01Personal data controller
The controller of personal data is DigitalData s.r.o. (hereinafter the “Controller”), which hereby, in accordance with Article 12 GDPR, informs you about the processing of your personal data and about your rights.
When processing personal data, we honour and respect personal data protection standards and adhere to the following principles: we always process personal data for a clearly and comprehensibly defined purpose, by defined means and in a defined manner, and only for as long as strictly necessary. We collect personal data of our clients and employees only to the extent necessary and do not pass it on to third parties, except for those directly involved in the company’s internal processes for the purpose of its necessary processing. Cooperating persons (employees, suppliers, subcontractors) are required to subscribe to the Controller’s personal data processing principles and undergo regular training. As data controller, the company has established the role of Data Protection Officer (DPO), who oversees the proper protection of the personal data of its owners, i.e. the company’s customers. The DPO’s contact details are published in a remotely accessible manner on the Controller’s (company’s) website.
02Scope of personal data processing
Personal data are processed to the extent provided to the Controller by the relevant data subject in connection with the conclusion of a contractual or other legal relationship with the Controller, on the grounds of legitimate interest, or data that the Controller has otherwise collected and processes in accordance with applicable legislation or to fulfil the Controller’s legal obligations.
03Sources of personal data
- directly from data subjects (registration, web contact forms and chat, e-mails, telephone, websites, business cards, etc.)
- publicly accessible registers, lists and records (e.g. the Commercial Register, Trade Register, Land Registry, etc.)
- automated recording of electronic communications under Act No. 127/2005 Coll. and Decree No. 357/2012 Coll.
04Categories of personal data processed
- address and identification data used for the unambiguous identification of the data subject (e.g. first name, surname, title, where applicable birth number, date of birth, permanent address) and data enabling contact with the data subject (contact details – e.g. contact address, telephone number, fax number, e-mail address and other similar information)
- IP addresses, telephone numbers and other traffic and location data resulting from the operation of services, collected and retained due to a legal obligation
- IP addresses and other traffic and location data to the extent necessary to maintain service quality
- descriptive data (e.g. bank details)
- other data necessary for the performance of a contract
- data provided beyond the scope of the relevant laws, processed on the basis of the data subject’s consent (processing of photographs, use of personal data for recruitment procedures, etc.)
05Purpose of personal data processing
- purposes covered by the data subject’s consent
- negotiating a contractual relationship
- performance of a contract
- protection of the rights of the Controller, the recipient or other persons concerned (e.g. recovery of the Controller’s receivables)
- archiving required by law
- recruitment for vacant positions
- fulfilment of the Controller’s legal obligations
06Method of processing and protection of personal data
Personal data are processed by the Controller. Processing takes place at the Controller’s premises, branches and registered office by individual authorised employees of the Controller or by a processor. Processing is carried out using computer technology and, for personal data in paper form, also manually, in compliance with all security principles for the management and processing of personal data. To this end, the Controller has adopted technical and organisational measures to ensure the protection of personal data, in particular measures to prevent unauthorised or accidental access to personal data, their alteration, destruction or loss, unauthorised transfers, unauthorised processing, and any other misuse of personal data.
All entities to which personal data may be made available respect the data subjects’ right to privacy and are obliged to act in accordance with the applicable legislation on personal data protection.
Your data are therefore processed in particular in the following systems:
- Identification, traffic and location data of data subjects using Jablotron intruder alarm systems are processed in the MyJablotron application on the servers of Jablotron Security a.s., K dubu 2328/2a, 149 00 Prague 4.
Traffic and location data include data on the data subject’s contact persons and logs in the individual systems, as well as configuration parameters of the services provided and records of service usage. These are processed in the Controller’s applications and on the Controller’s servers at Jana Masaryka 108/10, 120 00 Prague 2 and at Podskalská 6, 128 00 Prague 2.
07Period of personal data processing
In accordance with the time limits set out in the relevant contracts, in the Controller’s filing and shredding rules or in the relevant legislation, this is the period strictly necessary to secure the rights and obligations arising both from the contractual relationship and from the relevant legislation.
Typically, personal data are processed in full only for the duration of the contractual relationship; after it ends, the data are processed only as required by law.
After the end of the contractual relationship, personal data are retained only for the period strictly necessary on the grounds of the Controller’s legitimate reason or to fulfil legal obligations, but for no longer than 10 years.
