The processing of personal data is governed by Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (the “GDPR”) and by Act No. 110/2019 Coll., on the Processing of Personal Data, as amended.
Effective from 1 May 2023
These Principles contain basic information on the processing of personal data carried out by the controller, in particular, though not exclusively, in connection with a contractual or non-contractual relationship with the controller, the provision or receipt of services or goods, and the operation of these websites.
Please do not send any of your personal data if you do not wish it to be used in the manner described in these Principles.
In relation to your personal data, the controller is Hyverr s.r.o., Company ID No. 06696236, with its registered office at Velkopřevorské náměstí 488/5, Malá Strana, 118 00 Prague 1 (the “Controller”).
The Data Protection Officer for the group of undertakings formed by the above controllers is Ing. Lukáš Bajgar.
Personal data are processed to the extent in which the relevant data subject has provided them to the Controller, in connection with the conclusion of a contractual or other legal relationship with the Controller, or where the Controller has otherwise collected them and processes them in accordance with applicable legal regulations or for the performance of the Controller’s legal obligations.
Personal data will not be used for decision-making based solely on automated processing, including profiling.
The source of the personal data processed and collected is primarily the data subject.
The Controller may also collect personal data from third parties, such as public authorities, business partners, or publicly available sources and databases.
The following personal data may be processed:
Personal data may be disclosed to other companies within the group of companies of which the Controller forms part, in particular where such company provides certain services for the Controller.
Personal data may also be transferred to an external person ensuring the operation of the Controller’s technical equipment (in particular software and hardware), and such person may also be one or more of the other group companies of which the Controller also forms part.
The Controller’s advisers and external collaborators, or those of other companies within the group of companies of which the Controller also forms part, e.g. tax advisers, legal advisers, etc., may have access to certain personal data, but only if they need such personal data for the fulfilment of the processing purpose.
The above recipients must provide sufficient and trustworthy guarantees regarding the technical and organisational security of personal data protection.
The Controller does not intend to transfer personal data to a third country, i.e. a country outside the European Union, or to an international organisation.
Where the Controller processes personal data for the purposes of performing a contract or dealing with a submitted request, the personal data are processed for the duration of the contractual relationship, or for the time necessary to deal with the submitted request, and subsequently for five years after termination of the contract so that the Controller may defend any legal claims, and thereafter for any period required by legal regulations.
Where the Controller processes personal data for the purposes of complying with legal obligations, it processes them for the period stipulated by the relevant law.
Where the Controller processes personal data for the purposes of protecting the Controller’s legitimate interests, such personal data are retained for the limitation period stipulated by legal regulations, but for at least three years.
Where the Controller processes personal data on the basis of consent, it is entitled to process them in accordance with the purpose and for the period stated in the consent, or until the consent is withdrawn. Please note that the withdrawal of your consent does not affect the lawfulness of processing based on consent before its withdrawal.
Under the conditions laid down by legal regulations, in particular Chapter III of the GDPR, you have:
If you have any doubts as to compliance with obligations related to the processing of your personal data, you may contact the Data Protection Officer whose contact details are given above, or lodge a complaint with the Office for Personal Data Protection.
The Controller has implemented technical and organisational measures within the meaning of Article 32 GDPR that are necessary and at the same time appropriate to ensure that all processing is carried out in accordance with legal regulations, in particular the GDPR, and that the protection of the rights and freedoms of data subjects is ensured in connection with the processing of personal data. These measures consist in minimising the processing of personal data, carrying out pseudonymisation as quickly as possible, ensuring transparency, necessity and proportionality of the processing of personal data, and enabling the Controller to create and improve security features.
The Controller’s implemented technical and organisational measures are reviewed and updated as necessary.
These Principles become effective on 1 May 2023.
Please note that these Principles may be amended or updated. Any changes to these Principles shall become effective upon their publication on the Controller’s websites.