Principles of Personal Data Processing

Who processes your personal data?

Your personal data are processed by D O A S, a. s. Your personal data are processed by D O A S, a. s. with its registered office at 5590/56 Košická Street, 821 08 Bratislava, company registration number: 31 373 917, registered in the Commercial Register of the City Court Bratislava III, section: Sa, insert No: 622/B (hereinafter referred to as “operator or company D O A S”). When processing personal data by the operator, you are in the position of the data subject, i.e. the person about whom personal data relating to him/her are processed. Your personal data will be processed securely, in accordance with the operator’s security policy.

What rights do you have as a data subject?

Right of access – you have the right to get a copy of the personal data we have about you, as well as the information on how we use your personal data (click HERE for application form). Right to rectification – if you believe that the data we have are inaccurate, incomplete or out of date, please do not hesitate to ask us to correct, update or complete this information (click HERE for application form). Right to erasure (to be forgotten) – you have the right to ask us to erase your personal data (click HERE for application form). Withdraw consent – in cases where we process your personal data based on your consent, you have the right to withdraw this consent at any time. Withdrawal of consent does not affect the legality of the processing of personal data that we were processing about you on its basis (click HERE for application form). Right to restrict processing – under certain circumstances, you are entitled to ask us to stop using your personal data (click HERE for application form). Right to data portability – under certain circumstances, you have the right to ask us to transfer the personal data you have provided to us to another third party of your choice (application form HERE). Right to object – you have the right to object to the processing of personal data, which is based on our legitimate interests (click HERE for application form). Right to submit a proposal to initiate a procedure on the protection of personal data – if you believe that we process your personal data unfairly or illegally, you can file a complaint with the supervisory authority, which is the Personal Data Protection Office of the Slovak Republic. Right not to be subject to automated individual decision making, including profiling. Right not to be subject to automated individual decision making, including profiling. If the provision of personal data is a legal/contractual requirement, you, as the data subject, are obliged to provide these personal data. Failure to provide personal data necessary for concluding a contract may result in not concluding a contractual relationship.In the event of an objection regarding the processing of your personal data, you have the right to submit an initiative or request in writing to the address of the company’s registered office: Košická St. 5590/56, 821 08 Bratislava or to e-mail: doas@doas.sk The operator does not transfer personal data to third countries or international organizations.

WEB

I. Contact Form

Purpose of processing ensuring communication through the contact form on the website, handling requests
Legal basis legitimate interest pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is ensuring effective communication via the web
Category of data subjects those interested in information
Category of personal data first name, last name, e-mail address, subject of the message, company name if the interested party is a legal person
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law, website administrator
Deadline for erasure of personal data 10 days from the end of the month in which the request was received

II. Newsletter

Purpose of processing sending business information, including information about the company’s activities in the form of a newsletter
Legal basis consent of the data subject pursuant to Art. 6 para. 1 letter. a) of GDPR
Category of data subjects those interested in information
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law, website administrator
Deadline for erasure of personal data 2 years from the end of the calendar year in which the consent was granted

REAL ESTATE ACTIVITY

I Pre-contractual Negotiations

Purpose of processing assessing the potential client’s demand and introducing measures before concluding the contract
Legal basis pre-contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR
Category of data subjects potential clients, a person authorized to act on behalf of a potential client, a potential client’s contact person
Category of personal data first name, last name, title, position, e-mail, phone number, identification data of the company on the basis of which it is possible to identify the data subject, the subject of pre-contractual negotiations
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law, an external partner ensuring the search for potential clients
Deadline for erasure of personal data 3 months after closing pre-contractual negotiations

II. Contract on Future Purchase Contract

Purpose of processing conclusion and administration of a contractual relationship in terms of the subject of the contract on future purchase contract, including the agreement on the termination of the contract on future purchase contract
Legal basis contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR
Category of data subjects future buyer, person authorized to act on behalf of the future buyer
Category of personal data Natural persons:title, first name, last name, maiden name, place of permanent residence, birth identification number, nationality, identity document number, status, signature, phone number, e-mail, data on the property to be the subject of the future purchase contract, future purchase price Legal persons/Self-employed persons:title, first name, last name, position of a person authorized to act on behalf of a legal person or entrepreneur in the case of self-employed persons, identification data of the company/self-employed person on the basis of which it is possible to identify the data subject in the scope of: business name, company registration number, TIN, VAT number, account number, registered office/place of business, information from the commercial register/trade register, data on the property to be the subject of the future purchase contract, the future price of the property
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law, (cooperating financial institutions, if interested in using the services in question)
Deadline for erasure of personal data 10 years from the termination of the contractual relationship

