of numerals or other symbols and abbreviations used in accounting, the depreciation schedule, inventories, inventory records and the chart of accounts shall be kept for ten years following the year to which they relate. Compliance with the tax code is also ensured and the documents will be available until the right to levy tax is extinguished. Law 222/2004 on Value Added Tax, as amended, also requires invoices to be kept for 10 years. This obligation does not only apply to new documents after 1 January 2018. The new retention period of ten years also applies to those records relating to the manner and form of keeping the accounts (software, information carriers on CDs, etc.).
The period of custody of the documents necessary for the correct determination of the assessment base and the amount of advance payments of insurance Prémiovýs and Prémiovýs for health insurance and sickness, pension and unemployment insurance may be derived from the right to prescribe or enforce insurance Prémiovýs, which is provided for in the various laws as set out in the following worksheet:
- 10 years following the year to which they relate: miscellaneous accounting documents, account books, depreciation schedule, inventories, inventory records
- 5 years following the year to which they relate: Tax documents
- 10 years following the year to which they relate: Payrolls and other payroll documentation
- 10 years following the year to which they relate: Annual payrolls
- At least 20 years following the year to which they relate: Personal files
Note: Archiving of accounting documents and related documents is not only required by the Accounting Act, but the entity must also comply with Act No.395/2002 Coll. on archives and registers, as amended, when archiving. The archiving of various documents is also regulated by other laws, such as the VAT Act, the Social Insurance Act and the Health Insurance Act. If another piece of legislation provides for longer archiving periods, it is necessary to apply that longer period.
Collection of data from third parties
In special situations of lawful processing of personal data (Section 78(2) and (6) of Act No. 18/2018 Coll. on the Protection of Personal Data)
As the Controller, we may also process personal data without the data subject’s consent if the processing of personal data is necessary for the purposes of informing the public by means of mass communications and if the personal data are processed by the controller whose business purpose so requires; this does not apply if the processing of personal data for such purpose by the controller violates the data subject’s right to protection of his or her personality or right to protection of his or her privacy, or if such processing of personal data without the data subject’s consent is excluded by a special regulation or an international treaty to which the Slovak Republic is bound.
Personal data about the data subject may be obtained from another natural person and processed in the information system only with the prior written consent of the data subject; this shall not apply if, by providing personal data about the data subject to the information system, another natural person protects his or her rights or legally protected interests, communicates facts that justify the application of the data subject’s legal liability.
International transfers of personal data within and outside the EU
Your personal data is processed only in the territory of the Slovak Republic and is not transferred to other countries within or outside the European Union.
Note: Cross-border transfers (not by us) may also involve countries outside the European Union (“EU”) and to countries that do not have laws that provide specific protection for personal data. If we did make transfers of personal data outside the EU, they would be done lawfully and with adequate protection under the GDPR. Transfers would be made under a contract that covers EU requirements for the transfer of personal data outside the EEA, such as standard contractual clauses agreed by the European Commission or granted an adequacy list decision:
https://dataprotection.gov.sk/uoou/sk/content/prenos-do-krajin-zarucujucich-primeranu-uroven-ochrany
In the absence of an adequacy decision, the controller (or processor) shall use at least one of the security measures, which include, for example:
- Explicit consent of the data subject
- A legally binding and enforceable instrument imposed by public authorities.
- Binding corporate rules
- standard contractual clauses on data protection adopted by the Commission in accordance with the GDPR review procedure. Standard contractual clauses on data protection adopted by the supervisory authority and approved by the Commission in accordance with the GDPR review procedure
- An approved code of conduct, together with binding and enforceable obligations on the controller or processor in the third country to apply the relevant safeguards, including as regards the rights of data subjects.
- An approved certification mechanism together with binding and enforceable commitments by the controller or processor in the third country to apply the relevant safeguards, including the rights of data subjects.
Rights and obligations of authorised persons
The operator has also tkz. Authorised persons who have access to and process personal data.
