1. Data controller and purpose of these processing terms
The controller of personal data is K2 invest s.r.o., Company ID (IČO): 26008921, with its registered office at Na úlehli 758/10, Michle (Praha 4), 141 00 Praha, registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, File 412199, e-mail info@k2holding.cz (hereinafter also the „Controller“).
The purpose of this document is to fulfil the Controller's information obligation arising from Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the General Data Protection Regulation; hereinafter the „GDPR“), towards visitors to its website, subscribers to commercial communications (newsletters) and customers who are natural persons (hereinafter the „Data Subjects“ or individually a „Data Subject“).
These terms are available on the website https://www.awam.cz/.
2. Purposes and legal basis for processing personal data
The Controller processes the personal data of Data Subjects for the following purposes:
- compliance with statutory tax obligations (compliance with a legal obligation);
- compliance with obligations under Act No. 326/1999 Coll., on the Residence of Foreign Nationals in the Czech Republic (compliance with a legal obligation);
- compliance with obligations under Act No. 565/1990 Coll., on Local Fees (compliance with a legal obligation);
- conclusion and performance of a contract for the supply of goods or services (performance of a contract);
- recovery of receivables from Data Subjects or handling other customer disputes, in particular complaints about services (legitimate interest);
- securing evidence in case the Controller needs to defend its rights (legitimate interest);
- sending commercial (marketing) communications (legitimate interest in the case of Data Subjects to whom the Controller has previously supplied goods or services; consent in the case of Data Subjects to whom the Controller has not previously supplied any goods or services);
- recognising existing users of the Controller's website, tailoring services to user preferences, carrying out analyses and measurements to determine how the Controller's services are used, analysing user preferences and displaying content that matches the individual user's needs, etc. (consent, legitimate interest).
Providing the personal data necessary for the performance of the contract and for compliance with the Controller's legal obligations is necessary. Without the provision of personal data for these purposes, the Controller would not be able to supply the goods or services under the contract. The Controller does not need consent to process personal data for these purposes. Consent is required only for the requested sending of commercial (marketing) communications to Data Subjects to whom the Controller has not previously supplied any goods or services, and for the purposes of using cookies.
The legal basis for processing the personal data of Data Subjects is compliance with legal obligations, performance of a contract, the legitimate interest of the Controller, and the consent of the Data Subject.
3. Categories of personal data processed
The Controller processes the personal data of Data Subjects to the following extent:
- Address and identification data: in particular first name and surname, number and validity period of a travel document or identity card, date of birth, nationality, permanent address or place of residence;
- Contact data: e-mail address, telephone number, residential address;
- Descriptive data: bank details, payment card number;
- Order data: in particular data on the services the Data Subject orders from the Controller, payments including the payment account number and payment card number, and data on complaints;
- Data on the Data Subject's behaviour on the Controller's website: in particular the goods and services the Data Subject views, the links they click, how they navigate the website, scrolling, and also data on the device from which the Data Subject views the website, such as IP address and the location derived from it, device identification, its technical parameters such as operating system and its version, screen resolution, browser used and its version, as well as data obtained from cookies and similar device identification technologies.
4. Categories of recipients of personal data
In fulfilling its commitments and obligations under contracts, the Controller uses the professional and specialised services of other entities. Where these suppliers process personal data passed on by the Controller, they have the status of personal data processors and process personal data solely within the scope of the Controller's instructions and may not use it otherwise. This concerns in particular debt recovery, lawyers, auditors, IT system administrators, internet advertising or commercial representation. The Controller carefully selects each such entity and concludes a personal data processing agreement with it, in which the processor is bound by strict obligations to protect and secure personal data.
The processors are companies established both in the Czech Republic and in a member state of the European Union or in so-called safe third countries. Any transfer and processing of personal data in countries outside the European Union always takes place in accordance with applicable legislation.
Based on the consent of Data Subjects, the Controller passes personal data on to cookie operators, as described in Article 7 of these terms.
The Controller also passes personal data on to administrative authorities or other public administration bodies as required by applicable legislation, as part of fulfilling its statutory obligations.
5. Transfer of personal data to third countries
As part of the transfer of personal data to the Controller's processors or to cookie operators, personal data may also be transferred to third countries outside the European Economic Area, which nevertheless ensure an adequate level of personal data protection.
6. Period of personal data processing
The personal data of Data Subjects is processed for the duration of the contract concluded with the Controller and for a period of 4 years from the date the contractual relationship ends. Where processing is based on compliance with legal obligations, it lasts for the period laid down in the relevant legislation; where processing is based on legitimate interest, it lasts for the period strictly necessary to protect the Controller's legitimate interest, or until the Data Subject objects to further processing. Where consent has been granted, personal data is processed for 5 years from the date consent to the processing of personal data was granted, or until such consent is withdrawn.
