The provided information regulates the conditions for the protection of personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (hereinafter referred to as the "Personal Data Protection Regulation") and Act No. 18/2018 Coll. on the protection of personal data and on the amendment and supplementation of certain laws (hereinafter referred to as the "Personal Data Protection Act"), effective from 25.05.2018, in connection with personal data provided by data subjects to the controller on its website.
Controller: Urocard, s.r.o., with registered office at Osloboditeľov 431/40, Košice - Barca district 040 17, Company ID: 53 814 380, registered in the Commercial Register of the District Court Košice I, insert 51640/V.
Phone: +421 56 672 7718
Email: info@nehnutelnostivdubaji.sk
Website:
Personal data means any information relating to an identified or identifiable natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, surname, identification number, location data, online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Processing of personal data means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Data subject means any natural person whose personal data are processed.
Controller means the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data and processes personal data on their own behalf.
Processor means a natural or legal person who processes personal data on behalf of the controller.
Restriction of processing personal data means marking stored personal data with the aim of limiting their processing in the future based on the data subject's request under the conditions set out in this information.
Personal data are processed by the controller lawfully in accordance with the Personal Data Protection Regulation and the Personal Data Protection Act so that the fundamental rights of the data subject are not violated.
The controller collects personal data for a specific, legitimate and explicitly stated purpose and does not further process personal data in a manner incompatible with that purpose.
Processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes is in accordance with a special regulation and appropriate safeguards for the rights of the data subject are observed.
The personal data processed are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
The personal data processed must be accurate and, where necessary, kept up to date. The controller shall erase or rectify without delay personal data that are inaccurate with regard to the purposes for which they are processed.
The controller stores personal data in a form that permits identification of the data subject for no longer than is necessary for the purposes for which the personal data are processed. Personal data may be stored for longer periods if processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with a special regulation and with appropriate safeguards for the rights of the data subject.
Personal data are processed by the controller in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical and organizational measures.
The data subject has the following rights in connection with the processing of their personal data:
The right to request access to personal data from the controller:
The data subject has the right to obtain from the controller confirmation as to whether or not personal data concerning them are being processed.
The controller is obliged to provide the data subject with the personal data it processes. For repeated provision of personal data requested by the data subject, the controller may charge a fee corresponding to the administrative costs related to handling the request.
The controller is obliged to provide personal data to the data subject in the manner requested.
In addition to providing the personal data processed, the controller shall provide the data subject with information on the purpose of processing, categories of personal data processed, identification of the recipient or category of recipients to whom the personal data have been or will be disclosed, if such recipients exist, the retention period of personal data and, if not possible, the criteria used to determine that period, the right to request correction, erasure or restriction of processing of personal data concerning the data subject, the right to object to processing, the right to lodge a complaint with the supervisory authority under Section 100 of the Personal Data Protection Act, the source of the personal data if not obtained from the data subject, and the existence of automated decision-making including profiling.
The right to rectification of personal data:
The data subject has the right to request the controller to rectify inaccurate personal data concerning them without undue delay.
The data subject has the right to request the controller to complete incomplete personal data, taking into account the purposes of the processing. Otherwise, the controller may refuse to complete the personal data.
The right to erasure of personal data:
The data subject has the right to request the controller to erase personal data concerning them without undue delay under the conditions set out in these paragraphs.
The controller is obliged to erase personal data without undue delay upon request of the data subject if:
The above does not apply if processing is necessary for exercising the right of freedom of expression and information, compliance with a legal obligation, performance of a task carried out in the public interest or in the exercise of official authority, archiving purposes in the public interest, scientific or historical research purposes or statistical purposes according to Section 78(8) of the Personal Data Protection Act, if erasure is likely to render impossible or seriously impair the achievement of the objectives of processing, or for the establishment, exercise or defense of legal claims.
