(general information)
In accordance with Act no. 110/2019 Coll. on the Personal Data Processing, as amended, (hereinafter referred to as the “Act”) and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to as the “Regulation”), TollNet a.s., with registered office at Holušická 2221/3, 148 00 Praha 4, Czech Republic, Company Reg. No.: 29055059, VAT ID: CZ29055059, registered in the Companies Register kept by the Municipal Court in Prague, insert No. B 16063 (hereinafter referred to as the “TollNet” in the appropriate grammatical form), processes your personal data within the scope and under the conditions specified in the following articles.
Principles of Personal Data Protection
- In case of personal data processing by TollNet, you are a data subject, i.e. a person whose personal data is being processed.
- TollNet processes your personal data exclusively on the basis of the conditions specified in the Act or the Regulation.
- Your personal data will be stored securely, in accordance with the security policy of TollNet, only for the time necessary to fulfil the purpose of processing and only for the purpose they were obtained for.
- Access to personal data will be limited to persons who are entrusted by TollNet with the processing of personal data and who process the personal data on the basis of TollNet’s instructions.
- TollNet has a legal obligation to provide your personal data during inspections, supervisory activities, reporting obligations or at the request of authorised government bodies or institutions, if it ensues from legal regulations.
- TollNet may also provide your personal data to recipients who are processors or third-parties. TollNet hereby declares that it has duly concluded contracts with its processors, who ensure an appropriate level of personal data protection, in accordance with applicable regulations related to the personal data protection, including the Act and the Regulation.
- Personal data will never be published and will never be used for automated individual decision-making, including profiling.
- TollNet does not intend to transfer the personal data to a third country or an international organisation within the meaning of chapter V (articles 44 – 50) of the Regulation.
Lawfulness of Personal Data Processing
TollNet processes your personal data exclusively based on :
- your prior consent to the processing of your personal data,
- the needs necessary for the performance of the contract to which the data subject is a party or for the implementation of a pre-contractual measure upon the data subject’s request,
- a legal regulation or an international treaty the Czech Republic is bound by,
- a legitimate interest of TollNet or a third party, except in cases where the interests or rights of the data subject requiring the protection of personal data prevail over these interests, especially if the data subject is a child.
Scope of Personal Data Processing
TollNet processes personal data to the extent specified in the following subsections.
Area of Processing Activity: Personnel and Payroll Agenda
Purpose of processing: performance of the employer’s obligations related to the employment relationship or similar relationship (e.g., contract for work), including pre-contractual relationships (e.g., open competitions or job interviews).
Data subjects: employees, spouses of employees, persons dependent on employees, former employees, job seekers
Period of personal data processing: as stipulated by applicable legal regulations
Legal basis of processing (major regulations):
- Act No. 262/2006 Coll., Labour Code, as subsequently amended,
- Act No. 48/1997 Coll., on Public Health Insurance, as subsequently amended,
- Act No. 258/2000 Coll., on Public Health Protection, as subsequently amended,
- Act No. 592/1992 Coll., on Public Health Insurance Contributions, as subsequently amended,
- Act No. 155/1995 Coll., on Pension Insurance, as subsequently amended,
- Act No. 187/2006 Coll., on Sickness Insurance, as subsequently amended,
- Act No. 117/1995 Coll., on Supplementary Benefits, as subsequently amended.
Recipient categories: health insurance companies, Czech Social Security Administration, payroll accounting provider, legal counsels, tax advisors, statutory auditor
Area of Processing Activity: Recruitment Activities
Purpose of processing:
- keeping records on promising job seekers where conclusion of employment contract (or other type of contract of similar purpose) is not imminent
- keeping records on received job applications received on demand or unsolicitedly (including CV, motivation letters, professional certificates and others)
Data subjects: job seekers
Period of personal data processing:
- 3 years, if the applicant confirms consent to be included in the records of job seekers,
- 30 days if the applicant does not confirm its consent
Legal basis of processing: explicit consent of data subject (for the period of 3 years); consent expressed by submission of documents (like CV, motivation letter, professional certificates and others) in order to get employment (for the period of not more than 30 days)
Recipient categories: contract recruitment agencies
Area of processing activity: Contractual partners – employees of contractual partners
Purpose of processing: performance of the contractual relationship with the data subject’s employer, including pre-contractual relationships
Data subjects: natural persons – employees of a contractual partner in a contractual relationship with TollNet, including contract negotiations and terminated contracts
Period of personal data processing: 10 years, if applicable legal regulations do not stipulate longer period
Legal basis of processing: legitimate interest
Recipient categories: statutory auditor, legal counsels, tax advisers, contracting authorities
Note: This area of processing activity is similarly applied to co-workers of TollNet’s contractual partners operating in the self-employed regime (usually on the basis of a co-operation agreement concluded with a TollNet contractual partner).
