General Data Protection Regulation
GDPR
GDPR (General Data Protection Regulation) Oder die Allgemeine Datenschutzverordnung. Es handelt sich um eine Verordnung der Europäischen Union, die den bisherigen Datenschutzgesetz regelt und ersetzt.
GDPR
INFORMATION
Operator:
Business name: | TOMARK, s.r.o.
|
Seat: | Strojnícka 5, 080 01 Prešov, SR
|
ID: | 31 712 428
|
VAT number: | 2020520546
|
VAT: | SK2020520546 |
Web: | www.tomark.sk
|
Enrolled: | Commercial Register of the Prešov District Court, Section Sro, File No. 2482 / P
|
Operator contact details:
Name and surname: | Ing. Daniel Tomko
|
Phone: | 051 7480 561
|
Mail: | info@tomark.sk |
Responsible person:
Name and surname: | Ing. Pavol Kleban
|
Phone: | 0907 931 085
|
Mail: | pavol.kleban@gdpr-pass.sk |
1. The processing of personal data of a natural person shall be governed by:
- Act no. 18/2018 Coll. on Personal Data Protection and on Amendments to Certain Acts, hereinafter referred to as „Act 18“
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46 / EC (General Data Protection Regulation), hereinafter “ GDPR Regulation „
2. Responsible person of the DPO:
- the responsible person of the DPO is not designated
3. The operator processes personal data of website visitors:
- when visiting the website:
- cookies
- when sending a complaint via the contact form:
- title, name, surname, tel. number, email address, message text
- when sending the order (www.tomarkearo.com)
- title, name, surname, email address, delivery address
4. Purpose of the processing of personal data:
- processing of the request / initiative sent from the contact form
- website traffic statistics
- sending special and price offers, newsletters
- issuance of a tax document / invoice
- delivery of ordered goods
5. Legal basis for the processing of personal data:
- the provision of personal data is voluntary; § 13, par. (1), letter a) of Act 18
- the provision of personal data is a legal requirement; § 13, par. (1), letter c) of Act 18
- Act no. 431/2002 Coll. on accounting as amended
6. Retention period of personal data:
- other personal data / until revocation of consent
- personal data for tax document / 10 years
7. Legitimate interests of the operator:
- without the legitimate interests of the operator
8. Identification of the recipient of personal data:
- post office, courier
- Tax Office
9. Transfer of personal data to a third country or international organization:
- personal data is not transferred
10. Rights of the person concerned:
- Pursuant to Act 18, the data subject has the right to access personal data (§ 21), the right to correct personal data (§ 22), the right to delete personal data (§ 23), the right to restrict the processing of personal data (§ 24), the right for the portability of personal data (§ 26), the right to object to the processing of personal data (§ 27), the right to file a motion to initiate proceedings (§ 100) and the processing of personal data based on consent to the processing of personal data, has the right to consent to process personal data at any time (§ 14)
11. Existence of automated individual decision making + profiling:
- without the existence of automated individual decision-making, including profiling
12. The Operator declares that the principles and conditions of personal data processing of the Act 18 are observed when processing personal data:
- principle of legality § 6
- principle of purpose limitation § 7
- principle of minimization of personal data § 8
- principle of correctness § 9
- principle of minimizing storage § 10
- principle of integrity and confidentiality § 11
- principle of liability § 12
- conditions for providing consent to the processing of personal data § 14
- conditions for providing consent in connection with information society services § 15
13. The operator complies with the provisions of Act 18:
- obligations in exercising the rights of the person concerned § 29
- general obligations of the operator § 31
- standard and specific protection of personal data § 32
- processing security 39