GUIDELINES ON PERSONAL DATA PROCESSING



Introduction

As of May 25, 2018, the regulation by the European Parliament and the Council (EU) 2016/679 from April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (“GDPR”), which newly regulates the protection of personal data becomes effective.

Our company Engage Hill s.r.o., Ident. No.: 271 60 246, seated in Francouzská 175/14, Vinohrady, 120 00 Praha 2, Czech Republic, listed in the business register which is managed by the Municipal Court in Prague and registered under reference number C 100881, (“Engage Hill”) will act as your data controller and give your data careful consideration. The safety of your data is very important to us.

These guidelines concern the processing of personal data of our customers, suppliers, subjects to our surveys and analyses, and visitors of websites managed by Engage Hill https://engagehill.com/.

In these guidelines on personal data processing (“Guidelines”) you can find the summary of information regarding which personal data are being processed, for what use, to whom and for what reason they can be disclosed in addition to which rights belong to natural persons in terms of processing their personal data.

These Guidelines are effective as of May 25, 2018 and were developed in accordance with GDPR and will be updated from time to time.

Processing of personal data

According to GDPR, personal data means any information relating to an identified or identifiable natural person (the data subject).

Which personal data are being processed and how do we obtain them?

Engage Hill processes personal data to the extent in which the data was given by the data subject or to the extent in which Engage Hill gathered the data otherwise. Engage Hill processes the data according to legislation or in terms of fulfilling legal obligations. Engage Hill processes primarily these categories of personal data:

  • identification data, contact and address details of customers or potential customers of Engage Hill (e.g. name and surname, address, e-mail. telephone number, identification number (Ident. No.), tax identification number (VAT Ident. No.)),
  • data about subjects of surveys and analyses provided by such subjects to Engage Hill within the surveys and analyses (e.g. age interval, gender, name of profile/team, selected colors for individual objects)
  • communication with the customers or potential customers of Engage Hill (especially e-mail correspondence, records of personal communication),
  • information about the activity of data subjects on Engage Hill websites (more detailed description is available in the “Cookies” section of the document).

This enumeration however, does not imply that each Engage Hills´ data subject is subdued to all categories of data processing mentioned above.

Engage Hill can collect personal data variously, not only from the data subject but for example from public indexes (business register, trade register), all according to legislation.

Engage Hill services are not designated for individuals under the age of 16. Personal data of children younger than 16 years are not being processed. If you are not of the age of 16 or above please do not use our websites without supervision and consent of your legal representative.

Why do we process personal data?

Engage Hill uses personal data in order to offer and provide their services, improve upon them, change and develop them as well as to answer your questions, wishes or complaints.

Engage Hill uses personal data for fulfilling the mutual contract or a request of a data subject, based on fulfilling legal obligations or in terms of legitimate interest.

Engage Hill requires personal data in order to identify its customers or potential customers, provide them with information about the services offered, answer questions, wishes or complaints.

Engage Hill also processes personal data to protect its own rights and legitimate interests, e.g. in case of settling disputes with legal action.

Engage Hill processes personal data of its customers or potential customers also for marketing and business communications.

If you are an Engage Hill customer, Engage Hill may send you marketing and commercial communications about its services because of its legitimate interest. If you do not wish Engage Hill to continue to send you such marketing and business communications on a basis of a legitimate interest, you may object as set out below in this Guidelines.

In other than the above cases, Engage Hill may send you marketing and commercial communications based on your consent. You may withdraw your consent at any time by communicating such information to Engage Hill to one of the below contacts.

If you are a subject to surveys and analyses of Engage Hill your personal data is processed in terms of legitimate interest of Engage Hill towards conducting such surveys and analyses in which we identify your attitudes to terms and activities, for our customers who have commissioned such survey or analysis and have asked you to participate in such a survey or analysis. The personal data collected by Engage Hill does not allow Engage Hill to directly identify you.

For how long do we process personal data?

Engage Hill processes personal data for a necessary period of time in order to complete the goal for which the data was collected, e.g. for a necessary period of time to provide Engage Hill services.

In case of personal data being processed by Engage Hill based on a consent, the data is being processed for a period of time for which the consent has been given.

The period of time for data processing can also be defined by legal regulations.

Is providing us with your personal data your obligation?

Unfortunately, without you providing Engage Hill with your personal data, Engage Hill cannot offer their services to their full extent or at all.

If you are a subject to surveys and analyses of Engage Hill, then, in relation to Engage Hill, you are participating voluntarily and therefore you are not obligated to provide Engage Hill with your personal data.

If the processing of data is based on a consent, you are not obligated to provide Engage Hill with your personal data or your consent for processing them. If you provide your consent, you may withdraw it anytime.

Who has access to personal data?

The access to personal data is restricted only to employees of Engage Hill who need the data for their performance.

Can we give access to personal data to third parties?

