CONFIDENTIALITY AND PERSONAL DATA PROCESSING POLICY
GENERAL CONFIDENTIALITY POLICY
WHO WE ARE
ECOTIC ASSOCIATION and ECOTIC BAT SRL are associated personal data operators.
ECOTIC ASSOCIATION is an organization specializing in the management of electric and electronic waste and ECOTIC BAT SRL is an organization founded on the need to separately and efficiently organize a complementary component to the core business of ECOTIC: the collection and recycling of portable and industrial batteries and accumulators.
In this context, the processing of personal data is carried out jointly within the two organizations which are only formally distinct and all principles, policies and practices applicable to the ECOTIC ASSOCIATION apply to ECOTIC BAT SRL and vice versa.
ECOTIC ASSOCIATION, with headquarters in 48 Turturelelor St., district 3, Bucharest with the mailing address in 86 Splaiul Unirii, 4th floor, district 4, Bucharest, Phone: 031.805.57.43, Fax: 021.332.32.38, https://www.ecotic.ro ; e-mail: firstname.lastname@example.org; e-mail address of the Data Protection Officer: email@example.com., is a personal data operator processing data collected in the course of its legitimate business activity – registered with ANSPDCP under no. 16448.
ECOTIC BAT SRL, with headquarters in Splaiul Unirii, No. 86, 4th floor, district 4, Bucharest, Phone: 031.805.57.43, Fax: 021.332.32.38, https://www.ecotic.ro; e-mail: firstname.lastname@example.org; the e-mail address of the Data Protection Officer: email@example.com, is a personal data operator processing data collected in the course of its legitimate business activity – registered with ANSPDCP under no. 0024994.
The ECOTIC and ECOTIC BAT Associations, as associate operators, collect data in in several ways: when you contact us by e-mail, when you visit our website, when your employers sign a new contract transferring responsibilities in order to achieve the annual WEEE and DBA collection targets, or when a request for collaboration is addressed to us. We also collect data when you visit one of our offices, as well as when you submit CVs or job applications.
Personal data (Data) – any information regarding an identified or identifiable individual (the data subject); an identifiable natural person is a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more specific elements, proper to his/her physical, physiological, genetic, psychic, economic, cultural or social identities. Special categories of personal data – any information revealing racial or ethnic origin, political opinions, religious confession or philosophical beliefs or membership of trade unions, genetic data, biometric data for the sole identification of a natural person, data on health or data on the sexual life or sexual orientation of a natural person. Processing of personal data (Processing) – any operation or set of operations performed on personal data or on personal data sets with or without the use of automated means such as collecting, recording, organizing, structuring, storing, adaptation or modification, extraction, consultation, use, disclosure, dissemination or making it available in any other way, alignment or combination, restriction, erasure or destruction. Target person – a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more specific elements, proper to his/her physical, physiological, genetic, psychic, economic, cultural or social identities. Operator – a natural or legal person, a public authority, an agency or other body which, alone or with others, determines the purposes and means of processing personal data; where the purposes and means of processing are laid down by Union or national law, the operator or the specific criteria for designating it may be laid down in Union or national law.
Associated operators – two or more operators who jointly determine the purposes and means of processing, establish transparently their responsibilities in fulfilling their obligations under GDPR, in particular as regards the exercise of the rights of data subjects and the duties of each of them to provide the information referred to in Articles 13 and 14, by agreement between them, and designate a single point of contact for the data subjects.
Person mandated by the Operator (Proxy / Processor) – natural or legal person, public authority, agency or other body processing personal data on behalf of the operator.
Third Party – a natural or legal person, public authority, agency or body other than the data subject, the operator, the person mandated by the operator and the persons who, under the direct authority of the operator or person mandated by the operator, are authorized to process personal data.
Consent – any manifestation of free, specific, informed and unambiguous will of the person concerned through which it accepts, through a statement or unequivocal action, that the personal data concerning him/her are processed.
Pseudonymization – means the processing of personal data in such a way that it can no longer be attributed to a particular data subject without the use of additional information, provided that such additional information is stored separately and is subject to measures of a technical and organizational nature meant to ensure that such personal data is not allocated to an identified or identifiable natural person. Principles for the processing of personal data apply to pseudonymized data as they are personal data.
Anonymisation – refers to the processing of personal data in a way that is irreversible and transforms the data so that it can no longer be attributed to a particular target person. The principles on the processing of personal data do not apply to anonymized data as they are no longer personal data.
ANSPDCP – refers to the independent public supervisory authority in Romania, namely the National Supervisory Authority for Personal Data Processing.
GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46 / EC.
OUR VISION ON PERSONAL DATA PROCESSING AND COMMITMENTS OF THE ECOTIC AND ECOTIC BAT ASSOCIATION
The processing of personal data in ECOTIC and ECOTIC BAT is always subject to the following principles:
- All data processing has a valid legal basis
- All data processing is done in a fair manner
- We inform the data subjects about what data we process, why, how, and for how long we process them, whether and to whom we transfer them, as well as the rights they have regarding their data
- Data are collected for determined, explicit and legitimate purposes and are not subsequently processed in a way incompatible with these purposes
- The data are appropriate, relevant and limited to what is required in relation to the purposes for which they are processed
- We are concerned about using only accurate data and, if necessary, we will ensure its updating
- Data shall be kept in a form that allows the identification of the data subjects for a timeframe not exceeding the time required for the purposes for which the data are processed; personal data may be stored for longer periods as long as they are processed solely for purposes of archiving in the public interest, for scientific or historical research purposes or for statistical purposes, subject to the application of technical measures and organizationally appropriate
- Data is processed in a way that ensures the proper security of personal data, including protection against unauthorized or illegal processing, and against loss, destruction or accidental damage by taking appropriate technical or organizational measures
ECOTIC and ECOTIC BAT Association will ensure that these principles are respected with regard to its current activities as well as if in the future it introduces new data processing technologies, such as, but not limited to, new IT systems.
