Personal data protection
GDPR
- GDPR. Data protection is very important to us. For this reason, we ensure compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“GDPR”).
- Identity and contact details of the operator. Your personal data is processed by the controller: Zhiva, j. s. a., with registered office at Robotnícka 11591/1J, 036 01 Martin, ID No.: 53766148, registered in the Commercial Register of the District Court of Žilina, Section: Sja, Insert No.: 18/L, email: info@zhiva.sk
- Objective. Your personal data is processed for the purpose of
(a) handling your enquiry or answering a question you send us via the “Contact Us” contact form, or evaluating your feedback and suggestions for improvement;
b) to assert rights and claims or conduct legal defence, in out-of-court negotiations, court and other proceedings and processes, if initiated;
c) the fulfilment of obligations under GDPR, in particular the handling of enquiries, requests, security incidents in the area of personal data protection. - Categories of personal data. We process your personal data that you provide when registering on zhiva.sk. Thus, when registering on zhiva.sk, you fill in the following data:
(a) Your personal data that you provide in the “Contact us” contact form, in particular your name, e-mail and the personal data specified in the content of the message you send us. - Affected persons. We only process the personal data of those individuals who have completed and submitted the contact form and voluntarily provided their other personal data on the zhiva.sk website.
- Legal basis. For the processing of your personal data, we need to have a proper legal basis, and in the case of the purposes of processing personal data under paragraph 3 (a) to (c), it is your consent, which you give us before submitting the contact form and thus before making an inquiry on the zhiva.sk website. Since the personal data you fill in on zhiva.sk may also relate to your health, we need your explicit consent, as otherwise the processing of this special category of personal data is prohibited. You give your consent to the processing of your personal data when you submit the contact form on the zhiva.sk website by clicking (opt-in) to consent to the processing of your personal data. You are entitled to withdraw your consent to the processing of personal data at any time by sending a request to the e-mail address of the operator info@zhiva.sk. The processing for the purpose referred to in paragraph 3 (b) is carried out on the legal basis of a legitimate interest of our company, which will assert its rights and claims in the event of any dispute, or conduct an appropriate defence against claims that we believe would be unjustifiably asserted against us; the aforementioned is also permitted pursuant to Article 9 (2) (f) of the GDPR. In the case of the processing of personal data for the purpose referred to in paragraph 3 (c), this is carried out on the grounds that it is necessary for the fulfilment of the legal obligation of the controller arising from the GDPR and data protection legislation.
- Beneficiaries. Only our employees, collaborators and contractors who ensure the implementation of solutions, in particular our intermediaries, have access to your personal data provided via zhiva.sk (i) ESPRI, s. r. o., with registered office Koperníkova 47, 821 04 Bratislava, ID No.: 36 764 442. Due to the fact that communication with you is carried out in the online space, we also use the services of external partners in this regard, who provide cloud services and hosting for us. The cloud servers (Amazon Web Services) on which your personal data is stored are located in the European Union and therefore your personal data is not transferred to third countries or international organisations.
- Retention period. Your personal data will be processed for no longer than is necessary to achieve the purpose of the processing, i.e. for the duration of the consent you have given and which has not been withdrawn by you, but for a maximum of 5 years from the date of consent. After this period, we may request consent from you again, and you are free to choose whether or not to grant it. The retention period starts on 1 January of the calendar year following the year in which you gave us consent. We will process the personal data processed for the purposes of paragraph 3(b) and (c) for as long as we can reasonably be expected to need to process it (e.g. until the expiry of a limitation period or the possibility of initiating proceedings or imposing a penalty). After the retention period has expired, we will anonymise your personal data or ensure that it is permanently deleted.
- Rights of the data subject. As a data subject, you have several rights under GDPR, including the right to withdraw consent to the processing of personal data, the right of access to personal data pursuant to Article 15 of the GDPR, the right to rectification and/or completion pursuant to Article 16 of the GDPR, the right to erasure in the cases referred to in Article 16 of the GDPR, the right to data protection pursuant to Article 15 of the GDPR, the right to data protection pursuant to Article 16 of the GDPR, the right to data protection pursuant to Article 15 of the GDPR and the right to data protection pursuant to Article 16 of the GDPR. 17 GDPR, the right to restrict their processing pursuant to Article 18 GDPR, the right to data portability pursuant to Article 20 GDPR if the processing is based on a legal basis of consent and the right to lodge a complaint with the supervisory authority – the Office for Personal Data Protection of the Slovak Republic (https://dataprotection.gov.sk/uoou/). In the case of processing of personal data on the legal basis of legitimate interest, you have the right to object to the processing of personal data pursuant to Article 21 GDPR. Individual rights can be exercised by sending a request to the email address of the controller indicated above or by sending a written request to the address of the controller’s registered office, unless otherwise specified in these terms and conditions.
- Disclosure of personal data. The provision of your personal data is voluntary, but failure to provide it may result in the inability to use the Zhiva application and its individual functionalities, or the inability to obtain or provide data and information about the Zhiva application. In the case of a legitimate interest or to comply with a legal obligation, disclosure may be required under the relevant generally applicable law.