III. Purchase Contract

Purpose of processing conclusion and administration of a contractual relationship pursuant to the subject of the purchase contract
Legal basis contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR
Category of data subjects buyer, person authorized to act on behalf of the buyer
Category of personal data Natural persons: title, first name, last name, maiden name, place of permanent residence, birth identification number, nationality, identity document number, status, signature, phone number, e-mail, data on the property to be the subject of the future purchase contract, purchase price Legal persons/Self-employed persons:
title, first name, last name, position of a person authorized to act on behalf of a legal person or entrepreneur in the case of self-employed persons, identification data of the company/self-employed person, on the basis of which it is possible to identify the data subject in the scope of: business name, company registration number, TIN, VAT number, account number, registered office/place of business, information from the commercial register/trade register, data on the property to be the subject of the future purchase contract, price of the property
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law, (cooperating financial institutions, if interested in using the services in question), external partner ensuring the implementation of the project (construction, improvement of property, etc.)
Deadline for erasure of personal data 10 years from the termination of the contractual relationship

IV. Contract of Lease

Purpose of processing conclusion and administration of a contractual relationship in terms of the subject of the contract of lease
Legal basis contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR
Category of data subjects tenant/person authorized to act on behalf of the tenant if the tenant is a legal person
Category of personal data title, first name, last name, position of a person authorized to act on behalf of a legal person or entrepreneur in the case of self-employed persons, identification data of the company/self-employed person, on the basis of which it is possible to identify the data subject in the scope of: business name, company registration number, TIN, VAT number, account number, registered office/place of business, information from the commercial register/trade register, data on the property to be the subject of the contract of lease, rental price of the property
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law
Deadline for erasure of personal data 10 years from the termination of the contractual relationship

V. Contract of Lease of Non-residential Premises

Purpose of processing conclusion and administration of a contractual relationship in terms of the subject of the contract of lease
Legal basis contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR
Category of data subjects tenant/person authorized to act on behalf of the tenant if the tenant is a legal person
Category of personal data title, first name, last name, position of a person authorized to act on behalf of a legal person or entrepreneur in the case of self-employed persons, identification data of the company/self-employed person, on the basis of which it is possible to identify the data subject in the scope of: business name, company registration number, TIN, VAT number, account number, registered office/place of business, information from the commercial register/trade register, data on the property to be the subject of the contract of lease, rental price of the property
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law
Deadline for erasure of personal data 10 years from the termination of the contractual relationship

VI. Agreement on the Establishment of an Easement

Purpose of processing conclusion and administration of contractual relationships in connection with the establishment of an easement
Legal basis contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR
Category of data subjects obliged from the easement
Category of personal data first name, last name, date of birth, birth identification number, permanent residence, nationality, data on the property that is encumbered
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law
Deadline for erasure of personal data 10 years from the termination of the contractual relationship

VII. Brokerage Contract

Purpose of processing conclusion and administration of a contractual relationship in terms of the subject of the brokerage contract
Legal basis contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR
Category of data subjects those interested in brokerage
Category of personal data title, first name, last name, position of a person authorized to act on behalf of a legal person or entrepreneur in the case of self-employed persons, identification data of the company/self-employed person, on the basis of which it is possible to identify the data subject in the scope of: business name, company registration number, TIN, VAT number, account number, registered office/place of business, information from the commercial register/trade register, data on the subject of brokerage
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law
Deadline for erasure of personal data 10 years from the termination of the contractual relationship

VIII. Affidavit

Purpose of processing execution and administration of an affidavit in connection with the purchase of property
Legal basis contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR
Category of data subjects buyer
Category of personal data Natural persons: title, first name, last name, maiden name, place of permanent residence, birth identification number, nationality, identity document number, status, signature, phone number, e-mail, data on the property to be the subject of the purchase contract Legal persons/Self-employed persons: title, first name, last name, position of a person authorized to act on behalf of a legal person or entrepreneur in the case of self-employed persons, identification data of the company/self-employed person, on the basis of which it is possible to identify the data subject in the scope of: business name, company registration number, TIN, VAT number, account number, registered office/place of business, information from the commercial register/trade register, data on the property to be the subject of the purchase contract
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law
Deadline for erasure of personal data 10 years from the termination of the contractual relationship

