I. In general
ATT & AT doo takes the protection of your personal data seriously and takes all necessary technical and organizational measures to protect them in accordance with the law of the Republic of Croatia and the European Union, and especially in accordance with the General Data Protection Act (OG 42/18) and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data.
This privacy policy describes what personal information we collect and on what basis, for what purposes we use it, how we protect it from unauthorized access, and your rights in relation to that information.
The head of personal data processing is the company ATT & AT doo, Industrijska zona jug 5, 31000 Osijek, OIB: 35839148644.
Personal data protection officer in the company ATT & AT doo.
Address: Industrijska zona jug 5, 31000 Osijek, np Personal Data Protection Officer
E-mail address: osobnipodaci@bor-plastika.hr
II. Personal information
Personal data is any information relating to a natural person that has been identified or can be identified; an identifiable person is a person whose identity can be established directly or indirectly, in particular on the basis of an identification number or one or more characteristics specific to his or her physical, psychological, mental, economic, cultural or social identity.
The controller, in accordance with the purposes set out below and the privacy policy, collects the following personal data:
• basic data about the respondent (name and surname, address, date of birth, location);
• contact details and data on your communication with the processing manager (e-mail address, telephone number, date, time and content of postal or email communication, date, time and duration of telephone calls);
• data on the respondent's use of the processing manager's website (dates and time of visit to the website, visited pages, ie URLs, retention time on each page, number of visited pages, total time of website visit, actions on the website), and data on use received messages (e-mail, SMS) of the processing manager;
• data from voluntarily filled in forms by the respondents, eg personal data of the family members of the respondents in order to exercise their rights from social welfare;
• other information that the respondent voluntarily provides to the bidder when requesting certain services, for which this information is needed.
III. Purpose of processing and legal basis for processing personal data
The specific purpose and methods of processing your personal data largely depend on the type of relationship on the basis of which we collect your data. In our activities we are guided by the basic principles of personal data protection, which means that we process data legally, transparently and fairly and that processing is limited only to the purpose for which the data was collected and that only those data necessary for that purpose are processed. We store your personal data only to the extent necessary to achieve the purpose of processing, except when we are bound by certain regulations to store personal data longer, or when required by our legitimate interests (for example, to set, implement or protect legal claims). The accuracy, reliability, confidentiality and integrity of your personal information are also principles
which we are guided by when processing. Only authorized persons have access to your personal data.
ATT & AT jdoo, as the head of personal data processing, protects your privacy and processes only those personal data that are necessary to it and that are obtained as part of its activities, whether the data is obtained from you, by third parties or publicly available sources, and for the following:
• performance of contractual obligations - when processing is necessary for the performance of the contract to which you are a party or for taking action at your request before concluding the contract;
• Satisfaction of legitimate interests - when necessary, we process personal data outside the specific contractual relationship, in order to satisfy our legitimate interests. For example, such a legitimate interest could be: making decisions in the domain of the Law on Communal Economy, keeping court proceedings and keeping records on them, protection of persons and property, answering your inquiries and comments;
• meeting your requirements and enabling you to exercise your rights;
• necessary compliance with legal obligations;
• processing of personal data for a special purpose or several special purposes described by the consent, only after we receive your consent for the processing of personal data for a particular purpose. Your consent is in accordance with the relevant provisions of the Regulation, is unconditional and given freely. In doing so, you also reserve the right to revoke your consent at any time.
IV. Freedom of choice
You decide on the personal data that you provide to the processing manager. However, if you choose not to provide the information necessary to fulfill your request, the processing manager will not be able to comply with your request.
V. Temporary storage of personal data
The controller will keep your personal data for as long as it takes to achieve the purposes for which the personal data was collected and processed.
All personal data processed by the controller on the basis of law are kept by the controller within the legally determined period.
