PRIVACY POLICY

Xelto Digital Czechia s.r.o.

ID: 10964452

with its registered office at Rybná 716/24, Staré Město, 110 00 Prague 1

company registered at the Municipal Court in Prague, Section C, Insert 351443

Email: xd_czechia@xelto.com

Website: https://xeltodigital.cz/cs/ (hereinafter referred to as the “Website“)

(hereinafter referred to as the “Company“)

As part of its activities, it manages and processes the personal data of the entities listed below. These Personal Data Processing Principles (hereinafter referred to as the “Principles“) inform data subjects about the circumstances of the processing of their personal data and the rights they have in relation to such processing.

  1. DATA SUBJECTS, PURPOSES, SCOPE, DURATION AND LEGAL BASIS FOR PROCESSING

 

  1. CUSTOMERS – ENTREPRENEURS (SELF-EMPLOYED)

The Company, as the administrator, processes the personal data of customers – entrepreneurs (self-employed) for the purpose, to the extent, for legal reasons and for the following periods:

  1. Purpose: Negotiation of the conclusion of a contract for the provision of services, conclusion of this contract and performance of this contract.

Scope of data: Name and surname/business name, IČO, DIČ, registered office, data on registration in the public register, telephone number, e-mail address, bank account number, signature.

Legal ground: Necessity for the processing of personal data for the performance of a contract to which the data subject is a party or for the implementation of measures taken at the request of the data subject prior to entering into a contract.

Period: For the time necessary for negotiating the conclusion of the contract and for the performance of the contract.

 

  1. Purpose: Accounting and tax purposes and fulfillment of archiving obligations.

Scope of data: Name and surname/business name, IČO, DIČ, data on registration in a public register, registered office, bank account number, signature.

Legal reason: Necessity of processing to meet legal obligations imposed on the Company by law.

Period: For the necessary period of 10 years, unless longer periods are laid down by law.

 

  1. Purpose: Enforcement of any claims of the Company (storage of data necessary as evidence in litigation).

Scope of data: Name and surname / business name, ID number, registered office, data on registration in a public register, signature.

Legal ground: Legitimate interest.

Period: For the duration of the contract and after its termination for the duration of the limitation periods.

 

  1. Purpose: Sending unsolicited commercial communications.

Scope of data: Name, surname, e-mail address.

Legal ground: Legitimate interest (direct marketing).

Duration: For the duration of the cooperation with the customer, and after the end of the cooperation for 3 years.

 

  1. Purpose: Sending commercial communications for marketing and advertising purposes.

Scope of data: Name, surname and e-mail address.

Legal ground: Consent.

Period: For as long and reasonable as necessary, until the consent is withdrawn.

 

  1. CONTACT PERSONS OF CUSTOMERS – LEGAL ENTITIES: A MEMBER OF THE STATUTORY BODY OR OTHER PERSON AUTHORIZED TO NEGOTIATE THE CONCLUSION AND TERMS OF A CONTRACT FOR THE PROVISION OF SERVICES, OR A CHANGE IN THE TERMS OF THE CONTRACT AND COMMUNICATION CONCERNING THE PERFORMANCE OF THE CONTRACT ON THE PART OF THE CUSTOMER

As a processor, the Company processes personal data of a member of the statutory body or another person authorized to negotiate the conclusion and terms of a contract for the provision of services, or a change in the terms of the contract and communication relating to the performance of the contract on the part of the customer, for the purpose, to the extent, for legal reason and for the following periods:

  1. Purpose: Negotiation of the conclusion, conditions or change of the terms of the Contract for the Provision of Services and communication relating to the performance of the Contract, communication relating to the provision of other services of the Company.

Scope of data: Name, surname, e-mail address, telephone number, signature.

Legal ground: A service agreement concluded with a customer.

Period: For the period necessary for negotiations on the conclusion, conditions or changes to the terms of the contract and for the duration of communication concerning the performance of the contract.

  1. Purpose: Enforcement of any claims of the Company (storage of data necessary as evidence in litigation).

Scope of data: Name, surname, signature.

Legal ground: Legitimate interest.

Period: For the duration of the contract and after its termination for the duration of the limitation periods.

