Personal Data Protection (GDPR)
in accordance with Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter the “GDPR Regulation”)
Identification of the CONTROLLER:
LIVING PRO, s. r. o., registered office: Dolné Rudiny, RONDEL OFFICES building 2956/3, 010 01 Žilina, Company ID (IČO): 52006140, registered in the Commercial Register of the District Court Žilina, section: Sro, insert No.: 71070/L (hereinafter the “Controller” or the “real estate agency”).
tel. kontakt: +421 948 278 777 e-mail: info@livingpro.sk
The Controller has not appointed a representative or a data protection officer.
The Controller ensures the protection of personal data of natural persons in accordance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the “GDPR”) and Act No. 18/2018 Coll. on the protection of personal data and on amendments to certain acts (hereinafter the “Act”).
Personal data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as: name, surname, date of birth; an identification number – birth number, ID card number, location data — address; genetic data relating to the inherited or acquired genetic characteristics of a natural person; data concerning the health of the data subject which provide information about their past, current or future physical or mental health; data specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; an online identifier — natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols (IP address, cookies or other identifiers).
The Controller processes personal data in accordance with the principles of lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.
The Controller processes in particular the following categories of personal data
a) identification data: name, surname, birth number, date of birth, nationality, identity document number, photograph
b) contact details: permanent or other residence address, place of business address, registration number in the register in which the entrepreneur is registered, company ID, telephone numbers, e-mail addresses.
The Controller obtains personal data when concluding contracts, during acts related to the conclusion of contracts (e.g. statutory obligations arising from Act No. 297/2008 Coll. on protection against money laundering and terrorist financing) and the performance of contracts, as well as from publicly available sources (public registers).
Purposes and legal basis for processing the Data Subject’s personal data: The legal basis for processing personal data is the performance of a contract between the Controller and the Data Subject pursuant to Article 6(1)(b) of the GDPR Regulation. The processing is necessary for the performance of a contract to which the Data Subject is a party, or in order to take steps at the request of the Data Subject prior to entering into a contract.
The purpose of processing the Data Subject’s personal data by the Controller is the handling and performance, or exercise of rights and obligations, arising from the contractual relationship concluded between the Controller and the Data Subject and from the legal regulations applicable to that contractual relationship. Providing personal data is a necessary requirement for concluding and performing the contract. Without providing personal data, it is not possible to conclude the contract or subsequently perform it.
a) Processing of data necessary for the performance of a contract – in particular the conclusion of a purchase contract, lease contract, reservation contract, contract for brokering a sale, purchase or lease, deposit agreement, agreement on a future contract, set-off agreement, preparation of a handover protocol, documents for cadastral proceedings, preparation of consumer information for distance contracts or off-premises contracts. Further, in particular, the preparation of the relevant contract or other listed documents, the registration of the contract and related documents including all their changes in the Controller’s system, the performance of the subject of the contract, the handling of complaints, and the recovery of receivables or other rights arising in connection with non-performance of the contract.
b) Preparation of a viewing record — the legitimate interest of the real estate agency in this case is the proper and undisturbed conduct of its business activity, which could not be carried out if it were not possible to process the personal data of potential buyers/tenants of real estate brokered by the real estate agency, in order to prove that it brokered a specific transaction.
c) Fulfilment of the Controller’s legal obligations, in particular: • customer due diligence under Act No. 297/2008 Coll. on protection against money laundering and terrorist financing, • keeping accounts and issuing accounting documents, in particular under Act No. 431/2002 Coll. on accounting and Act No. 222/2004 Coll. on value added tax, as amended, • registering mail and records management, in particular under Act No. 395/2002 Coll. on archives and registries.
d) Marketing and advertising activities of the Controller – with the consent of the Data Subject.
Recipients of personal data
The Controller may entrust the processing of personal data to third parties, so-called processors, e.g. natural or legal persons providing IT services, real estate agents cooperating with the Controller under a mandate contract, and natural or legal persons who prepare contractual documents – external law firms or lawyers. A processor may process personal data only on the basis of a data processing agreement meeting the requirements of the Regulation and the Act. The Controller is also obliged to provide personal data to the Slovak Trade Inspection, the tax office, the Office for Personal Data Protection, law enforcement authorities, or other public authorities if the Controller is requested to provide such personal data in accordance with national law or the law of the European Union.
