Principles of Personal Data
Processing
of the company
TOPSEARCH, s.r.o.
(general)
Version No. 2 dated 25 May 2019
Dear Sir/Madam,
in this document, we would like to inform you about how we handle your personal data that you have provided to our company TOPSEARCH s.r.o., with its registered office at K Rybníčkům 282/19, 100 00 Prague 10, Strašnice, ID No.: 274 14 779, registered in the Commercial Register maintained by the Municipal Court in Prague, File No. C 111415 (hereinafter referred to as “we,” the “company,” or “TOPSEARCH”).
With this document, we fulfill our information obligation towards you pursuant to Articles 12, 13, and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter “GDPR”), as well as obligations under Act No. 110/2019 Coll., on the processing of personal data (hereinafter “PDP Act”). You can find the text of GDPR here. You can find the text of the PDP Act, for example, here.
A. Who is the controller of the personal data you provided and how can you contact them?
The controller of the personal data you provided is us, the company TOPSEARCH.
Regarding the processing of your personal data, you may contact us in person at our offices located at Konviktská 24, 110 00 Prague 1, Staré Město, during normal business hours (working days from 10:00 to 16:00).
You may also contact us by phone at +420226211880 or by email at hr@topsearch.cz
Instead of you, a representative chosen by you may contact us regarding the processing of your personal data, provided they present us with a written power of attorney.
B. In which situations do we process your personal data?
We process your personal data in the following cases:
-
in connection with business correspondence with clients (customers), suppliers, and other persons communicating with the company; in this case, we process personal data of the persons sending us such correspondence, in particular name, surname, job title/position, phone number(s), email address, social network address, Skype contact, signature, degree(s);
-
in connection with the conclusion of contracts for the provision of our services with our clients (customers); in this case, we process personal data of the contracting parties (name, surname, degrees, position), contact details of persons stated in the contract (name, surname, phone number, fax number, email address, and other similar contact data), and signatures;
-
in connection with the provision of services to clients (customers) under the concluded contract; in this case, we process personal data provided to us for the fulfillment of the contract, i.e., mediation of employment for or to the client (customer), in particular data on name, surname, date of birth, birth number, education, skills, work history, former employers, personal characteristics, income and property details, health status including biometric data such as photo, voice recording or video recording, as well as any other personal data included in your professional CV;
-
in connection with contracts for the supply of goods and services to our company from our suppliers;
-
in connection with the purchasing process (orders, acceptance of orders) of goods and services by our company from suppliers;
-
in connection with maintaining a unified database of suppliers and customers of our company; in this case, we process mainly contact data of persons authorized to act or communicate on behalf of the supplier/customer, such as name, surname, phone number, fax number, social network account, Skype contact, signature, position/function;
-
in connection with the employment of employees and the recruitment process for new employees (including legal relations to the company’s executives); information processed in this case is covered by a separate Privacy Policy for employees, to which we hereby refer;
-
in connection with entry to and movement within the company’s premises and offices; in this case, we process names, surnames, and ID document numbers of persons entering the premises, CCTV records of movements within buildings where our offices are located (if installed), information on health condition (e.g., extent and duration of treatment of an injury), and biometric data (CCTV records if taken);
-
in connection with the operation of the company’s websites; in this case, we process cookies data and users’ IP addresses;
-
in connection with the company’s social media profiles; in this case, we process data on comments and statements made by persons visiting the profile, and data on persons interacting with the profile, including their identifiers; the company itself does not further process these data, leaving processing to the social network operator;
-
in connection with participation in fairs, presentations, lectures, and similar events; in this case, we may process journalistic-type photographs of people at the event for documentation purposes (not portraits of every visitor), and video recordings of the event; the company carefully considers anonymization of individuals outside the company captured in such recordings;
-
in connection with receivables and dispute agendas; in this case, we process data on receivables of natural persons, contact data of persons authorized to act for our debtors, and details of court disputes and persons participating in them;
-
in connection with accounting agendas; in this case, we process information about bank accounts of natural persons, contact persons on individual tax documents, and information on payments to and from natural persons.
C. What categories of personal data do we process?
We generally process the following personal data (to the extent provided by the data subject):
-
first name,
-
surname,
-
address,
-
marital status,
-
nationality,
-
passport/ID card number,
-
date of birth,
-
birth number (C),
-
gender,
-
telephone number(s),
-
email address(es),
-
social media account details,
-
biometric data (C),
-
photograph and video recording (C),
-
health condition (C),
-
IP address associated with you and cookies,
-
work history, skills, and experience,
-
property details,
-
criminal record information (C).
For your information, we have marked with “(C)” those personal data which are sensitive.
We process sensitive personal data only if they are necessary for providing the relevant service to you or if there is a legal basis for their processing. For further details, please refer to section K of this notice.
D. How do we approach the processing of personal data? For what purposes do we process your personal data, and what is the legal basis for processing your personal data? What are our legitimate interests in processing your personal data?
