NOTICE FOR THE PROCESSING OF PERSONAL DATA
This Privacy Notice (hereinafter: ‘Notice’) describes the way in which we deal with the personal data that we collect, use, or otherwise process. This Notice does not address the processing of personal data of our employees, which is subject to a separate set of rules. ‘Personal data’ means any information relating to an identified or identifiable natural person (‘data subject’).
We will process your personal data in the way and for the purposes specified in this Privacy Notice. The collection and processing of your personal data is carried out in accordance with current data protection legislation, in particular in accordance with Regulation (EU) 2016/679 (hereinafter: ‘General Data Protection Regulation’), the Act on Implementation of General Data Protection Regulation (OG No. 42/2018) as amended from time to time, and other applicable data privacy and protection regulations.
- Who is the data controller?
The controller for the processing of your personal data with regard to the purposes specified in this Notice is Markoja d.o.o., Selska cesta 93, Zagreb, OIB: 10585552225 (hereinafter: ‘Markoja’). In case of any requests relating to the processing of your personal data or in case of exercising your rights set out in Clause 4 of this Notice, you can contact us in person, by phone: +385 1 3651 340 or by email at firstname.lastname@example.org.
- What personal data do we collect about you? For what purpose and for how long do we collect it?
We process your personal data only to the extent determined by the particular services we provide to
- For the purpose of protecting persons and property through video surveillance of external entrances to the buildings, as well as entrance halls and parts of the office and other premises, we may process video recordings of the specified spaces that record your face. This processing is based on our legitimate interest and the personal data will be processed for a period specified by relevant standards and legislation but no longer than six months. Only a responsible person authorized by Markoja has the right to access these records. Moreover, in order to prevent unauthorized access to such records, Markoja has set up an automated video surveillance and access control system, in accordance with applicable regulations.
- For the purpose of performance of a contract to provide goods and services to our users, we process the personal data of our current users, persons authorized to represent our beneficiaries who are legal persons, their employees, persons associated with them, and third parties such as persons who are authorized by our users to take certain actions for the purpose of performance of a contract. Such personal data may include name, surname, personal identification number, date and place of birth, sex, place of residence, email address, vehicle registration and phone number. The legal ground for such processing is the performance of a contract to provide goods and services, i.e. the legitimate interest of the data controller. The personal data will be processed for the duration of the contractual relationship and up to five years from the beginning of the statutory limitation period in each particular case. In the event that you as a user do not provide us with all the required information, we may not be able to enter into a contract with you or perform all of our obligations arising from such contract.
- For the purpose of compliance with the obligations laid down by relevant legislation, in particular the Accounting Act, the Electronic Communications Act, and General Tax Code, we process your personal data, which may include name, surname, personal identification number, date and place of birth, sex, place of residence, email address, phone number. The processing is based on compliance with legal obligations to which we are subject. The personal data will be processed for a period specified by the particular legislation.
- For employment purposes, we collect the personal data of potential employees and other candidates (e.g. students on internship). Personal data collected in this regard includes CVs and/or other data usually found in a CV and/or usually relating to the recruitment process, such as name, surname, personal identification number, date and place of birth, sex, place of residence, email address, phone number, information on education and past work experience, and photographs. This information may also include specific categories of personal data (e.g. health status). In the event that you do not provide us with all the required information, we may not be able to enter into a contract with you or perform all of our obligations arising from such contract. If a candidate is not offered a position, i.e. an individual role on a given occasion, but we consider that such candidate may be suitable for a different role in the future, with the consent of such candidate, we may keep their personal data for future consideration. The data
- collected on the basis of consent given for future employment considerations will be erased after the withdrawal of consent and/or termination of processing due to the fulfillment of the purpose for which it was given and/or termination of processing due to the decision of the national data protection authority.
- For the purpose of providing information about our goods and services, we may process the personal data of our users, potential users and their employees, including name and surname, email address, phone number, job title. This personal data is collected during our business contacts based on consent or legitimate interest. However, you may opt out of such notifications about our offers and services at any time (i.e. you may request exclusion from the database). Consent given for the purpose of providing information about our services is valid until its withdrawal and/or termination of processing due to the fulfillment of the purpose and/or termination of processing due to the decision of the national data protection authority.