Personal data may be provided to other, third parties of Engage Hill:

  • if it is necessary in order for Engage Hill to provide their services
  • if your consent is given
  • if it is demanded or allowed in terms of legal regulations

Third parties which can obtain personal data in these cases are mainly processors, meaning subjects, which are assigned by Engage Hill to process personal data (e.g. external advisors etc.), providers of server, web, cloud or IT services, providers of external accounting, tax, legal services etc.

Engage Hill provides surveys and analyses to a customer who ordered them. These surveys or analyses do not contain all data which you, as subject of surveys and analysis, have provided to Engage Hill. It is however not possible to entirely exclude that in rare cases the customer  may conclude how you reacted in terms of the survey or analysis, that thanks to the data available to the customer, not to Engage Hill.

Engage Hill can transfer your personal data to third countries outside of European Union. In case of transfer of data to countries outside the European Union the countries involved will be the so-called safe countries and it will happen according to an effective legislative.

Cookies

What are cookies?

Cookies are small data files which are sent from a web page to your device (computer, tablet, smartphone etc.). The file is saved into your device and is sent back with every future visit to the given website. The cookie file therefore allows the website to e.g. recognize whether or not you have previously visited it or what are your saved preferences for the website.

Cookies can be classified by who arranges them as:

  • First party cookie – they are arranged by an organization which is the owner of the web page that you are visiting
  • Third party cookie – they are arranged by an organization which is not the owner of the web page that you are visiting, e.g. they can be arranged by a different web page which launch the content on the page that you are currently viewing or by an independent analytic company

Further, cookies can be classified according to their validity as:

  • Session cookie – they are only saved in short-term while you are viewing the web page and are deleted from your device after closing the browser
  • Persistent cookie – this type of cookie is saved on your device for a set amount of time which is determined by the kind of used application

Why and what kinds of cookies do we use?

Engage Hill web pages use cookies in order to provide the best user experiences possible.

Engage Hill uses these cookies on their website:

  • session and persistent cookies in order to secure the functioning of used web applications and to better the quality of user interface

Third party cookies used on Engage Hill websites:

  • Google analytics.

Managing cookies

Engage Hill can use cookies which are essential for the website to work properly or to carry out a service requested even without your consent.

Engage Hill can use other cookies which are not essential for the website to work properly only with your consent which is given through the settings on your browser. If your browser is set to automatically forward cookies to third parties it is considered as your consent with using these cookies.

Cancelling or restricting cookies

Turning off cookie files is possible by setting up your browser is such way that it cannot receive cookies. If you do so you will likely restrict functions not only on Engage Hill web pages but also other web pages because cookies are a standard part of all modern web pages.

Your rights in terms of processing personal data

We will take the liberty of informing you on your rights in terms of processing your personal data. The rights mentioned below are applicable to company Engage Hill unless mentioned otherwise.

The right of access

You have the right to access personal data and other information relating to it specified by legal regulations, mainly by Art. 15 GDPR.

Information regarding the personal data and other information relating to it can be conveyed to you only after a thorough verification of your identity according to specific circumstances.

The right to rectification

You have the right to have your data which is being processed by Engage Hill rectified in case it is inaccurate, or to have incomplete personal data completed.

The right to erasure

In cases stated in Art. 17 GDPR you have the right to have any personal data erased in case the company Engage Hill does not prove legitimate interests for their processing.

The right to restriction of processing

In cases stated in Art. 18 GDPR you have the right to obtain restriction on the processing of any personal data until the resolution of your incentive.

The right to data portability

In cases stated in Art. 20 GDPR you have the right to acquire any personal data which you have already provided the company Engage Hill with in a structured, commonly used and machine - readable format to transmit it to another collector.

The right to withdraw consent

You have a right to withdraw your consent in cases in which personal data are being processed based on your consent. The withdrawal of your consent does not have any influence on the processing of personal data before the withdrawal of your consent nor does it have influence on processing for other reasons.

The right to object

You have the right to object against processing of personal data based on legitimate interests and that also includes profiling. Engage Hill will not process personal data unless it can demonstrate serious legitimate reasons for processing that outweigh the interests or rights and freedoms of the data subject or for the purpose of determining, enforcing or defending legal claims.

Furthermore, you have the right to object against processing of personal data for the purposes of direct marketing based on legitimate interest, profiling included, at any time. If a data subject objects processing for direct marketing purposes, personal data for that purpose will no longer be processed.

The above-stated objections can be made against the collector, in this case Engage Hill. The right to object is stated in Art. 21 GDPR.

The right to turn to supervising agency with a complaint

You have the right to lodge a complaint with a supervisory authority in case you believe that GDPR is violated by processing  personal data. The supervisory authority in the Czech Republic is the Office for Personal Data Protection (www.uoou.cz).

Contact information of the collector

In case you have any questions or want to apply your right to any of the above-stated procedures, please use the below stated contact:

Engage Hill s.r.o.
addressed to MUDr. Filip Brodan
Francouzská 175/14
120 00 Praha 2 - Vinohrady
E-mail: info@engagehill.com