Information Duty of the Controller
(hereinafter also referred to as the "Privacy Policy")
According to Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter the "Regulation") in compliance with § 19 of Act No. 18/2018 Coll. on Personal Data Protection (hereinafter the "Act")
Controller:
Business Name: Radomír Takáč – 3D Special
Registered Office: Jánošíkovská 472/21, 900 42 Dunajská Lužná, Slovakia
Company ID (IČO): 55279830
Registered at: District Office Bratislava, Business Register No.: 110-325034
Contact Information:
Contact Person: Radomír Takáč
Phone: +421 918 695 517
Email: info@3dspecial.sk
Address: Jánošíkovská 21, 900 42 Dunajská Lužná
Rights of Data Subjects:
A data subject is a natural person whose personal data we process, primarily but not exclusively employees and clients. Such data subjects, whose personal data are processed in our information systems for specific defined purposes, have rights they can exercise in writing or electronically by contacting the responsible person designated by the Controller. You are the data subject.
Right of Access to Personal Data
This is the right to obtain confirmation from the responsible person about whether personal data of the data subject making the request is processed, as well as the right to access this data. As a data subject, you are entitled to information regarding the purposes of processing, categories of personal data involved, recipients, retention periods, details about any automated processing, and the implications of such processing, etc. (Article 15 of the Regulation). The Controller has the right to take all reasonable measures to verify the identity of the data subject requesting access to data, particularly in connection with online services and identifiers. Upon request, the Controller will issue confirmation on whether personal data concerning the data subject are processed. If the Controller processes such data, a copy of the personal data will be provided upon request. The first copy is provided free of charge; any additional copies requested will incur an administrative fee. If information is requested electronically, it will be provided in a commonly used electronic format via email unless another method is specifically requested.
Right to Restriction of Processing
You may exercise this right if you, as a data subject, contest the accuracy of the personal data or other requirements under Article 18, Recital 67 of the Regulation, through temporarily moving selected personal data to another processing system, restricting user access, or temporarily suspending processing.
Right to Rectification
If the Controller maintains incorrect personal data, the data subject has the right to request correction. You also have the right to supplement incomplete personal data. The Controller shall correct or supplement personal data without undue delay upon your request.
Right to Erasure
This right allows for the "forgetting" of personal data concerning the data subject. Due to its nature and seriousness, this right is subject to certain conditions. The Controller will delete personal data without undue delay upon your request if:
a) The data are no longer necessary for the purposes they were collected or otherwise processed;
b) You withdraw consent on which processing is based;
c) You object to the processing of personal data;
d) The data were processed unlawfully;
e) Deletion is required by law, special regulation, or international treaty binding Slovakia; or
f) Data were collected in relation to information society services offered to a person under 16 years old.
However, the data subject does not have the right to erasure if processing is necessary:
a) For exercising the right of freedom of expression and information;
b) To fulfill legal obligations under Slovak or international law, or for tasks performed in the public interest or under official authority;
c) For reasons of public interest in public health;
d) For archiving purposes in the public interest, scientific or historical research, or statistical purposes where erasure would seriously impede or prevent the achievement of such purposes; or
e) For establishing, exercising, or defending legal claims.
The Controller will erase personal data promptly after evaluating that the data subject’s request is justified.
Right to Lodge a Complaint
Data subjects may lodge a complaint with the Office for Personal Data Protection of the Slovak Republic if they believe their data protection rights have been violated.
Right to Object
Data subjects have the right to object at any time to the processing of their personal data based on:
a) Processing related to public interest tasks or official authority, or legitimate interests of the Controller;
b) Direct marketing purposes;
c) Scientific, historical research, or statistical purposes.
We will assess objections within a reasonable timeframe. In such cases, we shall no longer process the personal data unless we demonstrate compelling legitimate grounds that override your rights or interests, or for the establishment, exercise, or defense of legal claims.
Right to Data Portability
You have the right to request that your personal data provided to the Controller be transferred to another controller in a commonly used, machine-readable format, provided that the data was collected based on your consent or a contractual relationship and processed by automated means.