The right to restriction of processing personal data:
The data subject has the right to request the controller to restrict processing of their personal data if:
If processing is restricted, the controller may process the personal data only with the consent of the data subject or for the establishment, exercise or defense of legal claims, or for the protection of the rights of another natural or legal person or for reasons of important public interest.
The controller shall inform the data subject before the restriction is lifted.
The right to data portability:
The data subject has the right to receive the personal data concerning them which they have provided to the controller in a structured, commonly used and machine-readable format and has the right to transmit those data to another controller if technically feasible.
Exercising the right to data portability does not affect the right to erasure under the conditions described above.
The right to be informed about a personal data breach if it is likely to result in a high risk to the rights and freedoms of natural persons:
The controller shall notify the data subject without undue delay of a personal data breach, providing a clear and simple description of the nature of the breach, contact details of the responsible person or other contact point where more information can be obtained, likely consequences of the breach, and measures taken or proposed to address the breach including mitigation of possible adverse effects, if necessary.
Notification is not required if:
The right to object to the processing of personal data
The data subject has the right to object to the processing of their personal data based on their particular situation where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, or for the purposes of the legitimate interests pursued by the controller or a third party, except where overridden by the interests or fundamental rights and freedoms of the data subject, especially if the data subject is a child, including profiling based on these grounds. The controller shall no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defense of legal claims.
The data subject has the right to object to processing of personal data for direct marketing purposes including profiling to the extent that it relates to direct marketing. If the data subject objects to such processing, the controller shall no longer process the personal data for direct marketing purposes.
The right to lodge a complaint with the Personal Data Protection Office under Section 100 of the Personal Data Protection Act:
The data subject has the right to lodge a complaint with the Personal Data Protection Office under Section 100 of the Personal Data Protection Act.
The data subject has been explicitly informed that where the legal basis for processing personal data is consent for a specific purpose, the data subject has the right to withdraw consent at any time.
The controller shall handle the data subject's request without undue delay and at the latest within one month of receipt. This period may be extended by two further months where necessary, taking into account the complexity and number of requests, even repeatedly.
The controller shall inform the data subject of any such extension within one month of receipt of the request, together with the reasons for the delay. If the data subject submitted the request electronically, the information shall be provided electronically unless otherwise requested.
If the controller does not take action on the data subject's request, it shall inform the data subject within one month of the reasons for not acting and the possibility to lodge a complaint with the Personal Data Protection Office under Section 100 of the Personal Data Protection Act.
If insufficient data prevent the controller from clearly identifying the requester or from processing the request, the controller shall request the requester to provide additional information or to sufficiently prove their identity. If the requester does not comply within 7 days of receipt of the request, the controller may refuse to act on the request.
Information, notifications and measures shall be provided free of charge if the data subject's request is the first of its kind and is not manifestly unfounded or excessive. The controller shall assess manifestly unfounded or excessive requests.
If the data subject's request is manifestly unfounded or excessive, especially because of its repetitive character, the controller may:
The controller processes personal data only to the extent necessary and for a specific purpose in accordance with the legal basis.
The controller has implemented appropriate technical, security and personnel measures to ensure increased protection of the personal data of data subjects and handles the processed personal data sensitively in accordance with the principles of data protection.
The personal data processed by the controller come directly from the data subject or from publicly available sources.
The controller declares that personal data are not transferred to third countries outside the European Union or to international organizations and that processed personal data are not made public.
The controller may perform automated decision-making including profiling for direct marketing purposes according to criteria set by the controller. If automated decision-making including profiling is performed, the controller shall specify the basic criteria used.
For the purpose of fulfilling statutory registry obligations, the controller records received and sent mail, processing the following personal data:
These personal data are processed based on Act No. 395/2002 Coll. on archives and registries and on the amendment of certain laws as amended. Providing personal data is a legal obligation and failure to provide them would prevent the controller from fulfilling its legal obligations.
The controller stores these personal data for 5 years from the first day of the relevant calendar year in which the personal data for correspondence were obtained and 3 years for the books of received and sent correspondence.