All personal data processed by the controller for the purpose of performing a contractual relationship with the respondent shall be kept by the controller for the period necessary for the execution of the contract and for another 5 years after the termination of the contract, unless there is a dispute between you and the controller. , when the controller keeps the data for 5 years after the final court judgment or settlement, and in case there is no court dispute, the controller keeps the data for 5 years after the day of peaceful settlement of the dispute.
All personal data processed by the controller on the basis of the consent of the respondent or a legitimate interest, the controller maintains permanently until the withdrawal of consent by the respondent, ie until the request to stop processing. This data is deleted by the controller before the withdrawal of consent by the respondent only if the purpose of the processing of personal data has been achieved or if so provided by law.
YOU. Security of personal data
The processing manager takes all necessary (technical and physical) measures to ensure the security of your personal data. Your data is protected at all times from loss, forgery, manipulation, unauthorized access and unauthorized disclosure.
Manual records of personal data are stored in binders, in locked lockers, while personal data in the format of electronic records on personal computers are protected by an input password and protection systems (firewall, antivirus program).
VII. Forwarding of personal data
The controller will pass on your personal data to third parties only in cases where he is obliged to do so by law or other regulations (HZMO, HZZO, the Tax Administration and other competent authorities).
The controller may also entrust your personal data to the IT system maintainer, who may process this data only in the name and within the limits of the controller's authority and in accordance with this personal data protection policy.
VIII. Internet and website
Confidentiality of data
We want to make it clear that when visiting the company’s website ATT & AT Ltd. your personal information remains confidential unless you wish to disclose it voluntarily. We undertake not to disclose to other parties the information we have received, except in the cases listed in the previous chapter.
Server statistics
Our global network server uses statistical software. These programs are a standard feature of all Internet servers and are not unique to our site. Such statistical programs allow us to customize our pages in a way that is as efficient and simple as possible for our visitors (identifying data that most or least interests our users, customizing pages for individual browsers, the effectiveness of our site structure and traffic to our pages.)
Use of cookies
To facilitate browsing of our websites, our global network server uses cookies. These are very small text files that the server places on the user's computer in order to monitor the selection of individual language variants of our pages, as well as when entering parts of the pages that require a username and password. Cookies cannot be used to run programs or install viruses on your computer. Cookies set by our internet server are automatically deleted from your computer at the end of the session, ie the moment you leave our site. Viewing our pages is also possible without the use of cookies, if your internet browser is set up in this way.
Email
When you send us an e-mail (e-mail) with personally identifiable information, either by e-mail with a question or comment, or by the form you send us by e-mail, we use that information solely for the purpose and to the extent necessary to fulfill it. your claims) to make, pursue or defend legal claims;
• right to processing restriction: you have the right to obtain a processing restriction from the processing manager if one of the following is met:
a) if you dispute the accuracy of personal data, for the period during which the controller is allowed to verify the accuracy of personal data;
b) the processing is illegal and you oppose the deletion of personal data and instead seek a restriction on their use;
c) the controller no longer needs personal data for processing purposes, but you request them in order to set, realize or defend legal claims;
d) you have lodged an objection to the processing pursuant to Article 21 (1) of the General Data Protection Regulation pending confirmation that the legitimate reasons of the controller relay your reasons;
• right to data portability: you have the right to receive personal data relating to you that you have provided to the controller in a structured, commonly used and machine-readable format, and you have the right to transfer this data to another controller without interference by the controller provided, if the processing is based on consent or contract and if the processing is carried out automatically; when exercising this right, you have the right to transfer directly from one controller to another if technically feasible; this right shall not apply to processing necessary for the performance of a task in the public interest or in the exercise of official authority conferred on the controller, and shall not adversely affect the rights and freedoms of others;
• right to object:
a) if the processing of personal data is necessary for the performance of a task of public interest or in the exercise of the official authority of the controller, and when the processing is necessary for the legitimate interests of the controller or a third party, you have the right to object at any time processing of personal data relating to you; if you lodge such an objection, the controller may no longer process your personal data unless it proves that there are compelling legitimate reasons for the processing that go beyond your interests, rights and freedoms or to set, exercise or defend legal claims;
