THE PROTECTION OF NATURAL PERSONS RIGHTS WITH REGARD TO THE PROCESSING OF PERSONAL DATA
INTRODUCTION
Why is this privacy notice made? During its operation, the Data Controller handles personal data for several purposes, while respecting the rights of the data subjects and fulfilling legal obligations. The Data Controller also considers it important to present to the data subject the handling and the most important characteristics of the personal data that came to the controller’s knowledge during the data processing activities.
What is the legal basis of processing the data subjects’ personal data? Personal data is only processed for a specific purpose and on an appropriate legal basis. These purposes and legal bases are presented individually, in relation to specific data processing.
What external assistance is used to process your personal data? Personal data is mostly processed by the Data Controller at own premises. However, there are operations for which a data processor’s external help is necessary. The data processor may change according to the characteristics of each data processing.
Who is processing your personal data? The data subject may receive information about the data processors employed by the Data Controller and their contact details in section II of this privacy notice.
SECTION I.
NAME OF THE DATA CONTROLLER
The issuer of this privacy notice and the Data Controller:
COMPANY NAME: TutiTours s. r. o. REGISTERED SEAT: Senný trh 3116/7, 945 01 Komárno, Slovakia COMPANY REGISTRATION NUMBER (IČO): 53242122 TAX NUMBER (DIČ): 2121324788 EU VAT NUMBER (IČ DPH): SK2121324788 (Registered under §7a from 8.10.2020)
WEBSITE:
SECTION II.
NAME OF THE DATA PROCESSORS
Data Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller; (Regulation 2016/679 Article 4 8.) To use a data processor, prior consent from the data subject is not required, but he or she must be notified. Accordingly, the following information is provided:
Hosting Provider: COMPANY NAME: Tárhely.Eu Kft. REGISTERED SEAT: 1144 Budapest, Ormánság street 4. X. floor 241. CONTACT:
Website development: IT and marketing service provider company.
Data processor performing invoicing and payroll tasks: COMPANY NAME: Shark kzm s.r.o. REGISTERED SEAT: Senný trh 3116/7, 945 01 Komárno, Slovakia COMPANY REGISTRATION NUMBER: 52 363 813 CONTACT:
Recipients:
-
COMPANY NAME: Google LLC REGISTERED SEAT: Mountain View, California, USA CONTACT:
https://mail.google.com/ -
COMPANY NAME: Facebook, Inc. REGISTERED SEAT: Menlo Park, California, USA
CONTACT: https://www.facebook.com/ -
COMPANY NAME: Stripe, Inc.
REGISTERED SEAT: 1 Grand Canal Street Lower, Dublin, County Dublin, IE CONTACT: https://stripe.c om/en-hu -
COMPANY NAME: Zendesk, Inc.
REGISTERED SEAT: 1019 Market Street, San Francisco, CA 94103, US CONTACT: https://www.zendesk.com/ -
COMPANY NAME: Tatra banka, a.s.
REGISTERED SEAT: Hodžovo námestie 3, 811 06 Bratislava 1 CONTACT: https://moja.tatrabanka.sk/html-tb/ -
COMPANY NAME: PayPal (Európa) S.à r.l. et Cie, S.C.A. REGISTERED SEAT: 283, route d'Arlon, L-1150 Luxembourg. CONTACT:
https://www.paypal.com/
Where the Privacy Notice generally refers to transfers to the Company's data processors, in those cases it should also be understood to refer to transfers to the above recipients.
SECTION III. LAWFULNESS OF PROCESSING
1. Data processing based on the data subject’s consent Where the Company intends to carry out data processing based on consent, the data subject's consent to the processing of his or her personal data shall be obtained by means of the data request form and information as set out in the Data Processing.
2. Data processin
3. Data processing based on legitimate interests The legitimate interests of the Company or a third party may provide a legal basis for the processing, provided that the interests, fundamental rights and freedoms of the data subject do not override them.
