This document describes how companies Red Basket, s. r. o., with its registered seat Hroznová 1, 831 03 Bratislava, Slovak republic company ID number: 53 067 240, Business register of the District Court of Bratislava I, Section: Sro, Insert No.: 146039/B (hereinafter as the “Controller” or “we”) process and protect personal data of the visitors (data subjects) visiting the webpage of the www.redbasket.agency (hereinafter as “our web” or “Red Basket web”).
When processing your personal data via means of Red Basket web, the Controller of your personal data is Red Basket, s. r. o. Your personal data are always processed in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter as “Regulation“), respective Slovak national data protection legislation and other legislation in relation to personal data protection (hereinafter as “Personal data protection legislation“).
You may contact the Controller at the following addresses in matters relating to the processing of your personal data on our web: Red Basket, s. r. o., with its registered seat Hroznová 1, 831 03 Bratislava, Slovak republic or e-mail: team@redbasket.agency.
Purpose of data collection | Why we process your data | Categories of your data we collect | Time limits for erasure of personal data | Categories of recipients | Transfer to the third countries |
Processing of accounting documents | processing of personal data is necessary for the compliance with the legal obligation to which the controller is subject | ordinary personal data necessary for fulfilment of statutory obligations | 5 years following the year to which they relate | respective Tax Office, processor providing accounting and payroll services, processor providing Accounting platform | a transfer of the data to USA – Google LLC when Google spreadsheet and Google drive is used |
Processing of documents in accordance with the registry order and registry plan of the controller including processing of received and sent mail | processing of personal data is necessary for the compliance with the legal obligation to which the controller is subject | ordinary personal data necessary for fulfilment of statutory obligations | in accordance with the relevant provisions of Act of July 14, 1983 on the national archival resource and archives | Ministry of Interior of the Slovak republic, other authorized entity | a transfer to a third country or an international organisation does not take place |
Processing of data subjects’ requests | processing of personal data is necessary for the compliance with the legal obligation to which the controller is subject | ordinary personal data necessary for the fulfilment of legal obligations – handling of the request of the data subject | during the handling of the application or exercised rights | Supervisory authority of Slovak republic, court, law enforcement authorities, company providing cloud services | a transfer to a third country takes place by using cloud services (transfer to USA to Google LLC company and Alphabet Inc. |
Keeping records of the executed rights of data subjects and submitted requests | the processing of personal data is carried out for the purposes of the legitimate interest pursued by the Controller | ordinary personal data necessary for the fulfilment of legal obligations – handling of the request of the data subject | 5 years following the year to which they relate to | Supervisory authority of Slovak republic, court, law enforcement authorities | a transfer to a third country or an international organisation does not take place |
Receiving and registering orders for services and implementing pre-contractual relations | the processing of personal data is necessary for the performance concluded with a data subject or in order to take steps at the request of the data subject prior to entering into contract (pre-contractual relations) | ordinary personal data necessary for the performance of contractual obligations (Name, surname, business name, registered seat address, ID, contact details – e-mail address, phone no., bank account details) | during the duration of a contractual relationship with the internal contractor and after its termination until the expiration of the legal limitation period or until the full settlement of the legal claims (or until the termination of a position of a data subject as a representative of internal contractor) | courts, law enforcement bodies, processor providing e-mail hosting services, processor – a company providing an online platform for sharing and saving documents, cooperating persons providing services, company providing cloud services | a transfer to a third country takes place by using cloud services (transfer to USA to Google LLC company and Alphabet Inc. |
Fulfilment of legal obligations related to the conclusion of a distance contract (provision of information, withdrawal from the contract) | the processing of personal data is necessary for fulfilment of legal obligations | ordinary personal data necessary for the performance of contractual obligations (Name, surname, business name, registered seat address, ID, contact details – e-mail address, phone no., bank account details) | during the duration of a contractual relationship with the internal contractor and after its termination until the expiration of the legal limitation period or until the full settlement of the legal claims (or until the termination of a position of a data subject as a representative of internal contractor) | courts, law enforcement bodies, processor providing e-mail hosting services, processor – a company providing an online platform for sharing and saving documents, cooperating persons providing services, company providing cloud services | a transfer to a third country takes place by using cloud services (transfer to USA to Google LLC company and Alphabet Inc. |