In particular, the entitled person has the right to:
- assignment of access rights to the designated information systems of the personal data controller to the extent necessary for the performance of its tasks; the necessity is directly determined by the functional, occupational or similar position of the authorised person,
- re-education if there has been a substantial change in the person’s job or function and the content of his or her work activities has changed significantly, or if the conditions for processing personal data or the scope of the personal data processed within the job or function have changed significantly,
- exemption from the obligation of confidentiality if this is necessary for the performance of the tasks of courts and law enforcement authorities under a special law or in relation to the Office for Personal Data Protection of the Slovak Republic in the performance of its tasks under the Act; the provisions on the obligation of confidentiality under special regulations shall not be affected thereby,
- carrying out processing operations with personal data on behalf of the controller to the extent necessary for the performance of the authorised person’s work tasks,
- refusal to carry out an instruction to process personal data which is contrary to generally applicable law or good morals
In particular, the authorised person is obliged to:
- maintain confidentiality of the personal data with which he or she comes into contact; he or she may not use it for personal use and may not disclose it to anyone or make it available to anyone without the consent of the controller; the obligation of confidentiality shall continue even after the authorised person ceases to hold office or after his or her employment has terminated,
- take care to process personal data securely,
- not to use personal data for personal use,
- not to work with personal data outside the premises and computing facilities designated and reserved for this purpose,
- be instructed and informed of the rights and obligations, responsibilities for their violation before the first operation with personal data is carried out,
- to obtain only the necessary personal data exclusively for the purpose defined or established by the Law; it is inadmissible for the authorised person to obtain personal data under the pretext of another purpose of processing or another activity,
- before obtaining personal data from the data subject, inform him or her of the name and location of the controller, the purpose of the processing of the personal data, the scope of the processing of the personal data, the envisaged range of third parties for the provision of personal data or recipients for the disclosure of personal data, and third countries where a cross-border transfer of personal data to those countries is envisaged or apparent,
- to carry out the permitted processing operations only with correct, complete and, where necessary, updated personal data in relation to the purpose of the processing,
- only process personal data that is compatible with the purpose for which it is processed,
- process only those personal data with which he or she is authorised to come into contact in the course of his or her employment or function,
- to process personal data in accordance with good morals and to act in a manner that does not contradict the Act, other generally binding legal regulations and the relevant internal regulations of the controller,
- ensure that the personal data in the information system are true, correct and up-to-date; incorrect or incomplete personal data must be corrected or supplemented without undue delay,
- to process personal data only in the premises designated by the controller and to ensure the confidentiality of the processing,
- to act exclusively in accordance with the technical, organisational and personnel measures adopted by the operator in its internal rules,
- contact the controller or the responsible person in case of any uncertainties regarding the processing of personal data,
- destroy personal data that are part of no longer needed working documents (e.g. various working files, working versions of documents in paper form) by disassembling, erasing or physically destroying the tangible media in such a way that the personal data cannot be reproduced from them; this does not apply to personal data that are part of the content of the controller’s registry records,
- protect received documents and files from loss and damage, misuse, theft, unauthorised disclosure, disclosure or other unacceptable forms of processing,
- provide the data protection officer with assistance in the exercise of supervision over the protection of personal data,
- to provide the control authority of the Office for Personal Data Protection of the Slovak Republic with the necessary assistance in the performance of its supervision or control activities,
- inform the Controller or the responsible person of the risk that threatens the protection of personal data and requires measures beyond the scope of the authorised person,
- to comply with all obligations of which the authorised person has been informed,
- other powers and duties of the authorised person are included in the “Instruction to the authorised person”,
- familiarise yourself with the Organisational Directive for the processing of personal data
Rights of data subjects in relation to their processing
We want you to be in control of how your data is used. You have certain rights under the Data Protection Act in relation to the processing of your personal data. You have the right to know:
- What categories of personal data we process
- Why we process your personal data
- Who we share your personal data with
- How long do we keep your personal data or what are the criteria for determining this period
- What rights you have
- Where we get your personal data from (if we didn’t get it from you)
- Where the processing involves automated decision-making (so-called profiling)
- If your personal data has been transferred to a country outside the EEA, how will we ensure the protection of your personal data
Here is a list of these rights and what they mean for you:
The data subject has the right to be informed before obtaining personal data to the following extent:
- the contact details of any responsible person (i.e. there is no obligation to designate);
- processing purposes
- legal basis for processing
- where the processing is based on Article 6(1)(f) of the GDPR, the legitimate interests pursued by the controller or the third party;
- the recipients or categories of recipients of the personal data, if any;
- the period of retention of the personal data or, if this is not possible, the criteria for determining it;
- the existence of the right to require the controller to have access to personal data relating to the data subject and the right to rectification or erasure or restriction of processing or to object to processing, as well as the right to data portability;
- where the processing is based on Article 6(1)(a) or Article 9(2)(a) of the GDPR, the existence of the right to withdraw consent at any time without affecting the lawfulness of processing based on consent given prior to its withdrawal;
- the right to lodge a complaint with the supervisory authority;
- information on whether the provision of personal data is a legal or contractual requirement or a requirement necessary for entering into a contract, whether the data subject is obliged to provide personal data, as well as the possible consequences of not providing such data;
- the existence of possible automated decision-making, including profiling as referred to in Article 22(1) and (4) of the GDPR, and at least in these cases meaningful information about the procedure used as well as the significance and foreseeable consequences of such processing for the data subject.
Data subject’s right of access (Article 15 GDPR)
The data subject shall have the right to obtain confirmation from the controller as to whether personal data relating to him or her are being processed and, if so, to obtain access to those personal data.
Right to rectification (Article 16 GDPR)
The data subject shall have the right to have inaccurate personal data concerning him or her rectified by the controller without undue delay. With regard to the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by providing a supplementary declaration.