7. Cookies
The Controller informs Data Subjects that when they visit its website, small files known as cookies will be stored on and subsequently read from their device. Cookies are small data files that allow the websites visited to remember the actions and settings individual users have made on them, so that this information does not have to be entered repeatedly. Cookies are stored on individual computers or other electronic devices via the web browser. Cookies make it possible, for example, to recognise a user as an existing user (e.g. when logging into their e-mail account, etc.) or to tailor a given service to user preferences (e.g. a weather forecast).
Another group consists of third-party cookies (e.g. Google Analytics, through which the Controller monitors where the user came from, which browser they use, how long they spend on the site, which pages they view, etc.). These cookies are controlled by third parties and the Controller has no access to read or write this data.
Every Data Subject has the option to refuse the use of cookies. It may happen, however, that in some cases it will not be possible to display a particular service or product of the Controller without the use of cookies.
If the internet browser used by the Data Subject has cookies enabled, the Controller will assume that the Data Subject consents to the use of standard cookies by the Controller's website. If the Data Subject does not wish to store cookies, their use can be blocked.
8. Rights of data subjects
As a result of the processing of their personal data, every Data Subject has the following rights:
- The right to request access to their personal data from the Controller.
- The right to rectification of inaccurate personal data processed about them by the Controller.
-
The right to restriction of processing. Restriction of processing means that the Controller must mark the personal data whose processing has been restricted and, for the duration of the restriction, must not process it further, except for storing it. A Data Subject has the right to restriction of processing if:
- they contest the accuracy of the personal data, for a period enabling the Controller to verify the accuracy of the personal data;
- the processing is unlawful and the Data Subject opposes the erasure of the personal data and requests the restriction of its use instead;
- the Controller no longer needs the personal data for the purposes of the processing, but the Data Subject requires it for the establishment, exercise or defence of legal claims;
- they have objected to the processing, pending verification of whether the Controller's legitimate grounds for processing override the interests, rights and freedoms of the Data Subject.
- The right to erasure of personal data. This applies only to personal data processed by the Controller for purposes other than compliance with its legal obligations. The right to erasure applies exclusively where the personal data processed is no longer necessary for the given purpose, the processing is based on consent and that consent has been withdrawn by the Data Subject, the Data Subject objects and there are no overriding legitimate grounds for further processing, the personal data has been processed unlawfully, erasure is required of the Controller by legislation, or where the personal data was collected in relation to the offer of information society services under Article 8(1) of the GDPR.
- The right to data portability. The Data Subject may request that the Controller provide them with their personal data for the purpose of transferring it to another data controller, or that the Controller transfer it to another controller itself. The Data Subject has this right only in respect of personal data processed by the Controller by automated means on the basis of consent or a contract.
- The right to lodge a complaint with a supervisory authority, in the event that the Data Subject believes that the processing of personal data breaches personal data protection legislation. The Data Subject may lodge a complaint with the supervisory authority in the place of their habitual residence, place of work or the place where the alleged breach occurred. In the Czech Republic, the supervisory authority is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), with its registered office at Pplk. Sochora 27, 170 00 Praha 7, website www.uoou.cz.
- The right to object to processing where the Controller processes the Data Subject's personal data for the purposes of its own legitimate interests or those of another party. The Data Subject may raise an objection at the address of the Controller's registered office or at its e-mail address given in Article 1. If the Data Subject raises such an objection, the Controller is entitled to continue such processing only if it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the Data Subject, and further where the processing is necessary for the establishment, exercise or defence of legal claims.
- The right to object to direct marketing. Where the Controller processes the Data Subject's personal data for direct marketing purposes, the Data Subject has the right to object at any time to the processing of personal data concerning them for such marketing, which includes profiling. If the Data Subject objects, personal data will no longer be processed for these purposes.
9. Method of processing and protection of personal data
The processing of the personal data of Data Subjects is carried out mainly at the Controller's place of business and registered office, by individual authorised employees of the Controller, or by processors. Processing takes place by means of electronic devices, or manually in the case of personal data in paper form.
In order to secure the protection of the personal data processed and to ensure that processing is carried out in accordance with the GDPR, the Controller has implemented appropriate organisational and technical measures in accordance with Articles 24 and 25 of the GDPR.
Controller: K2 invest s.r.o., Company ID (IČO) 26008921 · Na úlehli 758/10, 141 00 Praha 4 ·
info@k2holding.cz