On 04.15.2019. year ALPHA LUXE GROUP d.o.o. (from now on referred to as ALPHA LUXE), represented by Robert Budimir, Director, pursuant to Regulation (EU) 2016/679 of the EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and on The repeal of Directive 95/46 / EC (hereinafter referred to as the Regulation) has:
POLICY ON THE PERSONAL DATA MANAGEMENT SYSTEM AND THE PRIVACY PROTECTION OF THE INDIVIDUAL
I. INTRODUCTORY PROVISIONS
Our websites (content, structure, texts, photos, videos) are copyrighted. Copyright, in particular, is granted to all copies, reproductions, translations, storage and processing by other means, including storage or processing by electronic means, and all processing of photographs or videos contained on this website. Any duplication of information or data, in particular the use of text or parts of text or images, and videos or any other exploitation or sharing, requires the prior written consent of Henkel. ALPHA LUXE has distribution and reproduction rights. Any other unauthorized use will be considered a violation of copyright or intellectual property rights and is subject to legal action.
Personal information is any information relating to a natural person (individual) whose identity is established or identifiable; an identifiable individual is a person who can be identified, directly or indirectly, especially based on name, location, network identifier, or by one or more characteristics specific to his or her physical, physiological, mental, economic, cultural or social identity.
Respondent - is a natural person (individual) whose identity can be ascertained directly or indirectly, in particular on the basis of name, identification number, location information, network identifier or by one or more characteristics specific to his / her physical, physiological, mental, economic, cultural or social identity.
Personal Data Processing - - is any process or set of operations performed on personal data or on sets of personal data, whether by automated or non-automated means such as collecting, recording, organizing, structuring, storing, adjusting or modifying, finding, accessing, using, discovering by transferring, expanding, or otherwise making available, synchronizing, or combining, restricting, deleting, or destroying.
Processing manager - - a natural or legal person, who alone or together with others determines the purposes and means of personal processing data;
Information system - the comprehensiveness of technological infrastructure, organization, people and processes for collecting, processing, generating, storing, transmitting, displaying and disseminating information and disposing of it. The information system can also be defined as the interaction of information technology, data and data processing procedures and the people who collect and use the data. Supervisory Authority - an independent public authority body established by the Republic of Croatia to control and ensure the implementation of the Regulation
. Supervisory Authority - an independent public authority body established by the Republic of Croatia to control and ensure the implementation of the Regulation.
Confidentiality - The property of information (data) that is not available or disclosed to unauthorized entities .
Consent - any voluntary, specific, informed and unambiguous expression of the wishes of the respondent by which he/she gives a statement or explicit affirmative action to consent to the processing of personal data relating to him/her;
Breach of personal data - a breach of security that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access to personal data that has been transferred, stored or otherwise processed;
Profile Creation - any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects related to an individual, especially for the analysis of wishes and needs when buying and selling real estate.
Third parties - natural or legal person, public Authority, ALPHA LUXE or other non-respondent, processing manager, processing executor or persons authorized to process personal data under the direct responsibility of the processing manager or processing agent
Distribution channels - represent the means and means by which the access, contracting, use of ALPHA LUXE products and services, as well as the sending of commercial information and offers related to ALPHA LUXE products and services, include the ALPHA LUXE headquarters and website, and more. Information on available distribution channels ALPHA LUXE is available to the Client by telephone call at any time.
The consent of the respondents is any voluntary, specific, informed and unambiguous expression of the wishes of the respondents by which he/she gives a statement or an explicit affirmative action to consent to the processing of personal data relating to him/her.
Protection of personal data is protected against private data breach which is a breach of security and which violation leads to accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access to personal data that has been transferred, stored or otherwise processed.
III. SCOPE AND OBJECTIVE
A personal data protection policy for the purpose is to establish a personal data protection framework in accordance with the General Data Protection Regulation. The Policy sets rules related to the protection of individuals concerning the collection and processing of personal data and practices related to the free movement of personal data.
The Policy applies to all processing of personal data, except where the processing is of such a nature that it is a statistical analysis from which it is not possible to identify an individual.
IV. PRINCIPLES OF DATA PROCESSING
The principles of data processing are the basic rules that ALPHA LUXE conducts during the processing of personal data of respondents, and the processing that is carried out in accordance with the principles stated below is considered legal.