We process your personal data in order to fulfill the purpose of a contract concluded with you, or under which your personal data was provided to us (processing under Art. 6(1)(b) GDPR). We therefore process them for the purpose of providing you with the agreed contractual performance or for the purpose of providing performance to the person who provided us with your personal data and with whom you are in an employment or similar relationship, or on whose behalf you are entitled to communicate with us.
We also process your personal data for the protection of your vital interests or those of another natural person. This means we process them, for example, when investigating your injury if it occurs on our premises.
The information processed for the protection of your vital interests or those of another natural person is processed for the purpose of conducting investigations we are obliged to carry out, for fulfilling our legal duty to prevent damage, and for transferring such information to the relevant state or administrative authorities conducting the investigation or providing you with assistance in connection with an extraordinary event in which you are involved and which also affects us and which we are obliged to investigate. In this case, the purpose of processing your personal data is to ensure the highest possible protection of your life and health, or your property (processing under Art. 6(1)(d) GDPR).
We further process your personal data for the legitimate interests of our company. We define these legitimate interests as (a) protecting our rights arising from a contract if it is breached and your data was provided to us in connection with such contract, or (b) if you assert any claim against us in connection with a contract concluded with us, or a claim is asserted against us by the contracting party of such a contract in which your personal data was provided to us. We therefore process your personal data for the purpose of using them in judicial and enforcement proceedings for the recovery of our claims and rights in the event of breach of contract, and for the purpose of legal defense if any claim is asserted against us in connection with such a contract (processing under Art. 6(1)(f) GDPR). In this respect, please note that you have the right to object under Art. 21 GDPR to the processing of your personal data on the grounds of our legitimate interests as defined above. You may address such objection to us via the contacts listed in section B above.
We process your personal data on the basis of consent that you have granted us in writing (if you have done so) (processing under Art. 6(1)(a) GDPR). The scope of such data processed is described in more detail in the granted consent.
Lastly, we process your personal data in order to fulfill the legal obligations applicable to us. These concern, in particular, obligations to financial, customs, and administrative authorities of the Czech Republic, labor inspection authorities, the state statistical service, the Labour Office of the Czech Republic, the Police of the Czech Republic, courts, and similar authorities performing their functions under the relevant legal regulations (processing under Art. 6(1)(c) GDPR).
We also use your personal data in the form of your email address to send company newsletters or specific job offers if we provide you with employment intermediation services. Please note that you may inform us at any time that you do not agree with further sending of newsletters or job offers (see section I of this notice for more information).
E. Who are the recipients of your personal data?
The recipient of your personal data is our company.
Given the nature of the services to be provided to you under the contract, your personal data will also be provided by us, to the necessary extent, to:
(a) transportation providers,
(b) accommodation providers, if arranged for you by the company,
(c) an insurance company with which insurance will be arranged for you or for the person who provided us with your personal data, where disclosure of your personal data is necessary for concluding the contract,
(d) providers of other services agreed in the contract concluded with our company,
(e) state and administrative authorities conducting investigations of accidents, extraordinary events, or incidents, if such a case occurs,
(f) state and administrative authorities for the purpose of protecting your vital interests (see section D above),
(g) healthcare facilities, doctors, paramedics, or similar persons providing you with treatment and/or saving your life, if an event requiring intervention occurs on our premises,
(h) our company’s legal representatives for the purpose of collecting outstanding receivables and/or protecting our rights in case of breach of contract and/or defending against claims made against us,
(i) entities engaged in and/or authorized to collect outstanding receivables,
(j) state and administrative authorities, if we are requested to provide them, in connection with the exercise of such authorities’ powers,
(k) IT service providers,
(l) providers of accounting and audit services,
(m) persons involved in fulfilling the subject matter of a contract to which we are a party,
(n) prospective employers to whom we mediate your employment.
F. Will your personal data be transferred abroad?
Given the nature of the services we provide, your personal data may be transferred to other Member States of the European Union and to third countries (i.e., countries outside the European Union) if our service is delivered abroad and it is necessary to share the data to ensure the provision of the service to the parties concerned.
In the case of transfers of personal data to third countries, we will proceed on the basis of a contract concluded with the recipient of the personal data, which will contain the standard contractual clause as required by the legal regulations of the European Union. We will always transfer personal data only to the extent strictly necessary.
G. For how long will your personal data be processed by the company?
With respect to personal data for which you have granted consent to processing (if applicable), such data, as described in the consent, will be processed for the duration of the consent granted.
For information regarding the duration of your consent to the processing of personal data, you may contact us using the contact details provided in Section A of this notice.
With respect to personal data processed on the basis of the relevant provisions arising from the GDPR (see Section C above), such data will be processed for as long as necessary to provide/receive the agreed performance under the contract, for as long as necessary to demonstrate the provision of the service under the accounting and tax regulations to the competent authorities of the Czech Republic, and for as long as necessary to protect our rights in the event of your breach of contract. In all cases, however, data will be retained for at least the period of the statutory limitation period for any claims, whether yours or those of our company, arising from or in connection with the concluded contract. The length of the statutory limitation period is set out in the Civil Code (Act No. 89/2012 Coll.).
