This document sets out the personal data protection terms of Mediatoring.com s.r.o. Its purpose is to inform clients, visitors and other interested parties about the Company’s principles and procedures for collecting, processing, storing and using personal data. The personal data protection terms are designed to comply with the applicable legislation, in particular the European General Data Protection Regulation (GDPR) and other relevant laws and regulations. This document describes the scope and purpose of personal data processing, the rights of individuals and the Company’s responsibilities in connection with the protection of personal data.
1. Definition of the term “personal data”
The term personal data refers to any information about an identified or identifiable natural person. An identifiable natural person is an individual who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Personal data may include, but is not limited to, the following information:
- First name and surname
- Address
- E-mail address
- Telephone number
- Date of birth
- IP address
- Cookies
- Payment method information
- Professional details, such as employment or position within a company
- Identification number, for example a personal identification number
- Photographs or image recordings
- Social and cultural preferences
All of this data is protected in accordance with the applicable legislation and Mediatoring.com s.r.o. undertakes to process, store and protect this data correctly.
2. Identification of the data controller and data processors
2.1 Data controller
The data controller is Mediatoring.com s.r.o., with its registered office at Nádražní 385/34, Ostrava, 702 00, Company ID No.: 04954025, registered in the Commercial Register kept by the Regional Court in Ostrava under file No. C 74487.
Contact e-mail of the controller: [email protected]
The data controller is responsible for the collection, processing, storage and use of personal data in accordance with the applicable legislation.
2.2 Data processors
Data processors are third parties that the data controller entrusts with the processing of personal data for the purpose of providing certain services or performing specific tasks. Data processors may include, but are not limited to, cloud service providers, IT security providers, analytics tools, and payment and marketing service providers.
Mediatoring.com s.r.o. concludes contracts with data processors that guarantee compliance with personal data protection legislation and an appropriate level of security when processing personal data. When selecting data processors, the Company ensures that all the necessary requirements and safeguards for the protection of personal data are met. A list of data processors and their contact details will be provided on request.
3. Types of data collected
Mediatoring.com s.r.o. collects and processes various types of personal data depending on the nature of the services provided and on interaction with clients, website visitors and users of other services. Below is a list of the types of personal data that may be collected:
- Basic identification data: First name, surname, address, e-mail address, telephone number, date of birth.
- Professional and business data: Company name, Company ID No., VAT No., registered office address, contact details, role or position within the company.
- Technical data: IP address, browser type, operating system, information about the devices used, date and time of access, information about interaction with the website or service.
- Account and service data: Information about accounts created, registration, login, passwords, use of services, orders and payment information.
- Communication data: Records of communication by e-mail, chat, telephone calls or other communication channels.
- Cookies and tracking technologies: Information collected through cookies and other tracking technologies that make it possible to monitor traffic and user preferences.
- Marketing data: Data on preferences, interests, interaction with marketing materials and other information related to marketing.
- Other data: The Company may collect further personal data where this is necessary for the provision of specific services or the performance of specific tasks, always in accordance with the applicable legislation.
The Company collects this data directly from individuals, automatically through the use of its websites and services, or from other sources such as public databases, business partners or social networks. Mediatoring.com s.r.o. always provides information about the processing of personal data and obtains the consent of individuals where this is required by the applicable legislation.
When collecting and processing personal data, Mediatoring.com s.r.o. follows the principle of data minimisation, which means that it collects only the data that is strictly necessary for the purposes of providing services, fulfilling contractual obligations, communicating with clients and users, ensuring security and improving the quality of the services provided.
The Company is committed to transparency in the collection and processing of personal data and provides individuals with all information about the purposes of processing, their rights and the options for choice and control that they have in connection with the protection of their personal data.