1. Legality, fairness and transparency - Personal data are lawfully, fairly and transparently processed concerning the respondent; In certain situations, ALPHA LUXE will require respondents to search for some personal items that are not required to provide a specific service, but are required by law to collect (e.g., the Anti-Money Laundering and Terrorist Financing Act). ALPHA LUXE also ensures the transparency of the processing of personal data in accordance with which it will provide the respondents with all the necessary information and, upon request, provide the respondents with an insight into their data, the explanations of the processing, the foundations and the lawfulness of the processing, etc. and their use or processing, as well as the extent to which such personal information is or will be processed. The respondent will be informed of all relevant information promptly or before the data collection itself.
2. Restriction of purpose - personal data must be collected for specific, explicit and lawful purposes. They may not be further processed in a manner inconsistent with those purposes unless other processing is required by law or necessary for the quality delivery of the service itself.
3. Data Reduction - The collection and processing of personal data are appropriate, relevant and limited to what is necessary for the purposes for which they are processed.
4. Accuracy - personal information is accurate and up-to-date; ALPHA LUXE will take all reasonable steps to ensure that personal information that is incorrect is taken into account without delay, or corrected, taking into account the purposes for which it is processed; ALPHA LUXE ensures the application of this principle through communication with respondents through which a correction of information may be requested if a respondent notes that some of his or her personal information is incorrectly stated.
5. integrity and confidentiality - personal data have been processed in such a way as to ensure adequate security of personal data, including protection against unauthorized or unlawful processing and accidental loss, destruction or damage by appropriate technical or organizational measures;
6. storage restriction - personal data is stored in a form that allows the respondents to be identified only for as long as is necessary for the purposes for which the personal data are processed; personal data may be stored for extended periods of personal data will be processed solely for statistical purposes, subject to appropriate technical and organizational measures, or if there is a legitimate interest (e.g. in a court case)
V. CONFIDENTIALITY OBLIGATION
All ALPHA LUXE employees must comply with the measures defined in this Policy. ALPHA LUXE will ensure that third parties who, as part of their cooperation with ALPHA LUXE, gain access to personal information are aware of the measures defined in this Policy to comply with them.
All persons under a contract of employment, or any arrangement of a business relationship that may directly or indirectly access personal information, undertake to respect the confidentiality and protection of the individual's privacy, including the prevention of unauthorized access to personal data and equipment used in processing data or their unauthorized use.
ALPHA LUXE will forward respondents' data to state institutions when there is a legal basis for doing so (for example, forms for the Anti-Money Laundering Financing of Terrorism Act).
VI. THE LAWFULNESS OF THE PROCESSING OF PERSONAL DATA
ALPHA LUXE considers the personal data of the respondents to be their property, and to them, it relates. However, for ALPHA LUXE to be able to provide a service to the respondent, and under the laws set out below, it is necessary to process the minimum data set essential for the quality of the service provided. Therefore, if the respondent refuses to provide the requested data set, ALPHA LUXE will not be able to provide him with the service.
Accordingly, the personal data of respondents are processed when one of the following conditions is met:
a) processing is necessary for the performance of the contract in which the respondent is a party or to take action at the request of the respondent before the conclusion of the contract
b) processing is necessary to comply with legal obligations - when the law authorizes or obliges ALPHA LUXE to perform specific processing, ALPHA LUXE will process the personal data of the respondents according to that law.
c) processing is necessary for the legitimate interests of ALPHA LUXE - except where the interests or fundamental rights and freedoms of respondents requiring the protection of personal data are more reliable than those, especially if the respondent is a child. Under the legitimate interest of ALPHA LUXE includes treatments that serve to enhance the process, product development and business improvement, modernize services, offer products and services that are evident to facilitate its business with ALPHA LUXE, and for the benefit of litigation and for the purpose that is necessary and justified for the protection of persons and property.
d) the respondent has given consent to the processing of his or her data. In essence, the consent must be verifiable and voluntary, written in easy to understand language and the respondent has the right to withdraw his / her consent at any time (withdrawal of the consent must be as simple as giving the consent. Presentation of new products and services, as well as the offer of real estate that ALPHA LUXE communicates through available distribution channels ALPHA LUXE considers part of the service and will not ask for the consent of the respondents, as long as the processing itself is under the processing principles set out in point IV and is based on one of the stated processing laws.
e) processing is necessary to protect the critical interests of the respondents;
VII. RESPONSIBLE RIGHTS
Respondent has the following rights:
1) Right of access - The respondent has the right at any time to contact ALPHA LUXE and obtain confirmation that personal data relating to him are being processed and, if such personal data is processed, to request access to personal data and information to which he is entitled concerning the protection of personal data.