Area of processing activity: Contractual partners – natural persons
Purpose of processing: implementation of a contract with a natural person
Data subjects: natural persons who are in a pre-contractual relationship, natural persons with whom a contractual relationship has been concluded and natural persons with whom a contractual relationship has ended.
Period of personal data processing: as stipulated by applicable legal regulations
Legal basis of processing: contract with a natural person
Recipient categories: statutory auditor, legal counsels, tax advisers, contracting authorities
Area of processing activity: CCTV Monitoring of Common Areas at TollNet’s Premises
Purpose of processing: protection of the company’s assets, protection of employees belongings at workplaces
Data subjects: employees, visitors and employees of TollNet’s contractual partners in common areas at TollNet’s premises (entrance/door areas, coridors)
Period of personal data processing: 5 working days
Legal basis of processing: legitimate interest
Recipient categories: law enforcement authorities, CCTV supplier (only during service and maintenance activities or at security incident investigation)
Data Protection Officer
TollNet appointed Mr. Petr Vandas as data protection officer (hereinafter referred to as the “Data Protection Officer”), who can be contacted via e-mail sent to gdpr(at)tollnet.cz or in writing at the correspondence address: GDPR, TollNet a.s., Holušická 2221/3, Praha 4, 148 00, Czech Republic.
Your Rights under the Regulation
Your rights as a data subject referred to in Article 15 et seq. of the Regulation encompass:
- the right to obtain confirmation from TollNet whether personal data concerning you are being processed (if TollNet processes such personal data, you, as the data subject, have the right to obtain access to this personal data),
- the right to request from TollNet the correction of personal data concerning you as a data subject (if incorrect or invalid data is processed)
- the right to request from TollNet the deletion of personal data concerning you as a data subject (if any of the conditions set out in Article 17 of the Regulation is met),
- the right to request from TollNet restrictions on the processing of personal data concerning you as a data subject (if any of the conditions set out in Article 18 of the Regulation are met),
- the right to object to the processing of personal data carried out in the legitimate interests of TollNet, including direct marketing (under the conditions laid down in Article 21 of the Regulation),
- the right to withdraw consent to the processing of personal data at any time,
- the right to obtain information on whether the provision of personal data is a legal requirement or a contractual requirement or a requirement necessary for the conclusion of the contract, and whether you as a data subject are obliged to provide personal data, as well as the possible consequences of not providing personal data,
- the right to obtain information about the source of personal data, if personal data have not been obtained from you as a data subject,
- the right to obtain information in relation to TollNet’s obligation to notify you as a data subject without undue delay of a personal data breach, if such breach of personal data protection may lead to a high risk to your rights as a natural person.
As a data subject, you can exercise your rights as follows:
- in writing in paper form with an authenticated signature; the content of the application must clearly show that you are exercising your rights under the Regulation,
- in writing in electronic form (i) by e-mail delivered to the Data Protection Officer with your recognised electronic signature, (ii) by a data message delivered to TollNet’s data box from your data box,
- in cases where we process your personal data on the basis of your consent, you can further revoke this consent electronically, by delivering an e-mail message to the address of the responsible person.
We will process your request within 30 days of receiving your request in accordance with the conditions herein. In some special cases, a longer period may be required to examine your request. We will process such a request within 60 days from the date of receipt of the request, and we will inform you, as data subject, in writing about the application of the longer period.
As a data subject, you also have the right to address your complaint directly to the Office for Personal Data Protection (https://www.uoou.cz), if you are of the opinion that the processing of your personal data by TollNet has violated the Regulation.
Contact details of the Office:
- postal address: Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Praha 7, Czech Republic
- e-mail: posta@uoou.cz
- data box: qkbaa2n