Pursuant to Article 13(1) and (2) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (OJ EU L 119 of 4.5.2016) — hereinafter referred to as the "GDPR", we hereby inform you that:
1. The controller of your personal data obtained from video surveillance is Nowodvorski Lighting sp. z o.o.| Bojemskiego 11 | 42-202Częstochowa. If you have any questions regarding the video surveillance conducted, please contact the Data Protection Officer at: iod@nowodvorski.com
2. Video surveillance is operated on the premises of the workplace on the basis of Article 222 of the Labour Code. The following areas are subject to surveillance:
- main entrances to buildings,
- communication routes,
- technological routes,
- parking areas,
- storage or warehousing areas,
- other premises used exclusively by the Employer.
3. Your personal data will be processed for the purposes of:
- ensuring the protection of main entrances to buildings, communication routes, technological routes, parking areas, storage or warehousing areas, and other premises used by the Employer (Article 6(1)(f) GDPR in connection with Article 222 of the Labour Code),
- pursuing the legitimate interests of the Controller consisting in the establishment, exercise, or defence of legal claims (Article 6(1)(f) GDPR).
4. Your data will be processed for a period not exceeding 3 months, and in the event of legal claims, until the final conclusion of the relevant proceedings.
5. As a rule, we process data provided directly by you.
6. The recipients of your data may include:
- public authorities or other entities authorised under applicable law, where necessary to fulfil legal obligations,
- entities providing us with IT tools for data processing,
- law firms providing legal assistance.
7. As a rule, your personal data will not be transferred to third countries outside the European Economic Area (EEA — comprising the EU Member States as well as Iceland, Norway, and Liechtenstein). However, given the services provided by subcontractors of the Controller in relation to the support of ICT services and IT infrastructure, the Controller may entrust certain tasks or operations to reputable subcontractors operating outside the EEA, which may result in the transfer of your data outside the EEA.
Recipients outside the EEA, pursuant to a decision of the European Commission, ensure an adequate level of personal data protection in line with EEA standards. In the case of recipients in countries not covered by a European Commission adequacy decision, the Controller enters into agreements with such recipients based on standard contractual clauses issued by the European Commission in accordance with Article 46(2)(c) GDPR, in order to ensure an adequate level of data protection.
8. A copy of the standard contractual clauses may be obtained from the Controller by contacting the contact details indicated above. The safeguards applied by the Controller are compliant with the principles set out in Chapter V of the GDPR. You may request further information regarding such safeguards, obtain a copy of these safeguards, and information on where they have been made available.
9. You have the following rights:
a) the right to access your data and obtain a copy thereof,
b) the right to rectification (correction) of your data,
c) the right to erasure of personal data,
d) the right to restriction of data processing,
e) the right to data portability where the legal basis for processing is consent (Article 6(1)(a) or Article 9(2)(a) GDPR) or a contract (Article 6(1)(b) GDPR),
f) the right to withdraw consent to data processing where processing is based on consent (Article 6(1)(a) GDPR), without affecting the lawfulness of processing based on consent before its withdrawal,
g) the right to object to the processing of your personal data where the legal basis for processing is the legitimate interest (Article 6(1)(f) GDPR).
10. No automated decision-making (decisions without significant human involvement), including profiling, will be carried out in relation to you.
11. If you believe that the processing of your personal data violates the provisions of the GDPR, you have the right to lodge a complaint with the supervisory authority, i.e. the President of the Personal Data Protection Office.