ALPHA LUXE provides a copy of the personal information being processed. For any additional copies requested by the respondent, the Company may charge a reasonable fee based on administrative costs. If the respondent submits the request electronically and unless the respondent requests; otherwise, the information is provided in the usual electronic format.
2) Right to Correction Respondent has the right, without undue delay, to obtain from ALPHA LUXE the correction of inaccurate personal data relating to him. Considering the purposes of the processing, the respondent has the right to complete incomplete personal data, including by making an additional statement. The Company shall disclose any correction of personal data to any recipient to whom the personal data have been published unless this proves impossible or requires a disproportionate effort. The Company notifies the respondent of those recipients if requested by the respondent.
3) Right to erasure (Right to be forgotten) - The respondent has the right to submit a request for deletion of personal data relating to him. A legitimate request for the removal of data must be fulfilled without undue delay. If the respondent is entitled to the erasure of the data, but the eradication is not possible or unreasonable, the data must be protected by blocking against unauthorized processing. The prescribed data retention periods must be respected.
ALPHA LUXE communicates any deletion of personal information to any recipient to whom personal information has been disclosed unless this proves impossible or requires a disproportionate effort. The Company notifies the respondent of those recipients if requested by the respondent.
4) Right to Restrict Processing - Respondent has the right to receive from ALPHA LUXE a restriction of processing in cases of disputing accuracy, the illegality of processing, termination of need for processing, and exceeding legitimate data processing rights. Under applicable regulations, ALPHA LUXE may process personal data even when processing is restricted.
5) Right to Data Portability - Respondent has the right to receive personal data relating to him provided by ALPHA LUXE in a structured, commonly used and machine-readable format, and has the right to transfer this information to another processing manager without interruption by ALPHA LUXE if the processing is based on consent or contract and is performed by automated means.
6) Right of Objection - - The Respondent has the right to object at any time to the processing of personal data relating to him or her, if the processing is based on the legitimate interests of ALPHA LUXE, including profile creation and processing for direct marketing purposes. ALPHA LUXE may then no longer process personal data unless it proves that there are legitimate reasons for processing that go beyond the interests, rights and freedoms of the respondents or for the purpose of making, exercising or defending legal claims. Furthermore, if personal data are processed for direct marketing purposes, the respondent is entitled at any time to object to the processing of personal data relating to him or her for such marketing, which involves the creation of a profile to the extent related to such direct marketing.
7) Right to Withdrawal of Privilege - Respondent has the right to withdraw his consent at any time. The withdrawal of the privilege does not affect the lawfulness of the processing based on the opportunity before its withdrawal. Removal of the attachment must be as simple as giving it..
8) Right to Compensation and Liability - Respondent who has suffered property or non-material damage due to violation of the prescribed legal provisions is entitled to compensation from the processing manager or the processing agent for the damage sustained.
Method of exercising rights - - the respondent may exercise his rights stated in this article through the contact information published on the ALPHA LUXE web site and in the information received in the pre-contracting process. If he considers that there has been an irregularity in the processing of his data, the respondent has the right to contact ALPHA LUXE and the right to submit a complaint to the national supervisory authority.
Respondent has the right not to be affected by a decision based solely on automated processing, including the creation of a profile, which produces legal effects that affect or similarly significantly affect it, unless that decision is necessary to make or execute it. of the agreement between the respondents and ALPHA LUXE, as permitted by law, or based on the express consent of the respondents.
ALPHA LUXE ensures that the respondent is provided with all information to be provided if personal information is collected from the respondent or if personal information is not obtained from the respondent and that the respondent is informed of his or her rights under the previous article. ALPHA LUXE will publish information on the protection of personal data on its official website.
IX. RECORDING AND STORING DATA
ALPHA LUXE has established and maintains records of personal data and processing that is carried out on them. It is continuously ensured that only personal data for whose processing there is a legitimate basis are included in the processing.