b) if personal data are processed for the purposes of scientific or historical research or for statistical purposes, you have the right, at any time based on your particular situation, to object to the processing of personal data relating to you, unless
processing necessary to carry out a task performed in the public interest; required to perform a task performed for reasons of public interest;
• right to complain to the supervisory authority: you have the right to lodge a complaint with the supervisory authority, in particular in the Member State in which you have your habitual residence, where your employment is
IX. Respondents' rights
• right to withdraw consent: if you have given your consent to the processing of your personal data, you have the right to withdraw that consent, provided that the withdrawal of consent does not affect the lawfulness of the processing prior to its withdrawal; withdrawal of consent does not have any negative consequences for the respondent, however, it is possible that, after withdrawal of consent for processing
data that are necessary for the exercise of some of your rights, you will no longer be able to exercise a particular right;
• right of access to personal data: from the controller you have the right to receive confirmation whether your personal data are processed and when they are processed, access to personal data and the following information: purpose of processing, category of personal data, data transmission, data retention time or criteria for determining it, the existence of the right to correct or delete personal data, the right to restrict processing, the right to object to processing, the right to complain to the supervisory authority, the source of the data (if the data has not been collected from you);
• the right to correction of personal data: you have the right, without undue delay, to obtain from the controller the correction of inaccurate personal data relating to you, as well as to supplement incomplete data;
• right to erasure of personal data ("right to forget"): you have the right, without undue delay, to obtain from the controller the erasure of personal data relating to you, if one of the following conditions is met:
a) the data are no longer necessary in relation to the purposes for which they were collected or otherwise processed,
b) if you withdraw the consent on which the processing is based and there is no other legal basis for the processing,
c) if you object to the processing and there are no stronger legitimate reasons for the processing;
d) personal data have been illegally processed;
e) personal data must be deleted in order to comply with a legal obligation under Union law or the law of the Member State to which the controller is subject;
except to the extent that processing is necessary:
a) to exercise the right to freedom of expression and information;
b) to comply with a legal obligation requiring processing under Union or Member State law to which the controller is subject, either for the performance of a task in the public interest or in the exercise of the official authority of the controller;
c) for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes, to the extent that the right of erasure is likely to impede or seriously jeopardize the achievement of the purposes of such processing;
the place or place of the alleged breach, if you consider that the processing of personal data concerning you violates the General Data Protection Regulation; in the country where you reside, work or where the breach allegedly occurred, if you think that the processing of personal data relating to you violates the rules on the protection of personal data;
• the right to an effective remedy against the supervisory authority: you have the right to an effective remedy against the legally binding decision of the supervisory authority that applies to you, as well as if the competent supervisory authority does not resolve the complaint or notify you of progress or outcome within three months complaints lodged
All questions and requests related to the exercise of your rights in relation to personal data can be sent to the address: ATT & AT doo, Industrijska zona jug 5, 31000 Osijek, eg Personal Data Protection Officer or to the e-mail address: osobnipodaci @ bor-plastika .hr
For the purpose of reliable identification of the respondent in exercising the rights related to personal data, the controller may request the provision of additional information, and in case the respondent cannot be reliably identified, he may refuse to act upon the request.
X. Notification of personal data breach
In case of personal data breach, the controller is obliged to inform the supervisory body (Personal Data Protection Agency), unless it is unlikely that the personal data breach will cause a risk to the rights and freedoms of the individual.
In the event of a personal data breach that is likely to pose a high risk to the rights and freedoms of the individual, the controller must inform the respondent, unless he has taken appropriate technical and organizational protection measures (eg encryption) or taken subsequent measures to ensure that it is no longer likely that there will be a high risk to the rights and freedoms of respondents or that a disproportionate effort would be required (in the latter case, there must be public information or a similar measure to inform respondents in an equally effective way).
XI. Announcement of changes
Any changes to the Privacy Policy will be posted on the Company's bulletin board.