Nawigacja stroną

INFORMATION CLAUSE ON PERSONAL DATA PROCESSING

Your personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to as “RODO”).

I. Objectives and scope

  1. This Policy will apply to Eiffage Group companies in Poland, i.e. Eiffage Polska Budownictwo S.A. based in Warsaw, Eiffage Polska Serwis sp. z o.o. based in Warsaw, Eiffage Immobilier Polska sp. z o.o. based in Warsaw, hereinafter collectively referred to as the “Controller”.
  2. Personal data security means protecting the data from all threats in order to ensure business continuity, minimise risk and maximise the return on business opportunities. The security is achieved through a number of technical and organisational measures.
  3. Maintaining security of personal data processed is understood as ensuring its confidentiality, integrity, availability and accountability, whereby:
    1. a) confidentiality is understood as ensuring that only authorised persons have access to the information,
    2. b) integrity is understood as ensuring the accuracy and completeness of the information and its processing methods,
    3. c) availability is understood as ensuring that authorised persons have access to information and related resources when needed,
    4. d) accountability is understood as ensuring that an activity carried out can be unambiguously attributed to a specific entity.
  4. The Controller takes continuous measures to ensure the lawfulness of the processing and to improve the security of the processed personal data in its possession and entrusted to it for processing by other entities under agreements.
  5. The purpose of the Policy is to set out the principles and procedures to be followed in order to fulfil the legal requirements and to ensure the security of personal data.
  6. The entirety of the activities covered by the Policy should be regarded as measures to protect the privacy of the data subjects and as compliance with a statutory requirement.

 

II. Information obligation and data subject requests

  1. When data is obtained from a person, the Controller provides the person with information on their data processing.
  2. Any person whose data is processed by the Controller has at any time the right to request:
    1. a) access to the data and to information about their processing,
    2. b) a copy of the data,
    3. c) rectification of data (updating and rectification),
    4. d) deletion of data,
    5. e) restriction of data processing,
    6. f) data portability,
      g) as well as the right to object to the processing.
  3. Any data protection issues can be reported in the following way:
    1. a) by email: poland@eiffage.com
    2. b) by mail: “Eiffage Polska Serwis Sp. z o.o. based in Warsaw at ul. Domaniewskiej 28, 02-672 Warsaw, “RODO”.

 

III. Data Sharing and Data Processing Entrustment

  1. The Controller makes personal data available in situations defined by applicable law or to other entities with the knowledge and consent of the data subject.
  2. Your personal data will be processed until you withdraw your consent to its processing if the processing of your personal data is based on your consent (legal basis: Article 6(1)(a) of RODO)
  3. The recipients of your personal data may be:
    1. a) employees and associates of the Controller,
    2. b) entities providing services to the Controller, in particular IT, marketing and telecommunications services, to which the Controller entrusts the processing of personal data.
  4. Your personal data will not be transferred to third countries, i.e. countries located outside the European Economic Area.
  5. You have the right to request access to your personal data, rectification, erasure, restriction of processing, as well as the right to data portability.
  6. You have the right to object to the processing of your personal data for direct marketing purposes.
  7. You have the right to withdraw your consent to the processing of your data at any time without affecting the lawfulness of the processing carried out on the basis of your consent prior to its withdrawal.
  8. You have the right to lodge a complaint with the supervisory authority in charge of personal data protection (President of the Personal Data Protection Office).
  9. The provision of personal data is voluntary. As a consequence of failing to provide your personal data, the data cannot be processed for direct marketing of products and services.
  10. The Controller carries out automated processing of personal data (profiling), including information about your activity on the website, in order to provide you with information about products and services that you may be most interested in. However, the decision to provide specific information is made by an employee of the Controller, which means that it is not a solely automated decision.

 

 

COOKIE CLAUSE