Principles of Personal Data Processing
Principles of Personal Data Processing
Who processes your personal data?
Your personal data are processed by D O A S, a. s. Your personal data are processed by D O A S, a. s. with its registered office at 5590/56 Košická Street, 821 08 Bratislava, company registration number: 31 373 917, registered in the Commercial Register of the City Court Bratislava III, section: Sa, insert No: 622/B (hereinafter referred to as “operator or company D O A S”). When processing personal data by the operator, you are in the position of the data subject, i.e. the person about whom personal data relating to him/her are processed. Your personal data will be processed securely, in accordance with the operator’s security policy.
What rights do you have as a data subject?
Right of access – you have the right to get a copy of the personal data we have about you, as well as the information on how we use your personal data (click HERE for application form). Right to rectification – if you believe that the data we have are inaccurate, incomplete or out of date, please do not hesitate to ask us to correct, update or complete this information (click HERE for application form). Right to erasure (to be forgotten) – you have the right to ask us to erase your personal data (click HERE for application form). Withdraw consent – in cases where we process your personal data based on your consent, you have the right to withdraw this consent at any time. Withdrawal of consent does not affect the legality of the processing of personal data that we were processing about you on its basis (click HERE for application form). Right to restrict processing – under certain circumstances, you are entitled to ask us to stop using your personal data (click HERE for application form). Right to data portability – under certain circumstances, you have the right to ask us to transfer the personal data you have provided to us to another third party of your choice (application form HERE). Right to object – you have the right to object to the processing of personal data, which is based on our legitimate interests (click HERE for application form). Right to submit a proposal to initiate a procedure on the protection of personal data – if you believe that we process your personal data unfairly or illegally, you can file a complaint with the supervisory authority, which is the Personal Data Protection Office of the Slovak Republic. Right not to be subject to automated individual decision making, including profiling. Right not to be subject to automated individual decision making, including profiling. If the provision of personal data is a legal/contractual requirement, you, as the data subject, are obliged to provide these personal data. Failure to provide personal data necessary for concluding a contract may result in not concluding a contractual relationship.In the event of an objection regarding the processing of your personal data, you have the right to submit an initiative or request in writing to the address of the company’s registered office: Košická St. 5590/56, 821 08 Bratislava or to e-mail: doas@doas.sk The operator does not transfer personal data to third countries or international organizations.
WEB
I. Contact Form
Purpose of processing | ensuring communication through the contact form on the website, handling requests |
Legal basis | legitimate interest pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is ensuring effective communication via the web |
Category of data subjects | those interested in information |
Category of personal data | first name, last name, e-mail address, subject of the message, company name if the interested party is a legal person |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law, website administrator |
Deadline for erasure of personal data | 10 days from the end of the month in which the request was received |
II. Newsletter
Purpose of processing | sending business information, including information about the company’s activities in the form of a newsletter |
Legal basis | consent of the data subject pursuant to Art. 6 para. 1 letter. a) of GDPR |
Category of data subjects | those interested in information |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law, website administrator |
Deadline for erasure of personal data | 2 years from the end of the calendar year in which the consent was granted |
REAL ESTATE ACTIVITY
I Pre-contractual Negotiations
Purpose of processing | assessing the potential client’s demand and introducing measures before concluding the contract |
Legal basis | pre-contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR |
Category of data subjects | potential clients, a person authorized to act on behalf of a potential client, a potential client’s contact person |
Category of personal data | first name, last name, title, position, e-mail, phone number, identification data of the company on the basis of which it is possible to identify the data subject, the subject of pre-contractual negotiations |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law, an external partner ensuring the search for potential clients |
Deadline for erasure of personal data | 3 months after closing pre-contractual negotiations |
II. Contract on Future Purchase Contract
Purpose of processing | conclusion and administration of a contractual relationship in terms of the subject of the contract on future purchase contract, including the agreement on the termination of the contract on future purchase contract |
Legal basis | contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR |
Category of data subjects | future buyer, person authorized to act on behalf of the future buyer |
