INFORMATION ON PERSONAL DATA PROCESSING
TriLAB Group s.r.o.
Dear Sir or Madam,
By this document, we would like to provide you with information about personal data processing in the company TriLAB Group s.r.o. in accordance with art. 12 et seq. of the Regulation of the European Parliament and the Council (EU) 2016/679 of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing directive 95/46/EC (hereinafter, the “GDPR“) and the Act No. 110/2019 Coll., on the processing of personal data; among others, by means of the DeltaControl application.
This information about personal data processing (hereinafter, the “Information“) will be updated as required. The updated version will always be available on our website www.trilab3d.com.
By visiting our website or using our application you confirm that you have become familiar with this information.
LAWFULNESS OF PROCESSING
As a personal data administrator, we are responsible for the compliance of all our processing activities with legal requirements.
Lawful processing of personal data and its protection always go without saying in our company. This is why we would like to assure you that we particularly comply with the following principles:
- lawfulness, accuracy, transparency – we process personal data accurately, in a lawful and transparent manner;
- purpose restriction – we process personal data for specific, expressly formulated and legitimate purposes and do not process it in a way that is not compatible with these purposes;
- minimisation of data – we only process relevant personal data within a scope necessary in relation to the purpose for which it is processed;
- accuracy – we process accurate and current personal data; we take all reasonable measures to immediately erase or correct personal data that is inaccurate with regard to the purpose of the processing;
- storage restriction – we process personal data for a period not longer than necessary for the purpose for which it is processed;
- integrity and confidentiality – we process personal data in a way that will ensure its due securing, including protection using suitable technical or organizational measures, against illegitimate or illegal processing and against accidental loss, destruction or damage.
IDENTIFICATION AND CONTACT DATA
TriLAB Group s.r.o., ID 05288746, with registered office at Purkyňova 649/127, Medlánky, 612 00 Brno, a company entered in the Commercial Register maintained by the Regional Court in Brno, Section C, Insert 94527.
Any questions regarding the protection of personal data in our company can be addressed to these contacts: telephone: +420 732 565 456, e-mail: info@trilab.cz.
We have not designated a personal data protection officer, as we are not an obliged subject pursuant to Art. 37 GDPR.
SUBMISSION OF PERSONAL DATA TO THIRD COUNTRIES
We do not submit personal data to third countries nor to international organizations within the meaning of Art. 44 et seq. GDPR.
SUPERVISION AUTHORITY
The supervision authority is the independent public government authority competent for personal data protection in the given country. The supervision authority for the registered office of TriLAB Group s.r.o. is the Office for Personal Data Protection with registered office at Pplk. Sochora 27, 170 00 Prague 7, e-mail: posta@uoou.cz, tel.: +420 234 665 125.
PERSONAL DATA WE PROCESS ABOUT YOU AND THE PURPOSE OF PROCESSING
As our client, you have the opportunity to choose which information you want to share with us. We process personal data within a scope necessary to fulfil the purposes mentioned below:
Purpose of processing (legal basis for processing) | Personal data processed |
For the purposes of performing a contract, if concluded between us, and creating a user account within the DeltaControl application, we process the following personal data: | name, surname, ID/VAT in the case of a natural entrepreneur, address of residence/place of business, e-mail, telephone |
For the purposes of performing legal obligations, especially keeping accounts and issuing and registering invoices, we process the following personal data: | name, surname, ID/VAT, address of residence/place of business |
For the purpose of a legitimate interest we process the following personal data: | for the purpose of sending commercial communications: e-mail, telephone
In addition, we process data obtained from the visitors of our website, especially for the purpose of analysing web traffic and ensuring security: IP address or other online identifiers. |
If we intend to process other kinds of personal data than those set out above, we can only do so on the basis of a written consent to personal data processing granted in a valid manner. You will grant us your consent to personal data processing in a separate document.
If you are below 15 years of age and want to provide us with your personal data in order for us to process it for some purpose, please ask your legal representative to give their consent before providing it. Without such an approval, you are not authorized to provide your personal data to us.
We do not process any personal data which can be included in a special category (the so-called sensitive data) within the meaning of Art. 9 GDPR. Simultaneously, we do not process personal data related to verdicts in criminal matters and criminal acts within the meaning of Art. 10 GDPR.
DATA PROCESSING PERIOD
We process personal data throughout the duration of the contractual relationship and subsequently for a maximum of 5 years after the termination of the contractual relationship.
The personal data processed to perform obligations arising from special legislation is processed for a period of time stipulated by this legislation.
In the case of a need to use personal data to protect our legitimate interests, this personal data is processed for a period necessary to assert these rights.
If personal data is processed on the basis of a consent, we perform the processing only for the period for which the consent is granted.
RECIPIENTS OF PERSONAL DATA
We submit personal data processed for the purpose of performing obligations arising from special legislation to public administration bodies or other competent authorities only when obliged to do so by the law.
We use the following processors of personal data:
Area of cooperation | Processor identification |
CRM system | RAYNET s.r.o., ID: 26843820, with registered office at Francouzská 6167/5, Poruba, 708 00 Ostrava |
Service GSuite and GDrive | Google Ireland Limited, registration number: 368047, with registered office at Gordon House, Barrow Street, Dublin 4, Ireland |
Service asana.com (planning of work, tasks, goals, projects, etc.) | Asana, Inc., with registered office at 1550 Bryant Street, Suite 200, San Francisco, CA 94103
(the company with seat in the United States of America, which undertook to comply with the principles of the “Privacy Shield“ programme, ensuring an adequate level of personal data protection, on the basis of the Decision of the Commission 2016/1250 of 12 July 2016 pursuant to the directive of the European Parliament and Council 95/46/EC on the adequate level of protection provided by the EU-USA privacy protection shield) |
Personal data processing can be performed for by processors exclusively on the basis of a personal data protection contract, i.e. with guarantees of organizational and technical securing of this data and the definition of the purpose of processing, with processors not allowed to use the data for other purposes.
