These privacy conditions explain how we process personal data within the company when providing our services Rapsodia s.r.o., with registered office at: Strojárenská 1059/5, Košice – Staré Mesto district 040 01 , ID No.: 54 819 806 , registration: Commercial Register of the Municipal Court Košice, section: Sro, file no. 54814/V (hereinafter referred to as " controller “ or „ we '). For any questions regarding the protection of personal data or to receive and process requests from data subjects, do not hesitate to contact us:
E-mail: info@rapsodiacentrum.sk
Phone number: 0940 945 335
Correspondence address: Hviezdoslavova 2 , Košice – Old Town district 040 01
These privacy policies serve primarily to fulfill the information obligations under Art. 13 and 14 of the GDPR towards data subjects whose personal data we process. Typically, these are mainly our employees or employees of our business partners, clients, or suppliers. When processing personal data, we are guided primarily by the EU General Data Protection Regulation (" GDPR ), which also governs your rights as a data subject, [1]these provisions of Act no. 18/2018 Coll. on the protection of personal data (hereinafter referred to as the " Personal Data Protection Act “), which apply to us as well as other legal regulations. If you do not fully understand any information provided in these terms, please do not hesitate to contact our responsible person.
Why do we process personal data?
Processing of personal data is necessary on our part, in particular, so that we can:
- to provide our services and products and for this purpose to process the personal data of our clients, suppliers, business partners, employees, and other persons;
- effectively manage our human resources;
- fulfill various legal and contractual obligations; and
protect our legitimate interests.
For what purposes and on what legal grounds do we process personal data?
We process personal data for the following purposes based on the following legal grounds:
| Purpose of processing personal data | Legal basis | |
| 1. | Service reservation (reservation system) | Pre-contractual relations |
| 2. | Conclusion of a contractual relationship with a customer for the purpose of delivering goods and services | Performance of contract |
| 3. | Handling of complaints and claims (complaint procedure) | Fulfillment of legal obligations |
| 4. | Proving, exercising or defending legal claims (legal agenda) | Legitimate interest |
| 5. | Agenda of data subjects' rights | Fulfillment of legal obligations |
| 6. | Accounting and tax purposes | Fulfillment of legal obligations |
| 7. | Archival purposes and records management | Art. 89 GDPR |
| 8. | Statistical purposes | Art. 89 GDPR |
What are the legitimate interests we pursue when processing personal data?
For the following purposes, we rely on the legal basis of legitimate interest according to Art. 6 para. 1 lit. f) GDPR. Below you will find a more detailed explanation of these purposes or legitimate interests:
| Proving, exercising or defending legal claims (legal agenda) | In isolated cases, we may need to prove, exercise or defend our legal claims in court or out of court, or we may need to report certain facts to public authorities, which we consider to be our legitimate interest. |
What personal data about you do we process?
We only process common personal data such as title, first name, last name, address (billing, delivery), phone number, email.
To whom do we provide your personal data?
We take the confidentiality of personal data very seriously, and therefore we have adopted internal policies thanks to which your personal data is shared only with authorized employees of our company or verified third parties. Our employees and workers may have access to your personal data exclusively on a " need-to-know “ basis, i.e., only authorized employees of the specific department related to the processing of personal data may have authorized access, while this access is typically limited by the position, function, and job description of the specific employee. We provide personal data of our clients, employees, business partners, and other natural persons only to the necessary extent to the following categories of personal data recipients:
- our verified and duly legally bound processors;
- our professional advisors (e.g. lawyers, auditors);
- payroll and accounting companies;
- providers of software and cloud services;
- provider of technical (IT) and organizational (event agency) support for our company;
- Social Insurance Agency, pension management insurance companies, supplementary pension insurance companies, health insurance companies, Office of Social Affairs and Family;
- by postal service and courier services;
- employees of the above-mentioned persons.
