Privacy Policy
SANAS, a. s., Hollého 37, Sabinov 083 01, IČO: 36458562
as an operator, provides this data subject notification for the purpose of ensuring fairness and transparency towards the affected persons
about the processing of personal data in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as the “Regulation”) and § 19 of Act No. 18/2018 Coll. on the Protection of Personal Data and on Amendments and Supplements to Certain Acts
under the title
DATA PROTECTION PRINCIPLES
Purpose of processing personal data in the Accounting and Tax Document Register:
Within the scope of activities, personal data is processed in the processing of accounting documents and related agenda.
Scope of data subjects: natural persons – clients, employees List of personal data: name, surname, title, permanent address, temporary address, phone number, email address, date of birth, type and number of identity document, signature, bank account number of the individual Legal basis for processing personal data: Act No. 431/2002 Coll. on Accounting as amended, Act No. 222/2004 Coll. on Value Added Tax as amended, Act No. 40/1964 Coll. Civil Code as amended, Act No. 152/1994 Coll. on the Social Fund and on Amendment of Act No. 286/1992 Coll. on Taxes on Income as amended, Act No. 311/2001 Coll. Labour Code as amended Categories of recipients: social insurance company, health insurance companies, tax office and entities to which a special regulation entrusts the authority to decide on the rights and obligations of natural persons: courts, authorities active in criminal proceedings Transfer of personal data to third countries is not carried out. Deadlines for erasure of personal data:
Accounting documents – 10 years
Automated decision-making including profiling is not carried out.
Due to compliance with the principle of minimization, all personal data provided by you are a necessary legal requirement for the purpose of their processing.
Purpose of processing personal data in the Incoming and Outgoing Mail Registry and Registry Management:
Within the scope of activities, personal data is processed in the registry of incoming and outgoing mail and activities related to registry management.
Scope of data subjects: natural persons – recipients, employees List of personal data: name, surname, title, address, organization name, job title, email address, subject and content of mail Legal basis for processing personal data: Act No. 395/2002 Coll. on Archives and Registries and on Amendments to Certain Acts as amended Categories of recipients: entities to which a special regulation entrusts the authority to decide on the rights and obligations of natural persons: courts, authorities active in criminal proceedings Transfer of personal data to third countries is not carried out. Deadlines for erasure of personal data:
Routine correspondence – 3 years
Automated decision-making including profiling is not carried out.
Due to compliance with the principle of minimization, all personal data provided by you are a necessary legal requirement for the purpose of their processing.
Purpose of processing personal data in the Debt Collection Record:
Within the scope of activities, personal data is processed for the purpose of debt collection.
Scope of data subjects: natural persons – debtors List of personal data: name, surname, title, permanent/temporary residence, ID card number, debt amount Legal basis for processing personal data: Contract, Act No. 40/1964 Coll. Civil Code, Act No. 233/1995 Coll. on Bailiffs and Enforcement Activities (Execution Order) Categories of recipients: Bailiff – Act No. 233/1995 Coll. on Bailiffs and Enforcement Activities (Execution Order) as amended and on Amendment and Supplement of Some Acts as amended, Courts, OČTK – processing is necessary to fulfill the operator’s legal obligation in accordance with Act No. 301/2005 Coll. Criminal Code as amended, Act No. 162/2015 Coll. Administrative Judiciary Code as amended by Act No. 88/2017 Coll., Act No. 125/2016 Coll. on Certain Measures Related to the Adoption of the Civil Procedure Code, the Non-contentious Civil Procedure Code and the Administrative Judiciary Code and on Amendment and Supplement of Some Acts, Competent State Authority – processing is necessary to fulfill the operator’s legal obligation in accordance with the General Data Protection Regulation Transfer of personal data to third countries is not carried out. Deadlines for erasure of personal data:
Arrears, enforcement, demands, reminders, debt takeover – 10 years
Debt assumption as a guarantor – 5 years
Automated decision-making including profiling is not carried out.