Performance of contractual obligations of the Controller, including pre-contractual relations with business partners | the processing of personal data is necessary for the performance concluded with a data subject or in order to take steps at the request of the data subject prior to entering into contract (pre-contractual relations) | ordinary personal data necessary for the performance of contractual obligations (Name, surname, business name, registered seat address, ID, contact details – e-mail address, phone no., bank account details) | during the duration of a contractual relationship with the internal contractor and after its termination until the expiration of the legal limitation period or until the full settlement of the legal claims (or until the termination of a position of a data subject as a representative of internal contractor) | courts, law enforcement bodies, processor providing e-mail hosting services, processor – a company providing an online platform for sharing and saving documents, cooperating persons providing services, company providing cloud services | a transfer to a third country takes place by using cloud services (transfer to USA to Google LLC company and Alphabet Inc. |
Keeping records of business partners and clients – natural persons (their contact persons / representatives) | the processing of personal data is carried out for the purposes of the legitimate interest pursued by the Controller | ordinary personal data (name, surname, business name, phone no., e-mail address, business ID, contract details | during the duration of a contractual relationship with the internal contractor and after its termination until the expiration of the legal limitation period or until the full settlement of the legal claims (or until the termination of a position of a data subject as a representative of internal contractor) | courts, law enforcement bodies, processor providing e-mail hosting services, cooperating persons providing service, company providing cloud services | a transfer to a third country takes place by using cloud services (transfer to USA to Google LLC company and Alphabet Inc.) |
Performance of contractual obligations of the Controller, including pre-contractual relations with natural persons – internal contractors | the processing of personal data is necessary for the performance of agreement concluded with a data subject or in order to take steps at the request of the data subject prior to entering into contract (pre-contractual relations) | ordinary personal data necessary for the performance of contractual obligations (Name, surname, business name, registered seat address, ID, contact details – e-mail address, phone no., bank account details) | during the duration of a contractual relationship with the internal contractor and after its termination until the expiration of the legal limitation period or until the full settlement of the legal claims (or until the termination of a position of a data subject as a representative of internal contractor) | courts, law enforcement bodies, processor providing e-mail hosting services, time-tracking services, administrative services, IT services marketing services, cloud services, co–operating persons providing services, company providing cloud services | a transfer to a third country takes place by using cloud services (transfer to USA to Google LLC company and Alphabet Inc. |
Conducting business communication with clients – natural persons and representatives of suppliers/customers in the capacity of legal entities, including pre-contractual relations | the processing of personal data is carried out on the basis of the legitimate interest of the controller, which consists in the need to ensure the fulfilment of the contractual obligations of the controller, informing business partners of the facts necessary for the fulfilment of the contractual relationship and the proper performance of the business activities of the controller, which cannot be carried out without the processing of personal data of the data subjects – designated representatives acting for / on behalf of business partners (suppliers / customers) in the capacity of legal persons | ordinary personal data necessary for the performance of contractual obligations (Name, surname, business name, registered seat address, ID, contact details – e-mail address, phone no., bank account details) | during the duration of a contractual relationship with the internal contractor and after its termination until the expiration of the legal limitation period or until the full settlement of the legal claims (or until the termination of a position of a data subject as a representative of internal contractor) | courts, law enforcement bodies, processor providing e-mail hosting services, time-tracking services, administrative services, IT services marketing services, cloud services. | a transfer to a third country or an international organisation does not take place unless it is cloud services (transfer to USA to Google LLC company and Alphabet Inc.) e-mail communication – in that case personal data may be transferred to USA Stripo, Inc. – company providing e-mail services secured by the standard contractual clauses in place as well and to other third countries provided that client is based there |
Keeping records of legal disputes, administrative disputes | the processing of personal data is necessary for fulfilment of legal obligations | ordinary personal data and special category of personal data necessary for compliance with leal obligations | 10 years following the year to which they relate | other parties to the proceedings, courts, law enforcement authorities, law firms, experts, translators, any other entity authorised by law | a transfer to a third country or an international organisation does not take place |