The Company, as the personal data controller of the above-mentioned data subjects, performs the processing of personal data for the purpose, to the extent, for legal reasons and for the following periods:

  1. Purpose: Sending unsolicited commercial communications.

Scope of data: Name, surname, e-mail address.

Legal ground: Legitimate interest (direct marketing).

Period: For the duration of cooperation with the customer-legal entity, and after the termination of cooperation for a period of 3 years, or until the end of the representation of the customer by the data subject.

 

  1. Purpose: Sending commercial communications for marketing and advertising purposes.

Scope of data: Name, surname and e-mail address.

Legal ground: Consent.

Period: For as long and reasonable as necessary, until the consent is withdrawn.

 

 

  1. DATA SUBJECTS WHOSE PERSONAL DATA ARE CONTAINED IN CUSTOMER INFORMATION SYSTEMS

As a processor, the Company processes personal data of third parties contained in the information systems of the Company’s customers for the purpose, to the extent, for legal reasons and for the following periods:

  1. Purpose: Provision of services by the Company to customers on the basis of a service contract.

Scope of data: To the extent specified by the customer, usually name, surname, bank account, e-mail address, date of birth, ID number, VAT number, billing address.

Legal ground: Necessity of processing personal data for the performance of a contract for the provision of services to which the customer is a party.

Period: For the duration of the Service Agreement.

 

  1. CONTACT PERSONS OF POTENTIAL CUSTOMERS

The Company as an administrator processes the personal data of contact persons of potential customers of the Company for the purpose, to the extent, for legal reasons and for the following periods:

  1. Purpose: Contacting a person for the purpose of establishing cooperation and presenting the Company’s offer of services, concluding a contract for the provision of services.

Scope of data: Name, surname, e-mail address, or telephone number.

Legal ground: Legitimate interest (acquisition of new customers).

Period: For the time necessary to present the Company’s services and establish business cooperation, at the latest until the Company’s offer is accepted or rejected.

 

If the Company does not obtain the above personal data directly from the data subject, the source of personal data obtained by the Company is:

  1. the website of a potential client, or another publicly accessible website on the Internet, or
  2. a publicly accessible profile of the data subject on the social network Linkedin.

 

  1. JOBSEEKERS

The Company, as the controller, processes the personal data of job applicants for the purpose, to the extent, for legal reasons and for the following periods:

  1. Purpose: To carry out a selection procedure for a position.

Scope of data: Data stated in the CV, usually name, surname, title, date of birth, home address, e-mail address, telephone number, completed education, previous employment.

Legal ground: Necessity for the processing of personal data for the performance of a contract to which the data subject is a party or for the implementation of measures taken at the request of the data subject prior to entering into a contract.

Duration: For the duration of the selection procedure.

 

 

 

  1. EMPLOYEES – EMPLOYMENT CONTRACT
  1. Purpose: Negotiation of the conclusion of an employment contract, conclusion of this contract and performance of this contract.

Scope of data: Name, surname, title, birth number, date of birth, home address, telephone number, e-mail address, signature, completed education, health information (mandatory medical examinations), bank account number.

Legal ground: Necessity for the processing of personal data for the performance of a contract to which the data subject is a party or for the implementation of measures taken at the request of the data subject prior to entering into a contract.

Period: For the period necessary for negotiating the conclusion of the contract and the performance of the contract.

 

  1. Purpose: Accounting, payroll and tax purposes and fulfillment of archiving obligations.

Scope of data: Name, surname, birth number, date of birth, home address, marital status (information on the number of children, information on spouse), name and code of the health insurance company, number of the insured person, signature.

Legal reason: Necessity of processing to meet legal obligations imposed on the Company by law.

Period: For a period of necessary, a maximum of 30 years, unless other time limits are laid down by law.

 

  1. Purpose: Enforcement of any claims of the Company (storage of data necessary as evidence in litigation).

Scope of data: Name, surname, birth number, date of birth, home address, signature.

Legal ground: Legitimate interest.

Period: For the duration of the contract and after its termination for the duration of the limitation periods.

 

  1. Purpose: Presentation of the Company on the Website

Scope of data: Name, surname, job title, portrait.

Legal ground: Consent.

Period: For the duration of the employment relationship or until the consent is withdrawn.