Personal data retention period:
The Data Subject’s personal data will be processed to the necessary extent for the period required to fulfil the obligations under the contract and, in accordance with the Act on archives and registries, the Accounting Act and the VAT Act, for 10 years following the year to which they relate (the year in which the last invoice was issued). After the retention period expires, the Controller will delete the personal data.
Rights of the data subject:
– Right of access to personal data (Art. 15 of the GDPR Regulation) The Data Subject has the right to obtain from the Controller confirmation as to whether their personal data are being processed and, where that is the case, the right to access their personal data.
– Right to rectification of personal data (Art. 16 of the GDPR Regulation) Data Subjects have the right to have their personal data rectified if they are inaccurate or incomplete, or if they have changed or need to be supplemented. The Data Subject may also request erasure if their data are processed unlawfully and in breach of the GDPR. The Controller must comply with a request for rectification of personal data without undue delay. The Data Subject has the right to have incomplete personal data completed.
– Right to erasure (right to be forgotten) (Art. 17 of the GDPR Regulation) The Data Subject has the right to obtain from the Controller the erasure of their personal data without undue delay if one of the following grounds applies: • the personal data are no longer necessary for the purposes for which they were collected or otherwise processed, • the Data Subject withdraws the consent on which the processing is based, • there is no other legal ground for the processing of personal data, • the Data Subject objects to the processing and there are no overriding legitimate grounds for the processing, • the Data Subject objects to the processing and the personal data have been unlawfully processed, • the personal data have to be erased for compliance with a legal obligation under Union or Member State law to which the controller is subject, • the personal data have been collected in relation to the offer of information society services. The Controller does not apply a request for erasure where the processing is necessary: • for exercising the right of freedom of expression and information, • for compliance with a legal obligation, • for the performance of a task carried out in the public interest, • for reasons of public interest in the area of public health, • for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, • for the establishment, exercise or defence of legal claims.
– Right to restriction of processing of personal data (Art. 18 of the GDPR Regulation) The Data Subject has the right to have the Controller restrict the processing of their personal data where one of the following applies: • the Data Subject contests the accuracy of the personal data, for a period enabling the Controller to verify the accuracy of the personal data, • the processing is unlawful and the Data Subject opposes the erasure of the personal data and requests the restriction of their use instead, • the Controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims, • the Data Subject has objected to processing pursuant to Article 21(1), pending the verification whether the legitimate grounds of the Controller override those of the Data Subject. Where processing has been restricted, such personal data shall, with the exception of storage, only be processed: • with the Data Subject’s consent, • for the establishment, exercise or defence of legal claims, • for the protection of the rights of another natural or legal person, • for reasons of important public interest of the Union or of a Member State.
– Right to data portability (Art. 20 of the GDPR Regulation) The Data Subject has the right to receive the personal data they have provided to the Controller and the right to transmit those data to another Controller (e.g. when changing the provider of a certain service). Upon request, the Controller is obliged to enable the transfer of data in a structured, commonly used and machine-readable format (e.g. XML or CSV).
– Right to object to processing for direct marketing purposes and profiling (Art. 21 of the GDPR Regulation) Where personal data are processed for direct marketing purposes, the Data Subject has the right to object at any time to the processing of their personal data, including profiling. If the Data Subject objects to processing for direct marketing purposes, the Controller may no longer process their personal data for such purposes. The Controller does not use automated decision-making or profiling when processing personal data.
– Right to lodge a complaint with the Office for Personal Data Protection The Data Subject may at any time submit a petition or complaint regarding the processing of personal data to the supervisory authority, which is the Office for Personal Data Protection of the Slovak Republic, with its registered office at Hraničná 12, 820 07 Bratislava 27.
The Controller hereby declares that it has taken all necessary measures to secure the personal data of data subjects.