If we use a processor for the processing of personal data, we always verify in advance whether the processor meets organizational and technical requirements in terms of ensuring the security of the processing of your personal data. If we use our own recipients (internal staff of our company) for the processing of personal data, your personal data are always processed on the basis of authorizations and instructions by which we instruct our recipients not only regarding internal personal data protection rules, but also regarding their legal responsibility for violations thereof. If we are requested by a public authority to disclose your personal data, we examine the conditions for disclosure established by legislation and do not provide your personal data without verifying whether the conditions are met. If you are interested in information regarding our current processors, please do not hesitate to contact us.
To which countries do we transfer your personal data?
By default, we restrict any cross-border transfers of personal data to third countries outside the European Economic Area (EU, Iceland, Norway, and Liechtenstein).
How long do we retain your personal data?
We retain personal data for no longer than is necessary for the purposes for which the personal data are processed. In general, the retention period is derived from legal regulations. If the retention period does not derive from legal regulations, we always determine the retention period of your personal data in relation to specific purposes through our group internal policy and/or our records management schedule. If we process your personal data based on consent, after its withdrawal we are obliged to no longer process the personal data for that purpose. However, this does not exclude the possibility that we may continue to process your personal data on another legal basis, especially when it comes to the fulfillment of legal obligations.
General retention periods for personal data for our defined purposes of processing personal data are as follows:
| Purpose | General retention period for personal data |
| Service reservation (reservation system) | During the reservation and then for 30 days |
| Conclusion of a contractual relationship with a customer for the purpose of delivering goods and services | During the term of the contractual relationship and the fulfillment of rights and obligations arising from it. |
| Handling of complaints and claims (complaint procedure) | For a period of 3 years. |
| Proving, exercising or defending legal claims (legal agenda) | Until the expiration of the legal claim. |
| Agenda of data subjects' rights | Until the expiration of the legal claim. |
| Accounting and tax purposes | For ten years following the accounting year to which the accounting documents, accounting books, lists of accounting books, lists of numerical characters or other symbols and abbreviations used in accounting, depreciation plan, inventory lists, inventory records, chart of accounts relate. |
| Archival purposes and records management | During the retention periods according to the records management plan. |
| Statistical purposes | During the duration / existence of other processing purposes. |
The retention periods mentioned above set only general periods during which personal data is processed for the given purposes. In reality, however, we proceed to liquidate or anonymize personal data even before the expiration of these general periods if we consider the given personal data to be unnecessary from the perspective of the above-mentioned processing purposes. Conversely, in some specific situations, we may retain your personal data longer than stated above if required by legal regulations or our legitimate interest. If you are interested in information regarding the specific retention period for storing your personal data, please do not hesitate to contact us.
How do we obtain personal data about you?
We most often obtain your personal data directly from you. In such a case, the provision of personal data is voluntary. You can provide personal data to our company in various ways, e.g.:
- by registering on our pages (as a job applicant);
- in the process of concluding a contract with our company;
- communication with you;
- by participating in events organized by our company;
- by participating in our company's social media activities;
- by sending the contact form with your comments, queries or questions.
However, we may also obtain your personal data from your employer or from the company in connection with which we process your personal data. Most commonly, these are cases where we are concluding or negotiating a contractual relationship or its terms with the company in question. If the acquisition of personal data relates to a contractual relationship, it is most often a contractual requirement or a requirement necessary for the conclusion of a contract. Failure to provide personal data (whether yours or your colleagues') may have negative consequences for the organization you represent, as the contractual relationship may not be concluded or implemented. If you are a member of the statutory body of an organization that is our contractual party or with which we are negotiating the conclusion of a contractual relationship, we may obtain your personal data from publicly available sources and registers. In any case, we do not further systematically process any accidentally obtained personal data for any purpose of personal data processing defined by us.
What rights do you have as a data subject?