 

  1. EMPLOYEES – AGREEMENTS TO WORK OUTSIDE THE EMPLOYMENT RELATIONSHIP
  1. Purpose: Negotiation of the conclusion of an agreement to work performed outside the employment relationship (hereinafter referred to as the “Agreement”), conclusion of this Agreement and the implementation of this Agreement.

Scope of data: Name, surname, title, birth number, date of birth, home address, telephone number, e-mail address, signature, bank account number.

Legal ground: Necessity for the processing of personal data for the performance of an agreement to which the data subject is a party or for the implementation of measures taken prior to the conclusion of an agreement at the request of the data subject.

Period: For the time necessary for the negotiation of the conclusion of the agreement and the implementation of the agreement.

 

  1. Purpose: Accounting, payroll and tax purposes and fulfillment of archiving obligations.

Scope of data: Name, surname, birth number, date of birth, home address, marital status (information on the number of children, information on spouse), name and code of the health insurance company, number of the insured person, signature.

Legal reason: Necessity of processing to meet legal obligations imposed on the Company by law.

Period: For a period of time, maximum 10 years, unless other time limits are laid down by law.

 

  1. Purpose: Enforcement of any claims of the Company (storage of data necessary as evidence in litigation).

Scope of data: Name, surname, birth number, date of birth, address, signature.

Legal ground: Legitimate interest.

Period: For the duration of the agreement and, after its termination, for the duration of the limitation periods.

 

  1. Purpose: Presentation of the Company on the Website

Scope of data: Name, surname, job title, portrait.

Legal ground: Consent.

Period: For the duration of the employment relationship or until the consent is withdrawn.

 

  1. SUPPLIERS (SELF-EMPLOYED)

The Company, as the administrator, processes personal data of suppliers (self-employed) for the purpose, to the extent, for legal reasons and for the following periods:

  1. Purpose: Negotiation of the conclusion of a contract with the supplier, conclusion of this contract and performance of this contract.

Scope of data: Name and surname/business name, IČO, DIČ, registered office, information on entry in a public register, telephone number, e-mail address, bank account number, signature.

Legal ground: Necessity for the processing of personal data for the performance of a contract to which the data subject is a party or for the implementation of measures taken at the request of the data subject prior to entering into a contract.

Period: For the period necessary for negotiating the conclusion of the contract and the performance of the contract.

 

  1. Purpose: Accounting and tax purposes and fulfillment of archiving obligations.

Scope of data: Name and surname/business name, IČO, DIČ, registered office, bank account number, signature.

Legal reason: Necessity of processing to meet legal obligations imposed on the Company by law.

Period: For the necessary period of 10 years, unless longer periods are laid down by law.

 

  1. Purpose: Enforcement of any claims of the Company (storage of data necessary as evidence in litigation).

Scope of data: Name and surname/business name, ID number, registered office, signature.

Legal ground: Legitimate interest.

Period: For the duration of the contract and after its termination for the duration of the limitation periods.

 

  1. Purpose: Presentation of the Company and its partners on the Website

Scope of data: Name, surname, relationship to the company, photographs.

Legal ground: Consent.

Period: For the duration of cooperation with the Company or until the consent is withdrawn.

 

 

  1. WEBSITE VISITORS

The Company, as an administrator, processes cookies in relation to visitors to the Website.

 

Cookies are text files containing small amounts of information that are downloaded to the Website’s mobile, computer or other device when visiting the Website. On each subsequent visit to the Website, cookies are then sent back to the original Website or to another site that recognizes cookies. Simply put, using cookies, the Website stores information about visiting the Website.

 

The Website uses different categories of cookies for different purposes. Necessary cookies are necessary for the basic functionality of the Website. Thus, in order for the Website to fulfill its basic function, the Company cannot do without these cookies. Necessary cookies may be processed by the Company without the consent of the Website visitor. All other cookies may be processed by the Company only with the consent of the Website visitor, which the Website visitor may revoke (reject) at any time in the cookie settings. However, withdrawal or non-consent may affect browsing the Website.

 

  1. PERSON WHO CONTACTS THE COMPANY

The Company, as the controller, processes the personal data of persons who contact the Company by e-mail, telephone or via a web form on the Website, for the purpose, to the extent, for legal reasons and for the following periods:

  1. Purpose: To answer the questions of the enquiring person.

Scope of data: Name, surname, e-mail address, telephone number or business name, ID number, registered office, job position.