Category of personal data | Natural persons:title, first name, last name, maiden name, place of permanent residence, birth identification number, nationality, identity document number, status, signature, phone number, e-mail, data on the property to be the subject of the future purchase contract, future purchase price Legal persons/Self-employed persons:title, first name, last name, position of a person authorized to act on behalf of a legal person or entrepreneur in the case of self-employed persons, identification data of the company/self-employed person on the basis of which it is possible to identify the data subject in the scope of: business name, company registration number, TIN, VAT number, account number, registered office/place of business, information from the commercial register/trade register, data on the property to be the subject of the future purchase contract, the future price of the property |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law, (cooperating financial institutions, if interested in using the services in question) |
Deadline for erasure of personal data | 10 years from the termination of the contractual relationship |
III. Purchase Contract
Purpose of processing | conclusion and administration of a contractual relationship pursuant to the subject of the purchase contract |
Legal basis | contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR |
Category of data subjects | buyer, person authorized to act on behalf of the buyer |
Category of personal data | Natural persons: title, first name, last name, maiden name, place of permanent residence, birth identification number, nationality, identity document number, status, signature, phone number, e-mail, data on the property to be the subject of the future purchase contract, purchase price Legal persons/Self-employed persons: title, first name, last name, position of a person authorized to act on behalf of a legal person or entrepreneur in the case of self-employed persons, identification data of the company/self-employed person, on the basis of which it is possible to identify the data subject in the scope of: business name, company registration number, TIN, VAT number, account number, registered office/place of business, information from the commercial register/trade register, data on the property to be the subject of the future purchase contract, price of the property |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law, (cooperating financial institutions, if interested in using the services in question), external partner ensuring the implementation of the project (construction, improvement of property, etc.) |
Deadline for erasure of personal data | 10 years from the termination of the contractual relationship |
IV. Contract of Lease
Purpose of processing | conclusion and administration of a contractual relationship in terms of the subject of the contract of lease |
Legal basis | contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR |
Category of data subjects | tenant/person authorized to act on behalf of the tenant if the tenant is a legal person |
Category of personal data | title, first name, last name, position of a person authorized to act on behalf of a legal person or entrepreneur in the case of self-employed persons, identification data of the company/self-employed person, on the basis of which it is possible to identify the data subject in the scope of: business name, company registration number, TIN, VAT number, account number, registered office/place of business, information from the commercial register/trade register, data on the property to be the subject of the contract of lease, rental price of the property |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law |
Deadline for erasure of personal data | 10 years from the termination of the contractual relationship |
V. Contract of Lease of Non-residential Premises
Purpose of processing | conclusion and administration of a contractual relationship in terms of the subject of the contract of lease |
Legal basis | contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR |
Category of data subjects | tenant/person authorized to act on behalf of the tenant if the tenant is a legal person |
Category of personal data | title, first name, last name, position of a person authorized to act on behalf of a legal person or entrepreneur in the case of self-employed persons, identification data of the company/self-employed person, on the basis of which it is possible to identify the data subject in the scope of: business name, company registration number, TIN, VAT number, account number, registered office/place of business, information from the commercial register/trade register, data on the property to be the subject of the contract of lease, rental price of the property |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law |
Deadline for erasure of personal data | 10 years from the termination of the contractual relationship |
VI. Agreement on the Establishment of an Easement
Purpose of processing | conclusion and administration of contractual relationships in connection with the establishment of an easement |
Legal basis | contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR |
Category of data subjects | obliged from the easement |
Category of personal data | first name, last name, date of birth, birth identification number, permanent residence, nationality, data on the property that is encumbered |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law |
Deadline for erasure of personal data | 10 years from the termination of the contractual relationship |
VII. Brokerage Contract
Purpose of processing | conclusion and administration of a contractual relationship in terms of the subject of the brokerage contract |
Legal basis | contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR |
Category of data subjects | those interested in brokerage |
Category of personal data | title, first name, last name, position of a person authorized to act on behalf of a legal person or entrepreneur in the case of self-employed persons, identification data of the company/self-employed person, on the basis of which it is possible to identify the data subject in the scope of: business name, company registration number, TIN, VAT number, account number, registered office/place of business, information from the commercial register/trade register, data on the subject of brokerage |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law |
