1 SUMMARY OF OUR PROCESSING ACTIVITIES
The following summary gives you a quick overview of the processing activities carried out on our website. See the sections below for more information.
- When you visit our website for informative reasons without making a purchase, only limited personal information, needed to deliver the website to you, will be processed.
- In the event that you make a purchase of the Services or products or subscribe to our newsletter, further personal information will be processed as part of such services.
- Furthermore, your personal information will be used to provide advertising for our services and products and for statistical analysis to help us improve our website; in addition, we will improve you experience of our website with third-party content.
- Your personal information may be disclosed to third parties located outside your country of residence, potentially applying different data protection standards.
- We have put in place appropriate safeguards to protect your personal information, which we only keep for as long as necessary.
- In accordance with the law applicable to you, you may be entitled to exercise certain rights in relation to the processing of your personal information.
Personal information: means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Processing: means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
3 INFORMATIVE USE OF THE WEBSITE
If you visit our website for informative reasons, i.e. without providing personal information in any form, we may automatically collect information about you that will contain personal information in limited cases only and are automatically recognized by our servers, such as:
- the website from which you were directed to our website;
- date and time of your claims;
- device type, screen resolution and browser version;
- your internet service provider;
- information about your operating system, including language settings;
- information about the offers you have visited on our website.
We use this information only to assist us in providing efficient services (e.g. to tailor our website to the needs of your device) and to collect broad demographic data for anonymous sharing.
The personal information we collect automatically is necessary to secure the website and for our legitimate interest in ensuring the stability and security of the website.
Personal information that is collected automatically is immediately anonymized and all personally identifiable information is deleted accordingly.
4 USE OF THE WEBSITE FOR PURCHASING ONLINE SERVICES AND/OR PRODUCTS
Our website offers coaching sessions and programs, consulting sessions and programs, mentoring sessions and programs and online video tutorials. If you visit our website for the purchase of any of the beforementioned services in connection with such use of the website, we process the following information:
- your name, surname, address, telephone, email address, date of birth, job title and professional interest(s);
- communications you have sent (e.g. via email or communication forms on the website);
- whenever you make a transaction via our website, further data processing procedures may take place, of which you will be specifically informed.
We will use personal information so that our services can be made available to you (e.g. implementation of consulting services, delivering online video tutorials) and that we can provide required information or communicate with you.
Personal information we collect is necessary for the performance of contractual obligations between the user and the controller (processing on the basis of law and contractual relations) as well as for our legitimate interest.
With your email address you can subscribe to our newsletter, which provides you with the latest information about our services and products, whereas it may also include advertisements related to our services and products. The legal basis for processing your personal information is your consent. Your email address will be kept as long as you are subscribed to our newsletter. You can unsubscribe from this service at any time by clicking “unsubscribe” at the footer of each newsletter received.
6 ONLINE ADVERTISING
Our website uses online advertising services to present you with ads that match your interests. Such advertising is marked with the name of the provider (e.g. Google Ads). This service helps us improve our website and make your visit more interesting. To this end, we collect statistics about you that are processed by the provider of such advertising. Such processing represents our legitimate interest in improving the experience with our website and promoting our services and products.
8 WEB ANALYTICS
For statistical analysis we use web analytics to collect information about the use of this website.
General tracking information
Web analytics tools collect information such as:
- device and browser information (operating system information, mobile device identifier, mobile operating system, etc.);
- IP address;
- access to the website; URL click flow (the chronological order of our websites you’ve visited);
- geographical location;
- time of visit;
- the reference site, application or service from which you were directed to our website.
We use the information we obtain from web analytics tool providers only to determine the most useful information you are looking for and to improve and optimize the website. We do not combine data, collected with such tools, with personal information.
The legal basis for this type of data processing is our legitimate interest in analyzing the traffic on our website and improving user experience and optimizing the website in general.