GDPR establishes the general conditions for exercising your individual rights. However, their existence does not automatically mean that your exercise of these rights will be granted by us, as exceptions may apply in specific cases, or certain rights are tied to specific conditions that may not be met in every instance. Your request concerning a specific right will always be addressed and examined from the perspective of legal regulations and our internal policy for handling data subject requests. As a data subject, you particularly have:
- The right to request access to personal data under Article 15 GDPR that we process about you. This right includes the right to confirmation as to whether we process personal data about you, the right to access this data, and the right to obtain a copy of the personal data we process about you, if technically feasible;
- Right to rectification and completion of personal data according to Article 16 GDPR, if we process incorrect or incomplete personal data about you;
- Right to erasure of your personal data under Article 17 GDPR;
- Right to restriction of processing of personal data under Article 18 GDPR;
- Right to data portability pursuant to Article 20.
If you believe that we are processing incorrect personal data about you with regard to the purpose and circumstances and you cannot change such personal data through the features of the application, account, or websites, you can request the correction of incorrect personal data or the completion of incomplete personal data using the additional statement below (all information is voluntary) and / or contact us via our contact details:
| Supplementary statement on the correction of personal data | |
| Your name and surname: | |
| Contact details: | |
| Relevant processing purpose: | Please specify the purpose of processing your request relates to. |
| Context or relationship between you and our company: | Please state if you are our employee, business partner, job applicant, etc. |
| Nature of your repair: | Please explain whether you are requesting a correction of incorrect personal data or the completion of incomplete personal data. |
| Context of your correction request: | Please explain why you believe we are processing your incorrect or incomplete personal data. |
| Repair: | Please specify which specific personal data you require to be corrected or supplemented. |
| Please send us this supplementary statement for the correction of personal data via the contact details provided above. | |
You also have the right to lodge a complaint at any time with the Office for the protection of personal data of the Slovak Republic or to file a lawsuit with the competent court. In any case, we recommend resolving any disputes, questions, or objections primarily through communication with us.
Is there automated individual decision-making?
No, we are not currently carrying out processing operations that would lead to a decision with legal effect or other significant impact on your person, based solely on fully automated processing of your personal data within the meaning of Art. 22 GDPR.
How do we protect your personal data?
It is our duty to protect your personal data in an appropriate manner and for this reason we pay due attention to its protection. Our company has implemented generally accepted technical and organizational standards in order to maintain the security of the processed personal data, especially against their loss, misuse, unauthorized modification, destruction, or other impact on the rights and freedoms of the data subjects. In situations where sensitive data is transferred, we use encryption technologies, see e.g. communication with the payment gateway. Your personal data is stored on our secure servers or servers of the operators of our websites located in data centers located in the Slovak Republic. In the case of using third-party analytical tools, the data is stored on third-party servers (see cookies).
Cookies
Cookies are small text files that improve the use of the website, e.g. by making it possible to recognize previous visitors when logging into the user environment, by remembering the visitor's choice when opening a new window, by measuring the website's traffic or the way it is used for its user improvement. Our website uses cookies mainly for the purpose of measuring its traffic. If we are able to identify the person visiting our web environment during recording, it will be the processing of personal data. For such processing, we must have a legal basis. One legal basis can be your consent as the data subject. If we process your data based on your consent, this consent can be revoked at any time.
You can control or delete cookies as you wish. For details, see aboutcookies.org. You can delete all cookies stored on your computer and most browsers can be set to prevent them from being stored.
Cookies are useful as long as site owners do not misuse them for unauthorized data collection. If you do not trust cookie functionality, you can regularly delete them from your disk. In some cases, information obtained through cookies may be incorrectly recorded, leading to login issues in, for example, our web applications. Instructions for deleting all cookies, including incorrectly recorded ones, can be found below. Instructions for deleting cookies in individual internet browsers
Internet Explorer™
Safari™
Opera™
Mozilla Firefox™
Google Chrome™ https://support.google.com/chrome/answer/95647?hl=sk&hlrm=en
Privacy Policy Change
Personal data protection is not a one-time matter for us. The information we are required to provide regarding our processing of personal data may change or become outdated. For this reason, we reserve the right to modify and change these terms at any time and to any extent. If we change these terms in a material way, we will bring this change to your attention, for example, by a general notice on this website or by a special notice via email.
Rapsodia s.r.o.
In Košice, dated 1.6.2023