Deadline for erasure of personal data | 10 years from the termination of the contractual relationship |
VIII. Affidavit
Purpose of processing | execution and administration of an affidavit in connection with the purchase of property |
Legal basis | contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR |
Category of data subjects | buyer |
Category of personal data | Natural persons: title, first name, last name, maiden name, place of permanent residence, birth identification number, nationality, identity document number, status, signature, phone number, e-mail, data on the property to be the subject of the purchase contract Legal persons/Self-employed persons: title, first name, last name, position of a person authorized to act on behalf of a legal person or entrepreneur in the case of self-employed persons, identification data of the company/self-employed person, on the basis of which it is possible to identify the data subject in the scope of: business name, company registration number, TIN, VAT number, account number, registered office/place of business, information from the commercial register/trade register, data on the property to be the subject of the purchase contract |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law |
Deadline for erasure of personal data | 10 years from the termination of the contractual relationship |
IX. Another Contract Type
Purpose of processing | conclusion and administration of a contractual relationship related to the purchase/rental of property |
Legal basis | contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR |
Category of data subjects | buyer, tenant |
Category of personal data | Natural persons: title, first name, last name, maiden name, place of permanent residence, birth identification number, nationality, identity document number, status, signature, phone number, e-mail, data on the property to be the subject of the purchase contract Legal persons/Self-employed persons: title, first name, last name, position of a person authorized to act on behalf of a legal person or entrepreneur in the case of self-employed persons, identification data of the company/self-employed person, on the basis of which it is possible to identify the data subject in the scope of: business name, company registration number, TIN, VAT number, account number, registered office/place of business, information from the commercial register/trade register, data on of the property to be the subject of the purchase contract, these data may be modified depending on the contractual relationship in accordance with the principle of minimization |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law (the recipient of personal data can be a cooperating financial institution, lawyer, external partner providing property insurance, depending on the subject of the contractual relationship) |
Deadline for erasure of personal data | 10 years from the termination of the contractual relationship |
X. Client Records
Purpose of processing | records of clients and contact persons |
Legal basis | legitimate interest pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is effectively ensuring communication with the contractual partner |
Category of data subjects | clients, person authorized to act on behalf of the client, the client’s contact person |
Category of personal data | first name, last name, title, position, e-mail, phone number, identification data of the company, on the basis of which it is possible to identify the data subject |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law |
Deadline for erasure of personal data | after termination of the contractual relationship |
Transfer of personal data to third countries or international organizations | does not take place |
PROTECTION AGAINST MONEY LAUNDERING AND PROTECTION AGAINST TERRORIST FINANCING
Purpose of processing | fulfilment of obligations related to ensuring protection against the money laundering and ensuring protection against the terrorist financing |
Legal basis | Act No 297/2008 Coll. on protection against money laundering and terrorist financing and on amendment of certain acts (hereinafter referred to as “the Act”) |
Category of data subjects | clients, or other persons to whom the act applies |
Category of personal data | For the purpose of performing care in relation to the client and for the purpose of detecting an unusual business operation according to § 14 of the Act, the person liable is authorized to detect, acquire, record, store, use and otherwise process personal data and other data to the extent according to § 10 par. 1, § 11 par. 3 and § 12 par. 1 and 2 of the Act; at the same time, the person liable is authorized to obtain personal data necessary to achieve the purpose of processing by copying, scanning or otherwise recording official documents on a data carrier and to process birth identification numbers and other data and documents without the consent of the data subject to the extent according to § 10 par. 1, § 11 par. 3 and § 12 par. 1 and 2 of the Act
For five years from the end of the contractual relationship with the client or from the execution of occasional business outside the business relationship, the person liable is obliged to keep: a) data and written documents obtained according to § 10, § 11, § 12 and 14 of the Act |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law |
Deadline for erasure of personal data | The person liable is obliged to store data for five years from the end of the contractual relationship with the client or from the execution of an occasional transaction outside the business relationship. The person liable is obliged to store data and written documents according to paragraph 2 for longer than five years, if the financial intelligence unit requests it in writing after a thorough assessment of the need and adequacy of such further storage. In the application, the financial intelligence unit shall state the period, which may not exceed the next five years, and the extent of the retention of data and written documents. |
