GDPR
CONDITIONS FOR PERSONAL DATA PROTECTION
NEW EVENT d.o.o., having its registered office at Karadjordjeva 8/56, Belgrade, Serbia (hereinafter referred to as “NEW EVENT d.o.o.”), as the controller, processes the personal data of data subjects in accordance with the applicable legal regulations, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the “General Data Protection Regulation”), and Act No. 18/2018 on Personal Data Protection and on Amendments and Supplements to Certain Acts (hereinafter referred to as the “Personal Data Protection Act”).
The protection of the personal data of our customers and other individuals is important to us. These Conditions contain information on the method, scope, purpose and period for the processing of your personal data.
I. CONTROLLER
The Controller which processes your personal data is our company – NEW EVENT d.o.o., having its registered office at Karadjordjeva 8/56, Belgrade, Serbia.
II. SCOPE, LEGAL BASIS AND PURPOSE OF THE PROCESSING OF PERSONAL DATA
We process your personal data in accordance with the applicable legal regulations and based on legal grounds under the applicable legal regulations, with your consent or without your consent.
Personal data processing with your consent:
1. Distribution of marketing materials
a) scope of personal data:
– name, surname, e-mail address, telephone number and, where applicable, Business ID No. if you are an individual entrepreneur (sole trader)
b) legal basis:
– processing based on your consent as the data subject under Article 6, paragraph 1, letter a) of the GDPR
c) purpose:
– marketing purposes
2. Opening and maintaining a customer account
a) scope of personal data:
– name, surname, e-mail address, telephone number, address, business history, or fax, company name, company ID No., Tax ID No., other address
b) legal basis:
– processing based on your consent as the data subject under Article 6, paragraph 1, letter a) of the GDPR
c) purpose:
– providing the customer account service
3. Registration of job seekers
a) scope of personal data:
– name, surname, e-mail address, telephone number, highest education attained and, where applicable, other information stated in the reply or response to a job offer
c) legal basis:
– processing based on your consent as the data subject under Article 6, paragraph 1, letter a) of the GDPR
c) purpose:
– inclusion in the selection process
Personal data processing without your consent:
1. Performance of a contract, including the handling of any complaints
a) scope of personal data:
– basic information which includes your name and surname, address and, where applicable, Business ID No., Tax ID No., VAT ID No. if you are an individual entrepreneur (sole trader),
– contact data which include your e-mail address, phone number or contact address,
– transaction data, especially information on your payments and payment methods,
– other data listed in an order form,
– records of e-mail communication or other communication in electronic or other written form.
b) legal basis:
– the processing of personal data is necessary
for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract pursuant to Article 6, paragraph 1, letter b) of the GDPR
– processing is necessary for compliance with the Controller’s legal obligation pursuant to Article 6, paragraph 1, letter c) of the GDPR
c) purpose:
– the exercise and discharge of rights and obligations based on a contract or pre-contractual relationship
2. Accounting and tax purposes
a) scope of personal data:
– billing data which include your name and surname, address, Business ID No., Tax ID No. and, where applicable, VAT ID No. if you are an individual entrepreneur (sole trader),
b) legal basis:
– processing is necessary for compliance with the Controller’s legal obligation pursuant to Article 6, paragraph 1, letter c) of the GDPR
c) purpose:
– accounting and tax records
3. Recovery of unpaid overdue receivables
a) scope of personal data:
– all personal data stated within and related to the performance of a contract pursuant to point 1
b) legal basis:
– processing is necessary for the purposes of the legitimate interests pursued by the Controller pursuant to Article 6, paragraph 1, letter f) of the GDPR
c) purpose:
– proper fulfilment of pecuniary obligations ensuing from a contractual relationship
4. Processing messages sent through a contact form
a) scope of personal data:
– name and surname, e-mail address or other data stated in a contact form
b) legal basis:
– the processing of personal data is necessary
for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract pursuant to Article 6, paragraph 1, letter b) of the GDPR
– processing is necessary for the purposes of the legitimate interests pursued by the Controller pursuant to Article 6, paragraph 1, letter f) of the GDPR
c) purpose:
– sales promotion and communication with prospects and customers
5. Contact phone and e-mail
a) scope of personal data:
– information you provide to us by phone or e-mail
b) legal basis:
– processing according to the specific content of your notification
– processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party pursuant to Article 6, paragraph 1, letter f) of the GDPR
c) purpose:
– sales promotion and communication with prospects and customers
6. Camera system operated in the office and in the parking lot and on the grounds around the office and the parking lot
a) scope of personal data:
– visual and sound recordings
b) legal basis:
– processing is necessary for the purposes of the legitimate interests pursued by the Controller pursuant to Article 6, paragraph 1, letter f) of the GDPR
c) purpose:
– property protection
7. Browsing a website
a) scope of personal data:
– date and time of access, URL (address) of the referring website, file displayed, amount of data sent, browser type and version, operating system, IP address
b) legal basis:
– processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party pursuant to Article 6, paragraph 1, letter f) of the GDPR
c) purpose:
– statistics
8. Cooperation with the public authorities
a) scope of personal data:
– all personal data required by a public authority
b) legal basis:
– processing is necessary for compliance with the Controller’s legal obligation pursuant to Article 6, paragraph 1, letter c) of the GDPR
c) purpose:
– according to the specific requirement of a public authority
III. CATEGORIES OF RECIPIENTS OF PERSONAL DATA
We only provide your personal information in justified cases and to the necessary extent to the following categories of recipients:
a) Courier and shipping companies
b) Suppliers and service providers
c) Accounting offices, auditors and tax advisers
d) IT service providers
e) Law offices, collection agencies, courts and distrainors
f) Public authorities, including law enforcement agencies
g) External service providers within the corporate network
We obtain your personal information from the following sources:
a) we have been provided with the personal data by you as a data subject; or
b) we have obtained the personal data in certain justified cases from public sources, lists and registers (such as the companies register, the trades register, etc.).
Our company does not transfer your personal data to third countries (non-EU countries) or international organisations.
IV. PERIOD OF STORAGE OF PERSONAL DATA
If consent is given by the data subject pursuant to Article 6, paragraph 1, letter a) of the GDPR, we process your personal data until you withdraw your consent, but for no longer than 5 years after you grant it.
In case of the performance of a contract under Article 6, paragraph 1, letter b) of the GDPR, we process your personal data for the duration of the contractual relationship, including the warranty period, the complaint terms, and the limitation period of any of our or your related claims.
In case of compliance with a legal obligation pursuant to Article 6, paragraph 1, letter c) of the GDPR, we process your personal data for the period of time under special legal regulations.
In case of a legitimate interest pursuant to Article 6, paragraph 1, letter f) of the GDPR, we process your personal data for the duration of the legitimate interest, depending on the particular purpose of the processing of personal data.
V. YOUR RIGHTS AS THE DATA SUBJECT
With respect to your personal data, you have the following rights against us that we are ready to fulfil in relation to you:
1) You have the right to obtain from our company confirmation as to whether or not your personal data are being processed, and, where that is the case, access to the personal data and the following information:
a) the purposes of the processing;
b) the categories of personal data concerned;
c) the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
d) where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
e) the existence of the right to request from our company the rectification or erasure of your personal data, restriction of processing, the right to object to such processing and the right to lodge a complaint with a supervisory authority;
f) where the personal data are not collected from you as the data subject, any available information as to their source;
g) the existence of automated decision-making, including profiling, referred to in Article 22, paragraphs 1 and 4 of the GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for you as the data subject;
h) on the appropriate safeguards pursuant to Article 46 of the GDPR relating to the transfer, provided that your personal data are transferred to a third country or to an international organisation.
If you make a request by electronic means, we will provide you with information in a commonly used electronic format unless otherwise requested by you.
We will provide you with a copy of the personal data undergoing processing. For any further copies requested by you, we may charge a reasonable fee based on administrative costs. The right to obtain a copy shall not adversely affect the rights and freedoms of others.
2) You have the right to the rectification of your personal data which we are processing about you if your personal data are inaccurate or incomplete or have changed. Contact us and we will rectify them without undue delay.