Handling of contractual complaints and keeping of related statutory records | processing of personal data is necessary for the compliance with the legal obligation to which the controller is subject | ordinary personal data (name, surname, business name, phone no., e-mail address, business ID, contract details | until the complaint is handled and after it´s handling until the expiration of the legal limitation period or full settlement of possible the legal claims | courts, law enforcement bodies, processor providing e-mail hosting services, other competent and supervisory authorities | a transfer to a third country or an international organisation does not take place |
Providing a reply to messages and handling of queries/requests from data subjects received via Controller’s profiles on social networks, or via e-mail or telephone communication | processing is necessary for the purposes of legitimate interest pursued by the controller | name, surname, e-mail address, phone no., other data contained in the message | 3 months from the date of receipt of the request (message) or until the request has been processed, whichever is the earlier | processor providing e-mail hosting services, operator of the social networks (Facebook, Instagram, LinkedIn, and Twitter) | transfer of data to USA – Meta Inc., Twitter Inc., and LinkedIn Corporation – parent companies of the European affiliates of the operators of the social networks (in cases specified by respective legislation), secured by the standard contractual clauses in place and Stripo, Inc. – company providing e-mail services secured by the standard contractual clauses in place as well |
Providing a reply to and handling of queries/requests delivered to the Controller via messages delivered via the contact form on the website www.redbasket.agency or other forms on this site | processing is necessary for the purposes of legitimate interest pursued by the controller | name, surname, phone number, e-mail address, a name of a company, on which behalf data subject acts, country, in which the data subjects is interested to be provided with, other data provided in the query or message | until the query or request is handled (up to 3 months) | processor providing hosting and e-mail hosting services, company providing cloud services | a transfer to a third country takes place by using cloud services (transfer to USA to Google LLC company and Alphabet Inc. |
Direct marketing – former and current customers (newsletter) and other formulars on www.redbasket.agency | the processing of personal data is carried out on the basis of the legitimate interest of the controller, which consists in the need for the controller to inform its clients about business offers and other information concerning the clients | e-mail address, first name, surname, affiliation to the client’s company | 3 years from the date of provision of the service or until unsubscribing from the newsletter | courts, law enforcement authorities, intermediaries providing hosting services, the intermediary providing the newsletter service, other authorised entity, company providing cloud services | the company operating the newslettering service, secured by means of appropriate safeguards in accordance with the Regulation (SSC in accordance with the terms of use of the above services and the concluded contract of entrustment with the processing of personal data), using cloud services (transfer to USA to Google LLC company and Alphabet Inc.) |
Direct marketing | the processing of personal data is carried out on the basis of the data subject’s consent | e-mail address, first name, surname, affiliation to the client’s company, social media profile | for a period of 3 years from the date of consent or until its revocation, whichever is earlier | processor – email hosting service providers, social network operators, company providing cloud services | transfer to a third country or international organisation – for Facebook and Instagram, the transfer is to Meta Inc. in the US, and for LinkedIn, the transfer is to LinkedIn Corporation in the US, using cloud services (transfer to USA to Google LLC company and Alphabet Inc. |
For the purpose of measuring website traffic on our website, we collect information on the type of device or internet browser you use, time of your visit, subpages you visited on our website and in specific case also the IP address of the device you use.
In certain cases, the Controller may be obliged to provide your personal data to public authorities that are authorized to process your personal data, e. g. to courts or law enforcement authorities and in some cases also to the competent supervisory authorities, in particular the competent data protection authorities of the Slovak Republic.
The Controller also provide your personal data to their processors, i. e. external entities that process your personal data on behalf of the Controller. Processors process personal data on the basis of a contract concluded with the Controller in which they have undertaken to take appropriate technical and security measures for the purpose of the secure processing of your personal data. The controller’s processors regarding the processing of your personal data via our web include: a company providing hosting services and services connected to the adjustments of our web.
Among the recipients of your personal data may also be a company Google, LLC, which is a parent company of its European affiliate providing website analytical services, if you give the Controller permission to store cookies on your device when you visit the website. In this case, your personal data may be transferred to the United States, in accordance with the terms of use of the above stated services of Google, LLC and applicable US laws. The transfer of your personal data is secured by the usage of standard contractual clauses which are part of the above state terms of use of this service.