We use Google Analytics, a web analytics service provided by Google Ireland Ltd., Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”). On our behalf Google will use the information generated by a cookie for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet activity in connection with the use of the website.
We have activated the IP-anonymisation within the Google Analytics service, and your IP address will be truncated within the area of member states of the European Union or other parties to the Agreement on the European Economic Area. Only in exceptional cases the whole IP address will be first transferred to a Google server in the USA and truncated there. The IP-address your browser conveys within the scope of Google Analytics will not be associated with any other data held by Google.
9 OPT-OUT OF ANALYTICS
10 SOCIAL MEDIA PLUG-INS
11 INFORMATION SHARING
Your personal data will only be disclosed to a third party to the extent necessary to fulfill our contractual relationship. Legal basis for the transfer of your personal data is Article 6 sec. 1 sent. 1 lit. b and f GDPR and represents our legitimate interest to implement our general terms and conditions of business or any other agreements concluded with you.
We may disclose anonymous aggregate statistics about users of the website in order to describe our services to prospective partners, advertisers and other reputable third parties and for other lawful purposes, but these statistics will include no personal data.
We may disclose your personal data to our contractors who assist us in providing the services we offer through the website. Such a transfer will be based on data processing agreements. Therefore, our contractors will only use your personal data to the extent necessary to perform their functions and will be contractually bound to process your personal data only on our behalf and in compliance with our requests.
In the event that we undergo re-organisation or are sold to a third party, any personal data we hold about you may be transferred to that re-organised entity or third party in compliance with applicable law.
We may disclose your personal data if legally entitled or required to do so (for example if required by law or by a court order).
12 CROSS BORDER DATA TRANSFERS
Within the scope of our information sharing activities set out above, your personal information may be transferred to other countries (including countries outside the EEA) which may have different data protection standards from your country of residence. Please note that data processed in a foreign country may be subject to foreign laws and accessible to foreign governments, courts, law enforcement, and regulatory agencies. However, we will endeavor to take reasonable measures to maintain an adequate level of data protection when sharing your personal data with such countries.
In the case of a transfer outside of the EEA, this transfer is safeguarded by either Privacy Shield or EU Model Clauses. You can find further information about the aforementioned safeguards by contacting us via email@example.com.
We have reasonable state of the art security measures in place to protect against the loss, misuse and alteration of personal data under our control. For example, our security and privacy policies are periodically reviewed and enhanced as necessary and only authorised personnel have access to personal data. Whilst we cannot ensure or guarantee that loss, misuse or alteration of information will never occur, we use all reasonable efforts to prevent it.
You should bear in mind that submission of information over the internet is never entirely secure. We cannot guarantee the security of information you submit via our website whilst it is in transit over the internet and any such submission is at your own risk.
14 DATA RETENTION
15 THE EU GENERAL DATA PROTECTION REGULATION (EEA RESIDENTS)
As of May 25, 2018, a new data privacy law known as the EU General Data Protection Regulation (the “GDPR”) will be in effect through the EEA, Switzerland, and the UK. The GDPR requires the company and those using our website to provide users with certain information about the processing of their “Personal Data.” “Personal Data” is a term used under the GDPR that means, generally, data that identifies or can identify a particular unique user or device – for instance, names, addresses, cookie identifiers, Mobile IDs, precise location data, and biometric data.
To comply with the GDPR, we provide the below representations and information, which are specific to persons located in the EEA, Switzerland, or the UK and to the processing of personal data in the context of the activities of the company.
