DATA CONTROLLER
Ralton s.r.o.
Next to 4706/21
46604 Jablonec nad Nisou
ID: 432 24 733
DIC: CZ43224733
+420 483 317
info@ralton.cz
In connection with the provision of our services, our company, in its capacity as a personal data controller, processes (i.e., in particular, collects, stores and uses) personal data of customers to the extent set out below, in accordance with Regulation (EU) No 216/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as "GDPR").
This data processing policy provides customers with a comprehensive understanding of how our company processes personal data, as well as the rights of customers as data subjects. This policy fulfills the conditions of the information obligation under Article 13 of the GDPR.
BASIC PROCESSING RULES
Personal data of customers are:
• always processed correctly and lawfully and transparently,
• collected for specific, explicit, and legitimate purposes,
• proportionate, relevant, and limited to what is necessary in relation to the purpose for which they are processed,
• accurate and updated where necessary,
• stored in a form that permits identification of data subjects for no longer than is necessary in relation to the relevant purpose of the processing,
• processed in a way that ensures adequate security of the personal data.
LEGAL BASIS FOR PROCESSING
The legal bases for the processing of customers' data by our company are:
• consent to processing for marketing purposes according to Article 6(1)(a) GDPR
• the conclusion and performance of a contract with customers, or steps following a request for our goods or services from a customer according to Article 6(1)(b) GDPR
• a legitimate interest in the provision of direct marketing (in particular for sending commercial communications and newsletters) according to Article 6(1)(f) GDPR
• the fulfillment of our company's legal obligations (in particular accounting and tax obligations) under Article 6(1)(c) GDPR.
SCOPE OF THE PROCESSING OF PERSONAL DATA
In connection with the legal basis for processing described above, our company processes the following personal data of customers:
• name, surname, academic title,
• the customer's home address or delivery address,
• the customer's date of birth or birth number,
• email address and phone number,
• bank account number,
• in the case of a customer-entrepreneur, also the address of its registered office, VAT number, and VAT number,
• other information relating to the customer or third parties that is necessary for the proper provision of our services.
Personal data are processed mainly manually. We take appropriate security measures (in particular technical and organizational) to protect personal data from any accidental loss, destruction, misuse, damage, and unauthorized or unlawful access.
PURPOSE OF PROCESSING PERSONAL DATA
The purpose of processing personal data is:
• purchase order processing and the exercise of rights and obligations arising from the contractual relationship with customers; when placing an order, personal data are required that are necessary for the successful processing of the order (name and address, contact), the submission of personal data is a necessary requirement for the conclusion and performance of the contract, without the provision of personal data it is not possible to conclude or perform the contract;
• sending commercial communications and other marketing activities.
RECIPIENTS OF PERSONAL DATA
As a data controller, our company only discloses customer personal data:
• to its employees;
• personal data processors who are in a contractual relationship with our company (e.g. IT services, accounting, etc.) and who are involved in:
o delivery of goods/services/payments under the contract;
o provision of our services;
o providing marketing services.
• in justified cases to other processors, while respecting the legal provisions,
• public authorities, such as courts or administrative authorities,
• to other recipients if such disclosure is consistent with the needs and instructions of the customer.
PERIOD OF PROCESSING OF PERSONAL DATA
Personal data are processed for the following periods:
• period before consent to the processing of personal data is withdrawn;
• period necessary for the exercise of the rights and obligations arising from the contractual relationship between the customer and the controller and the exercise of claims arising from such contractual relationship;
• the duration of our obligations under Act No. 499/2004 Coll., on archiving and filing services, as amended.
RIGHTS OF DATA SUBJECTS
As a data subject, the customer has the rights granted by law in connection with the processing of his/her personal data by our company. These are:
• Right of access to personal data. The customer has the right to obtain information from our company as to whether it processes his personal data and, if so, what the data is and how it is processed. The customer also has the right to have inaccurate personal data concerning him corrected by our company as a controller without undue delay at his request. The customer has the right to complete incomplete personal data at any time.
• Right to erasure. Based on the customer's request and subject to the conditions under the GDPR, our company is obliged to delete and dispose of the personal data it processes regarding the requesting customer.
• Right to restriction of processing of personal data. In cases specified by law, the customer has the right to have our company restrict the processing of his/her personal data. In addition, the customer has the right to object to processing that is based on the legitimate interests of the controller, or a third party, or is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.
• Right to portability of personal data. The customer is entitled to obtain from our company the personal data he has provided to us in a common and machine-readable format. The customer may subsequently transfer this personal data to another controller or, if technically feasible, request that our company share it with another controller.
If the customer is in any way dissatisfied with the processing of his/her personal data by our company, he/she may file a complaint either directly with us or contact the Office for Personal Data Protection, ID No.: 70837627, located at Pplk. Sochora 27, 170 00 Prague.