H. In what manner will your personal data be processed and protected?
Your personal data will be processed in electronic form within the company’s electronic system or, where applicable, within the electronic systems of third parties to whom the data are transferred.
Your personal data will also be processed in the form of physical documents (paper documents or similar tangible media), which will be stored in the company’s filing system.
We assure you that we have implemented measures to ensure that your personal data are always protected to the maximum extent against misuse or loss.
All persons within our company who come into contact with personal data have been properly trained and vetted for this purpose. The archive of physical documents is secured against unauthorized access and protected with locks and other physical security measures. Personal data processed electronically are stored in a secured database.
I. What rights do you have in relation to the processing of personal data?
(a) If you have given your consent to the processing of personal data, you have the right to withdraw such consent. You may withdraw your consent by means of a written notice sent by post to the address of our registered office (see Section A above) or electronically to hr@topsearch.cz,stating your identification details, including name, surname, date of birth, and permanent address. It is sufficient to include the wording: “I hereby withdraw my consent granted to TOPSEARCH, s.r.o. for the processing of my personal data.”
Please note that even if you withdraw your consent, our company remains entitled to process your personal data if the processing is based on another lawful ground provided for under the GDPR.
We also draw your attention to the fact that the withdrawal of consent does not affect the lawfulness of processing carried out on the basis of the consent prior to its withdrawal. Thus, any processing performed while your consent was valid shall remain lawful.
(b) You have the right to request access to your personal data, as provided in Article 15 GDPR.
(c) You have the right to rectification of your personal data, as provided in Article 16 GDPR.
(d) You have the right to request the erasure of your personal data, as provided in Article 17 GDPR.
(e) You have the right to request restriction of the processing of your personal data, as provided in Article 18 GDPR.
(f) You have the right to data portability to another controller, as provided in Article 20 GDPR, i.e., you may request us to transfer your personal data to another controller.
(g) You have the right to lodge a complaint against us, as the controller of your personal data, with the supervisory authority, which is the Office for Personal Data Protection (https://www.uoou.cz/) (Article 77 GDPR).
(h) You have the right to notify us that you do not agree to the continued sending of the company’s newsletters and/or job offers, if we provide you with job placement services. Such notification of objection may be made by written notice sent by post to the address of our registered office (see Section A above) or electronically to hr@topsearch.cz, stating your identification details, including name, surname, date of birth, and permanent address. It is sufficient to include the wording: “I object to TOPSEARCH, s.r.o. sending me its newsletter/job offers.”
If you choose to exercise any of the above rights, we are required to identify you, i.e., to verify that the request is being made by the person whose personal data we process.
J. Do you process my sensitive personal data?
In the case of sensitive personal data, we process such data only if they have been provided to us by you and/or disclosed by you, or if their processing is necessary to protect your vital interests or those of another natural person. The sensitive personal data we typically process are listed in Section C above.
In other cases, we process such sensitive personal data only if you have given your consent to their processing.
K. Is the provision of your personal data a necessary condition for concluding a contract with TOPSEARCH?
Without providing a signature on the contract, the necessary contact details, and the necessary information for making payments, we cannot provide the agreed performance. These data are essential for concluding a contract with us (identification of the contracting parties and of the persons to whom the performance is to be provided), and without them the contract cannot be concluded.
If we provide or arrange employment services for you, we cannot deliver our services unless we have information about your name, surname, contact details, education, experience, skills, work history, and health status (in the form of your declaration of general ability to work). The provision of such data is necessary for fulfilling the purpose of the employment placement contract concluded with you and/or for the provision of job placement services.
We assure you that the data obtained are provided to prospective employers only to the minimum extent necessary.
L. What is meant by the processing of personal data?
The processing of personal data means any operation or set of operations performed on personal data or on sets of personal data, whether carried out manually or by automated means. Processing includes the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction of personal data.
For the avoidance of doubt, personal data means any information relating to an identifiable natural person who can be identified, directly or indirectly, by means of an identifier such as a name, identification number, online identifier, or one or more factors specific to the physical, physiological, psychological, economic, cultural, or social identity of that natural person. Personal data does not include information about a legal entity.
M. Additional information
This notice, version no. 2 dated 25 May 2019, is valid and effective as of 25 May 2019.
If we change the purpose of processing your personal data, we will inform you in advance.
If your personal data are provided to us by a third party, we will inform you accordingly.
If anything in this notice is unclear to you, we are ready to answer your questions. You may contact our Data Protection Officer using the contact details provided in Section A above.
If we amend this notice, we will inform you of the change.
This notice is available in physical or electronic form at the registered office of our company and in electronic form on our website www.topsearch.cz