Legal ground: Legitimate interest in reply.

Time: Strictly necessary for answering the question and follow-up communication.

 

  1. Purpose:Arranging an appointment with a representative of the Company via a calendar on the Website.

Scope of data: Name, surname, e-mail address, telephone number, job title.

Legal ground: Legitimate interest in arranging an appointment.

Time: Strictly necessary for the implementation of the meeting and follow-up communication.

 

  1. Purpose: Sending commercial communications for marketing and advertising purposes.

Scope of data: Name, surname and e-mail address, telephone number or business name, ID number, registered office, position.

Legal ground: Consent.

Period: For as long and reasonable as necessary, until the consent is withdrawn.

 

  1. MANAGING DIRECTOR AND PARTNER OF THE COMPANY

The Company processes personal data about the Company’s executive and associates for the purpose, to the extent, for legal reasons and for the following periods:

  1. Purpose: Corporate Administration.

Scope of data: Name and surname, date of birth or birth number, place of residence and permanent residence, e-mail address, telephone number, signature.

Legal ground: Necessity of processing to meet legal obligations imposed on the Company by legal regulations.

Duration: For as long as necessary.

 

  1. Purpose: Accounting and tax purposes, fulfillment of archiving obligations.

Scope of data: Name and surname, date of birth or birth number, place of residence and permanent residence, bank account number, signature.

Legal reason: Necessity of processing to meet legal obligations imposed on the Company by law.

Period: For the period strictly necessary, 10 years, unless the law stipulates longer deadlines.

 

  1. Purpose: Presentation of the Company on the Website

Scope of data: Name, surname, job title, photograph.

Legal ground: Consent.

Period: During the performance of the function of the Company’s Managing Director or until the consent is withdrawn.

 

  1. VOLUNTARINESS OF DATA PROVISION

The data subject provides the Company with his or her personal data voluntarily. Failure to provide personal data may affect the Company’s ability to conclude a contract or provide performance to the data subject that is based on the necessary knowledge of information about the data subject, including personal data.

  1. RECIPIENTS AND PROCESSORS OF PERSONAL DATA

Personal data processors:

  • Accounting services: Connect Economy Group s.r.o.
  • Storage, email server, calendar, conference calls: Google Ireland Limited
  • Marketing services: Google Analytics, Leady, Imper CZ s.r.o. (Merk service),
  • CRM system: Zoho Corporation Pvt. Ltd.
  • IT service providers, sales representatives: Xelto Digital Sp. Z.o.o., Jiří Bendík, Daniel Kunovský, Michael Treml, Deal Factory s.r.o.
  • LinkedIn Sales Navigator: LinkedIn Ireland Unlimited Company
  • Processing of cookies: Google Ireland Limited, Meta Platforms Ltd., Hotjar Ltd.

 

The recipients of personal data may be the relevant state administration authorities (Tax Office, OSSZ, etc.).

However, please note that due to the changing persons of the providers of some services, it is not possible to name all current and future personal data processors. The above list of processors may therefore change over time.

The Company transfers personal data to a third country (outside the EU) to companies:

  • Zoho Corporation Pvt. Ltd. [has entered into a standard privacy clause with Zoho Corporation Pvt. Ltd.

The Company does not transfer personal data to an international organization.

  1. METHOD OF PROCESSING PERSONAL DATA

The Company and, where applicable, its processors process personal data manually (in electronic form) and electronically by automated means.

When processing personal data, no automated decision-making, including profiling, takes place.

  1. SECURITY OF PERSONAL DATA

To secure personal data, the Company does its utmost to secure them against misuse. As part of the Company’s activities, the Company will continue to do everything in its power to prevent such a security incident from occurring and will always use only reliable technical solutions.

However, there is always a certain risk that personal data could be leaked or misused or lost. If, despite the best efforts of the Company, a security incident occurs and this incident could pose a high risk to the rights and freedoms of the data subject, the Company will immediately inform the data subject of such a fact via the provided e-mail address and by publishing such information on the Website, including all necessary details.

