STATEMENT OF THE COMPANY H & D, as on the processing of personal data

Statement on the processing of personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons in connection with the processing of personal data and the instruction of data subjects (hereinafter referred to as "GDPR")

Personal data manager

The company H & D as, with registered office at Olomoucká 37, 796 01 Prostějov, ID: 60745451, registered in the commercial register maintained by the Regional Court in Brno, section B, file 1580, hereinafter referred to as the "administrator", hereby informs you about the processing of your personal data and your rights in accordance with Article 12 GDPR

Subject of personal data

The natural person whose personal data is processed.

Scope of personal data processing

Personal data is processed to the extent that the relevant data subject has provided it to the administrator, in connection with the conclusion of a contractual or other legal relationship with the administrator, or that the administrator has collected otherwise and processes it in accordance with applicable legal regulations or to fulfill the legal obligations of the administrator .

Sources of personal data

• directly from data subjects (registration and purchases via e-shop, e-mails, applications, requests, offers, contracts, etc.)

• publicly accessible registers, lists and records (e.g. commercial register, trade register, real estate cadastre, etc.)

Categories of personal data that are the subject of processing address and identification data used for unambiguous and unmistakable identification of the data subject (e.g. first name, surname, title, possibly birth number, date of birth, address of permanent residence, ID number, VAT number) and data enabling contact with by the data subject (contact data — e.g. contact address, telephone number, fax number, e-mail address and other similar information) descriptive data (e.g. bank details) and other data necessary for the performance of contractual relations between the administrator and the subject of personal data.

Categories of data subjects

- Customer manager

- Admin employee

- Supplier or recipient of the service

- Another person who is in a contractual relationship with the administrator

- Job applicant

Categories of recipients of personal data

- Processor

- Public institutions, state and other bodies within the framework of the fulfillment of legal obligations established by relevant legal regulations

The purpose of personal data processing

- Purposes associated with the creation of a business offer

- Negotiating a contractual relationship

- Fulfillment of the contract

- Protection of the rights of the administrator, recipient or other affected persons

- Archiving, conducted on the basis of the law

- Selection procedures for jobs at the administrator

- Fulfillment of legal obligations by the administrator

- Protection of the vital interests of the subject of personal data

Method of processing and protection of personal data

- The processing of personal data is carried out by the administrator. The processing is carried out at the administrator's headquarters by individual authorized employees of the administrator. The processing takes place through computer technology, or in a manual manner and in compliance with all security principles for the management and processing of personal data so that there can be no unauthorized or accidental access to personal data, their change, destruction or loss, unauthorized transmission or processing.

The administrator can entrust personal data to a third party - a processor for processing on the basis of a contract in which the principles of the GDPR are enshrined.

Time of personal data processing

- In accordance with the deadlines specified in the relevant contracts, in the file and shredding regulations of the administrator or in the relevant legal regulations.

Lesson learned

In accordance with Article 6, paragraph 1 of the GDPR, the controller may process the following data without the consent of the data subject:

- The processing is necessary for the fulfillment of the contract to which the data subject is a contracting party

- The processing is necessary to fulfill the legal obligation of the administrator, or necessary to protect the vital interests of the data subject or another natural person.

- Processing is necessary for the purposes of the legitimate interests of the administrator or a third party, except in cases where the interests, rights and freedoms of the data subject take precedence over these interests.

Personal data are not used for automatic decision-making.

Rights of the data subject

Right of access:

- the right to know what data we process about you, for how long, to whom we pass it on, and the right to access this information

Right to data portability:

- the possibility to obtain your personal data in a structured, commonly used and machine-readable format and the right to transfer this data to another administrator.

Right to rectification:

- if your data is incomplete or out of date, we have the right to correct or supplement it without undue delay.

Right to erasure:

- if the reason for which we stored your personal data is fulfilled and at the same time there is no legitimate reason to continue processing and storing it, you have the right to request their immediate deletion.

Right to restriction of processing:

- in certain cases, you can request the marking of those personal data that you do not wish to be further processed.

The right to object to processing:

- you have the right to object to the processing that takes place on the basis of the administrator's legitimate interest

Right to file a complaint:

- exercising your rights in the above manner does not affect your right to file a complaint with the competent authority (Office for the Protection of Personal Data)

In all matters related to the processing of personal data, you can contact the H & D , as company's switchboard, telephone +420 582 305 600 or the authorized employee Ms. Pavla Brablecová, telephone 582 305 645, e-mail: personal@hdas.cz

This statement is publicly available on the administrator's website.