PRINCIPLES OF PERSONAL DATA PROTECTION

I. Who is this document for?

This document regulates the principles of data protection in the company digitWin s.r.o., Nedbalova 12, Bratislava 811 01, IČO: 47 076 950, registered in the Commercial Register of the District Court Bratislava, Dept. Ltd., vl. No .: 88474 / B (hereinafter referred to as "digitWin") and in particular the rules for the collection, gthering, storage, use, dissemination, storage and security of personal data.

The document is intended for all natural persons whose personal data are processed by the controller:

  • Operator clients
  • Operator suppliers
  • Users of www.digitwin-ce.com and LinkedIn.

Questions, comments and requests for this document and the information contained therein are received by digitWin by email: gdpr@digitwin-ce.com

II. What basic terms does the document use?

Personal information is any personally identifiable information that directly or indirectly identifies an individual. Personal data is, for example, title, name, surname, job position, email, telephone number, signature. A personal data is any data that is specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Personal data processing is any operation, activity, or set of operations involving personal data or personal data files. The processing of personal data is considered to be, for example, the acquisition, recording, organization, storage, processing or alteration, retrieval, browsing, use, transmission, dissemination or otherwise, regrouping or combining, restriction, erasure or disposal. Processing is any such operation of personal data, regardless of the means by which it is performed.

A controller is an entity that processes personal data and determines the purposes and means of their processing. digitWin is a provider of personal data.

Broker is a person who processes personal data on behalf of the controller, on his behalf. Some digitWin suppliers are intermediaries who process the personal data of data subjects on its behalf, e.g. bookkeeping, providing programming, training and consulting services.

The data subject is the natural person to whom the personal data relates, resp. whose personal data are processed. The persons concerned are e.g. the operator's clients and suppliers.

A information system is any organized set of personal data processed according to certain criteria for a defined purpose, e.g. website, contracts with suppliers, contracts with clients, etc.

Profiling is any form of automated processing of personal data which consists in the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular the analysis or anticipation of aspects of the data subject related to work performance, assets, health , personal preferences, interests, reliability, behavior, position or movement. E.g. it may be a verification of the client's creditworthiness for the purposes of providing a mortgage loan. Automated decision making, including profiling, is not performed by digitWin .

Cookies are small text files that are stored on your browser or mobile device while you browse the web. digitWin uses functional and analytical cookies : Functional cookies are necessary for the operation of the website www.digitwin-ce.com and their possible ban can significantly complicate or completely prevent browsing the website , therefore, the person concerned is not required to consent to their storage and access. This type of cookie optimizes the user experience and stores information such as browser type, language, font size and other display settings, even after leaving the website. Analytics cookies are used to analyze website traffic. They also help to understand the interests of website visitors and their behavior on the web. DigitWin uses analytical cookies only with the consent of the website visitor.

GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46 / EC. ES (General Data Protection Regulation) .

Privacy Act is Act no. 18/2018 Coll. on the protection of personal data and on the amendment of certain laws as amended.

III. What personal data, for what purpose and for how long is it processed?

digitWin processes personal data of clients, suppliers and users of the website www.digitwin-ce.com. Detailed information on the scope of the personal data processed, the purposes as well as the retention periods are available at Processing Activity Logs .

IV. How, when and from whom does digitWin obtain personal data?

digitWin collects personal data directly from the persons concerned:

  • in concluding and performing the contract;
  • pri vystavovaní účtovných dokladov;
  • by filling out the forms on the website www.digitwin-ce.com;
  • by direct electronic or telephone communication;
  • by visiting www.digitwin-ce.com or LinkedIn;
  • in fulfilling the legal obligations of the operator (public procurement, GDPR agenda).

V. What rights do the persons concerned have?

digitWin emphasizes respect for the rights of the persons concerned. The persons concerned have the following rights:

Right to information

Every data subject has the right to information about the processing of his or her personal data. To this end, appropriate measures shall be taken to ensure that this information is properly provided to the persons concerned. digitWin fulfills its information obligation through this document, which will be permanently published on www.digitwin-ce.com.

