Privacy policy

1. INTRODUCTION

Pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR), and in accordance with Act No. 110/2019 Coll., on personal data processing, as amended, we hereby publish information on the processing of personal data.

2. DATA CONTROLLER

SEKELA CZ s.r.o., with its registered office at V Zahradách 502/19, Plzeň, postal code 326 00, company registration number 08608903. The controller's contact is: ProSEO Media s.r.o.

The controller operates the following website: www.sekela.cz

3. SCOPE OF PERSONAL DATA PROCESSING

Personal data are processed to the extent necessary for processing and to the extent provided to the controller by the relevant data subject, particularly in connection with the data subject's consent to personal data processing, performance of a contract to which the data subject is a party, compliance with a legal obligation applicable to the controller, protection of the vital interests of the data subject, or performance of tasks carried out in the public interest or in the exercise of official authority vested in the controller. This also includes data otherwise collected by the controller and processed in accordance with applicable legislation or to fulfil the controller's legal obligations. A data subject means only a natural person to whom the personal data relate.

4. PURPOSES AND LEGAL BASIS OF PERSONAL DATA PROCESSING

  • purposes covered by the consent provided by the data subject
  • negotiating a contractual relationship
  • performance of a contract to which the data subject is a party
  • protecting the rights of the controller, the recipient or other persons concerned (for example, collecting the controller's receivables)
  • archiving required by law
  • recruitment for vacant positions
  • fulfilment of the controller's legal obligations
  • protection of the data subject's vital interests
  • keeping records of data provided by the data subject when handling requests, submissions and other correspondence
  • fulfilment of the controller's obligations in connection with personnel and payroll records and accounting

5. SOURCES OF PERSONAL DATA

  • data obtained directly from data subjects
  • publicly accessible registers, lists and records (such as the Commercial Register, Trade Register, Land Register or public telephone directory)

6. CATEGORIES OF PERSONAL DATA PROCESSED

  • address and identification data used to identify the data subject clearly and unambiguously (such as first name, surname, title, personal identification number where applicable, date of birth, permanent address, company registration number and VAT identification number), and data enabling contact with the data subject (contact details such as a contact address, telephone number, fax number, email address and similar information)
  • descriptive data (such as bank account details)
  • other data necessary for the performance of a contract
  • data provided beyond the requirements of the relevant laws and processed within the scope of the data subject's consent (processing photographs, using personal data for personnel procedures, etc.), in all cases only to the extent necessary

7. CATEGORIES OF DATA SUBJECTS

  • persons giving consent
  • applicants
  • contracting parties
  • job applicants
  • the controller's employees
  • other persons in a contractual relationship with the controller

8. CATEGORIES OF RECIPIENTS OF PERSONAL DATA

  • processors
  • software providers
  • external accounting firms
  • external legal advisers
  • judicial, administrative, state and other authorities in connection with compliance with legal obligations under applicable legislation

9. METHODS OF PROCESSING AND PROTECTING PERSONAL DATA

Personal data are processed by the controller. Processing takes place at the controller's registered office and is carried out by individual authorised employees of the controller or, where applicable, by a processor. Data are processed using computer technology and, for personal data in paper form, also manually, in compliance with all security principles for the management and processing of personal data. To this end, the controller has adopted technical and organisational measures to protect personal data, particularly measures preventing unauthorised or accidental access to personal data, their alteration, destruction or loss, unauthorised transfers, unauthorised processing and any other misuse. All entities to which personal data may be disclosed respect data subjects' right to privacy and must act in accordance with applicable personal data protection legislation.

10. PERSONAL DATA RETENTION PERIOD

In accordance with the periods specified in the relevant contracts, the controller's records management and disposal rules, or applicable legislation, data are retained for the period strictly necessary to safeguard the rights and obligations arising from the contractual relationship and from applicable legislation.

11. INFORMATION ON PROCESSING

The controller processes data provided by the data subject or obtained from public registers, both on the basis of the data subject's explicit consent and in cases where lawful processing does not require the data subject's consent. Under Article 6(1) of the GDPR, processing is lawful if:

  • the data subject has given consent for one or more specific purposes;
  • processing is necessary for the performance of a contract to which the data subject is a party or to take steps at the data subject's request before entering into a contract;
  • processing is necessary for compliance with a legal obligation to which the controller is subject;
  • processing is necessary to protect the vital interests of the data subject or another natural person;
  • processing is necessary for the legitimate interests pursued by the controller or a third party, except where those interests are overridden by the interests or fundamental rights and freedoms of the data subject requiring protection of personal data.

12. RIGHTS OF DATA SUBJECTS

Every data subject has the right to:

  • withdraw consent at any time, if they have given consent to the processing of personal data;
  • ask the controller what personal data relating to them are being processed;
  • request an explanation from the controller regarding personal data processing;
  • object to processing;
  • request access to these data and have them updated or corrected;
  • request erasure of personal data;
  • request restriction of personal data processing;
  • have personal data processed by automated means on the basis of consent transferred to another controller in a structured, commonly used and machine-readable format;
  • contact the controller or the Office for Personal Data Protection if they have doubts about compliance with obligations relating to personal data processing;
  • lodge a complaint about the conduct of the controller or a recipient of personal data.

At the data subject's request, the controller must inform the data subject of the right of access to personal data and provide the following information:

  • the purpose of processing;
  • the categories of personal data concerned;
  • the recipients or categories of recipients to whom personal data have been or will be disclosed;
  • the planned period for which personal data will be stored;
  • all available information about the source of personal data if they were not obtained from the data subject, and whether automated decision-making, including profiling, takes place.

Any data subject who discovers or believes that the controller or processor is processing their personal data in a manner contrary to the protection of their private and personal life or contrary to law, particularly if the personal data are inaccurate in view of the purpose of processing, may:

  • ask the controller for an explanation;
  • require the controller to remedy the situation, particularly by blocking, correcting, supplementing or erasing personal data;
  • if the above request is found to be justified, the controller shall remedy the situation without delay;
  • if the controller does not comply with the data subject's request, the data subject has the right to contact the supervisory authority, the Office for Personal Data Protection, directly;
  • the above procedure does not prevent the data subject from submitting their concerns directly to the supervisory authority;
  • the controller has the right to request reasonable reimbursement for providing information, not exceeding the costs necessary to provide it.

13. PUBLICATION

This information on the protection and processing of personal data is publicly available on the controller's website www.sekela.cz.