For the purpose of contacting back and handling any request or order within the opening hours of the website visitor as a data subject, the controller processes the following personal data:
These data are processed by the controller based on its legitimate interests. Providing personal data in this case is neither a legal nor contractual obligation. Failure to provide personal data would prevent the controller from contacting back and handling the request or order.
The controller stores these personal data until the request or order specified in the form is handled, but no longer than 5 years from obtaining the personal data.
The controller's website is connected to third-party plugins (applications) such as Facebook, Google Plus, YouTube, Twitter, AddThis, Pinterest, Tumblr, etc. These applications are stored and run on third-party servers. The controller has no influence on the protection of personal data when using third-party applications.
The controller's website uses third-party add-ons that allow users to share, comment, rate website content on social networks or register via a third-party account. In such cases, the browser creates a direct connection between the user and the third party, during which cookies are used and user data are transmitted between the website, the user's browser, and the third-party server. The data are generally not linked to the user's personal data. The controller uses only reliable sources of plugins and add-ons but cannot guarantee the functionality or reliability of third-party plugins.
In case of user action on these websites via social plugins, these actions may be displayed on third-party sites depending on the user's account settings (e.g., Facebook Like, Google Plus, sharing on social networks, etc.).
The controller provides personal data to third parties exclusively based on a mediation contract in accordance with the purpose and legal basis stated above, as well as in accordance with the Personal Data Protection Act and the Personal Data Protection Regulation.
Recipients of personal data are mainly intermediaries providing accounting and personnel services, recruitment services, delivery-related services, maintenance services, legal services, debt collection services, technical and IT services, other advisory and consulting activities, etc.
Recipients of personal data also include employees of the controller who have been instructed in accordance with the law and are bound by confidentiality obligations, only if providing personal data to employees is necessary to achieve one of the purposes of personal data processing.
The controller provides or makes personal data accessible to state administration authorities, public administration bodies, or other state bodies and institutions if such provision or access is in accordance with generally binding legal regulations valid in the Slovak Republic and if necessary to comply with the relevant legal regulation or enforce contractual terms including their compliance control, prevention or investigation of fraud, technical and security incidents, enforcement of rights and claims in accordance with generally binding legal regulations valid in the Slovak Republic.
To facilitate tracking users on our website, we use protocol files called cookies (i.e., identifiers that the web server sends to the browser on your end device). Cookies are temporary files, meaning that after you finish browsing, cookies are automatically deleted from your device.
When visiting this website, protocol files with the following content are generated:
The above information about web behavior is anonymized for maximum protection and therefore cannot be assigned to a specific user.
Cookies do not harm the end device, do not contain viruses, trojans or other malicious software, and do not permanently store data on the data subject's device.
All cookies used are technical, functional or analytical cookies that serve to improve the functionality of the controller's website.
Each data subject can set their internet browser to refuse the use of cookies or to allow only some cookies. However, if the data subject does not allow the use of cookies, some functions may not work properly.
Cookie settings in the most commonly used browsers:
Details of used cookies:
c1vdubaji_projectlang - language retention for the system - approx. 12 years
ci_session - user session for the system - 11 days
_gid - Google Analytics - 1 day
_ga - Google Analytics - 2 years
_gat - Google Analytics - until session ends
The Personal Data Protection Office is a state administration authority with nationwide competence, responsible for protecting the fundamental rights of natural persons in the processing of personal data and supervising data protection. Any data subject may contact the Personal Data Protection Office if they believe their rights have been violated or threatened.
Address of the Personal Data Protection Office:
Hraničná 12
820 07 Bratislava 27
Slovak Republic
Company ID: 36064220
https://dataprotection.gov.sk
email: statny.dozor@pdp.gov.sk
Telephone consultations on data protection only on Tuesdays from 8:00 to 12:00: +421/2/3231 3220