Due to compliance with the principle of minimization, all personal data provided by you are a necessary legal requirement for the purpose of their processing.
Purpose of processing personal data in the Job Applicant Record:
Within the scope of activities, personal data is processed in the record of job applicants.
Scope of data subjects: Natural persons – job applicants List of personal data: name, surname, title, permanent residence, temporary residence, date of birth, phone number, education, experience, email address, additional data within the scope of CV, motivation letter, and job application Legal basis for processing personal data: Consent of the data subject Categories of recipients: entities to which a special regulation entrusts the authority to decide on the rights and obligations of natural persons: courts, authorities active in criminal proceedings Transfer of personal data to third countries is not carried out. Deadlines for erasure of personal data:
CVs
for the duration of consent
Automated decision-making including profiling is not carried out.
The data subject has the right to withdraw consent to the processing of personal data concerning them at any time. Withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal; before giving consent, the data subject must be informed of this fact. The data subject may revoke consent in the same manner as consent was given.
Purpose of processing personal data in Marketing:
Within the scope of activities, personal data is processed in the record of members for the purpose of sending marketing offers, newsletters, product information, and updates.
Scope of data subjects: natural persons List of personal data: name, surname, address, email, phone Legal basis for processing personal data: consent of the data subject Transfer of personal data to third countries is not carried out. Deadlines for erasure of personal data:
marketing – 13 months
Automated decision-making including profiling is not carried out.
The affected person has the right to withdraw consent to the processing of personal data concerning them at any time. The withdrawal of consent does not affect the lawfulness of processing personal data based on consent before its withdrawal; before giving consent, the data subject must be informed of this fact. The data subject may revoke consent in the same manner as consent was given.
Purpose of processing personal data in the Visitor Book:
Personal data is processed in the context of activities involving the identification of individuals upon a one-time entry, record of persons’ movement, and protection of property and individuals.
Categories of data subjects: individuals – visitors List of personal data: name, surname, ID number/service ID, time of arrival and departure Legal basis for processing personal data: Article 6(1)(f) of the Regulation Recipients categories: entities to whom a specific regulation entrusts the authority to decide on the rights and obligations of individuals: courts, authorities involved in criminal proceedings Transfer of personal data to third countries is not carried out. Deadlines for erasure of personal data:
Visitor Book – 5 years
Automated decision-making, including profiling, is not performed.
The main legitimate interest is the protection of the operator’s property, financial, and other interests, as well as the protection of the property, life, and health of the data subjects.
Purpose of processing personal data in the Camera Information System:
Personal data is processed for the purpose of maintaining order and security, detecting crime, and protecting health and property within activities.
Categories of data subjects: individuals located in areas monitored by the camera system List of personal data: [missing] Legal basis for processing personal data: Article 6(1)(f) of the Regulation Recipients categories: entities to whom a specific regulation entrusts the authority to decide on the rights and obligations of individuals: courts, authorities involved in criminal proceedings Transfer of personal data to third countries is not carried out. Deadlines for erasure of personal data:
Camera recording – 7 days
Automated decision-making, including profiling, is not performed.
The main legitimate interest is the protection of the operator’s property, financial, and other interests, as well as the protection of the property, life, and health of the data subjects.
Purpose of processing personal data in the Contract Records:
Personal data is processed as necessary to fulfill the contract, where the data subject is a party to the contract, or to take measures prior to entering into a contract based on the request of the data subject.
Categories of data subjects: individuals – contracting parties List of personal data: title, name and surname, address, telephone number, email Legal basis for processing personal data: Section 13(1)(b) of Act No. 18/2018 Coll. on the Protection of Personal Data and on Amendments to Certain Acts Recipients categories: entities to whom a specific regulation entrusts the authority to decide on the rights and obligations of individuals: courts, authorities involved in criminal proceedings Transfer of personal data to third countries is not carried out. Deadlines for erasure of personal data:
Contracts – 10 years
Automated decision-making, including profiling, is not performed.