Right of withdrawal of consent

If the data subject has given his consent to the processing of his personal data, he may withdraw it at any time. Withdrawal of consent shall not affect the lawfulness of the processing resulting from the consent prior to its withdrawal. Consent may be given by the website visitor for analytical cookies, all other processing activities are performed on a different legal basis, such as a contract, law or legitimate interest.

Right of access to data

digitWin will, at the request of the data subject, issue a confirmation of the processing of his or her personal data, as well as all information required by the applicable legislation.

Right of correction

The data subject has the right to process correct and up-to-date data. digitWin updates the data at the request of the data subject, or after verifying this data as part of communication with the data subject.

Right of deletion

The data subject may, under certain conditions, request the deletion of personal data. digitWin complies with this request or informs the data subject why he cannot delete the data.

Right to restrict processing

The data subject may, under certain conditions, request a restriction on the processing of personal data. digitWin complies with this request or informs the data subject why he cannot restrict the processing of his data.

Right to data portability

The rights to transfer personal data to another digitWin operator shall be exercised exclusively at the request of the data subject.

The right to object

The data subject has the right to object to the processing of his or her data in certain circumstances.

The right to lodge a complaint or a complaint with the Office for Personal Data Protection

The data subject may at any time file a complaint or a complaint regarding the processing of personal data with the supervisory authority, namely the Office for Personal Data Protection of the Slovak Republic, with its registered office at Hraničná 12, 820 07 Bratislava 27, Slovak Republic, ID number: 36 064 220, tel. no .: +421/2/3231 3220, website https://dataprotection.gov.sk/uoou/

VI. How can data subjects exercise their rights at digitWin?

The person concerned may exercise his rights in writing :

  • by mail to the operator's address: digitWin, s.r.o., Nedbalova 12, Bratislava 811 01 or
  • by email to gdpr@digitwin-ce.com.

The application for the rights of the persons concerned is available TU.

digitWin registers each request and processes it without undue delay according to the client's instructions, but no later than within one month . Within that period, it shall inform the person concerned who made the request of the action taken on his request. That period may be extended by a further two months, if necessary, taking into account the complexity of the application and the number of applications. The operator shall inform the person concerned of the extension within one month of the submission of the application, together with the reasons for the delay.

The notification of the manner in which the request is processed shall be given in the same way as the request was made, unless the person concerned requests otherwise.

digitWin handles the requests of the persons concerned free of charge . However, if the data subject's request is manifestly unfounded or repeated, digitWin may request that the person concerned:

  • a reasonable fee taking into account administrative costs;
  • refuse to act.

VII. Who can access personal data?

Providers may have access to personal data processed by digitWin operators without its consent:

  • bookkeeping;
  • programming, consulting, presentation and training services;
  • website hosting;
  • public authorities;
  • law enforcement authorities.

VIII. How is personal information protected at digitWin?

digitWin consistently ensures the protection of personal data. To this end, it has taken appropriate technical, organizational and security measures taking into account the risk involved, the nature of the processing, the latest knowledge and the costs of taking such measures.

digitWin protects personal data by appropriate and available means against misuse. In particular, it stores personal data in premises, places, environments or in a system to which access is limited, predetermined and controlled at all times.

digitWin evaluates the procedures for handling and processing personal data once a year. There is a rather brief record of the evaluation, the so-called evaluation report. If certain procedures are found to be outdated, unnecessary or have not proved successful, it shall take immediate action.

digitWin immediately handles any personal data security incident. If the incident is likely to result in a high risk to the rights and freedoms of natural persons, it shall always inform the person concerned and inform him of the remedial action he has taken. About each incident is rather a record. DigitWin informs the Office for Personal Data Protection about every serious incident.

IX. Document timeliness

This document is up to date on 01.05.2021.

The document is owned by digitWin and it checks its validity and timeliness at least once a year.