Principles of data processing for supplier-client relationships

At Westlogic with its registered seat at Olomoucká 267/29, Opava, Company ID No.: 28637372, we take the protection of personal data very seriously. Therefore, please read through this document where we explain how our company processes your personal data in connection with the provision of our products and services.

What kind of personal data do we need from you?

Our company Westlogic is the controller of the personal data you provide to us. We collect personal data that is relevant to the purpose for which it is processed. Under no circumstances do we collect your sensitive personal data (special category of personal data).

Why do we need your personal data?

  1. For the purpose of commercial (customer-supplier) relationships, in order to fulfil our contractual obligations, we process the following personal data:
    • First name, surname, title, date of birth, address of permanent residence, contact address, email address, telephone number, fax number, bank account details, company name, note for the seller, order, invoice, communication with client, refunds (order number, first name, surname, email address, claim outcome, photo, bank account number, refunded amount).

      Unless another legal regulation stipulates a longer period of time, we process the personal data for a maximum period of 10 years after the completion of the last part of performance under the agreement.
  2. In order to fulfil our statutory obligations, for the purposes of accounting and tax records, we process the following data: 
    • Tax and accounting records.

      We keep accounting documents for 5 years and tax documents for 10 years
  3. For the purposes of direct marketing aimed towards our customers, based on our legitimate interest, we process the following personal data:
    • First name, surname, email address, employer details, information concerning whether the message was read, clicking on an email link.

      We keep this personal data for a maximum period of 2 years from the last purchase or from the end of using the service.
  4. For the purposes of improving our services, we keep record of your queries concerning our services as our legitimate interest, including the following personal data:
    • Name, email address, query.

      We erase your queries concerning our services no later than upon the lapse of 6 months.
  5. For the purposes of recording and reporting of cases of personal data breach, in order to defend our legal claims, we have a legitimate interest in processing the following personal data:
    • First name, surname, date of birth, telephone number, email address, date of notice, incident description, measures adopted.

      We will keep such personal data for a period of 10 years.
  6. For the purposes of exercising the rights to personal data protection, in order to defend our legal claims, we have a legitimate interest in processing the following personal data:
    • First name, surname, date of birth, permanent residence, date of request, subject of request, date of response, response with respect to exercising the rights of data subjects, signature.

      We keep this personal data for a period of 10 days.

      You may object to the processing performed based on the legitimate interest of Westlogic with our Data Protection Officer.
  7. For the purposes of marketing and company promotion and based on your consent, we process the following personal data:
    • First name, surname, email address, employer details, information concerning whether the message was read, clicking on an email link.

      We keep this personal data for a maximum period of 5 years or until you withdraw your consent.
  8. Use of cookies is defined here

Your consent to receiving marketing materials can be withdrawn using the footer of every email or by notifying our Data Protection Officer.

Who do we share your personal data with?

Your personal data is provided to the following recipients:

  • For the purposes of customer communication and working with documentation, we use the services of Google Inc., with its registered seat at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
  • Our website is run by Automattic Inc. (20-2602536).
  • IT support is provided by individuals working at the company’s headquarters.
  • Marketing services are provided by  individuals working at the company’s headquarters.

The aforementioned recipients perform the processing of your personal data solely for the purpose and based on our instructions pursuant to relevant measures ensuring the confidentiality and security of your personal data.

When transferring personal data outside the EU, an additional guarantee is provided – Google Inc. is part of the Privacy Shield.

What are your rights?

In order to protect your personal data, you can exercise your rights gratuitously:

Right of access – If you wish to know which personal data our company holds about you.

Right to rectification – If the personal data you have provided to us is inaccurate or not updated, you can request that we perform the rectification of your personal data.

Right to erasure – Upon exercising this right, we will erase all your personal data that we identify as unnecessary (no legal grounds) or held unlawfully. The right to erasure is exercised automatically upon the lapse of the period designated for the storage of the personal data, upon withdrawal of your consent, or in the event that we recognize your objection to processing as justified.

Right to restriction of processing – Provided that you wish to defend your claims and our company fails to fulfil your requirements related to exercising your personal data protection rights, you can exercise your right to restriction of processing and we will not use your personal data besides the cases where the processing is stipulated by the law. In the event that we decide to keep processing your personal data, we will inform you of this fact.

Right to data portability – If you have provided us with data based on your consent or for the purposes of the agreement, upon your request, we are obliged to pass this data in an electronic form onto you or a recipient designed by you.

Right to object – to the processing of your personal data based on legitimate interest (e.g. protection of property or defence of rights) if your rights and freedoms are being breached.

Right to lodge a complaint – with our Data Protection Officer or with the Supervisory Authority.

Contacting our Data Protection Officer

If you wish to obtain further details concerning the way we process your personal data or the way you may exercise your rights, do not hesitate to contact our Data Protection Officer:

office@westlogic.eu

How do we process your personal data?

As the security and protection of personal data is of our highest priority, we process your personal data in compliance with the following procedures and methods:

  1. At all times, your personal data is processed for a specific, clear, understandable and stipulated purpose and only for a period of time necessary with respect to the purpose of processing;
  2. Your personal data is processed in a way that ensures the highest possible security of such data which prevents any kind of unauthorised access to your personal data;
  3. At all times, we inform you of the processing of your personal data and of your rights related to personal data processing;
  4. At our company, we adhere to the relevant technical and organisational measures in order to ensure the level of security corresponding to all potential risks. All persons who come in contact with our clients’ personal data are obliged to maintain confidentiality of the information acquired in connection with the processing of such data.

How do we protect your personal data?

Personal data processing at our company is managed by the method of enforcement of personal data security. Specific steps and processes are stipulated with respect to the organisational and technical security. Instructions and processes of personal data are updated regularly and their fulfilment is under constant review. While processing personal data, we use security mechanisms ensuring personal data protection of the highest possible level to prevent the data from the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of transferred, stored or otherwise processed personal data, or to prevent the unauthorised access to such data. 

The employees and persons using the personal data within their work duties or contractual obligations are bound by confidentiality by the relevant legal regulations or contractual relations; the confidentiality obligation is maintained even upon the termination of their employment or contractual relation with our company.