Privacy Policy

THE PROTECTION OF NATURAL PERSONS RIGHTS WITH REGARD TO THE PROCESSING OF PERSONAL DATA

INTRODUCTION

Why is this privacy notice made? During its operation, the Data Controller handles personal data for several purposes, while respecting the rights of the data subjects and fulfilling legal obligations. The Data Controller also considers it important to present to the data subject the handling and the most important characteristics of the personal data that came to the controller’s knowledge during the data processing activities.

What is the legal basis of processing the data subjects’ personal data? Personal data is only processed for a specific purpose and on an appropriate legal basis. These purposes and legal bases are presented individually, in relation to specific data processing.

What external assistance is used to process your personal data? Personal data is mostly processed by the Data Controller at own premises. However, there are operations for which a data processor’s external help is necessary. The data processor may change according to the characteristics of each data processing.

Who is processing your personal data? The data subject may receive information about the data processors employed by the Data Controller and their contact details in section II of this privacy notice.


SECTION I.

NAME OF THE DATA CONTROLLER

The issuer of this privacy notice and the Data Controller:

COMPANY NAME: TutiTours s. r. o. REGISTERED SEAT: Senný trh 3116/7, 945 01 Komárno, Slovakia COMPANY REGISTRATION NUMBER (IČO): 53242122 TAX NUMBER (DIČ): 2121324788 EU VAT NUMBER (IČ DPH): SK2121324788 (Registered under §7a from 8.10.2020)

WEBSITE: https://louvreticketguide.com/ E-MAIL: info@louvreticketguide.com PHONE: +1 434 442 5924


SECTION II.

NAME OF THE DATA PROCESSORS

Data Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller; (Regulation 2016/679 Article 4 8.) To use a data processor, prior consent from the data subject is not required, but he or she must be notified. Accordingly, the following information is provided:

Hosting Provider: COMPANY NAME: Tárhely.Eu Kft. REGISTERED SEAT: 1144 Budapest, Ormánság street 4. X. floor 241. CONTACT: https://mail.tarhely.eu/

Website development: IT and marketing service provider company.

Data processor performing invoicing and payroll tasks: COMPANY NAME: Shark kzm s.r.o. REGISTERED SEAT: Senný trh 3116/7, 945 01 Komárno, Slovakia COMPANY REGISTRATION NUMBER: 52 363 813 CONTACT: https://shark-kzm.sk/hu/

Recipients:

Where the Privacy Notice generally refers to transfers to the Company's data processors, in those cases it should also be understood to refer to transfers to the above recipients.


SECTION III. LAWFULNESS OF PROCESSING

1. Data processing based on the data subject’s consent Where the Company intends to carry out data processing based on consent, the data subject's consent to the processing of his or her personal data shall be obtained by means of the data request form and information as set out in the Data Processing. Consent shall also be deemed to be given if the data subject ticks a box when viewing the Company's website, makes the relevant technical settings when using information society services, or makes any other statement or takes any other action which clearly indicates the data subject's consent to the intended processing of his or her personal data in the relevant Silence, ticking a box or inaction therefore does not constitute consent. The continuation of a telephone call after having been duly informed shall constitute consent. Consent covers all processing activities carried out for the same purpose. Where processing is carried out for more than one purpose, consent shall be given for all the purposes for which the processing is carried out. The data subject may withdraw his/her consent at any time by sending an e-mail to the e-mail address indicated in Chapter I.

2. Data processing based on performing legal obligations In the case of data processing based on performing legal obligations, the scope of the data that can be processed, the purpose of the data processing, the duration of data storage and the recipients are governed by the provisions of the underlying regulation, regardless of the consent of the data subject.

3. Data processing based on legitimate interests The legitimate interests of the Company or a third party may provide a legal basis for the processing, provided that the interests, fundamental rights and freedoms of the data subject do not override them.

4. Data processing for the protection of the vital interests of the data subject or other natural person

5. Data processing based on contractual interests Data processing may also be based on a contractual interest if it is necessary for the performance of a contract in which the data subject is a party or if it is requested by the data subject in order to prepare the contract.

6. Promoting the rights of the data subject The Company is obliged to ensure the exercise of the rights of the data subject during all data processing.


SECTION IV.

