Information regarding the processing and protection of personal data
The company TMKG s.r.o. processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as “GDPR”), which repeals Directive 95/46/EC (General Data Protection Regulation), Act No. 18/2018 Coll. on the protection of personal data and on amendments and supplements to certain laws (hereinafter referred to as the “Personal Data Protection Act”), and other generally binding legal regulations.
Your personal data will be stored securely and only for the period necessary to fulfill the purpose of processing. Access to your personal data will be granted exclusively to persons authorized for personal data processing, who process them based on the controller’s instructions in compliance with the security policy.
Identification and contact details of the controller
Controller:
Name: TMKG s.r.o.
Registered Office: Zlatovská 1793, 911 05 Trenčín
Company ID: 51 699 931
Contact details of the responsible person:
Email: info@tmkg.sk
Terms related to personal data protection
To facilitate the understanding of the information provided to data subjects regarding the processing of personal data, the following basic terms are defined in accordance with the GDPR and the Personal Data Protection Act:
- Personal data refers to any data or information related to an identified or identifiable natural person; an identifiable natural person is one who can be identified directly or indirectly, particularly based on a generally applicable identifier, another identifier such as name, identification number, location data, online identifier, or based on one or more characteristics or features that form their physical, physiological, genetic, mental, economic, cultural, or social identity.
- A data subject is any natural person whose personal data are processed.
- The controller is any entity that alone or jointly with others determines the purpose and means of processing personal data and processes personal data in its own name.
- A processor is any entity that processes personal data on behalf of the controller.
- A responsible person is an individual designated by the controller to fulfill tasks under the GDPR and the Personal Data Protection Act.
- A recipient is any person to whom personal data are provided, regardless of whether they are a third party.
- The purpose of processing is a clearly defined or legally established intention of processing personal data associated with a specific activity.
- Processing of personal data means any operation or set of operations performed on personal data, such as collection, recording, organization, modification or correction, retrieval, browsing, utilization, restriction, disclosure, publication, cross-border transfer, storage, deletion, or destruction, regardless of whether performed by automated, partially automated, or non-automated means.
- Consent of the data subject is any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which they express consent to the processing of personal data relating to them through a clear affirmative action.
- Legitimate interest is the interest of the controller or another entity that outweighs the interests or fundamental rights and freedoms of the data subject.
- Profiling is any form of automated processing of personal data consisting of using personal data to evaluate certain personal aspects of a natural person, particularly to analyze or predict aspects related to the property status, personal preferences, interests, reliability, behavior, location, or movement of the data subject.
Information on personal data processing
Personal data processing in the conditions of the controller is generally carried out primarily for:
- Compliance with legal obligations under specific regulations,
- Performance of a contract or within pre-contractual relationships at the request of the data subject,
- The legitimate interests of the company or a third party in accordance with the GDPR and the Personal Data Protection Act,
- Based on the consent of the data subject.
Information on the processing of personal data for the purpose of processing a job applicant’s request
- The purpose of personal data processing is the processing and assessment of an application submitted by a natural person – a job applicant as a data subject.
- Processing of personal data for the purpose of processing and assessing a job application is carried out based on the request of the data subject sent to the controller within pre-contractual relationships and with the consent of the data subject as a job applicant.
- Personal data are not provided to recipients unless otherwise stipulated by a specific law. Cross-border transfer of personal data to third countries or international organizations does not take place, is not required by specific regulations, and is not intended by the controller. The controller does not process personal data based on automated individual decision-making nor does it perform profiling.
- The provision of personal data to the controller by the data subject is necessary to assess the fulfillment of the basic requirements of the job applicant by the controller; if personal data are not provided, it would not be possible to assess the suitability of the job applicant as a potential candidate for the vacant position.
- The controller processes personal data to the necessary extent, including name, surname, education, years of experience in the field, email address, and phone number.
- Personal data are processed for the period necessary to assess and process the data subject’s application, but no longer than one year, in accordance with the controller’s registry plan and Act No. 395/2002 Coll. on archives and registries and on amendments to certain laws, as amended. After this period, all personal data of the data subjects will be destroyed.
Rights of the data subject
- The right to withdraw consent to the processing of personal data – in cases where personal data are processed based on the data subject’s consent, the data subject has the right to withdraw this consent at any time. Consent can be withdrawn by sending a written notification of consent withdrawal to the controller’s registered office address. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
- The right to confirmation and access – the data subject has the right to request confirmation of whether their personal data are being processed. They also have the right to request access to their personal data processed by the controller, which will be provided in written form (either by email or in printed form, as requested by the data subject).
- The right to rectification – if the data held by the controller are inaccurate, incomplete, or outdated, the data subject may request their correction, update, or supplementation.
- The right to erasure (right to be forgotten) – the data subject has the right to request the deletion of their personal data, for example, if the personal data obtained by the controller are no longer necessary for the original purpose of processing. However, this right must be assessed in light of all relevant circumstances, as the controller may have certain legal obligations preventing compliance with such a request.
- The right to restriction of processing – the data subject has the right to request the controller to stop using their personal data, for example, if they believe that the personal data held by the controller may be inaccurate or that the controller no longer needs to use them.
- The right to data portability – under certain circumstances, the data subject has the right to request that the controller transfer their personal data to another third party of their choice.
- The right to object – the data subject has the right to object to processing based on their specific situation.
- The right to lodge a complaint with a supervisory authority – if the data subject believes their personal data protection rights are being violated, they have the right to lodge a complaint with the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27.