- For the purpose of ensuring IT system and network security, we may process your personal data in the scope necessary to ensure access to physical premises and information systems, and for the purpose of establishing mutual confidentiality obligations. The legal ground for such processing is our legitimate interest or the legitimate interest of a third party. Your personal data will be processed for the time required to fulfill this purpose.
- For the purpose of responding to user inquiries via www.markoja.hr contact form, we may process your personal data including name and surname, email address, phone number, and IP address. Such processing is based on legitimate interest or actions taken at the request of the data subject prior to concluding a contract. Your personal data will be processed for the time required to fulfill this purpose.
- For the purpose of enabling the use of markoja.hr web pages, we may process your personal data including network identifiers, technical cookies and related technical data. The legal ground for such processing is our legitimate interest. The personal data will be processed and stored for a period that is necessary for ensuring functionality of the website. Visitors of our website are not required to provide personal information to use most of its functionalities. However, visitors who want to send an inquiry via the contact form available on our website must fill in their name and surname, phone number, and email address.
- Furthermore, we may process and store your personal data including name and surname, phone number, email address, contract identification number for the purpose of potential claims in the future. This processing is based on our legitimate interest or the legitimate interest of a third party. The personal data will be processed for the period necessary to fulfill this purpose, however, no longer than ten years from the beginning of the statutory limitation period in each particular case.
- With whom do we share your personal data?
In certain cases, your personal data may be shared with trusted third parties providing us with
administrative and technical support or data processors implementing appropriate technical and
security measures and personal data protection mechanisms. We may also share your personal data with public authorities when such obligation is laid down in the applicable legislation and in accordance with their legal powers, as well as with external advisors and with other personnel who is subject to confidentiality obligations. We carefully select and monitor the work of such service providers. Only a limited number of our employees will have access to your personal data. Employees shall keep your personal data and measures taken for their protection strictly confidential. They have the right to handle personal data only according to our explicit instructions.
- What are your rights in relation to the processing?
At your request, we will inform you about the processing of your personal data and which data is processed. If all legal requirements are met, you have the right to rectification, erasure or restriction of processing of personal data. You can withdraw all declarations of consent that you have given and object to the processing. For this purpose, you can contact us through the channels indicated under point 1. You also have the right to receive the data you have provided to us in a structured, commonly used and machine-readable format; and you may request the transfer of this data to you or third parties. We shall respond to your request within one month from the date of receipt of your request, unless a longer period of time is required, in which case this period shall not exceed two months. You also have the right to lodge a complaint with the Croatian Personal Data Protection Agency, Martićeva 14, 10000 Zagreb, www.azop.hr, if you suspect a breach in the processing of your personal data. If you grant us your consent to the processing of your personal data, you do so entirely voluntarily and you have the right to withdraw or restrict the consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. If your personal data is processed for the purposes of direct marketing or on the basis of a legitimate interest, you also have the right to object to such processing at any time.
- How long do we keep your personal data?
We will only store your personal data for as long as necessary to fulfill the purpose of the processing in question, i.e. typically for the period of performance of the contractual relationship or for the period explicitly required by the applicable legislation. If we process your personal data based on your consent, such personal data will only be processed for the duration of the consent which you may withdraw or restrict at any time. If you do so, we will stop processing the personal data in question for the purposes for which you have given your consent. After that, your data will be deleted or anonymized, unless this data needs to be stored for a certain period of time for legal reasons, i.e. in accordance with corporate law, tax law or other regulations, iđ which case this data will no longer be processed for other purposes.
- Links to third-party websites
Our website may contain links to third-party websites. If you click on such links, such third parties may collect certain information about you, such as your IP address or search history, and may place cookies on the browsers of visitors. Please note that the processing of personal data collected in this way is subject to the rules adopted by the operators of such third parties and, therefore, this Notice does not apply.
- What if there are any changes to the processing?
Any changes to this Notice will be posted on our website www.markoja.hr and available through the
usual communication channels.
This Notice was last updated on 20 June 2019.