IX. Another Contract Type

Purpose of processing conclusion and administration of a contractual relationship related to the purchase/rental of property
Legal basis contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR
Category of data subjects buyer, tenant
Category of personal data Natural persons: title, first name, last name, maiden name, place of permanent residence, birth identification number, nationality, identity document number, status, signature, phone number, e-mail, data on the property to be the subject of the purchase contract Legal persons/Self-employed persons:
title, first name, last name, position of a person authorized to act on behalf of a legal person or entrepreneur in the case of self-employed persons, identification data of the company/self-employed person, on the basis of which it is possible to identify the data subject in the scope of: business name, company registration number, TIN, VAT number, account number, registered office/place of business, information from the commercial register/trade register, data on of the property to be the subject of the purchase contract, these data may be modified depending on the contractual relationship in accordance with the principle of minimization
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law (the recipient of personal data can be a cooperating financial institution, lawyer, external partner providing property insurance, depending on the subject of the contractual relationship)
Deadline for erasure of personal data 10 years from the termination of the contractual relationship

X. Client Records

Purpose of processing records of clients and contact persons
Legal basis legitimate interest pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is effectively ensuring communication with the contractual partner
Category of data subjects clients, person authorized to act on behalf of the client, the client’s contact person
Category of personal data first name, last name, title, position, e-mail, phone number, identification data of the company, on the basis of which it is possible to identify the data subject
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law
Deadline for erasure of personal data after termination of the contractual relationship
Transfer of personal data to third countries or international organizations does not take place

PROTECTION AGAINST MONEY LAUNDERING AND PROTECTION AGAINST TERRORIST FINANCING

Purpose of processing fulfilment of obligations related to ensuring protection against the money laundering and ensuring protection against the terrorist financing
Legal basis Act No 297/2008 Coll. on protection against money laundering and terrorist financing and on amendment of certain acts (hereinafter referred to as “the Act”)
Category of data subjects clients, or other persons to whom the act applies
Category of personal data For the purpose of performing care in relation to the client and for the purpose of detecting an unusual business operation according to § 14 of the Act, the person liable is authorized to detect, acquire, record, store, use and otherwise process personal data and other data to the extent according to § 10 par. 1, § 11 par. 3 and § 12 par. 1 and 2 of the Act; at the same time, the person liable is authorized to obtain personal data necessary to achieve the purpose of processing by copying, scanning or otherwise recording official documents on a data carrier and to process birth identification numbers and other data and documents without the consent of the data subject to the extent according to § 10 par. 1, § 11 par. 3 and § 12 par. 1 and 2 of the Act

For five years from the end of the contractual relationship with the client or from the execution of occasional business outside the business relationship, the person liable is obliged to keep:

a) data and written documents obtained according to § 10, § 11, § 12 and 14 of the Act
b) all data and written documents about transactions carried out, c) all data obtained as part of the performance of care in relation to the client, records of the procedure for assessing and determining the client’s risk profile, business correspondence, results of performed analyses, records of all performed actions including possible obstacles related to them, in the manner and scope which will ensure the provability of individual transactions and the procedures associated with them

Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law
Deadline for erasure of personal data The person liable is obliged to store data for five years from the end of the contractual relationship with the client or from the execution of an occasional transaction outside the business relationship. The person liable is obliged to store data and written documents according to paragraph 2 for longer than five years, if the financial intelligence unit requests it in writing after a thorough assessment of the need and adequacy of such further storage. In the application, the financial intelligence unit shall state the period, which may not exceed the next five years, and the extent of the retention of data and written documents.
Transfer of personal data to third countries or international organizations does not take place

