GDPR

This document provides information on the processing of personal data of external individuals and the rights related to this processing, particularly for the following data subjects:

  • employees and other cooperating individuals of our (potential) business partners, i.e., customers, suppliers, subcontractors, and collaborators,
  • employees and other individuals cooperating with persons providing various support services for our company, such as employment agencies, carriers, etc.,
  • self-employed individuals acting as business partners or providing support services,
  • visitors to our premises,
  • or other third parties whose personal data we are authorized to process.

We are the controllers of your personal data, and our primary contact details are:

OSTROJ a.s., IČO 451 93 681, se sídlem Těšínská 1586/66, Předměstí, 746 01 Opava
The company is registered in the Commercial Register of the Regional Court in Ostrava, Section B, Insert 349.
e-mail: gdpr@ostroj.cz, phone: + 420 553 872 111, www.ostroj.cz

On what legal basis and for what purpose will we process your personal data:

  • For the purpose of measures necessary to conclude a contract and subsequently to fulfill the concluded contract, including negotiations for contract conclusion, mutual discussions and correspondence, and compliance with the terms of the concluded business contract (delivery and acceptance of goods and services, including warranty and service conditions, etc.).
  • For the purpose of fulfilling legal obligations imposed on us by generally binding legal regulations, particularly the Accounting Act, the Value Added Tax Act, the Income Tax Act, etc., including issuing accounting and tax documents, maintaining accounting records, paying taxes, and related activities.
  • For reasons of our legitimate interest, particularly for the purpose of protecting property and personal safety, security, damage prevention, and the exercise and defense of our legal claims, especially debt recovery and defense against third-party claims, but always only when your interests and rights do not take precedence.

and this without the need for your consent.

With your consent:

There may be situations where we will require your explicit consent for certain purposes of personal data processing. In such cases, the provision of your personal data will be entirely voluntary, and you can withdraw your consent at any time. When granting consent, we will provide you with detailed information about this processing, its purpose, and your rights.

What personal data will we process:

We will process primarily the personal data listed below, always only to the necessary extent:

  1. Identification data, which include, in particular, first and last name, company name/trading name, title, date of birth, company identification number (IČO), tax identification number (DIČ), type and number of identity document, physical appearance captured by the camera system,
  2. Contact details, which include, in particular, permanent address, registered office or place of business, delivery address, email address, phone number, or any other contact information you provide to us,
  3. Payment and billing information, which includes, in particular, bank account number and billing address,
  4. Other data beyond the information mentioned in points A-C, such as the goods or services you order from us or we provide to you, data from mutual communication, data obtained during a visit to our premises, vehicle registration number, etc.

For completeness, we note that personal data is obtained either directly from you and/or from publicly available sources (e.g., the commercial register, trade register, land registry, from your website, etc.).

We operate a surveillance camera system

We operate a surveillance camera system on our premises for the purpose of protecting property and personal safety, ensuring security, and preventing damage. The operation of the camera system involves processing personal data of individuals, specifically capturing their physical appearance on the camera footage. The scope and placement of the individual camera systems are available here. Specific locations are clearly marked with an information sign. The recordings are stored on secure storage systems for a maximum period of 7 days and are then overwritten in loops, unless a longer storage period is required for the protection of our legitimate interests (e.g., for the purposes of an investigation by the Czech Police). For further information about the operation of the camera system, please contact the Head of Asset Management (use the contact details provided above).

What security measures will be in place for your personal data?

We handle your personal data with due care and in accordance with the GDPR and other applicable legal regulations. We strictly adhere to security measures and protect personal data to the highest possible extent, based on the technical capabilities of available resources; access to personal data is granted only to authorized individuals who are trained in the handling of personal data.

You have the right to:

  1. access to your personal data that we process – in simple terms, you have the right to know what data we process about you and why;
  2. the correction of your personal data if it is incomplete or inaccurate;
  3. the deletion of your personal data, or the restriction of its processing, if we no longer have a legal basis for processing it;
  4. the right to object to processing based on our legitimate interest;
  5. the right to transfer your personal data that you have provided to us to another controller;
  6. the right to withdraw your consent if we process your personal data based on your consent, without any additional costs or consequences. However, the withdrawal of consent will not affect the lawfulness of the processing of personal data based on that consent before its withdrawal.

Sharing of personal data with third parties

As a rule, we do not provide personal data to third parties. The exception is situations where this obligation arises from legal regulations (particularly in relation to government authorities) or in relation to external companies that provide us with support services (e.g., site security, insurance), to whom we provide personal data only to the minimum extent necessary and who are contractually obligated to ensure appropriate protection and security of personal data.

We do not intend to transfer personal data to third countries or international organizations outside the EU.

We do not engage in automated decision-making.

Your personal data will not be used for decision-making based solely on automated processing or profiling.

How long do we retain personal data?

We retain personal data only for as long as necessary to fulfill the purpose for which it is processed, and also for the duration required to protect our legitimate interests. Personal data processing principles at OSTROJ a.s. – for external individuals, particularly for the exercise or defense of our legal claims. Typically, this period does not exceed 3 years from the last contact with you. In some cases, it may be longer, depending on the archival periods established by applicable legal regulations, such as the Archives Act, the Accounting Act, etc.

You can contact us at any time.

You can contact us anytime via email at: gdpr@ostroj.cz, or use the other contact details provided above. We will address your request promptly, but you may be asked for additional information. The request may be subject to a fee under certain conditions, particularly if it is clearly unjustified or excessive, especially if it is repetitive.

You have the right to file a complaint with the supervisory authority.

Contact details for the supervisory authority: The Office for Personal Data Protection, located at Pplk. Sochora 27, 170 00 Prague 7., www.uoou.cz

img

Get in touch

Fill out the form or contact us, and we will get back to you.

Attachment
By submitting, you agree to the processing of personal data

OSTROJ a.s.
Tesinska 1586/66
746 01 Opava, CZ