Protecting the security and safety of personal data (hereinafter referred to as “PD”) is important to us, therefore, our activities are in accordance with applicable law on the protection and security of data (Regulation (EU) 2016/679 with subsequent amendments and completions, as well as the relevant Romanian legislation).
Through the procedures we develop, we aim to explain simply and transparently what type of data we collect, how and for what purpose we process it, how we protect it and how we respect the rights of data subjects.
TO WHOM THE POLICY APPLIES
This GDPR Policy (hereinafter referred to as “the Policy”) applies to, but is not limited to, the following categories of individuals:
- our employed staff;
- candidate staff for employment;
- the representatives of the clients with whom we have negotiated and / or, as the case may be, concluded contracts;
- representatives of suppliers of products and / or services;
- the employees and the clients of legal entities with which we have negotiated and / or concluded contracts;
- individuals – participants in events, webinars, courses, training programs etc.;
- individuals – participants in the process of recruitment, employment and / or management of human resources (including natural persons agents / intermediaries).
Processing of personal data (PPD) means any operation or set of operations performed on personal data or personal data sets, with or without the use of automated means, such as collection, registration, organization, structuring, storage, adaptation or modification, extraction, consultation, use, disclosure by transmission, dissemination or making available in any other way, alignment or combination, restriction, deletion or destruction.
CATEGORIES OF PROCESSED PERSONAL DATA (PD)
The personal data we collect depends on the categories of data subjects, as follows:
- PD of our staff: name, surname, domicile / residence, date and place of birth, sex, nationality, series and no. of the national identity card, CNP, phone no. / mobile, e-mail, parental first name, spouse data, minor children data, professional training, bank information (bank account for payment of salaries), health status (skills sheet), biometric data captured, as appropriate, by the cameras systems for monitoring or conducting online activities;
- PD of candidates for employment: name, surname, domicile / residence, date and place of birth, sex, nationality, series and no. of the national identity card, CNP, phone no. / mobile, e-mail, professional training;
- PD of the customer representatives with whom we negotiated and / or concluded contracts: first name, last name, position, signature;
- PD of the representatives of the suppliers of products and / or services: first name, last name, position, signature;
- PD of individuals – participants in events, webinars, courses, training programs etc.: name, surname, series and no. of national identity card, CNP, address, place and date of birth, marriage certificate, diploma of studies, skills file, personal mobile no., e-mail, signature, biometric data captured by the cameras of the online business systems;
- PD of individuals – participants in the process of recruitment, employment and / or management of human resources (including natural agents / intermediaries): name, surname, series and no. of national identity card, CNP, address, place and date of birth, marital status, professional training, personal mobile no., e-mail, signature;
- PD of all individuals listed above: biometric data coming from video recordings captured by the cameras of possible video monitoring / surveillance systems.
PURPOSE OF PROCESSING
The processing and provision of personal data is done in order to achieve the purpose for which they were collected and only in the name and for the customer, respecting the provisions of the GDPR, European Union law and Romanian legislation in force applicable in the matter.
The processing of personal data is done, in principle, but not limited to them, for:
- concluding employment contracts and / or other employment relationships;
- labor recruitment;
- concluding sale-purchase contracts and service contracts;
- concluding internship agreements and continuing education contracts;
- concluding collaboration contracts (eg suppliers of products and / or services, subcontractors etc.);
- executing sale-purchase contracts and service contracts;
- preparation of payment instruments related to the services performed;
- maintaining communication between the parties, for the proper performance of contracts (services or collaboration);
- managing customer relations, obtaining feedback on the activities carried out, in order to increase the quality level of services, services and / or goods;
- video surveillance.
TO WHOM PERSONAL DATA (PD) IS TRANSMITTED
Personal data (PD) is transmitted to the authorized persons of the operator to fulfill the provisions of the contract, to the authorized persons of the operator’s collaborators in order to perform the service contracts, to the authorized persons in order to perform the payment instruments related to the services with personal character, to the banks for the payment of salaries, to the suppliers regarding the insurance of other salary rights if applicable (meal vouchers, gift vouchers etc.) and, exceptionally, to other persons and institutions under the conditions provided by the applicable legislation.
As an operator, we process personal data (PD) for the purpose and in the situations set out above, in accordance with legal provisions and we will not store this data for personal purposes, contrary to law or for sale to third parties.
The transmission of personal data to third parties is done only at the express written notification of the operator by the customer or by the data subject and / or in cases where the law expressly provides for this.
The transfer of personal data is carried out in secure conditions, by the person authorized by the operator.
SECURITY OF PERSONAL DATA
In order to protect personal data from accidental or illicit destruction, from their loss or alteration and from the access of unauthorized persons, we make every effort to implement technical and organizational measures in the following directions: physical protection, personnel protection and information protection.
The transmission of personal data to third parties is done only at the express written notification of the operator by the customer or the data subject and / or in situations where the law expressly provides for this.
The transfer of personal data is carried out, in secure conditions, by the person authorized by the operator.
DURATION OF PERSONAL DATA PROCESSING
The processing of personal data is done throughout the duration of the contracts, regardless of their nature, and the data may be or are, as the case may be, subsequently retained, according to the provisions of the relevant legislation or according to internal procedures and policies.
THE RIGHTS OF THE PERSONS CONCERNED
The operator undertakes to respect the rights of data subjects in accordance with the provisions of the GDPR and the applicable legislation in force, namely: the right of access, rectification, the right to delete data (to be forgotten), the right to withdraw consent, the right to restrict consent, the right to restrict processing, the right to data portability, the right to object, the right not to be subject to a decision based solely on automatic processing of personal data, the right to lodge a complaint, the right to have recourse to justice.
The person / persons empowered and the persons authorized for the processing of personal data is / are appointed by internal decision and has / have specified in the job description the attributions incumbent on him / her in this respect.
The processing of personal data is done only after obtaining the consent of the data subject, and the person / persons empowered and / or authorized persons for the processing of personal data are instructed on the importance of maintaining the confidentiality of such data and the risks involved in processing personal data.
We are committed to making all necessary efforts to ensure the security and confidentiality of personal data processed on both paper and computer media.
Important: This GDPR Policy is complemented, where appropriate and possible, by our Privacy and personal data protection Policy.