Transfer of personal data to third countries or international organizations | does not take place |
COMPLAINTS
Purpose of processing | ensuring the complaint procedure |
Legal basis | Act No 250/2007 Coll. on consumer protection and on the amendment of Act of the Slovak National Council No 372/1990 Coll. on offenses as amended, contractual relationship pursuant to Art. 6 para. 1 letter. b) |
Category of data subjects | clients, person authorized to act on behalf of the client, the client’s contact person |
Category of personal data | first name, last name, title, position, e-mail, phone number, address, identification data of the company, on the basis of which it is possible to identify the data subject if the client is a legal person, subject of the complaint, data specified in the contract |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law |
Deadline for erasure of personal data | 2 years from handling the complaint-related agenda |
Transfer of personal data to third countries or international organizations | does not take place |
ACCOUNTING AND TAX OBLIGATIONS
Purpose of processing | fulfilment of legal obligations in the field of taxes and accounting in the area of business relations |
Legal basis | Act No 431/2002 Coll. on accounting, Act No 595/2003 Coll. on income tax as amended |
Category of data subjects | clients/suppliers, persons authorized to act on behalf of clients/suppliers |
Category of personal data | first name, last name, bank account number (or e-mail), payment-related data, company ID on the basis of which the data subject can be identified if the client/supplier is a legal person |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law, an intermediary ensuring the fulfilment of the operator’s legal obligations |
Deadline for erasure of personal data | 10 years from the fulfilment of the legal obligation |
Transfer of personal data to third countries or international organizations | does not take place |
SUPPLIER RELATIONS
1. purpose of processing | conclusion and administration of contractual relationships |
Legal basis | contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR |
Category of data subjects | suppliers, a person authorized to act on behalf of the supplier |
Category of personal data | first name, last name, title, position, e-mail, phone number, correspondence address, company identification data, on the basis of which it is possible to identify the data subject |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law |
Deadline for erasure of personal data | 10 years from the termination of the contractual relationship |
Transfer of personal data to third countries or international organizations | does not take place |
2. purpose of processing | records of suppliers and contact persons |
Legal basis | legitimate interest pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is effectively ensuring communication with the contractual partner |
Category of data subjects | suppliers, a person authorized to act on behalf of the supplier, the supplier’s contact person |
Category of personal data | first name, last name, title, position, e-mail, phone number, identification data of the company, on the basis of which it is possible to identify the data subject |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law |
Deadline for erasure of personal data | after termination of the contractual relationship |
Transfer of personal data to third countries or international organizations | does not take place |
EXERCISE OF THE RIGHTS OF THE DATA SUBJECTS –PERSONAL DATA PROTECTION
Purpose of processing | record of the exercised rights of the data subjects and violations of protection pursuant to Act No 18/2018 Coll. on the protection of personal data and on amendment of certain acts, record of the rights of the data subjects according to Chapter III and notifications according to Art. 33 and 34 of Regulation 2016/679 on the protection of natural persons in the processing of personal data and on the free movement of such data |
Legal basis | legitimate interest pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is the record of rights exercised and notifications of personal data protection breaches |
Category of data subjects | data subjects whom the application for the exercise of the right concerns; data subjects whom the breach of personal data protection concerns |
Category of personal data | data relevant for the exercise of the right, data provided by the notifier when reporting a breach of protection |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law |
Deadline for erasure of personal data | within 6 months from the expiry of 5 years from the exercise of the right or the occurrence of a data protection breach |
Transfer of personal data to third countries or international organizations | does not take place |
EXERCISE OF LEGAL CLAIMS
Purpose of processing | record of the exercised rights of the data subjects and violations of protection pursuant to Act No 18/2018 Coll. on the protection of personal data and on amendment of certain acts, record of the rights of the data subjects according to Chapter III and notifications according to Art. 33 and 34 of Regulation 2016/679 on the protection of natural persons in the processing of personal data and on the free movement of such data |
Legal basis | legitimate interest pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is the record of rights exercised and notifications of personal data protection breaches |
Category of data subjects | data subjects whom the application for the exercise of the right concerns; data subjects whom the breach of personal data protection concerns |
Category of personal data | data relevant for the exercise of the right, data provided by the notifier when reporting a breach of protection |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law |
Deadline for erasure of personal data | within 6 months from the expiry of 5 years from the exercise of the right or the occurrence of a data protection breach |
Transfer of personal data to third countries or international organizations | does not take place |