Right to erasure (right to be forgotten, Article 17 GDPR)
The data subject shall also have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall erase the personal data without undue delay if one of the following grounds is met:
- the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
- the data subject withdraws the consent on the basis of which the processing is carried out pursuant to Article 6(1)(a) or Article 9(2)(a) and where there is no other legal basis for the processing;
- the data subject objects to processing pursuant to Article 21(1) and there are no overriding legitimate grounds for processing or the data subject objects to processing pursuant to Article 21(2);
- personal data have been unlawfully processed;
- the personal data must be erased in order to comply with a legal obligation under Union law or the law of a Member State to which the controller is subject;
- the personal data were collected in connection with the offer of information society services pursuant to Article 8(1).
Right to restriction of processing (Article 18 GDPR)
The data subject shall have the right to have the controller restrict the processing in respect of one of the following cases:
- the data subject contests the accuracy of the personal data during a period allowing the controller to verify the accuracy of the personal data;
- the processing is unlawful and the data subject objects to the erasure of the personal data and requests instead the restriction of their use;
- the controller no longer needs the personal data for the purposes of the processing, but the data subject needs them to establish, exercise or defend legal claims;
- the data subject has objected to processing pursuant to Article 21(1), pending verification that the legitimate grounds on the part of the controller override those of the data subject.
Notification obligation in relation to rectification or erasure of personal data or restriction of processing (Article 19 GDPR)
The controller shall notify each recipient to whom the personal data have been disclosed of any rectification or erasure of personal data or restriction of processing carried out pursuant to Article 16, Article 17(1) and Article 18, unless this proves impossible or requires disproportionate effort. The controller shall inform the data subject of those recipients if the data subject so requests.
Right to data portability (Article 20 GDPR)
The data subject shall have the right to obtain the personal data concerning him or her which he or she has provided to the controller in a structured, commonly used and machine-readable format and shall have the right to transmit those data to another controller without being prevented by the controller to whom the personal data have been provided if:
- the processing is based on consent pursuant to Article 6(1)(a) or Article 9(2)(a) or on a contract pursuant to Article 6(1)(b), and
- where the processing is carried out by automated means.
When exercising his or her right to data portability pursuant to paragraph 1, the data subject shall have the right to have the personal data transmitted directly from one controller to another controller, insofar as this is technically feasible.
Right to object (Article 21 GDPR)
The data subject shall have the right to object at any time, on grounds relating to his or her particular situation, to processing of personal data concerning him or her which is carried out on the basis of Article 6(1)(e) or (f), including to profiling based on those provisions. If you believe that the processing of your personal data is in breach of the relevant legislation, in particular the Regulation, you can address your complaint to:
Personal Data Protection Authority at https://www.uoou.sk/ or Hraničná 12 820 07 Bratislava 27.
How you can exercise your rights
You can exercise your individual rights with our company through the communication channel you consider most appropriate for you. You will be responded to by the same communication channel or we will agree on another one in the minutes.
We provide all notifications and statements regarding the rights you have exercised free of charge. However, if the request is manifestly unfounded or unreasonable, in particular because it is repetitive, we are entitled to charge a fee to reflect the administrative costs of providing the requested information of €20.
How long before you can expect a reply
We will provide you with a statement and, where appropriate, information on the measures taken as soon as possible and within one month at the latest. We are entitled to extend the time limit by 1 month if necessary and in view of the complexity and number of requests. We will inform you of the extension, including the reason for it.
Notification of a personal data breach to the data subject
As a data controller, we are obliged to notify the data subject of a personal data breach without undue delay if such a personal data breach is likely to result in a high risk to the rights and freedoms of the natural person. The notification must include a clear and plainly worded description of the nature of the personal data breach and the contact details of the responsible person or other point of contact where more information can be obtained, a description of the likely consequences of the personal data breach, and a description of the measures taken or proposed by the controller to remedy the personal data breach, including, where necessary, measures to mitigate its potential adverse effects.
Notification is not required if:
- appropriate technical and organisational protection measures have been taken and applied to the personal data affected by the personal data breach, in particular encryption or other measures rendering the personal data unreadable to persons not authorised to have access to them,
- follow-up measures have been taken to ensure that the high risk of violation of the rights and freedoms of the persons concerned pursuant to paragraph 1 is no longer likely to have consequences,
- would require disproportionate effort; in such a case, it is necessary to take a similar measure to ensure that the data subjects are informed in the same effective manner.
Overview of selected legislation
European framework:
- Charter of Fundamental Rights of the EUROPEAN UNION
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (Obecné nařízení o ochraně osobních údajů, GDPR)
National legislation:
- Constitution of the Slovak Republic (published under No. 460/1992 Coll.)
- Act No. 18/2018 Coll. on Personal Data Protection
If you have any questions or concerns about the processing of your personal data, or if you wish to exercise any of your rights under this Notice, you may contact the Contact Person listed above. You may also contact the following with questions and complaints:
Address of the Control Authority:
Data Protection Authority
Border 12
820 07, Bratislava 27
Slovak Republic
E-mail in general: statny.dozor@pdp.gov.sk
Should there be changes that affect you (e.g. if we wish to process your personal data for purposes other than those set out above), we will inform you before they are put into effect.