Additional Information:
- The purpose of personal data processing is the specific reason why the Controller processes the personal data of data subjects in information systems based on specific legal grounds. Each instance of personal data processing is based on a clearly defined, legitimate, and expressly stated purpose.
- To maximize the protection of your personal data, we, as the Controller, have adopted appropriate personnel, organizational, and technical measures. Our goal is to prevent or minimize the risk of unauthorized disclosure, misuse, or other inappropriate uses of your personal data. If an incident occurs that poses a high risk to the rights and freedoms of natural persons, you, as the data subject, will be immediately contacted (Article 34 of the Regulation).
- To comply with the principles of data processing established by the Regulation and Act, particularly the principle of data minimization, we require only those personal data from you that are strictly necessary for legal or contractual purposes. Please note that failure to provide these mandatory data necessary for entering into a contract may result in the inability to establish a contractual relationship.
ECONOMIC-ACCOUNTING AGENDA
Purpose of Personal Data Processing:
The purpose of processing personal data includes handling orders, incoming invoices, customer invoicing, banking transactions, cash management (including cash receipts and expenditures), inventory management, recording fixed assets (including automatic depreciation) and minor assets, and maintaining single-entry/double-entry accounting.
Legal Basis:
Act No. 431/2002 Coll. on Accounting (as amended),
Act No. 222/2004 Coll. on Value Added Tax (as amended),
Act No. 18/2018 Coll. on Personal Data Protection,
Act No. 145/1995 Coll. on Administrative Fees (as amended),
Act No. 40/1964 Coll. Civil Code (as amended),
Act No. 513/1991 Coll. Commercial Code (as amended),
Act No. 595/2003 Coll. on Income Tax.
Categories of Recipients:
Recipients of personal data include relevant tax authorities, Financial Directorate, other public authorities as required by applicable law, an external accounting service provider, and authorized employees.
Retention Periods:
Invoices: 10 years
Internal documents: 10 years
Cash register records: 10 years
Debt collection documents: 5 years
Bank statements: 10 years
Annual statistics: 10 years
Monthly and quarterly statistics: 5 years
Financial statements: 10 years
Categories of Data Subjects:
The categories of individuals concerned are suppliers and customers who are natural persons or self-employed individuals, as well as employees and representatives of suppliers and customers.
Categories of Personal Data:
Personal data processed include first name, surname, title, permanent residence address, temporary residence address, date of birth, type and number of identification documents, phone number, email address, signature, and bank account number.
Security Measures:
The Controller has adopted appropriate personnel, organizational, and technical measures under Article 32(1) GDPR to ensure:
Permanent confidentiality, integrity, availability, and resilience of data processing systems and services.
Ability to timely restore availability and access to personal data following physical or technical incidents.
Regular testing, assessment, and evaluation of the effectiveness of technical and organizational measures ensuring processing security.
Automated Decision-making Including Profiling:
No automated decision-making or profiling is performed.
Cross-border Data Transfer:
Due to the nature and technological methods used in processing, cross-border processing of personal data may occur, ensuring full compliance with all provisions of the GDPR.
LEGAL RELATIONSHIPS
Purpose of Personal Data Processing:
The purpose of processing personal data within this agenda is to manage legal matters such as first-instance proceedings, handling appeals, managing court disputes, legal representation, enforcement of damage compensation rulings, claim recovery, enforcement of contractual obligations, and proposing organizational and legal measures, among other related activities.
Legal Basis:
Act No. 460/1992 Coll. Constitution of the Slovak Republic (as amended),
Act No. 40/1964 Coll. Civil Code (as amended),
Act No. 160/2015 Coll. Civil Procedure Code (as amended),
Act No. 161/2015 Coll. Non-Contentious Civil Procedure Code (as amended),
Act No. 162/2015 Coll. Administrative Court Procedure Code (as amended),
Act No. 300/2005 Coll. Criminal Code,
Act No. 301/2005 Coll. Criminal Procedure Code,
Act No. 71/1967 Coll. Administrative Procedure Code,
Act No. 233/1995 Coll. on Court Executors and Enforcement Activities (Enforcement Code), as amended,
Act No. 7/2005 Coll. on Bankruptcy and Restructuring, as amended,
Act No. 153/2001 Coll. on the Public Prosecutor's Office, as amended,
Act No. 372/1990 Coll. on Offenses (as amended),
Act No. 586/2003 Coll. on Advocacy and on amendments to Act No. 455/1991 Coll. on Trade Licensing (Trade Licensing Act), as amended,
Act on Personal Data Protection and related legislation, as amended.
