GDPR
Dear clients,
we would like to inform you how we handle the personal information that we process as part of our activities. We declare that we comply with Regulation (EU) 2016/679 of the European Parliament and of the Council, hereinafter referred to as “GDPR”.
WHO WORKS WITH PERSONAL DATA?
Pursuant to Article 4, paragraph 7) of the GDPR, the administrator is a natural or legal person who, alone or together with others, who determines the purposes and means of personal data processing.
TL STROJE s.r.o. located at Důl Libušín 940, 273 06 Libušín, Czech Republic, ID: 17957346. Hereinafter referred to as “Administrator”.
WHAT DATA DO WE PROCESS?
The administrator processes personal data on the basis of the legal titles listed below:
Provision of services and cooperation with clients’ Administrator:
- Name and surname
- Address
- Email address
- Telephone number
- ID number
- Project information
In relation to employees:
- Name and surname
- Address
- Email address
- Telephone number
For marketing purposes:
- Name and surname
- Address
- Email address
- Telephone number
HOW DO WE OBTAIN PERSONAL DATA?
We obtain personal data via a request from the client and by establishing cooperation. We do not specifically search for personal data. In order to meet the terms of the GDPR, personal data is collected on the basis of one of the legal titles listed below:
- the processing of personal data is necessary to fulfil the terms of the contract concluded by the Administrator with the client. This applies to all employees of TL STROJE s.r.o. and all subcontractors.
- the processing is necessary for the fulfilment of the Administrator’s legal obligation. This applies especially to company employees.
- TL STROJE s.r.o. and legal obligations that TL STROJE s.r.o. has towards them.
- These purposes include, but are not limited to, the payroll agenda and internal communication activities.
- processing is always carried out only in necessary cases in a legitimate manner, which is determined by the legal basis of the state.
- processing is based on the express consent of the client or entity. Direct consent is required only in cases that do not concern the aforementioned legal titles.
RECIPIENTS OF PERSONAL DATA
The recipient of personal data is the Administrator’s employees and its subcontractors. These entities have access to a secure server with client data. Subcontractors are contractually bound by confidentiality. The server is protected by encryption and the access address is hidden. Only the Administrator and subcontractors know it. Access itself is password protected. All data is regularly backed up.
All physical materials or other storage devices with personal data are kept in a locked room.
No personal data is passed on to third parties or other organisations.
RIGHTS OF PERSONAL DATA SUBJECTS
Subjects have, in accordance with Chapter III. GDPR these rights:
- in the case of personal data processing based on consent, withdraw such consent at any time,
- to provide information about the processing of your personal data in accordance with Article 13 and Article 14 GDPR,
- for access to processed personal data, correction and addition of such data,
- to the deletion of this data in accordance with Article 17 of the GDPR or restriction of processing,
- to transfer your personal data to another administrator,
- to object to the processing of personal data, including profiling and decision-making based on automated processing,
- contact the supervisory authority in case of conflict with the above or with the principles of personal data processing.
If you are interested in exercising any of the above-mentioned rights, please contact the Administrator in writing at Důl Libušín 940, 273 06 Libušín or at the email address info@tlstroje.cz