This document contains information for data subjects regarding the processing of their personal data  in the organisation, within the framework of the requirements imposed on the organisation as a  data controller by Article 13 of REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND  OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing  of personal data and on the free movement of such data, and repealing Directive 95/46/EC  (hereinafter referred to as GDPR).

Who processes your data?

Vortex steel s.r.o.
Butovická 137, Butovice, 742 13 Studénka
C 74883 registered at the Regional Court in Ostrava
Contact e-mail: dvorakova@vortexsteel.cz
hereinafter referred to as "we" or "controller" or "organisation"

What is personal data?

Personal data is virtually any information that can directly identify a living natural person or is  intended to reach such a person. Personal data can be divided into general (e.g. first and last name,  age, telephone number, place of birth, personal status, etc.) and sensitive (nowadays referred to as  special categories of personal data, with only the following personal data - biometric data, trade  union/political party membership, ethnic origin, philosophical beliefs, genetic data, information on  convictions and criminal offences, religious beliefs, political opinions, racial origin sexual  orientation/life, health status).

What is the processing of personal data?

Processing of personal data means the systematic activity that a controller carries out with personal  data for a specific purpose. The activities referred to in the preceding sentence are, in particular:  collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval,  consultation, use, disclosure by transmission, dissemination or any other disclosure, alignment or  combination, restriction, erasure or destruction.

Sources and categories of personal data:

The Controller processes personal data (directly from you) that you have provided to it or personal  data that it has obtained as a result of fulfilling your order.  Your identification and contact data and data necessary for the performance of the contract.

Lawful basis and purpose of processing

The lawful basis for processing is:

Your consent to the processing of your personal data for the purpose of providing direct marketing  pursuant to Article 6(1)(a) GDPR.

For the purpose of concluding and performing a contract (i.e. in accordance with the provision of our  services), we process your personal data in accordance with the provisions of Article 6(1)(b) GDPR.  The legal basis for the processing of your general personal data is therefore the contract.

Once the contract has been fulfilled, we must store your personal data for the period of time  prescribed by the relevant legislation. Here, the legal basis for the processing of your general  personal data is the fulfilment of a legal obligation, which is provided for in Article 6(1)(c) GDPR.

The purpose of the processing of personal data is:

To process your order and to exercise the rights and obligations arising from the contractual  relationship between you and the Controller. When placing an order, the personal data required for  the successful execution of the order are required in accordance with Article 1(b) of the Regulation  (this also includes the subsequent payment, delivery of services, handling of complaints, etc.); We  use the personal data you provide to us to conclude a contract with you and, if a contract is already  concluded between us, then we use it to fulfil it. The processing of the customer's personal data is  carried out without the customer's consent, as the legal basis for the processing of his/her personal  data for the purposes of contract performance is the specific contract between the customer and  the operator. The provision of personal data is a necessary requirement for the conclusion and  performance of the contract, without the provision of personal data it is not possible to conclude the  contract or for the operator to fulfil its terms.

What personal data will we process and to what extent?

In order to provide you with our services, we need to know the following personal data:  General personal data : name and surname, address of residence, address of delivery of services or  goods, your telephone number and email,

How long will we keep the data?

We will keep your personal data for as long as we fulfil our mutual contract. After the end of the  contractual relationship, we will keep your personal data for as long as necessary to comply with the  necessary archiving obligation under the legal regulations that provide for archiving (these  regulations are, for example, the Accounting Act, the Value Added Tax Act, the Archives and Records  Act ).

To whom do we pass on your personal data?

Your personal data may be transferred to the following parties: providers of legal, tax and  accounting services, providers of technical solutions.

Your personal data may also be passed on to public authorities and courts, but only if a specific legal  regulation so provides or you give your explicit consent.

Your personal data is always transferred to our processors on the basis of a processing contract and  in accordance with the minimum data protection standards required by the GDPR.