3) You have the right to the erasure of your personal data if:
a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
b) you have withdrawn your consent on which the processing is based, and where there is no other legal ground for the processing;
c) you have objected to being subject to decision-making based on the automated processing of your personal data and there are no overriding legitimate grounds for the processing, or you have objected to the processing of your personal data for direct marketing purposes;
d) the personal data have been processed unlawfully;
e) the personal data have to be erased for compliance with a legal obligation under the Union or Member State laws to which the controller is subject;
f) the personal data have been collected in relation to the offer of information society services.
If we have made your personal data public and are obliged to erase the personal data, we, taking account of the available technology and the cost of implementation, will take reasonable steps, including technical measures, to inform the controllers which are processing your personal data that you have requested the erasure by such controllers of any links to, or the copy or replication of, those personal data.
You do not have the aforementioned rights to the extent that processing is necessary:
a) for exercising the right of freedom of expression and information;
b) for compliance with a legal obligation which requires processing under the Union or Member State laws to which our company is subject or for the performance of a task carried out in the public interest or in the exercise of the official authority vested in our company;
c) for reasons of public interest in the area of public health in accordance with Article 9, paragraph 2, letters h) and i) as well as Article 9, paragraph 3 of the GDPR;
d) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89, paragraph 1 of the GDPR in so far as the right to erasure is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
e) for the establishment, exercise or defence of legal claims.
4) You have the right to the restriction of processing, provided that:
a) the accuracy of your personal data is contested by you, for a period enabling our company to verify the accuracy of your personal data;
b) the processing is unlawful and you oppose the erasure of your personal data and request the restriction of their use instead;
c) we no longer need your personal data for the purposes of the processing, but they are required by you as the data subject for the establishment, exercise or defence of legal claims;
d) you have objected to the processing of your personal data pursuant to Article 21, paragraph 1 of the GDPR pending the verification of whether the legitimate grounds of our company override your legitimate grounds as the data subject.
Where processing has been restricted, such personal data shall, with the exception of storage, only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.
You will be informed by us before the restriction of processing is lifted.
5) You have the right to the portability of data concerning you, which you have provided to us, or other controllers, in a structured, commonly used and machine-readable format without hindrance from us, where:
a) the processing is based on your consent pursuant to Article 6, paragraph 1, letter a) of the GDPR or Article 9, paragraph 2, letter a) of the GDPR or on the performance of a contract pursuant to Article 6, paragraph 1, letter b) of the GDPR; and
b) the processing is carried out by automated means.
You have the right to have the personal data transmitted directly from our company as the controller to another controller, where technically feasible.
The right to data portability shall not adversely affect the rights and freedoms of others.
6) You have the right to object to the processing of your personal data which is carried out by our company under Article 6, paragraph 1, letter e) of the GDPR or Article 6, paragraph 1, letter f) of the GDPR, including profiling based on those provisions, as well as you have the right to object to the processing of your personal data by our company for direct marketing purposes, which includes profiling to the extent that it is related to such direct marketing.
7) You have the right to automated individual decision-making if you find or believe that the processing is unlawful or contrary to your rights.
When processing personal data, there is no automated decision-making, including profiling, as referred to in Article 22, paragraphs 1 and 4 of the GDPR.
8) You have the right to withdraw your consent to the processing of your personal data if the processing of your personal data is based on consent, without affecting the lawfulness of the processing based on consent before its withdrawal.
9) You have the right to lodge a complaint with a supervisory authority, such authority being the Office for Personal Data Protection of the Republic of Serbia.
10) You have the right to lodge a request, question or complaint with our company.
You may send your requests, questions or complaints to our company by e-mail to office@newevent.rs, or by post to the registered address of our company.
We will respond to your request, question or complaint free of charge within 30 days. In the case of complexity or a large number of requests, we may extend this period for another 60 days. In that event, we will inform you of the extension of the period as well as the reasons for its extension.
In the event that your request, question or complaint is apparently unsubstantiated or repeated, we may charge a reasonable administrative fee to cover the costs associated with the provision of this service.
VI. YOUR RIGHTS AS THE DATA SUBJECT
Our company as the Controller may amend these Personal Data Protection Conditions, especially for the purpose of incorporating legislative changes or updating the purposes and legal basis of the processing of personal data or for other reasons. The amended Conditions for Personal Data Protection will be published on our website.