MARKETING
I. Social Networks
Purpose of processing | ensuring communication through social networks |
Legal basis | legitimate interest pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is ensuring effective communication |
Category of data subjects | those interested in information |
Category of personal data | data provided when communicating through social networks |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law |
Deadline for erasure of personal data | for the period of active use of the account on social networks |
Transfer of personal data to third countries or international organizations | does not take place |
NETWORK MANAGEMENT
Purpose of processing | ensuring network management (network security, information security) |
Legal basis | legitimate interest pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is ensuring information and network security |
Category of personal data | personal data located in defined workstations, personal data in electronic form, the processing of which is necessary for ensuring information and network security |
Deadline for erasure of personal data | depending on the processing operation, the criterion for its determination – personal data are processed on a regular basis |
Categories of recipients | entities who the operator is obliged to provide with personal data by law, authorized persons and other persons in a contractual relationship with the operator |
Category of data subjects | persons who are part of the contractual documentation, notifiers of data protection breaches, data subjects exercising rights, clients, contact persons of clients, suppliers, contact persons of suppliers, persons authorized to act on behalf of the listed entities in the case of legal persons |
PRIVATE SECURITY SERVICE
Purpose of processing | ensuring the safety and protection of property in the operator’s premises through a private security service (execution of relevant records) |
Legal basis | legitimate interest pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is ensuring the safety and protection of the company’s property |
Category of personal data | identification data of the person present in the guarded premises of D O A S, a.s. |
Deadline for erasure of personal data | recording is carried out in the event of an illegal action, or suspicion of illegal action, the deadline for erasure depends on the nature of the action (in the case of authorized actions by the data subject – 1 month from the end of the month in which the record was made/in the case of illegal actions by the data subject – depending on the scope and subsequent exercise of rights) |
Categories of recipients | entities who the operator is obliged to provide with personal data by law, authorized persons and other persons in a contractual relationship with the operator, the entity providing PCS in the operator’s premises |
Category of data subjects | persons present in the guarded premises of the operator |
Transfer of personal data to third countries or international organizations | does not take place |
MONITORING OF PREMISES WITH A CAMERA SYSTEM
The operator, company D O A S, a.s., uses a camera system with recording to ensure the safety of health and property. By means of the mentioned camera system, the operator monitors the administrative premises and the premises of industrial buildings that are under his management. By means of the camera system, the operator processes the video recording of data subjects present in the monitoring area.
Monitoring area – an area that is in the field of vision of the optics of the automatically or mechanically controlled cameras that are part of the camera system.
Administrative buildings at:
Industrial buildings at:
Personal data – in the case of monitoring premises by a camera system, an automatically stored video recording of a natural person present in the monitoring area is considered as personal data, a recording that can be used as a generally applicable identifier of the data subject. Data subject – a person present in a space that is subject to monitoring by a camera system. Camera system – a technical device – a security system with cameras located in the operator’s premises. Space accessible to the public – space that can be entered freely and in which one can stay freely without time limit or for a limited time, while other restrictions, if they exist and are fulfilled by the person, do not affect the entry and free movement of the person in this space. Space not accessible to the public – space that cannot be entered freely and in which one cannot stay freely.
MONITORING OF PREMISES WITH A CAMERA SYSTEM – ADMINISTRATIVE BUILDINGS
Purpose of processing | protection of life, health and property and ensuring safety in society |
Legal basis | legitimate interest of the operator pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is the protection of life, health and property and ensuring safety in society |
Category of personal data | video recording |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data based on a legal obligation, private security service, camera system administrator |
Deadline for erasure of personal data | 7 days from making the recording |
MONITORING OF PREMISES WITH A CAMERA SYSTEM – INDUSTRIAL BUILDINGS
Purpose of processing | protection of life, health and property and ensuring safety in society |
Legal basis | legitimate interest of the operator pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is the protection of life, health and property and ensuring safety in the operator’s premises |
Category of data subjects | persons present in the monitoring area |
Category of personal data | video recording |
Categories of recipients | authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data based on a legal obligation, private security service, camera system administrator |
Deadline for erasure of personal data | 7 days from making the recording |
Transfer of personal data to third countries or international organizations | does not take place |