{"id":299,"date":"2020-10-30T17:47:25","date_gmt":"2020-10-30T17:47:25","guid":{"rendered":"http:\/\/huttohuthikingslovenia.com\/gdpr\/"},"modified":"2022-12-12T14:26:01","modified_gmt":"2022-12-12T14:26:01","slug":"gdpr","status":"publish","type":"page","link":"https:\/\/huttohuthikingslovenia.com\/gdpr\/","title":{"rendered":"GDPR"},"content":{"rendered":"

Right to privacy is one of the most important human rights. In HUD d.o.o. (hereinafter referred to as the Company), we are very well aware of this and we, therefore, respect the privacy of our customers and treat their personal data responsibly, carefully and according to the applicable legislation. The access to personal data is permitted only to authorised Company personnel and contracted processors, to the extent and with the purpose strictly necessary for the smooth implementation, assurance and fulfilment of rights and obligations arising from concluded contractual relations.<\/p>

By taking proper measures, we ensure that unauthorised persons do not access personal data, protect its confidentiality and integrity, and prevent its loss or unintentional destruction throughout the entire time of being processed. We will not be held responsible for any \u201chacking\u201d into a computer system!<\/p>

Company and its processors fully respect the general principles regarding the processing of personal data, which are:<\/p>

We process user personal data legally, fairly and transparently.
We collect personal data for purposes that are pre-determined, explicit and legal; we do not process personal data for any other purpose, except in the case of processing for scientific or historical research purposes and for statistical purposes, under certain conditions.
Personal data is processed to the minimum extent for the purposes for which it is processed.
We ensure that the personal data we process is accurate and regularly updated; incorrect data is corrected or deleted.
We store personal data only as long as it is necessary for the purposes for which they are processed.
We ensure appropriate security of personal data, which includes prevention of unauthorised or unlawful processing and accidental loss, destruction or damage by appropriate technical and organisational measures.<\/p>

1. PRIVACY CONTACT<\/h4>

For questions related to the processing and use of personal data, information, corrections, blocking, deletion of personal data or cancellation of notification consent, cancellation of consent, please contact us on our official email address stated on our webpage.<\/p>

2. WHICH PERSONAL DATA ARE COLLECTED<\/h4>

\u2013 Basic personal data (e.g. name and surname);
\u2013 communication data (e.g. address, mail, telephone no.);
\u2013 information on communication between the Company and you; payments data;
\u2013 any other data obtained based on the consent.<\/p>

3. WHAT ARE THE LEGAL BASES FOR PROCESSING YOUR PERSONAL DATA<\/h4>

We can treat personal data in accordance with valid legislation from the field of protection of personal data:

 \u2013 if this is necessary for the conclusion and\/or fulfilment of a contract (application on an event, workshop, etc.)
 \u2013 if required by law;
 \u2013 if consent is given (which can be cancelled at any time);
 \u2013 if the processing is necessary for the legitimate interests pursued by the Company or a third party.<\/p>

3.1. PROCESSING BASED ON A CONCLUDED CONTRACT<\/h5>

The company processes personal data of individuals to fulfil its obligations under a contractual relationship for the organisation of events, workshops or other services agreed between the contractual parties. In the context of the exercise of rights and the fulfilment of contractual obligations, Company processes personal data of individuals for the following purposes:

 \u2013 identification of an individual;
 \u2013 preparation of the offer and conclusion of the contract;
 \u2013 providing services, whereby Company can give the data to contract partners that will implement an individual       service (e.g. a provider of overnight stays, etc.)
 \u2013 sending notifications to individuals regarding the implementation of the contractual relationship;
 \u2013 informing about changes in legislation in a particular field or changes in terms of sale;
 \u2013 invoicing services;
 \u2013 resolving objections or complaints;
 \u2013 implementation of any recovery procedures, a sale of receivables;
 \u2013 for other purposes, necessary for the conclusion or implementation of a contractual relationship.