4. Purpose of data processing
Personal data is processed for the purpose of providing services, fulfilling contractual obligations, communicating with clients, ensuring security, improving the quality of the services provided and carrying out marketing activities. Every processing of personal data is based on a legal basis under the applicable legislation, in particular the European General Data Protection Regulation (GDPR). Below is an overview of the purposes of processing and the legal bases for processing personal data:
- Fulfilment of contractual obligations: Personal data is processed on the basis of the contract between the Company and the client or user in order to provide services such as web hosting, mail server administration, creation of websites and e-shops, online marketing and other services. The legal basis for the processing is Article 6(1)(b) of the GDPR.
- Legitimate interest: The Company may process personal data where a legitimate interest exists, such as ensuring the security of services, preventing fraud, maintaining and improving the quality of services or carrying out marketing activities. The legal basis for the processing is Article 6(1)(f) of the GDPR.
- Consent: In some cases the processing of personal data may be based on the consent of the individual, for example sending newsletters, participation in competitions or the processing of sensitive data. The legal basis for the processing is Article 6(1)(a) of the GDPR.
- Legal obligation: Personal data may be processed where this is required by law or regulation, for example when keeping accounting records, fulfilling tax obligations or cooperating with public authorities. The legal basis for the processing is Article 6(1)(c) of the GDPR.
Mediatoring.com s.r.o. undertakes always to act in accordance with the applicable legislation when processing personal data and to respect the principles of personal data protection. Before starting to process personal data on the basis of a new purpose or new conditions, the Company will always assess the impact on the privacy of individuals and ensure that the relevant legal basis is met.
The Company informs individuals about the purposes of processing, the legal bases and their rights in connection with the protection of personal data, through this privacy policy, information materials or other communication channels.
If an individual has questions or concerns regarding the purposes of processing or the legal bases, they may contact the Company using the contact details given on this page. The Company undertakes to deal properly and promptly with all queries, requests or complaints relating to the protection of personal data.
5. Security of personal data
Mediatoring.com s.r.o. places great emphasis on the protection of personal data and the security of its processing. To secure personal data we take a range of technical and organisational measures that protect the data against misuse, loss, unauthorised access, alteration or disclosure. These measures include:
- Data encryption: Personal data is transmitted and stored in encrypted form so that it is protected against unauthorised access.
- Access rights: Only authorised persons who have the necessary authorisation and have completed the relevant training in personal data protection have access to personal data.
- Regular backups: Personal data is backed up regularly to ensure its availability and integrity if needed.
- Antivirus and anti-malware measures: The Company uses up-to-date antivirus and anti-malware programs and technologies that protect personal data against malicious software and attacks.
- Physical protection of premises: The premises in which personal data is stored or processed are protected against unauthorised entry, fire, flooding and other hazardous situations.
- Regular reviews and audits: The Company regularly reviews and audits its security measures and procedures to ensure that they are effective and compliant with the applicable legislation.
- Employee education and training: The Company provides its employees with training and education in personal data protection and information security in order to ensure the consistent protection of personal data across the organisation.
Mediatoring.com s.r.o. undertakes to update and improve its security measures and procedures on an ongoing basis in order to ensure the highest possible level of personal data protection.
6. Protection in connection with the use of AI
In providing its services, Mediatoring.com s.r.o. uses artificial intelligence (AI) technologies in order to improve the quality of its services, optimise processes and communicate efficiently with clients. When using AI, the Company follows these personal data protection principles:
- Transparency: The Company informs clients and users about the use of AI in connection with the processing of their personal data. This information is included in the privacy policy and may also be provided through other communication channels.
- Consent: Where necessary, the Company obtains the consent of the client or user for the use of AI to process their personal data, in particular where the AI would have a significant impact on the individual. Consent is obtained in accordance with the applicable legislation, such as the GDPR.
- Limitation of processing: The Company ensures that AI processes personal data only to the extent necessary to achieve the specific purposes of processing and that no more data is processed than is strictly necessary.
- Data security and protection: The Company takes measures to ensure the security of personal data processed using AI, such as data encryption, access rights and regular backups.