The Controller does not process your personal data by profiling or any form of automated individual decision-making, by which evaluation of your personal aspects would take place in the normal course of our business or when providing above stated services to you.
We make sure to keep the data safe. We have taken technical and organizational measures to ensure data security and adopted information and privacy security management systems in our company. The objective is to ensure protection and eliminate situations where data could be lost, or avoid situation of unlawful processing, access, transfer, copying or changes of your data. Data that you share with us, or vice versa we will share with you or third parties will be protected both when used electronically (password secured, encrypted, access limited) or physically (sealed document files, lockable containers, access only to authorized personnel).
We would like to confirm that access to the data is only provided to the authorized personnel (i. e. employees and suppliers) whose access is essential to secure the course of our business activities. That means, for example, that the queries address to the Controller will be delivered only to our Slovak entity and vice versa.
As the data subject, your rights regarding the processing of your personal data are as follows:
Right of access – You have the right to obtain a copy of the personal data which we hold about you, as well as the information on how we use your personal data. In most cases, your personal data will be provided to you by electronic means of communication, unless otherwise requested by you;
Right to rectification – We take reasonable measures in order to ensure that the data which we hold about you are accurate, complete and up to date. In case the personal data we hold are inaccurate, incomplete or outdated, we will modify, update or complete such personal data on basis of your request;
Right to erasure – under certain circumstances, you have the right to ask us to erase your personal data, for example, if the personal data we have obtained about you, are no longer necessary to fulfil the original purpose of processing or if you withdraw your consent to the personal data processing. We assess exercising your right to erasure (right to be forgotten) on the basis of individual circumstances of each particular case of processing;
Right to restriction of processing – You have also the right to ask us not to process your personal data. If you believe that the personal data, we process about you are not accurate, that the processing is unlawful and you request the restriction of their processing, that we no longer need your personal data, but they are required by you as the Data subject for the exercise of legal claims or if you believe that we as the controller are not entitled to further process your personal data, we will not further process your personal data on the basis of your request;
Right to data portability – Under certain circumstances, you have right to transmit the personal data to another subject according to your choice. However, the right to portability applies only to personal data that we process under the contract to which you are one of the parties or on the basis of the consent which you have granted us;
Right to lodge a complaint or request – If you believe that we breach personal data protection legislation when processing your personal data or that we have not handled your request in accordance with such legislation, you can lodge a complaint with the respective supervisory authority which is in Slovak Republic – Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava 27; Slovak Republic, telephone no. +421 2 3231 3214; e-mail: statny.dozor@pdp.gov.sk.
RIGHT TO WITHDRAW CONSENT – If we process your personal data on the basis of your consent, you have the right to withdraw such consent for further processing of your personal data. You may withdraw your consent at any time in writing, by e-mail or orally (in person).
RIGHT TO OBJECT – if we process your personal data based on our legitimate interest, you have the right to object to processing of your personal data, if you object to such personal data processing, we will not further process your personal data unless we demonstrate compelling legitimate grounds for such processing.
You may exercise your rights stated in the previous point of this Privacy policy via contact addresses stated in the beginning of this privacy policy. We will provide you with a response to a request regarding exercise of your rights within one month from the day of exercise of your rights. In certain cases, we are entitled to prolong the period for providing the response, i. e. in case of high number and complexity of the requests submitted by the data subjects, maximum by 2 months. We will always inform you in advance about prolongation of the period. Response to a request regarding exercise of your rights will be provided to you free-of-charge. In case of repeated, unreasonable, or disproportionate request to exercise your rights, we are entitled to charge a reasonable fee for providing the information.
On our web we do use cookies – small text files which an internet browser may store in your device upon instruction of the website when you visit the website. In general, they serve for ensuring functionality of certain components of website or for example for the websites being able to better record website traffic or for online marketing purposes. More information you can find in cookie bot.
This updated privacy policy is valid and effective as of September 7, 2023. As it is possible that an update of the information on personal data processing contained in this Privacy policy may be necessary in the future, the Controller is entitled to update this Privacy policy at any time. In such case, the Controller will inform you about it in an adequate manner in advance.