i. Legal Grounds for Processing Personal Data The GDPR requires us to tell you about the legal ground we are relying on to process any Personal Data about you. The legal grounds for us processing your Personal Data for the purposes set out in Section 2 above will typically be because:
- You provided your consent. In order to store and gain access to information stored on your device, we rely on your consent. We do so to fulfill our obligations under the ePrivacy Directive. We may choose to obtain consent in other cases as well, in which case we will adhere to applicable laws relating to such consent and its withdrawal;
- The processing is in our legitimate interest. In some cases, we rely on legitimate interest as a legal basis for processing Personal Data, in order to provide our and/or other data controllers’ services. Such processing goes beyond the original collection of mobile IDs. A legitimate interest we rely on, for instance, is maintaining the security of our services, such as to detect fraud or to ensure that bugs are detected and fixed;
- Contractual relationships. Sometimes, we process certain data as necessary under a contractual relationship we have (such as our customer records and contact information);
- Legal obligations. Finally, some processing of data may be necessary for us to comply with our legal or regulatory obligations.
ii. Transfers of Personal Data As the company works with global companies and technologies, we may need to transfer your Personal Data outside of the country from which it was originally provided. For instance, we may transfer your data to third parties that we work with who may be located in jurisdictions outside of the EEA, Switzerland, or the UK, and which have no data protection laws or laws that are less strict in comparison to those in Europe.
When we transfer Personal Data outside of the EEA, Switzerland, or the UK, we take steps to ensure appropriate safeguards are in place to protect your Personal Data. Please contact us at the contact information below for more information about the safeguards we have put in place to protect your Personal Data and privacy rights in these circumstances.
iii. Personal Data Retention As a general matter, we retain your Personal Data for as long as necessary to provide our services, or for other important purposes such as complying with legal obligations, resolving disputes, and enforcing our agreements.
iv. Your Rights as a Data Subject The GDPR provides you with certain rights in respect to Personal Data that data controllers hold about you, including certain rights to access Personal Data, to request correction of the Personal Data, to request to restrict or delete Personal Data, and to object to our processing of your Personal Data.
- Right to object. You have the right to object to the processing of your personal information that is processed on the grounds of legitimate interests. You are always free to opt out from the future collection of your personal information by us and our partners by not accessing and/or using the Websites.
- Right of access. You have a right to know what information we hold about you and in some cases to have the information communicated to you. If you wish to exercise this right please contact us by letting us know that you wish to exercise your right of access and what information in particular you would like to receive. We reserve the right to ask for reasonable evidence to verify your identity before we provide you with any information. Please note that we may not be able to provide all the information you ask for, for instance if the information includes personal information about another person. Where we are not able to provide you with information that you have asked for, we will explain to you why. We will try to respond to any request for a right of access as soon as possible, but we will always do so within 1 month of receipt of your request and verification of your identity.
- Right to correct personal information. We try to keep the information that we hold about you accurate and up to date. Should you realize that any of the information that we hold about you is incorrect, please contact us via firstname.lastname@example.org and we will correct it as soon as we can.
- Data deletion. You have a right to request deletion of the personal information that we hold about you. Should you wish to do that, please contact us at email@example.com. We reserve the right to ask to provide us additional information to verify your identity before we can start processing your request. Once we receive all information we need in order to be able to identify you, we will delete your personal information you requested us to delete as soon as possible, but we will always do so within 1 month of receipt of your request and verification of your identity. Please note that we may still retain some or all of that information, for example for complying with our legal obligations and protecting or enforcing legal rights. We may also retain your information in an anonymised form.
- Data portability. In some circumstances, you have the right to request that we provide you with the personal information which you have provided to us, so you can transfer this information to another data controller. Should you wish to do that, please contact us at firstname.lastname@example.org.
- Restriction of processing. In some cases, you may have the right to request a restriction of the processing of your personal information.
Right to file a complaint. You have the right to file a complaint against us. To do so, contact the supervisory authority in your country of residence.
16 QUESTIONS OR COMPLAINTS
You can direct any questions or complaints about the use or disclosure of your personal information to us at email@example.com. We will investigate and attempt to resolve any complaints or disputes regarding the use or disclosure of personal information within 45 days of receiving your complaint.
18 CONTACT US
BOC Institute d.o.o.
Železna cesta 16
BOC Institute d.o.o., Last update, July 2020