- Compliance with ethical principles: The Company undertakes to comply with ethical principles in the development and deployment of AI so that the interests and rights of individuals are respected, and to ensure fairness and non-discrimination in the processing of personal data.
- Review and monitoring of AI: The Company regularly reviews and monitors the AI tools it uses in order to ensure that they function correctly, comply with legislation and respect the principles of personal data protection.
- Responsibility and investigation of incidents: Mediatoring.com s.r.o. bears responsibility for the use of AI in connection with the processing of personal data and takes measures to identify and resolve any incidents that could jeopardise the protection of personal data. If any incident concerning the processing of personal data using AI is detected, the Company will immediately launch an internal investigation and take appropriate measures to remedy the situation and minimise risks.
- Informing clients about the risks associated with the use of AI: The Company informs clients about the potential risks associated with the use of AI for processing personal data and provides them with information about the measures it takes to reduce those risks.
- Rights of individuals in connection with the use of AI: The Company ensures that individuals are informed about their rights in connection with the use of AI for processing personal data, including the right of access, rectification, erasure, restriction of processing, data portability and the right to object to processing. The Company undertakes to deal properly and promptly with all requests and complaints from individuals concerning the use of AI for processing personal data.
Mediatoring.com s.r.o. is aware of the importance of personal data protection and of the associated risks when using AI. It therefore continuously monitors developments in the field of personal data protection and AI technologies and updates its procedures and measures in order to ensure the highest level of protection and compliance with the applicable legislation.
7. Data transfer
Mediatoring.com s.r.o. places great emphasis on security when transferring personal data between an e-shop and other tools or services. To secure these transfers we use encrypted and secure protocols such as SSL/TLS (Secure Sockets Layer/Transport Layer Security). These protocols ensure that data is encrypted before being sent and decrypted only on the recipient’s side, which protects its confidentiality and integrity during transfer.
In addition to using SSL/TLS protocols, the Company regularly monitors and updates its security procedures and technologies to ensure that the transfer of personal data always complies with the latest security standards and recommendations. This includes regular vulnerability checks, software updates and updates to company policies concerning data transfer.
Mediatoring.com s.r.o. also trains its employees in data security and informs them of best practices for maintaining security when transferring personal data. Employees are also required to sign confidentiality agreements that emphasise their commitment to protecting clients’ personal data.
Where necessary, we work with external cyber security experts in order to ensure the highest level of protection when transferring personal data. Mediatoring.com s.r.o. is committed to continuously improving its data security procedures and to ensuring that the transfer of personal data is always carried out in the safest possible way.
8. Data migration
When migrating data, including orders and the personal data of the customers of the client company, Mediatoring.com s.r.o. places great emphasis on ensuring the security and confidentiality of the data. For this purpose a range of measures and procedures has been introduced to ensure that data is protected throughout the entire migration process.
- Use of encrypted transfer protocols: During data migration all transfers are secured with encrypted protocols such as SSL/TLS, which ensure that data is protected against unauthorised access, interception or misuse.
- Anonymisation or pseudonymisation of data: Where possible and appropriate, the Company anonymises or pseudonymises personal data before migration, which reduces the risk of data misuse in the event of unauthorised access.
- Restriction of access to data: Access to data during migration is restricted to authorised persons only, who have completed the relevant data security training and signed a confidentiality agreement. This ensures that data is protected against unauthorised access or misuse.
- Regular data backups: The Company carries out regular data backups before, during and after migration in order to ensure the availability and integrity of the data in the event of technical problems or failure.
- Audit and review of migration processes: Mediatoring.com s.r.o. regularly checks and reviews its data migration procedures and technologies in order to ensure that they comply with the latest data security standards and recommendations.
- Cooperation with the client: The Company works closely with the client throughout the entire migration process in order to ensure that the client’s expectations are met and that the data migration is carried out as efficiently and safely as possible.
- Transparency of the migration process: Mediatoring.com s.r.o. is committed to transparency throughout the entire data migration process. Clients are informed about the progress of the migration, the expected time frames and any risks. Where necessary, detailed information about data security and migration procedures is provided.
