Processing of personal data and their protection

About DORS studio, spol. s r.o.

The personal information you provide to us is processed by the personal data administrator – DORS studio, spol. s r.o. with its registered office at Karolíny Světlé 137, 280 02 Kolín 1, Company Reg. No. 26507242, VAT ID No. CZ26507242 (hereinafter referred to as the company).

The processing of personal data is a necessary part of our activity. Without providing personal information and without processing it, we would not be able to provide you with our services, enter into a contractual relationship with you and fulfill the obligations arising from it. In the event the processing of personal data requires your consent, we will not enforce the consent in any way or make it conditional upon the threat of refusing to enter into a contractual relationship, providing a service of the sale of goods or the obligations set forth by us.

We treat your personal information within the limits of generally binding legal regulations and we ensure that it is not tampered with or misused. The protection of personal data, privacy and the rights of each individual is one of the fundamental values that our employees respect.

Our employees are fully aware of the value and sensitivity of the personal data they come into contact with and with which they work. They are also fully aware of the damages that the disclosure, destruction, or alteration of such data may cause to any subject, including you.

The company and each employee of the company personally undertakes to protect the confidentiality, accessibility, and integrity of the personal data they come into contact with and work with, as they regard it as a matter of their personal professional integrity, regardless of whether a legal act is binding for them. Our employees will not disclose your personal information, will not unduly distribute, modify or destroy any personal data, except to the extent of the content of the job. In order to avoid unintended disclosure, destruction or alteration of your personal data, our employees are regularly educated and undertake regular training in the area.

Every employee makes every effort to prevent the disclosure, destruction or alteration of your personal information. This means that they adhere to information security safety measures, protect personal data in paper form, are aware of their surroundings, and immediately report any suspicious behavior of computer technology, by their colleagues or third parties.

The company and its staff make every effort to ensure a fair and transparent processing of personal information. To that end, we have processes that we continuously improve so that each data subject has an answer to questions about their personal data and their processing in our company, and to ensure that the rights of data subjects are met, and to this end both the appropriate technologies and the right processes are implemented.

Who to contact in matters of your personal data and your rights

If you have any questions about your personal information or the exercise of your rights, please feel free to contact our staff who are ready to provide you with full information service or assistance in fulfilling your rights.

Tel: +420 321 725 416, e-mail: info@dors.cz

How we process your personal data

The personal data you provide to us and which we process is used to conclude and execute the contract. If you do not agree to provide your data for this purpose, you cannot conclude the contract. For this purpose (fulfillment of the subject matter of the agreement), only your identification data specified in the contract or your contact details will be processed to the necessary extent, as well as information relating to the subject matter of the contract (e.g. data on payments for products and services, including information such as the bank account number and other data necessary for the performance of the contract). We also have the right to process this range of personal information to protect our rights in the event of a dispute with a customer.

On what basis we process your personal data

The above personal information you provide to us is processed on the basis of the following legal basis:

  • Performance or conclusion of the contract
  • Purchase and sale of goods and services, invoicing, mutual communication
  • Fulfilment of legal obligations
  • Obligation under Czech law or EU law - such as the Act on Accounting, the Civil Code, the Act on Insurance, the Act on Commercial Corporations, the Act on the Legalization of Proceeds from Crime (AML)
  • Legitimate interest
  • Property protection (camera system), handing over within our company for administrative purposes, direct marketing.

To whom we provide your personal information

We only share your personal information within our company. Your personal data may be further provided and made available to third parties to the extent necessary. It concerns the following groups of recipients or processors:

  • Our suppliers to provide logistics (delivery of goods and services) - as part of the performance of the contract.
  • Our partners to secure registration, claims, and feedback to improve our products and services provided to our customers - within the legitimate interests of the administrator.
  • Audit companies - in the framework of the performance of legal obligations.
  • IT companies - based on the legitimate interest of the administrator. IT outsourcing services and random access to personal information within IT systems management.
  • State administration bodies - tax offices, health insurance companies, social insurance companies, courts, court executors and the like - on the basis of legal obligations.