To the extent strictly necessary for authentication and identification of transactions, Company processes data for the purpose of preparing reports and planning further activities.

For the purposes of organising events and related services or other services ordered by an individual, Company processes all information needed. This includes in particular, but not exclusively: name, first name, surname, birth date, address, place, country, telephone number, email, etc.

We do not need explicit consent for contractual processing of personal data.

At events or workshops that are strictly connected with photographing and publication of pictures (on Facebook, Twitter, YouTube in Instagram), it is numbered that photographing and publication of pictures are part of an event or workshop. In spite, that photographing and publishing of pictures is a contractual relationship, Company will still gain explicit consent of an individual. In a case where explicit consent for photographing and publication of pictures will not be given and Company will not be able to assure that an individual will not be on photograph, Company is justified to rejects application on such event or workshop.

If the individual does not provide all personal data that the Company needs to fulfil the contractual relationship, the Company cannot execute the individual\u2019s order. Hereby, Company always acquires and further processes only the personal data that is needed to fulfil the contractual relationship.<\/p>

3.2. PROCESSING BASED ON THE LAW<\/h5>

The legal basis means that the Company processes personal data of an individual to fulfil the applicable legal obligations imposed by the legislation. In the Republic of Slovenia, legal obligations to process certain personal data are determined in particular by:

Value Added Tax Act ZDDV-1;

Tax Procedure Act;

Companies Act;

Accounting Act;

Rules on the implementation of the Value Added Tax Act;

Slovenian Accounting Standards.

If Company processes personal data of an individual who has made an online purchase or service order, it keeps the invoice for 10 years (as well as individual\u2019s\/buyer\u2019s data on the account).<\/p>

3.3. PROCESSING BASED ON LEGITIMATE INTEREST<\/h5>

Company may process data on the basis of a legitimate interest which Company or a third party pursues, except when such interests are prevailed by the interests or fundamental rights and freedoms of an individual, to whom the data that requires the protection of personal data is related, in particular when the data relates to a child. In the case of further use of collected data on an individual, the Company implements the assessment according to the General Data Protection Regulation. Such further use of data in a pseudonymised or aggregated form, for example, represents the lawful use of data for marketing and other business or technical analyses of Company.

According to the General Data Protection Regulation, direct marketing also belongs to legitimate interests. For the purposes of direct marketing, Company may create individual profiles without any consent on the basis of basic information on selected services, such as e.g. the type or specific characteristics of the selected service, time of selection or past marketing contacts with the individual, in particular with respect to the expressed interest or lack of interest in certain services. Such basic profiling shall never include sensitive data. An individual may object to the processing according to the right to the restriction (item 7.4).

Based on legitimate interest, the Company may contact the individual to improve the service or determine his satisfaction with the services, even when this is not strictly necessary for the implementation of the contract. Due to the individuals\u2019 interest, the Company does not contact those individuals who have objected to this.

The company has a legitimate interest to keep and further use data for analyses and research for marketing, business planning and similar until the expiration of the legally prescribed retention period.<\/p>

3.4. PROCESSING BASED ON THE CONSENT TO PROCESS PERSONAL DATA<\/h5>

Explicit consent is the basis for personal data processing for which Company does not have a legal or contractual legal basis. For example, consent may relate to:

 \u2013 informing about other Company offers and services, which is implemented exclusively through the communication channel selected by the individual;
 \u2013 photographing and recording an event or workshop for the purpose of presenting Company activities and publishing photos, videos and sound recordings on the Company website and on Facebook, Twiter, YouTube and Instagram profiles.
 \u2013 The individual gives the consent for himself, in the case of a child, consent is given by one of the parents or a legal representative.

In these cases, the processing of personal data is implemented to the extent and for purposes allowed by the individual\u2019s statement and through agreed communication channels, until cancellation.

If the individual does not consent to the personal data collection and processing for one or more purposes specified in an individual consent, this does not have any consequences for the data the processing of which is implemented based on other legal bases.