The controller does not disclose, publish or make personal data available to third countries

Personal data security conditions

The controller declares that it has taken appropriate personnel, technical and organizational  measures to ensure the protection of personal data.

The controller has taken technical measures to secure data storage and storage of personal data in  file form.

The controller declares that personal data can be accessed only by persons authorised by him.

There is no automated decision-making or profiling in the personal data processing activities we  carry out in the course of our business.

What are your rights in relation to the processing of your personal data?

Under the conditions set out in the GDPR, you have:

- The right to access your personal data under Article 15 of the GDPR.
- The right to rectification of your personal data under Article 16 of the GDPR
- Right to restriction of processing
- Right to erasure under Article 17 GDPR
- Right to object under Article 21 GDPR
- Right to transfer personal data pursuant to Article 21 GDPR
- The right to withdraw consent (electronically or to a postal address)
- The right to lodge a complaint with the Data Protection Authority if you believe that your data  protection rights have been violated.

How can you exercise your rights?

Right of access

Upon your request, we must tell you whether or not we are processing your personal data. If we are  processing it, then you have the right to be told:
a) for what purpose we are processing your data,
b) the extent to which it is processed
c) how long it will be kept
d) to whom it will be disclosed
e) whether you can lodge a complaint with the Data Protection Authority.

You can submit your request electronically, by email to dvorakova@vortexsteel.cz or by post to  Butovická 137, Butovice, 742 13 Studénka

Right to rectification

If you believe that we are processing your incorrect (inaccurate) personal data, you have the right to  have it corrected. If you discover such inaccuracy in your personal data, please let us know and we  will correct it without undue delay.

You can submit your request electronically, by email to dvorakova@vortexsteel.cz or by post to  Butovická 137, Butovice, 742 13 Studénka

Right to remove

Under certain circumstances you have the right to have your personal data erased. You can ask us to  delete your data at any time. We will delete your personal data if:

- We no longer need your personal data for the purpose for which you provided it to us,
- you withdraw your consent,
- you object to the processing of your personal data,
- we process your personal data unlawfully,
- the personal data must be erased in order to comply with a legal obligation,
- if you are a child or parent of a child who has consented to the processing of personal data via the  internet.

Right to restriction of processing

You can ask us to restrict the processing of your personal data. If we comply with your request, we  will only store your personal data and will not process it further. The processing of your data will be  restricted if:

- Your personal data is incorrect until we have verified its accuracy,
- we are processing your personal data unlawfully, but you do not consent to its erasure and instead  request that we only restrict the processing of your personal data,
- we no longer need your data but you need it to prove, exercise or defend your rights
- you object to the processing of your personal data until we have verified that our legitimate  interests outweigh your reasons.

Right to data portability

You have the right to request that we provide you with your personal data in an electronic form (e.g.  an XML or CSV file) that allows you to easily transfer your data to another company. You can also ask  us to transfer your personal data directly to the company of your choice. We will comply with your  request if you have provided us with personal data directly and have given us your consent to  process it

Right to object

You have the right to object to us processing your personal data. If we process your personal data  in the following cases:

- for reasons of our legitimate interest,
- creating a customer profile,
- you can object to the processing if you have personal reasons to do so.  

How can you exercise these rights?

You can contact us with your request in any of the following ways:  By email: dvorakova@vortexsteel.cz or by post to Butovická 137, Butovice, 742 13 Studénka

If you believe that your personal data protection rights have been violated, you have the right to  file a complaint with the supervisory authority, the Office for Personal Data Protection, at:

Data Protection Authority
Pplk. Sochora 27
170 00 Prague 7
70837627

Phone: switchboard: +420 234 665 111 (does not provide consultations)
information: +420 234 665 800 (information line is available on Tuesdays and Thursdays   From 13.00 to 15.30)
WWW: https://www.uoou.cz
E-mail: posta@uoou.cz
Mailbox ID: qkbaa2n

Tyto Zásady ochrany osobních údajů jsou platné a účinné od: 24.04.2019
Updated 06.10.2022