These periods apply provided all obligations have been settled (loaned equipment, invoices, devices, etc.); otherwise your data will be retained until mutual settlement. These periods may also be extended, e.g. by legal proceedings, a tax audit, etc.
08Disclosure of personal data to other persons
The Controller will make your personal data available to other persons only to the usual extent and only to processors or other recipients, typically providers of external services, in compliance with all principles arising from the GDPR. Personal data may also be made available, to the extent strictly necessary, to legal, economic and tax advisers. Personal data relating to debtors may also be made available to debt collection agencies for the purpose of recovering receivables. Upon request or in the event of suspected unlawful conduct, personal data may also be provided to public authorities.
09Transfer of personal data abroad
Personal data are processed mainly within the EU and are not deliberately disclosed outside the EU. The exception is data stored in computer systems with servers located outside the EU, usually in the USA. In such cases, the conditions approved by the European Commission for the secure transfer of data between the EU and the USA, the so-called Privacy Shield, must be met.
10Legal basis for processing
The Controller processes data with the consent of the data subject, except in cases stipulated by law where the processing of personal data does not require the data subject’s consent.
In accordance with Article 6(1) GDPR, the Controller may process data without the data subject’s consent where:
- the data subject has given consent for one or more specific purposes,
- processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract,
- processing is necessary for compliance with a legal obligation to which the Controller is subject,
- processing is necessary in order to protect the vital interests of the data subject or of another natural person,
- processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller,
- processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
11Rights of data subjects
Under the GDPR, the data subject has the following rights:
- to request access to the personal data processed by the Controller, i.e. to obtain from the Controller confirmation as to whether or not personal data concerning them are being processed and, where that is the case, access to the personal data and the other information set out in Article 15 GDPR,
- to request rectification or completion of personal data processed by the Controller if they are inaccurate (Article 16 GDPR)
- to request erasure of personal data in the cases set out in Article 17 GDPR,
- to request restriction of processing in the cases set out in Article 18 GDPR,
- to obtain the personal data concerning them that are processed on the basis of their consent, or for the performance of a contract or for steps taken prior to entering into a contract,
- to receive such personal data in a structured, commonly used and machine-readable format and to transmit them to another controller, under the conditions and with the limitations set out in Article 20 GDPR,
- the right to object to processing under Article 21 GDPR
- the right to lodge a complaint with a supervisory authority – the data subject has the right to lodge a complaint about an alleged infringement of the General Regulation with a supervisory authority, in particular in the Member State of their habitual residence or place of work.
We will inform the applicant of the receipt of each request under the points above without delay and will provide the requested information, or information on the measures taken, without undue delay and in any event within 1 month. Where necessary, taking into account the complexity and number of requests, this period may be extended by a further two months. In certain specific cases defined in the GDPR, we are not obliged to comply with a request in whole or in part. This will be the case in particular where a request is manifestly unfounded or excessive, in particular because of its repetitive character. In such cases we may charge a reasonable fee taking into account the administrative costs of providing the requested information, or refuse to act on the request. The applicant will always be informed of this.
Where we have reasonable doubts about the identity of the person requesting information, we may ask them to provide additional information necessary to confirm their identity.
We will keep information on the exercise of data subjects’ rights for a reasonable period (typically 3 years) for the purposes of record-keeping and evidence, for statistical purposes, to improve our services and to protect our rights.
If the data subject believes that their personal data are being handled unlawfully or that we are otherwise infringing their rights, they have the right to lodge a complaint with the supervisory authority.
12Right to object
Where the legal basis for processing personal data is the so-called legitimate interest, the data subject has the right to raise a substantiated objection to such processing at any time. In that case, the personal data will no longer be processed unless there are compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or unless they are processed for the establishment, exercise or defence of legal claims. The person concerned may raise an objection to processing using the contact details below. In your e-mail, please describe the specific situation that leads you to conclude that the Controller should not process your data. Where data are processed for direct marketing purposes, an objection may always be raised without further justification.
13Contact information
For any matters concerning the protection of your personal data, you can contact us at any time at:
DigitalData s.r.o. Jana Masaryka 108/10120 00, Prague 2
E-mail: info@digitaldata.cz
Data box ID: s68wsc6
This statement is publicly available on the Controller’s website.