Personal data collected on the basis of consent will be processed only within the framework and for the purpose of the given consent and will not be transmitted to third parties unless this is explicitly stated in the consent and the individual agrees that personal data may be transmitted to the processor specified in the consent.

The individual can cancel the consent to process personal data at any time by contacting our data protection point (point 8). The consent can be cancelled by an email sent to the email address under point 1.<\/p>

4. HOW LONG IS PERSONAL DATA KEPT<\/h4>

Personal data shall be stored in accordance with the applicable regulations governing the protection of personal data. It shall be stored only as long as necessary for the purposes for which it is processed or according to the law. We store personal data, which we process based on the personal consent of the individual, permanently, until cancellation. Personal data, which we process based on the law or contractual relationship, is kept for as long as the law determines.

If the data is processed based on an individual\u2019s consent due to the marketing of Company, the data may be processed to the necessary extent for as long as necessary for such marketing or services.

After the expiry of the retention period, the personal data is effectively and permanently deleted or anonymised so that it can no longer be linked to an individual.<\/p>

5. HOW DO WE PROTECT PERSONAL DATA<\/h4>

We use technical and organisational security measures to protect personal data against unlawful or unauthorised access or use and also against unintentional loss or impairment of their integrity. We have designed these measures with regard to our IT infrastructure, possible impact on an individual\u2019s privacy and costs and according to current industry standards and practices. Our contractual processors shall process your personal data only if they comply with these technical and organisational security measures.

Maintaining data security means protecting the confidentiality, integrity and availability of personal data:

 \u2013 confidentiality and integrity: individuals\u2019 personal data shall be protected against unauthorised or illegal processing and against unintentional loss, destruction or injury;
 \u2013 availability: we shall ensure that authorised processors can access personal data only when necessary.

Our security procedures include access security, backup copies, monitoring, revision and maintenance, security incident management, etc.<\/p>

6. WHO PROCESSES PERSONAL DATA<\/h4>

Depending on the purposes for which we process individuals\u2019 personal data, we can disclose this data to the following categories of processors:

a) Within Company an employee.
b) Our business partners of which we demand to comply with the applicable laws and personal data protection policy and to pay great attention to the confidentiality of the personal data:

 \u2013 advertising, marketing and promotional agencies and providers, e.g. MailChimp, Google (Google \u2013 only cookie identifier for remarketing, e-mail address for displaying ads in Google AdWords, cookie identifier for analysis in Google Analytics; Facebook \u2013 only cookie identifier for remarketing, e-mail address for displaying ads in Facebook Custom Audiences), that help us implement and analyse the effectiveness of our campaigns and promotions.
 \u2013 companies that perform services for Company, i.e. accounting service provider
 \u2013 natural and legal entities who are our contractual partners and provide consulting or individual services for Company with the purpose of executing a contractual relationship between Company and an individual (e.g. partner agencies, hotels, airlines, carriers, etc.);

c) Other third persons when required by law or legally required for the protection of:
 \u2013 Company (compliance with laws, authority requirements, court orders, legal procedures, reporting obligations and obligations to inform the authorities, etc.), verification or enforcement of compliance with Company policy and agreements;
 \u2013 rights, property or security of Company and\/or its clients in relation to corporate transactions: in the context of transfer or disposal of all or part of its business or otherwise in connection with mergers, consolidations, changes of control, reorganisation of Company.

Our business partners listed above under item b), may only process individuals\u2019 personal data in the framework of our instructions and may not use personal data to pursue any of their own interests. Each individual must bear in mind that the processors listed in items b) and c) above, in particular, service providers that offer services within the framework of applications and\/or through their own channels may separately collect your personal data. In this case, they are solely responsible for its control and their cooperation with individuals must take place according to their terms.<\/p>

7. YOUR POSSIBILITIES AND RIGHTS REGARDING YOUR PERSONAL DATA<\/h4>

Depending on the purposes for which we process individuals\u2019 personal data, we can disclose this data to the following categories of processors:

a) Within Company an employee.
b) Our business partners of which we demand to comply with the applicable laws and personal data protection policy and to pay great attention to the confidentiality of the personal data:

 \u2013 advertising, marketing and promotional agencies and providers, e.g. MailChimp, Google (Google \u2013 only cookie identifier for remarketing, e-mail address for displaying ads in Google AdWords, cookie identifier for analysis in Google Analytics; Facebook \u2013 only cookie identifier for remarketing, e-mail address for displaying ads in Facebook Custom Audiences), that help us implement and analyse the effectiveness of our campaigns and promotions.
 \u2013 companies that perform services for Company, i.e. accounting service provider
 \u2013 natural and legal entities who are our contractual partners and provide consulting or individual services for Company with the purpose of executing a contractual relationship between Company and an individual (e.g. partner agencies, hotels, airlines, carriers, etc.);

c) Other third persons when required by law or legally required for the protection of:
 \u2013 Company (compliance with laws, authority requirements, court orders, legal procedures, reporting obligations and obligations to inform the authorities, etc.), verification or enforcement of compliance with Company policy and agreements;
 \u2013 rights, property or security of Company and\/or its clients in relation to corporate transactions: in the context of transfer or disposal of all or part of its business or otherwise in connection with mergers, consolidations, changes of control, reorganisation of Company.

Our business partners listed above under item b), may only process individuals\u2019 personal data in the framework of our instructions and may not use personal data to pursue any of their own interests. Each individual must bear in mind that the processors listed in items b) and c) above, in particular, service providers that offer services within the framework of applications and\/or through their own channels may separately collect your personal data. In this case, they are solely responsible for its control and their cooperation with individuals must take place according to their terms.<\/p>

7.1. RIGHT TO ACCESS DATA<\/h5>

Each individual can contact us to the email address E-mail address under point 1. to find out which personal data we process. Each individual has the right to access personal data and additional information concerning the processing of personal data, including:

 \u2013 the purpose of the processing;
 \u2013 the categories of personal data;
 \u2013 users and legal entities, to whom personal data have been or will be disclosed;
 \u2013 when possible, the estimated retention period of personal data or, if that is not possible, the criteria used to determine the retention period;
 \u2013 the existence of the right to require from the administrator to correct or delete personal data or to restrict personal data in relation to the  \u2013  \u2013  \u2013  \u2013  \u2013   \u2013 individual, to whom the personal data relates, or the existence of the right to object to such processing;
 \u2013 the right to lodge a complaint with a supervisory body;
 \u2013 when personal data is not collected from an individual, all available information related to its source.<\/p>

7.2. RIGHT OF RECTIFICATION<\/h5>

If an individual finds any error in his personal data or if he finds it incomplete or wrong, he may request Company to correct or supplement inaccurate or incomplete personal data without undue delay.<\/p>

7.3. RIGHT OF DELETION<\/h5>

An individual may request to delete his personal data without undue delay. The Company is obliged to delete personal data without undue delay:

 \u2013 when personal data is no longer required for the purposes for which it was collected or otherwise processed;
 \u2013 if the individual cancels the consent that is the basis for the processing of personal data and if there is no other legal basis for the processing;
 \u2013 if the individual objects to the processing on the basis of the legitimate interest of Company, while there are no prevailing legal reasons for the  processing of personal data;
 \u2013 if the individual objects to the processing for direct marketing purposes;
 \u2013 when personal data should be deleted for the fulfilment of a legal obligation according to EU law or the Slovenian legal order;
 \u2013 in the case of data incorrectly collected from a minor for the use of information society, who, according to the applicable law, cannot provide such data.
(except in some cases, for example, to prove the transaction or if required by law) \u2013 .<\/p>

7.4. RIGHT TO RESTRICTION<\/h5>

Each individual may request a restriction of the processing of his personal data when:

 \u2013 he challenges the correctness of the data, for the period which enables Company to verify the correctness of the personal data;
 \u2013 the processing is unlawful and the individual objects to the deletion of the personal data and instead requests their use to be limited;
 \u2013 The Company no longer needs the personal data for the purposes of the processing, but the individual, to whom the personal data relates, needs it to exercise, implement or defend legal requests;
 \u2013 the individual has filed an objection regarding the processing until it is verified whether legitimate reasons of Company prevail over the individual\u2019s reasons.<\/p>

7.5. RIGHT TO TRANSFERABILITY OF DATA<\/h5>

Each individual shall have the right to receive the personal data concerning him or her, which he or she has provided to Company, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the Company, where the processing is based on consent pursuant or on a contract pursuant and the processing is carried out by automated means.<\/p>

7.6. RIGHT TO OBJECT<\/h5>

On the basis of reasons related to their special circumstances, each individual has the right to object at any time to the processing of their personal data based on the legal interests pursued by Company or a third person. In this case, Company ceases to process personal data, unless it proves necessary processing reasons that prevail over the individual\u2019s interests, rights and freedoms, or for the enforcement or defence of legal claims. When personal data is processed for the purpose of direct marketing, each individual has the right to object at any time to the processing of personal data related to him for the purposes of such marketing, including profiling, if it relates to such direct marketing. If direct marketing is based on consent, the right to object can be exercised by cancelling the given consent.<\/p>

8. WHO CAN I CONTACT IF I HAVE QUESTIONS REGARDING MY PERSONAL DATA<\/h4>

We have organised a contact point that will address your questions or requirements regarding your personal data (and their processing) and the exercise of your rights. You can send us an email address under point 1.

For the purposes of reliable identification when exercising the rights connected to personal data, we may require additional data from you and we can deny action only if we can prove that we cannot identify you reliably.<\/p>

9. RIGHT TO FILE THE COMPLAINT RELATED TO PROCESSING OF PERSONAL DATA<\/h4>

Everyone has the right to file the complaint related to processing of personal data Complaints should be sent to the e-mail address under point 1. You also have the right to file a complaint directly to the Information Commissioner if you believe that the processing of personal data related to you violates Slovenian or EU regulations on the protection of personal data. If you have exercised the right to access the data and, after receiving the decision, you believe that the personal data that you have received is not the personal data you requested or that you did not receive all the personal data required, you can lodge a reasoned complaint to Company within 15 days, before submitting a complaint to the Information Commissioner. The Company will decide on the complaint as on a new request, within five working days of receipt.<\/p>","protected":false},"excerpt":{"rendered":"

Right to privacy is one of the most important human rights. In HUD d.o.o. (hereinafter referred to as the Company), we are very well aware of this and we, therefore, respect the privacy of our customers and treat their personal data responsibly, carefully and according to the applicable legislation. The access to personal data is … Continued<\/a><\/p>\n","protected":false},"author":47,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"open","ping_status":"open","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-299","page","type-page","status-publish","hentry"],"acf":{"page_subheading":"Find out more about how we handle your personal data without infringing upon your privacy rights."},"_links":{"self":[{"href":"https:\/\/huttohuthikingslovenia.com\/wp-json\/wp\/v2\/pages\/299","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/huttohuthikingslovenia.com\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/huttohuthikingslovenia.com\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/huttohuthikingslovenia.com\/wp-json\/wp\/v2\/users\/47"}],"replies":[{"embeddable":true,"href":"https:\/\/huttohuthikingslovenia.com\/wp-json\/wp\/v2\/comments?post=299"}],"version-history":[{"count":5,"href":"https:\/\/huttohuthikingslovenia.com\/wp-json\/wp\/v2\/pages\/299\/revisions"}],"predecessor-version":[{"id":715,"href":"https:\/\/huttohuthikingslovenia.com\/wp-json\/wp\/v2\/pages\/299\/revisions\/715"}],"wp:attachment":[{"href":"https:\/\/huttohuthikingslovenia.com\/wp-json\/wp\/v2\/media?parent=299"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}