Due to compliance with the principle of minimization, all personal data provided by you are a necessary contractual requirement to fulfill the purpose of their processing.
Purpose of processing personal data in the Complaint Records:
Personal data is processed in the recording of individuals for the purpose of asserting claims.
Categories of data subjects: individuals – clients List of personal data: name, surname, title, address, telephone, email, and nature of the complaint Legal basis for processing personal data: Act No. 40/1964 Coll. Civil Code as amended, Act No. 250/2007 Coll. on Consumer Protection as amended, and other related generally binding legal regulations Recipients categories: SOI – Act No. 128/2002 Coll. on State Market Supervision in Matters of Consumer Protection and on Amendments to Certain Acts, and entities to whom a specific regulation entrusts the authority to decide on the rights and obligations of individuals: courts, authorities involved in criminal proceedings Transfer of personal data to third countries is not carried out. Deadlines for erasure of personal data:
Complaints – 10 years
Automated decision-making, including profiling, is not performed.
Due to compliance with the principle of minimization, all personal data provided by you are a necessary legal requirement to fulfill the purpose of their processing.
Purpose of processing personal data – Consumer Contest:
Personal data is processed for the purpose of organizing consumer contests.
Categories of data subjects: individuals – customers/clients List of personal data: name, surname, address, date of birth, ID number, email, phone, and prize. Legal basis for processing personal data: Consent of the data subject Recipients categories: entities to whom a specific regulation entrusts the authority to decide on the rights and obligations of individuals: courts, authorities involved in criminal proceedings Transfer of personal data to third countries is not carried out. Deadlines for erasure of personal data:
Personal data of participants
for the duration of the purpose
Automated decision-making, including profiling, is not performed.
The affected person has the right to withdraw consent to the processing of personal data concerning them at any time. The withdrawal of consent does not affect the lawfulness of processing personal data based on consent before its withdrawal; before giving consent, the data subject must be informed of this fact. The data subject may revoke consent in the same manner as consent was given.
Affected individuals, whose personal data are processed for specific defined purposes, may exercise the following rights:
Right to request access to their personal data – Right to rectification of personal data – Right to erasure of personal data – Right to restriction of processing of personal data – Right to object to processing of personal data – Right to data portability – Right to lodge a complaint with the supervisory authority, i.e., the Office for Personal Data Protection of the Slovak Republic
The mentioned rights of the data subject are further specified in Articles 15 to 21 of the Regulation. The data subject exercises these rights in accordance with the Regulation and other relevant legal regulations. The data subject may exercise their rights against the controller through a written request or electronic means. If the data subject requests oral provision of information, the information may be provided provided that the data subject has proven their identity.
SANAS, a. s. has implemented all appropriate personnel, organizational, and technical measures to maximize the protection of your personal data in order to minimize the risk of their misuse. In accordance with our obligation under Article 34 of the Regulation, we notify you as data subjects that if a situation arises where we, as the controller, breach the protection of your personal data in a manner that is likely to pose a high risk to the rights and freedoms of individuals, we will notify you of this fact without undue delay.
Legal regulations and the related methods of processing your personal data may change. If we decide to update these policies, we will place the changes on our website and inform you of these changes. In cases where a significant change to these policies is to occur, or where the law requires us to do so, we will inform you in advance. We ask you to carefully read these policies and regularly check them when communicating with us or using our website.
If you have any questions regarding the processing of your personal data, including the exercise of the above-mentioned rights, you can contact our Data Protection Officer provided by EuroTRADING s.r.o
If you are not satisfied with our response, or if you believe that we are processing your personal data unfairly or unlawfully, you can lodge a complaint with the supervisory authority, which is the Office for Personal Data Protection of the Slovak Republic, located at Hraničná 12, 820 07 Bratislava 27.
You can contact them via:
Telephone: +421 /2/ 3231 3214 Email: statny.dozor@pdp.gov.sk
Their website is: dataprotection.gov.sk.