Privacy policy

PERSONAL DATA – INFORMATION OBLIGATION

We treat personal data protection seriously and we fully guarantee your right to information. When processing personal data, we comply with Regulation (EU) 2016/679 of the European Parliament and of the Council and with Act No. 18/2018 Coll. on personal data protection and on the amendment of certain acts. When processing personal data, we follow the principles of lawfulness and transparency, limitation of the purpose of processing, minimisation of the scope and storage. We apply the principles of information security management to ensure confidentiality, accessibility and integrity of personal data.

We process only such personal data that users provide us with themselves and solely for the purposes for which the data have been provided. Personal data will be processed only for a period of time necessary to fulfil the purpose of processing, which depends on the question or problem raised by the user when contacting our company. The provision of personal data is voluntary.

CONTROLLER
Business Name: GRANDSTONE, s.r.o.
Seat: Šachorová 29, 831 07 Bratislava
Company ID: 35 718 731
VAT ID: SK2020228287

DATA PROTECTION OFFICER
Given the scope and subject of our activities, our company is not legally obliged to designate a Data Protection Officer. To exercise the rights below, you can contact our company via email at grandstone@grandstone.sk or via standard mail sent to the company’s headquarters: GRANDSTONE, s.r.o., Vajnorská 135, 831 04 Bratislava, Slovakia.

PURPOSE OF PERSONAL DATA PROCESSING

Our company processes personal data for the following purposes:

  • Processing contractual and pre-contractual commitments,
  • Processing HR and payroll agenda,
  • Processing accounting agenda,
  • Security and property protection,
  • Staff attendance,
  • Customer service provision,
  • Marketing purposes,
  • Measures aimed at detection of corruption activities.

LEGAL BASIS FOR THE PROCESSING OF PERSONAL DATA OF DATA SUBJECTS

Your personal data may be processed only if one of the following legal bases applies:

  • if you have given us consent to the processing of your personal data for one or more specific purposes,
  • processing is necessary for the performance of a contract to which you are party or in order to take steps at the request of the data subject prior to entering into a contract,
  • processing is necessary for compliance with a specific regulation or international contract by which the Slovak Republic is bound,
  • processing is necessary for the protection of your life, health or property or of the life, health or property of other physical persons,
  • processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, or
  • processing is necessary for the purposes of legitimate interests of the company or a third party, with the exception of cases excluded by law.

PROVISION OF CONSENT BY THE DATA SUBJECT

  • consent to the processing of personal data is given freely, without exercising pressure or force, without threats of refusal of a contractual relationship, provision of services or obligations arising to the controller from applicable legislation,
  • consent is given individually for each purpose of personal data processing,
  • you can withdraw your consent as data subject at any time,
  • our company respects your privacy and treats personal data as confidential.

CONDITIONS AND MEANS OF PROCESSING OF PERSONAL DATA OF DATA SUBJECTS

  • personal data processing is carried out by automated and non-automated means,
  • personal data that we process are not disclosed, unless it is required by a specific legal regulation or a decision taken by the court or any other public authority,
  • we shall not process your personal data without your explicit consent or a lawful legal basis.

RIGHTS OF DATA SUBJECTS

As data subject, in accordance with relevant provisions of Act No. 18/2018 Coll. on personal data protection and on the amendment of certain acts and of Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on free movement of such data, and repealing Directive 95/46/EC, you have the following rights:

  1. right to withdraw your consent at any time,
  2. right of access to your personal data,
  3. right to rectification,
  4. right to object to processing,
  5. right to erasure ("right to be forgotten")
  6. right to data portability,
  7. right to restrict personal data processing,
  8. right to lodge a complaint with a supervisory authority, namely the Personal Data Protection Office of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27, Slovakia
  9. at the same time, if you have any doubts as to whether your personal data are processed in accordance with applicable legal regulations or whether your personal data are correct, you can ask for an explanation or removal of the condition, including blocking, rectification, amendment or disposal of your personal data.

RECIPIENTS

Our company can provide your personal data to the following recipients:

Legal recipients

  • recipients defined by applicable legal regulations of the Slovak Republic and of the EU – health insurance agencies, Social Security Agency, Financial Administration, national and local authorities, control authorities and law enforcement authorities.

Processors

  • who provide support services to our company in the area of payrolls and accounting, occupational security, property protection and webhosting services.
  • we declare that when selecting individual suppliers, we shall focus on their professional, technical, organisational and personal adequacy and their ability to guarantee security of processed personal data by taking security measures in accordance with applicable legal requirements,
  • in accordance with Section 34 of the Act on Personal Data Protection, relevant processors are authorized in writing to process personal data of data subjects to the extent, under the conditions and for the purposes agreed in a contract and in compliance with the Personal Data Protection Act.

STORAGE PERIOD OF PERSONAL DATA OF DATA SUBJECTS

Storage period depends on the purpose of personal data processing and on the requirements of special regulations. Personal data whose purpose of processing and storage period have ended shall be irretrievably destroyed.

TRANSFER OF PERSONAL DATA TO THIRD COUNTRIES

Transfer of personal data to third countries shall not take place

AUTOMATED INDIVIDUAL DECISION-MAKING, INCLUDING PROFILING

Apart from the data that you provide to our company, we also collect cookies information. This information is a result of monitoring of our website by means of analytical tools that prepare a data chain and monitor how visitors use websites. This information can include data on:

  1. websites linked to this website,
  2. third-party websites that you visit once you leave our website,
  3. your IP address and
  4. duration of your visit on our website.

You can disable the use of cookies in the settings of your browser. If you do so, websites might not function properly.

If you visit a website, the system generates a cookie file to record information related to your visit (pages visited, time spent on our website, data viewed, time when you left the website, etc.), however, these data cannot be linked to a specific visitor. This tool is designed to improve the ergonomic design of the website, to create a user-friendly website and to improve visitors’ online experience. Most internet browsers accept cookies, however, visitors can delete them or automatically refuse them.

Analytical and other tools

We use services of third parties providing us with external services:

  • Measuring is used for the analysis of traffic. We may use these data to adjust our services and marketing strategies for our services. This is a third-party service where the providers of such services use your data for their own purposes, including profiling and preparation of ads.
  • Online marketing is used for controlled marketing. This is a third-party service where the providers of such services use your data for their own purposes, including profiling and preparation of ads.
  • Social media is used for communication and presentation. This is a third-party service where the providers of such services use your data for their own purposes, including profiling and preparation of ads.
  • By providing you with the above information, we have informed you as data subject on the protection of your personal data and on your rights related to personal data protection to the extent of this written information obligation.