Personal data are adequate, relevant and limited to what is necessary for the purposes for which the data are processed. Therefore, it is ensured that the period during which personal data are stored is kept to a strict minimum. Personal data are processed only if the purpose of the processing could not reasonably be achieved by other means.
ALPHA LUXE continuously implements appropriate technical and organizational safeguards, taking into account the nature, scope, context and purposes of the processing, as well as the risks of varying levels of probability and severity to the rights and freedoms of respondents.
ALPHA LUXE does not allow the unauthorized collection, processing or use of personal information. The rule restricting access to data only applies to the data required to perform particular business tasks. ALPHA LUXE employees are strictly prohibited from using the personal data of respondents for any purpose that does not comply with the conditions defined in Chapter VI. The legality of processing. Finally, ALPHA LUXE, under applicable laws (e.g. the law on the prevention of money laundering and terrorist financing), has the right to access and process some of the personal information, but only to the extent necessary to comply with regulatory requirements or to execute the Agreement with the respondent.
Personal information is protected against unauthorized access, use, alteration and loss. Protection mechanisms apply to personal information within ALPHA LUXE, regardless of the form in which it is stored - paper or electronic.
The personal information that ALPHA LUXE collects and processes in its work is considered confidential and must be treated with special care, and may be used solely for the reason that it was collected.
ALPHA LUXE will only collect and store personal information to the extent necessary to fulfil the purpose of the processing. ALPHA LUXE only processes personal data that are relevant, relevant, moderate and limited to what is required for the purposes for which they are processed ("data reduction"); ALPHA LUXE takes all necessary steps to ensure that your information is accurate, complete and, where appropriate, up-to-date, and undertakes to collect respondents' permissions whenever necessary and to notify respondents of the processing of their personal data.
When storing data, personal data will be stored in as few places as they need to be adequately protected. Access to personal information may be made possible solely based on a business need. It is forbidden to use personal data to develop or test IT systems. Whenever possible, personal data must be protected by encryption, pseudonymization or anonymization.
X. LAWFUL PROCESSING AND RIGHT TO COMPLAIN
ALPHA LUXE will process respondents' data under positive legal and other regulations governing the prevention of money laundering for the purpose of monitoring and preventing fraud, money laundering, etc., which is carried out under the regulations, standards and recommendations of the European Union institutions or national supervisory authorities.
Under the Regulation, ALPHA LUXE grants respondents the right to object to the processing of data for direct marketing purposes, whether concerning initial or further processing, at any time and free of charge.
XI. TRANSFER OF PERSONAL DATA
In the case of entering into a business cooperation agreement, ALPHA LUXE can forward the personal data of the respondents to an external associate who has professional competences and who provides sufficient guarantees regarding the provision of appropriate own data protection measures and with which ALPHA LUXE has signed a cooperation agreement, all for the purpose of delivering as fast and quality service as possible. The same applies to business cooperation agreements with other business entities registered for real estate brokerage, law offices, architectural offices, surveying offices, etc.
ALPHA LUXE furthermore, and in the part of providing advertising services (Posters), may provide access to your personal information to its partners, who act as processing agents. These third-party service providers will only operate on the instructions of ALPHA LUXE. They will only have access to your personal information to fulfil the purposes for which personal information is collected and subject to the same privacy and privacy rules as ALPHA LUXE. ALPHA LUXE is required to obtain your consent before forwarding your personal information to partners for direct marketing purposes.
Besides, your data may be forwarded based on the following:
XII. INCIDENT MANAGEMENT AND RIGHT TO COMPLAIN
ALPHA LUXE takes all possible steps to protect the personal data of respondents. Besides, all employees have to notify the responsible person in the event of an incident related to the protection of personal data and in the event of a personal data breach. ALPHA LUXE is required to report the incident to the Personal Data Protection Agency within 72 hours of finding out the injury, if practicable. ALPHA LUXE also informs the respondent of a personal data breach without undue delay in the event of personal data breach likely to cause a high risk to the rights and freedoms of individuals. The respondent has the right to file a complaint with the supervisory authority (Personal Data Protection Agency) in the event of an incident concerning his data or if he considers that ALPHA LUXE violates his rights as defined in the Regulation.
XIII. FINAL PROVISIONS
This Policy shall enter into force on the date of its adoption.
ALPHA LUXE GROUP Ltd..