INFORMATION ABOUT DATA PROCESSING BY THE COMPANY

Customer data: managing data of contracting partners, contacts - registering customers, suppliers The Company may process the name, name at birth, date of birth, mother's name and address of the natural person who has a contractual relationship with it for the purposes of preparing, concluding, performing, terminating or granting a contractual benefit. Recipients of personal data: the Company's employees performing customer service tasks, employees performing accounting, tax, business, invoicing tasks and data processors. The period of storage of personal data is 8 years after the termination of the contract in view of the long-term business relationship of the Company.

Sending messages on the Company's website The natural person using the website (user) can give his/her consent to the processing of his/her personal data by ticking the relevant box. It is prohibited to tick the box in advance.

  • The scope of personal data processed: the name of the natural person (surname, first name), e-mail address, phone number.

  • Purpose of the processing of personal data: to enable the personalised and optimal functioning of the website (https://louvreticketguide.com/).

  • Recipients: the Company's IT data controllers; data processors.

  • Duration: 5 years or until the data subject's consent is withdrawn.

Data management in the Company's webshop Purchases made in the webshop operated by the Company shall be deemed to be a contract, subject to Article 13/A of Act CVIII of 2001 on certain issues of electronic commerce services and information society services. The Company may process the natural personal identification data and the address of the customer registering in the webshop for the purpose of creating, defining the content of, amending and monitoring the performance of the contract for the provision of information society services, invoicing the fees arising therefrom, and enforcing the claims related thereto.

  • Recipients: employees of the Company performing tasks related to customer service, money management, transport, marketing activities, as data processors (accounting, IT service provider, courier services).

  • Duration: until the registration/service is completed or until the data subject's consent is withdrawn (request for deletion), in case of a purchase, until the end of the 5th year following the year of purchase.

Data management in relation to social media (Facebook, Instagram) Our Company has only limited influence on the data processing of social media platforms. The Controller manages its own page on Facebook/Instagram.

  • Purpose of processing: to provide information on current information, news concerning the Data Controller, advertising on social media, presentation and promotion of services.

  • Legal basis: voluntary consent of the data subject.

  • Recipients: the employees of the data controller performing tasks related to customer service and marketing, the Company's data processors.

Management of recruitment data, applications, CVs

  • Purpose: application, assessment of the application, conclusion of an employment contract with the selected candidate.

  • Legal basis: the data subject's consent.

  • Duration: Until the application or tender is assessed, for a maximum of 2 years.

Data processing for tax and accounting obligations The Company shall process the data of natural persons who have come into contact with it for the purposes of fulfilling a legal obligation, tax and accounting obligations (bookkeeping, taxation) as provided for by law.

  • Recipients: employees and data processors of the Company performing tax, accounting, payroll and social security tasks.

  • Duration: 8 years after the termination of the legal relationship giving rise to the legal obligation.


SECTION V.

COOKIE POLICY ON THE WEBSITE OF THE COMPANY

Cookies are text files with small pieces of data, that are stored in the user’s computer or phone (HDD, SSD) until their expiration date.

  • Purpose of personal data processing: improvement in user’s internet experience, storage of personal adjustments on https://louvreticketguide.com/

  • Legal basis: the data subject’s freely given consent.

  • Categories of processed personal data: the Data Controller stores every analytical information without name or any other personal data.

  • Period for which the personal data are stored: The data subject can delete the cookies anytime on his or her computer or phone.


SECTION VI.

INFORMATION ABOUT THE RIGHTS OF DATA SUBJECT

You can find further information about the rights of the data subject in General Data Protection Regulation (https://eur-lex.europa.eu/legal- content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN).

  • Information and access to personal data (Article 13 and 14)

  • Right of access by the data subject (Article 15)

  • Right to rectification (Article 16)

  • Right to erasure (‘right to be forgotten’ – Article 17)

  • Right to restriction of processing (Article 18)

  • Right to data portability (Article 20)

  • Right to object (Article 21)

  • Right to not be subject to automated individual decision-making, including profiling (Article 22)

  • Right for remedies (Article 77-82).

Right to lodge a complaint with a supervisory authority: Every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes General Data Protection Regulation.

Contact of the supervisory authority:

Office for Personal Data Protection of the Slovak Republic (Úrad Na Ochranu Osobných Údajov) Hraničná 12 820 07 Bratislava 27 Slovakia

Tel. + 421 2 32 31 32 14 Fax + 421 2 32 31 32 34 Email: statny.dozor@pdp.gov.sk Website: http://www.dataprotection.gov.sk/

Place and date: Komárno, Slovakia,