4. Data processing for the protection of the vital interests of the data subject or other natural person
5. Data processing based on contractual interests Data processing may also be based on a contractual interest if it is necessary for the performance of a contract in which the data subject is a party or if it is requested by the data subject in order to prepare the contract.
6. Promoting the rights of the data subject The Company is obliged to ensure the exercise of the rights of the data subject during all data processing.
SECTION IV.
INFORMATION ABOUT DATA PROCESSING BY THE COMPANY
Customer data: managing data of contracting partners, contacts - registering customers, suppliers The Company may process the name, name at birth, date of birth, mother's name and address of the natural person who has a contractual relationship with it for the purposes of preparing, concluding, performing, terminating or granting a contractual benefit.
Sending messages on the Comp
-
The scope o
f personal data processed: the nam e of the natural person (surname, first name), e-mail address, phone number. -
Purpose of the processing of p
erso nal data: to enable the personalised and optimal functioning of the website ( ).https://louvreticketguide.com/ -
Recipients: the Company's IT data controllers; data processors.
-
Duration: 5 years or until the data subject's consent is withdrawn.
Data management in the Company's webshop Purchases made in the webshop operated by the Company shall be deemed to be a contract, subject to Article 13/A of Act CVIII of 2001 on certain issues of electronic commerce services and information society services.
-
Recipients: employees of the Company performing tasks related to customer service, money management, transport, marketing activities, as data processors (accounting, IT service provider, courier services).
-
Duration: until the registration/service is completed or until the data subject's consent is withdrawn (request for deletion), in case of a purchase, until the end of the 5th year following the year of purchase.
Data management in relation to social media (Faceb
-
Purpose of processing: to provide information on current information, news concerning the Data Controller, advertising on social media, presentation and promotion of services.
-
Legal basis: voluntary consent of the data subject.
-
Recipients: the employees of the data controller performing tasks related to customer service and marketing, the Company's data processors.
Management of recruitment data, application
-
Purpose: application, assessment of the application, conclusion of an employment contract with the selected candidate.
-
Legal basis: the data subject's consent.
-
Duration: Until the application or te
nder is assessed, for a maximum of 2 years.
Data processing for tax and accounting obligations
-
Recipients: employees and data processors of the Company performing tax, accounting, payroll and social security tasks.
-
Duration: 8 years after the termination of the legal relationship giving rise to the legal obligation.
SECTION V.
COOKIE POLICY ON THE WEBSITE OF THE COMPANY
Cookies are text files with small pieces of data, that are stored in the user’s computer or phone (HDD, SSD) until their expiration date.
-
Purpose of personal data processing: improvement in user’s internet experience, storage of personal adjustments on
https://louvreticketguide.com/ -
Legal basis: the data subject’s freely given consent.
-
Categories of processed per
sonal data: the Data Controller stores every analytical information without name or any other personal data. -
Period for which the personal data are stored: The data subject can delete the cookies anytime on his or her computer or phone.
SECTION VI.
INFORMATION ABOUT THE RIGHTS OF DATA SUBJECT
You can find further information about the rights of th
-
Information and access to personal data (Article 13 and 14)
-
Right of access by the data subject (Article 15)
-
Right to rectification (Article 16)
-
Right to erasure (‘right to be forgotten’ – Article 17)
-
Right to restriction of processing (Article 18)
-
Right to data portability (Article 20)
-
Right to object (Article 21)
-
Right to not be subject to automated individual decision-making, including profiling (Article 22)
-
Right for remedies (Article 77-82).
Right to lodge a complaint with a supervisory authority: Every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes General Data Protection Regulation.
Contact of the supervisory authority:
Office for Personal Data Protection of the Slovak Republic (Úrad Na Ochranu Osobných Údajov) Hraničná 12 820 07 Bratislava 27 Slovakia
Tel. + 421 2 32 31 32 14 Fax + 421 2 32 31 32 34 Email: statny.dozor@pdp.gov.sk Website:
Place and date: Komárno, Slovakia,