AUTOMATED INDIVIDUAL DECISION-MAKING AND PROFILING
The processing of personal data does not involve automated decision-making; not even on the basis of profiling.
Automated individual decision-making incl. profiling generally means any form of decision based on automated processing of personal data, i.e. without human intervention, which consists, among others, in the evaluation of some aspects related to the subject of the data, especially for the purpose of the analysis, estimation or prediction of aspects related to a person´s work performance, personal preferences, economic situation, health condition, interests, behaviour, reliability, place of stay or movement.
LEGITIMATE INTERESTS
We process personal data among others for the purpose of our internal and legitimate needs. In relation thereto, we inform you that such processing takes place especially for the purposes of:
- the protection of our rights and legally protected interests, authorized recipients or other competent persons, e.g. for debt collection;
- direct electronic marketing – sending commercial communications;
- security, analysis of website traffic.
YOUR RIGHTS IN RELATION TO PERSONAL DATA PROTECTION
In relation to personal data protection, you have the following rights. If you wish to assert any of these rights, please contact us via contact e-mail.
In some instances, the exercise of these rights is subject to certain exceptions; therefore, it may not be possible to assert them in all situations.
If your request is considered justified, we will take the required measures without undue delay, within a month at the latest. In substantiated cases, we can extend the deadline by another two months.
- The right to access personal data (Art. 15 GDPR): You have the right to obtain a confirmation from TriLAB Group s.r.o. on whether or not your personal data is processed. If your personal data is processed by TriLAB Group s.r.o., you have the right to gain access to this personal data and the information stated in Art. 15 GDPR. Simultaneously, you have the right to obtain a copy of the personal data processed. For more copies, TriLAB Group s.r.o. can charge you a reasonable fee considering administrative costs.
- The right to personal data correction (Art. 16 GDPR): You have the right to TriLAB Group s.r.o. correcting your inaccurate personal data or supplementing incomplete personal data without undue delay.
- The right to personal data erasure (Art. 17 GDPR): You have the right to TriLAB Group s.r.o. erasing your personal data without undue delay in instances laid down by Art. 17 GDPR. The right to erasure will not be applied if the processing is necessary for the compliance with legal obligations, for the determination, exercise or defence of legal claims and in other instances laid down in the GDPR.
- The right to processing restriction (Art 18 GDPR): You have the right to TriLAB Group s.r.o. restricting processing in any of the following instances: a) you dispute the accuracy of personal data, for a period necessary for TriLAB Group s.r.o. to be able to verify the accuracy of the personal data; b) the processing is illegal and you reject the erasure of personal data, asking instead for the restriction of its use; c) TriLAB Group s.r.o. no longer needs the personal data for the purposes of processing but you require it to determine, exercise or defend legal claims; d) you have raised an objection against the processing until it is verified whether the legitimate reasons of TriLAB Group s.r.o. prevail over your legitimate reasons.
- The right to information regarding the correction or erasure of personal data or processing restriction (Art 19 GDPR): TriLAB Group s.r.o. is obliged to notify individual recipients to whom personal data was disclosed of any personal data corrections or erasures or processing restrictions, with the exception of cases when this proves impossible or requires unreasonable effort. If you request so, TriLAB Group s.r.o. will inform you about these recipients.
- The right to data transferability (Art. 20 GDPR): If technically possible, you have the right to obtain all your personal data and submit it to another administrator.
- The right to be informed in the event of a personal data breach (Art. 33 GDPR): If a certain case of personal data security breach is likely to result in a high risk for your rights and liberties, TriLAB Group s.r.o. will announce this breach to you without undue delay.
- The right to lodge a complaint with a supervision authority: If you believe that TriLAB Group s.r.o. does not process your personal data in a lawful manner, you have the right to lodge a complaint with the supervision authority whose contact details are provided above.
We will be very happy if you approach us first. We will do our best to correct the faulty situation and process your personal data in a lawful manner.
- The right to revoke consent to personal data processing: If TriLAB Group s.r.o. processes any of the personal data on the basis of a consent, you have the right to revoke your consent to personal data processing in writing at any time, by sending your objection to personal data processing to the contact e-mail address. The revocation of consent shall be without prejudice to personal data processing in instances where a consent is not required.
More information about your rights can be found on the website of the Office for Personal Data Protection: https://www.uoou.cz/6-prava-subjektu-udaj/d-27276.
CONFIDENTIALITY
We would like to assure you that both the personal data processors we cooperate with and our employees are required to maintain confidentiality on the personal data and the security measures whose disclosure would threaten the security of your personal data.
SENDING COMMERCIAL COMMUNICATIONS, DIRECT MARKETING INFORMATION
When sending commercial communications, we proceed in accordance with the Act. No. 480/2004 Coll., on certain information society services as amended. The sending of commercial communications can be cancelled using an unsubscribe link in each e-mail sent.
The right to raise an objection against processing (Art. 21 para 1 GDPR): You have the right to raise an objection at any time regarding the processing of your personal data that TriLAB Group s.r.o. processes for the reasons of its legitimate interests. In such an instance, TriLAB Group s.r.o. will no longer process personal data unless it demonstrates serious legitimate reasons for processing that prevail over your interests or rights and liberties or for the determination, exercise or defence of legal claims.
The right to raise an objection to processing for direct marketing purposes (Art. 21 para 2 GDPR): If TriLAB Group s.r.o. processes your data for direct marketing purposes, you have the right to raise an objection to such processing. In such an instance, TriLAB Group s.r.o. will not further process your personal data.