  1. RIGHTS OF DATA SUBJECTS

The data subject has the following rights:

(a) Right of access to personal data

The data subject has the right to obtain from the Company confirmation as to whether or not personal data concerning him or her are being processed and, if so, he or she has the right to access such personal data and the following information:

  1. the purposes of personal data processing;
  2. the categories of personal data concerned;
  3. the recipients or categories of recipients to whom the personal data have been or will be disclosed
  4. the envisaged period for which the personal data will be stored or, if this cannot be determined, the criteria used to determine that period;
  5. the existence of the right to request from the Company rectification or erasure of personal data concerning the data subject or restriction of their processing or to object to such processing;
  6. the right to lodge a complaint with a supervisory authority;
  7. any available information as to the source of the personal data, if not obtained from the data subject.

The data subject also has the right to request a copy of the processed personal data from the Company, provided that the rights and freedoms of other persons are not adversely affected. For additional copies at the request of the data subject, the Company may charge a reasonable fee based on administrative costs. Where the data subject makes the request in electronic form, the information shall be provided in a commonly used electronic form, unless otherwise requested by the data subject.

  1. b) Right to rectification

The data subject has the right to obtain from the Company without undue delay the rectification of inaccurate personal data concerning him/her. Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by providing a supplementary statement.

  1. c) Right to erasure (right to be forgotten)
  1. The data subject has the right to have the Company delete personal data relating to the data subject without undue delay, and the Company has the obligation to delete personal data without undue delay if any of the following reasons apply:
  1. personal data are no longer needed for the purposes for which they were collected or otherwise processed;
  2. the data subject revokes the consent on the basis of which the personal data were processed, and there is no other legal reason for the processing;
  3. the data subject raises legitimate objections to the processing of personal data;
  4. personal data were processed illegally;
  5. personal data must be deleted to fulfill a legal obligation set out in the law of the European Union or the Czech Republic;
  6. personal data were collected in connection with the offer of information society services based on the consent given by the child.
  7. d) Right to restriction of processing

The data subject has the right to have the Company restrict processing in any of the following cases:

  1. the data subject denies the accuracy of the personal data, for the time required for the Company to verify the accuracy of the personal data;
  2. the processing is unlawful and the data subject refuses the erasure of personal data and instead requests the restriction of their use;
  3. The company no longer needs the personal data for processing purposes, but the data subject requires them for the determination, exercise or defense of legal claims.
  4. e) The right to portability of personal data

The data subject has the right to receive the personal data concerning him/her that he/she has provided to the Company in a structured, commonly used and machine-readable format, and the right to transfer this data to another administrator without the Company preventing it, in the event that:

  1. the processing is based on consent to the processing of personal data or it concerns the processing of personal data for the purposes of concluding and fulfilling a contract with the data subject; and at the same time
  2. processing is performed automatically.

When exercising his right to data portability, the data subject has the right to have the personal data transferred by the Company directly to another administrator, if this is technically feasible. The right to portability of personal data must not adversely affect the rights and freedoms of other persons

  1. f) The right to object

The data subject has the right to object to the processing of personal data. If the data subject raises a legitimate objection to processing for the purposes of direct marketing or profiling, personal data will no longer be processed for these purposes.

The objection will be evaluated and subsequently the Company will inform the data subject whether the objection was accepted and the Company will no longer process the data or that the objection was not justified and the processing will continue. Processing will be restricted until the objection is resolved.

  1. g) The right not to be the subject of an automated decision, incl. profiling

The data subject has the right not to be subject to any decision based solely on automated processing, including profiling (i.e. any form of automated processing of personal data consisting of their use to evaluate some personal aspects relating to the data subject), which has legal effects for him or her in a similar way significantly touches. This right does not apply if the automated decision is necessary for the conclusion or performance of a contract between the data subject and the Company or is based on the express consent of the data subject; however, in these cases, the data subject has the right to human intervention in the automated decision by the Company, the right to express his opinion and the right to challenge the automated decision.

  1. h) The right to lodge a complaint with the supervisory authority

The data subject has the right to lodge a complaint against the processing of his personal data by the Company with the supervisory authority, which for the Czech Republic is the Office for the Protection of Personal Data, Plk. Sochora 27, 170 00 Prague 7.

  1. Final Provisions

The company has not appointed a personal data protection officer.

The company is entitled to unilaterally change these principles of personal data protection and processing.

These principles of personal data protection and processing become effective on [1/17/2023].