Every entity / third party that we pass your personal data onto for the above purpose (unless it is the fulfillment of a legal obligation) is bound by a contract that includes, inter alia, the obligation to protect personal data, the confidentiality obligation and the duty of cooperation to check compliance with GDPR provisions.

Passing on your personal data abroad

We only transfer your personal information within our company and they are not transferred abroad.

How long we keep your personal information

We keep your personal information depending on the purpose for which we obtained it. We process your personal data for at least the duration of the contract, and then we are required to keep your personal data in accordance with the shredding deadlines set by the law.

If you are interested in particular shredding deadlines of your personal data, please do not hesitate to contact us at the above address.

Processing of cookies, IP address monitoring and other means of technological monitoring

We do not use any means to track, analyze, and evaluate cookies, IP addresses, and other electronic tags.

Profiling on the basis of personal data

We do not perform profiling based on the provided personal information.

Your rights

The company is committed to the principles established by European Parliament and Council Regulation 2016/679 on the protection of individuals with regard to the processing of personal data and the free movement of such data (GDPR) and is ready to fully cooperate in exercising your rights.

According to GDPR, your rights are:

  • The right of the PD entity to the deletion of PD (right to be forgotten), (Article 17 GDPR)
  • Your personal data will be erased except for the data necessary to fulfill a legal obligation, data necessary for the defense of legal claims or data necessary for the protection of public interests.
  • The right of the PD entity to be acquainted with the data that the administrator or the processor has on the entity (Article 15 GDPR)
  • You will be provided with a copy of the personal data we hold about you, except for our intellectual property or our business secret, as well as cases where the personal data of others may be transmitted.
  • • The right of the PD entity to object to the processing of personal data (Article 21 GDPR)
  • You can raise an objection at any time, which will be dealt with in a way that will not harm your interests. The objection may be invoked in cases where processing is necessary for the purposes of the legitimate interests of the relevant administrator or third party, or against the processing of personal data for direct marketing or profiling purposes. If you oppose processing for direct marketing purposes, your personal data will no longer be processed for this purpose.
  • The right of the PD entity to limit processing (Article 18 GDPR)
  • On the basis of your objection, to limit the processing of your personal data. The processing of personal data is limited until the resolution of the objection.
  • The right of the PD entity to transfer its personal data from the administrator to a third party (Article 20 GDPR)
  • If you provided us with your personal data on the basis of a contract or consent, your personal data will be exported in a structured, commonly used electronic format so that you can transfer it to a third party.
  • The right of the PD entity to request review by a person in the case of automated decision-making (Article 22 GDPR)
  • If you are in doubt about the accuracy of automated decision-making on the basis of the personal data you provide, we will ensure the implementation of the decision by an authorized role.
  • The right of the PD entity to the updating of personal data so that its outdated version does not cause harm (Article 16 GDPR)
  • We will ensure that your personal data is updated based on your request.

In accordance with Article 21 (4) of the GDPR, our company notifies you in particular that you have the right to object to automated individual decision-making under Article 21 of the GDPR and that under Section 21 para. 2 of the GDPR you have the right at any time to object to the processing of personal data for direct marketing purposes (see above). If you suspect that your personal data is being processed unlawfully, you have the right to file a complaint with the Czech Republic's Personal Data Protection Office.

Organisational and technical measures to protect personal data

Our company ensures the protection of your personal data by a security management system based on the analysis of personal data risks. We assure you that we continually assess the security situation and risks and modify our security plans to avoid compromising your personal data. We also want to make sure that adequate procedures and technologies are implemented to ensure informational, physical, personnel and administrative security, both through organizational and technical means. For understandable reasons, we do not mention these procedures and mechanisms at this point.

 

© 2022 DORS studio, spol. s r.o.

DORS studio