- Resolving potential problems: Should any problems or security incidents occur during data migration, Mediatoring.com s.r.o. will immediately launch an investigation and take all necessary measures to remedy the situation and minimise damage. Clients will be kept informed of the progress and results of the investigation.
- Compliance with legislation: Mediatoring.com s.r.o. complies with the applicable legislation and regulations concerning the protection of personal data, such as the GDPR (General Data Protection Regulation) and other relevant laws, and will ensure that the data migration process complies with these regulations.
- Consent to data migration: In cases where this is required by legislation or good business practice, Mediatoring.com s.r.o. will obtain the prior consent of the client or customers for the migration of their data. This ensures that the data migration takes place transparently and in line with the expectations of all parties involved.
These measures and procedures of Mediatoring.com s.r.o. enable secure and efficient data migration that respects the privacy of clients and customers and protects their personal data against unauthorised access, misuse or loss.
9. Access to, rectification and erasure of data
Individuals have the right to access, rectify and erase their personal data. Mediatoring.com s.r.o. makes it possible to exercise these rights via its website, by e-mail or by telephone. Requests for access to, rectification or erasure of data are handled in accordance with the applicable legislation, such as the GDPR.
10. Data retention
Personal data is retained for the period necessary for the purposes for which it was collected, or for the period laid down by legislation. The criteria for determining the retention period include the nature of the data, the purpose of processing and the data retention requirements laid down by legislation or contractual obligations.
11. Sharing data with third parties
Mediatoring.com s.r.o. shares personal data with third parties only for the purpose of fulfilling contractual obligations, providing the requested services or in accordance with legislation. When sharing data with third parties, the Company takes the following measures to ensure the protection and security of personal data:
- Data processing contracts and agreements: The Company concludes data processing contracts and agreements with third parties that include obligations concerning the protection of personal data, security measures and compliance with the applicable legislation, such as the GDPR (General Data Protection Regulation).
- Vetting of third parties: Before beginning cooperation with third parties, the Company assesses their security measures, personal data protection procedures and history of compliance with legislation. This ensures that cooperating third parties meet the same personal data protection criteria as Mediatoring.com s.r.o.
- Restriction of access to data: The Company restricts access to personal data to the extent strictly necessary to fulfil contractual obligations or provide services and requires third parties to observe the same restrictions.
- Audit and review: The Company regularly checks and reviews the third parties with which it shares personal data in order to ensure that they comply with the agreed personal data protection criteria and the applicable legislation.
- Informing the parties concerned: Clients and customers of Mediatoring.com s.r.o. are informed about the sharing of their personal data with third parties and about the purpose of such sharing. Where required by legislation or good business practice, the Company will obtain the consent of the persons concerned before sharing their data with third parties.
- Resolving problems and disagreements: In the event of disagreements or problems concerning the protection of personal data, Mediatoring.com s.r.o. undertakes to resolve these problems together with the third parties. In the event of serious problems or repeated failure by third parties to comply with the agreed conditions, the Company may terminate the contract and stop sharing personal data with that third party.
- Recording and documentation: Mediatoring.com s.r.o. keeps records and documentation concerning the sharing of personal data with third parties, including information about the third parties, the purpose of the sharing and the security measures taken. These records and documentation may be submitted to the relevant regulatory authorities if required.
- Notification of security breaches: Mediatoring.com s.r.o. requires third parties to inform the Company without undue delay if a breach of the security of personal data is detected. The Company will then take the necessary steps to resolve the situation and to inform the persons concerned and the relevant regulatory authorities in accordance with the applicable legislation.
This GDPR terms document represents the basic framework for the protection of personal data and for security when sharing data with third parties. Mediatoring.com s.r.o. undertakes to comply with these terms and to continuously update its procedures and measures in line with new legislation and technological developments in order to ensure the highest possible level of protection of the personal data of its clients and customers.
These personal data protection terms were updated on 19 April 2023