Categories of Recipients:
Recipients of personal data include judicial authorities, court executors, state administration bodies, public and governmental authorities under applicable legal regulations, and authorized employees.
Retention Periods:
Court disputes, employment disputes, legal assessments, and correspondence: 10 years
Significant contracts (contracts with municipalities, real estate contracts): 10 years
Other contract records (central procurements, supplier contracts, customer contracts, advisory contracts, insurance contracts, leasing agreements, investments, loan agreements, rentals, etc.): as required by applicable legal retention periods.
Categories of Data Subjects:
Data subjects include employees of the Controller, debtors, opposing parties in disputes, and other natural persons involved as parties in proceedings.
Categories of Personal Data:
Processed personal data include first name, surname, title, nationality, residence address, date of birth, ID card number, residence permits, passport numbers (for foreign nationals), bank account numbers, phone numbers, and email addresses.
Security Measures:
The Controller has implemented appropriate personnel, organizational, and technical measures under Article 32(1) GDPR to ensure:
Permanent confidentiality, integrity, availability, and resilience of data processing systems and services,
The capability to promptly restore data availability and access following physical or technical incidents,
Regular testing, assessment, and evaluation of the effectiveness of security measures.
Automated Decision-making Including Profiling:
No automated decision-making or profiling is conducted.
Cross-border Data Transfer:
Cross-border processing of personal data may occur, depending on the purpose of processing and technological use, in full compliance with all GDPR provisions.
CONTRACTUAL RELATIONSHIPS
Purpose of Personal Data Processing:
Monitoring compliance with legal regulations, handling legal matters, reviewing and preparing contractual relationships, property transfers, lease contracts, and purchase agreements. Participating in drafting contracts within supplier-customer relationships, enforcing contractual obligations and financial penalties, claims for damage compensation, and related actions.
Legal Basis:
Act No. 40/1964 Coll. Civil Code (as amended),
Act No. 513/1991 Coll. Commercial Code (as amended),
Act No. 108/2024 Coll. on Consumer Protection (as amended),
Act No. 372/1990 Coll. on Offenses (as amended),
Contracts concluded under the aforementioned legal regulations.
Categories of Recipients:
State administration bodies, public and governmental authorities (as per relevant legal regulations),
Banks (under Act No. 483/2001 Coll. on Banks, as amended),
Insurance companies (under Act No. 39/2015 Coll. on Insurance, as amended),
Slovak Post and courier services (under Act No. 324/2011 Coll. on Postal Services, as amended),
Suppliers (contractual basis),
Courts, law enforcement agencies (under Acts No. 160/2015 Coll., No. 161/2015 Coll., No. 162/2015 Coll., and Act No. 301/2005 Coll. Criminal Procedure Code, as amended),
Auditors of financial statements (under Act No. 431/2002 Coll. on Accounting, as amended).
Retention Periods:
Significant contracts (with municipalities, real estate contracts): 10 years,
Other contracts (central procurement, supplier, customer, advisory, insurance, leasing, investment, loan, rental agreements, etc.): 10 years,
Insurance claims: 10 years.
Categories of Data Subjects:
Contractual parties who are natural persons.
Categories of Personal Data:
Title,
First name,
Surname,
Date of birth,
Birth identification number,
Phone number,
Email address,
ID card number,
Price,
Bank account number.
Security Measures:
The Controller has implemented appropriate personnel, organizational, and technical measures under Article 32(1) GDPR to ensure:
Permanent confidentiality, integrity, availability, and resilience of data processing systems and services,
Capability to promptly restore data availability and access following physical or technical incidents,
Regular testing, assessment, and evaluation of the effectiveness of security measures.
Automated Decision-making Including Profiling:
No automated decision-making or profiling is performed.
Cross-border Data Transfer:
Due to the purpose of processing and technological methods used, cross-border processing of personal data may occur, ensuring compliance with all GDPR provisions.