COMPLAINTS

Purpose of processing ensuring the complaint procedure
Legal basis Act No 250/2007 Coll. on consumer protection and on the amendment of Act of the Slovak National Council No 372/1990 Coll. on offenses as amended, contractual relationship pursuant to Art. 6 para. 1 letter. b)
Category of data subjects clients, person authorized to act on behalf of the client, the client’s contact person
Category of personal data first name, last name, title, position, e-mail, phone number, address, identification data of the company, on the basis of which it is possible to identify the data subject if the client is a legal person, subject of the complaint, data specified in the contract
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law
Deadline for erasure of personal data 2 years from handling the complaint-related agenda
Transfer of personal data to third countries or international organizations does not take place

ACCOUNTING AND TAX OBLIGATIONS

Purpose of processing fulfilment of legal obligations in the field of taxes and accounting in the area of business relations
Legal basis Act No 431/2002 Coll. on accounting, Act No 595/2003 Coll. on income tax as amended
Category of data subjects clients/suppliers, persons authorized to act on behalf of clients/suppliers
Category of personal data first name, last name, bank account number (or e-mail), payment-related data, company ID on the basis of which the data subject can be identified if the client/supplier is a legal person
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law, an intermediary ensuring the fulfilment of the operator’s legal obligations
Deadline for erasure of personal data 10 years from the fulfilment of the legal obligation
Transfer of personal data to third countries or international organizations does not take place

SUPPLIER RELATIONS

1. purpose of processing conclusion and administration of contractual relationships
Legal basis contractual relationship pursuant to Art. 6 para. 1 letter. b) of GDPR
Category of data subjects suppliers, a person authorized to act on behalf of the supplier
Category of personal data first name, last name, title, position, e-mail, phone number, correspondence address, company identification data, on the basis of which it is possible to identify the data subject
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law
Deadline for erasure of personal data 10 years from the termination of the contractual relationship
Transfer of personal data to third countries or international organizations does not take place
2. purpose of processing records of suppliers and contact persons
Legal basis legitimate interest pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is effectively ensuring communication with the contractual partner
Category of data subjects suppliers, a person authorized to act on behalf of the supplier, the supplier’s contact person
Category of personal data first name, last name, title, position, e-mail, phone number, identification data of the company, on the basis of which it is possible to identify the data subject
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law
Deadline for erasure of personal data after termination of the contractual relationship
Transfer of personal data to third countries or international organizations does not take place

EXERCISE OF THE RIGHTS OF THE DATA SUBJECTS –PERSONAL DATA PROTECTION

Purpose of processing record of the exercised rights of the data subjects and violations of protection pursuant to Act No 18/2018 Coll. on the protection of personal data and on amendment of certain acts, record of the rights of the data subjects according to Chapter III and notifications according to Art. 33 and 34 of Regulation 2016/679 on the protection of natural persons in the processing of personal data and on the free movement of such data
Legal basis legitimate interest pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is the record of rights exercised and notifications of personal data protection breaches
Category of data subjects data subjects whom the application for the exercise of the right concerns; data subjects whom the breach of personal data protection concerns
Category of personal data data relevant for the exercise of the right, data provided by the notifier when reporting a breach of protection
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law
Deadline for erasure of personal data within 6 months from the expiry of 5 years from the exercise of the right or the occurrence of a data protection breach
Transfer of personal data to third countries or international organizations does not take place

EXERCISE OF LEGAL CLAIMS

Purpose of processing record of the exercised rights of the data subjects and violations of protection pursuant to Act No 18/2018 Coll. on the protection of personal data and on amendment of certain acts, record of the rights of the data subjects according to Chapter III and notifications according to Art. 33 and 34 of Regulation 2016/679 on the protection of natural persons in the processing of personal data and on the free movement of such data
Legal basis legitimate interest pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is the record of rights exercised and notifications of personal data protection breaches
Category of data subjects data subjects whom the application for the exercise of the right concerns; data subjects whom the breach of personal data protection concerns
Category of personal data data relevant for the exercise of the right, data provided by the notifier when reporting a breach of protection
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law
Deadline for erasure of personal data within 6 months from the expiry of 5 years from the exercise of the right or the occurrence of a data protection breach
Transfer of personal data to third countries or international organizations does not take place

MARKETING

I. Social Networks

Purpose of processing ensuring communication through social networks
Legal basis legitimate interest pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is ensuring effective communication
Category of data subjects those interested in information
Category of personal data data provided when communicating through social networks
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data by law
Deadline for erasure of personal data for the period of active use of the account on social networks
Transfer of personal data to third countries or international organizations does not take place

NETWORK MANAGEMENT

Purpose of processing ensuring network management (network security, information security)
Legal basis legitimate interest pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is ensuring information and network security
Category of personal data personal data located in defined workstations, personal data in electronic form, the processing of which is necessary for ensuring information and network security
Deadline for erasure of personal data depending on the processing operation, the criterion for its determination – personal data are processed on a regular basis
Categories of recipients entities who the operator is obliged to provide with personal data by law, authorized persons and other persons in a contractual relationship with the operator
Category of data subjects persons who are part of the contractual documentation, notifiers of data protection breaches, data subjects exercising rights, clients, contact persons of clients, suppliers, contact persons of suppliers, persons authorized to act on behalf of the listed entities in the case of legal persons

PRIVATE SECURITY SERVICE

Purpose of processing ensuring the safety and protection of property in the operator’s premises through a private security service (execution of relevant records)
Legal basis legitimate interest pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is ensuring the safety and protection of the company’s property
Category of personal data identification data of the person present in the guarded premises of D O A S, a.s.
Deadline for erasure of personal data recording is carried out in the event of an illegal action, or suspicion of illegal action, the deadline for erasure depends on the nature of the action (in the case of authorized actions by the data subject – 1 month from the end of the month in which the record was made/in the case of illegal actions by the data subject – depending on the scope and subsequent exercise of rights)
Categories of recipients entities who the operator is obliged to provide with personal data by law, authorized persons and other persons in a contractual relationship with the operator, the entity providing PCS in the operator’s premises
Category of data subjects persons present in the guarded premises of the operator
Transfer of personal data to third countries or international organizations does not take place

MONITORING OF PREMISES WITH A CAMERA SYSTEM

The operator, company D O A S, a.s., uses a camera system with recording to ensure the safety of health and property. By means of the mentioned camera system, the operator monitors the administrative premises and the premises of industrial buildings that are under his management. By means of the camera system, the operator processes the video recording of data subjects present in the monitoring area.
Monitoring area – an area that is in the field of vision of the optics of the automatically or mechanically controlled cameras that are part of the camera system.
Administrative buildings at:

  • AB DOAS, Košická 5590/56, 82108, Bratislava
  • VisionPark BA, Pribylinská 10, Bratislava

Industrial buildings at:

  • AB DOAS, Košická 5590/56, 82108, Bratislava
  • Parking Garage, Košická 54, 82108, Bratislava
  • VisionPark BA, Pribylinská 10, Bratislava

Personal data – in the case of monitoring premises by a camera system, an automatically stored video recording of a natural person present in the monitoring area is considered as personal data, a recording that can be used as a generally applicable identifier of the data subject. Data subject – a person present in a space that is subject to monitoring by a camera system. Camera system – a technical device – a security system with cameras located in the operator’s premises. Space accessible to the public – space that can be entered freely and in which one can stay freely without time limit or for a limited time, while other restrictions, if they exist and are fulfilled by the person, do not affect the entry and free movement of the person in this space. Space not accessible to the public – space that cannot be entered freely and in which one cannot stay freely.

MONITORING OF PREMISES WITH A CAMERA SYSTEM – ADMINISTRATIVE BUILDINGS

Purpose of processing protection of life, health and property and ensuring safety in society
Legal basis legitimate interest of the operator pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is the protection of life, health and property and ensuring safety in society
Category of personal data video recording
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data based on a legal obligation, private security service, camera system administrator
Deadline for erasure of personal data 7 days from making the recording

MONITORING OF PREMISES WITH A CAMERA SYSTEM – INDUSTRIAL BUILDINGS

Purpose of processing protection of life, health and property and ensuring safety in society
Legal basis legitimate interest of the operator pursuant to Art. 6 para. 1 letter. f) of GDPR. The main legitimate interest is the protection of life, health and property and ensuring safety in the operator’s premises
Category of data subjects persons present in the monitoring area
Category of personal data video recording
Categories of recipients authorized persons in a contractual relationship with the operator, entities who the operator is obliged to provide with personal data based on a legal obligation, private security service, camera system administrator
Deadline for erasure of personal data 7 days from making the recording
Transfer of personal data to third countries or international organizations does not take place