WHAT PERSONAL DATA WE PROCESS
ECOTIC and ECOTIC BAT ASSOCIATIONS specifically inform the data subjects about the personal data collected and processed in each case (for example, when sending a request for collaboration or a response to the request for collaboration, receiving a request for collection of waste of electric and electronic equipment (WEEE) and / or batteries and accumulators waste (DBA), receipt of a CV, etc.).
For example, if you submit a request for WEEE collaboration / collection through the site or directly to firstname.lastname@example.org, we will collect personal data regarding: the e-mail address and the contact details of the person or company representative contacting us, included in the request (example: name, first name, telephone number).
WHY AND HOW WE USE YOUR PERSONAL DATA
Your personal data is used to conduct WEEE / DBA management work, to conclude contracts for the transfer of responsibilities for the achievement of annual WEEE and DBA collection targets, in order to handle WEEE / DBA collection requests (in which case we need to clarify the factual situation and perform additional checks within a strictly legal framework), in order to respond to the requests made by the competent authorities that supervise and regulate our activity.
We process data to provide you with the services and information you require.
We also work on personal data and to ensure the security of the premises in which we operate, the goods we use for this purpose, the safety of our employees and the data and information we manage.
Your personal data is processed by collecting, recording, organizing, storing, modifying, consulting, using, disclosing by transmission, making available, combining, restricting, deleting, destroying, and so forth. Your personal data is not the subject of automated decision-making (including profiling) except in exceptional circumstances, in which case the data subject is informed of its existence and details of this particular processing mode.
ECOTIC and ECOTIC BAT ASSOCIATIONS specifically inform the data subjects about the purposes and modalities of processing in each case (for example, when submitting a request for collaboration or a response to the collaboration request when receiving a CV etc.).
THE BASIS FOR USING YOUR PERSONAL DATA
THE ECOTIC AND ECOTIC BAT ASSOCIATION shall pursue the processing of data in consideration of at least one of the following legal bases:
- a) Consent – If no other legality of processing is provided, ECOTIC ASSOCIATION and ECOTIC BAT always obtain the consent of the data subject for the processing of his or her personal data for one or more specific purposes.
- b) Execution / Conclusion of a contract – Processing is required for ECOTIC and ECOTIC BAT ASSOCIATION to execute a contract to which the data subject is party or to take action at the request of the data subject prior to the conclusion of a contract.
- c) Legal obligation – Processing is necessary for the fulfillment of a legal obligation of ECOTIC and ECOTIC BAT ASSOCIATION.
- d) Legitimate interest – Processing is necessary for the legitimate interests pursued by ECOTIC and ECOTIC BAT ASSOCIATION or by a third party, in accordance to the law. For example, in the case of registration of WEEE / DBA collection requests, ECOTIC ASSOCIATION and / or ECOTIC BAT has a legitimate probative or improvement interest in the services offered.
- e) Vital interest – Processing is necessary to protect the vital interests of the data subject or of another individual.
- f) Public interest – Processing is necessary for the performance of a task which is in the public interest or which results from the exercise of the public authority with which the operator is mandated.
In the case of special categories of personal data, ECOTIC and ECOTIC BAT ASSOCIATION refer to the applicable legal provisions to always ensure a valid legal basis for processing.
WHO WE TRANSMIT YOUR PERSONAL DATA TO
Your personal data may be passed on to third parties – competent authorities, collection or transport operators, etc. accounting and audit firms, etc. Whenever we do so, we make sure there is a solid justification, that we will only transmit data which is strictly necessary for the purpose of the transmission and will try to ensure that the recipient provides a high standard of personal data protection.
In the case of the data processing activities done by a third party provider / supplier / partner / intermediary for ECOTIC or ECOTIC BAT, based on a service contract of any type concluded between ECOTIC ASSOCIATION or ECOTIC BAT and the third party (which is a personal data procesor from a GDPR stanpoint), these contracts are concluded in writing and include a series of specific clauses to provide the ECOTIC and / or ECOTIC BAT ASSOCIATIONS with sufficient guarantees for the implementation of appropriate technical and organizational measures to ensure that processing complies with GDPR requirements and that the rights of the data subject are protected.
The transfer of personal data to an international organization or to a third country vis-à-vis the EU and EEA (EEA includes both the EU and Iceland, Liechtenstein and Norway) can only take place if the organization or state concerned, to which it intends to carry out the transfer, can provide an adequate level of protection as required by GDPR.
The transfer of data to an international organization or to a State whose legislation does not provide for an adequate level of protection recognized by a European Commission decision on adequacy is possible only if there are sufficient safeguards to protect the fundamental rights of the data subjects and provided that there are effective rights and effective remedies available to the data subject. These guarantees are established by ECOTIC ASSOCIATION and / or ECOTIC BAT, in compliance with GDPR, in contracts / agreements concluded with service providers to whom the data is transferred to or in other legal ways, on a case-by-case basis.
FOR HOW LONG AND HOW WE STORE YOUR PERSONAL DATA
We keep your personal data only as long as we are required or as required by applicable law.
During this time, we ensure that the data is kept secure and, in case of security breaches, we are prepared to apply all technical, organizational and legal measures to limit the possible consequences and inform the ANSPDCP, as well as the data subjects, if there are risks to them.
As far as possible, we will anonymize data that is no longer needed in a manner that allows us to identify the data subjects or apply pseudonimization to limit the risks of processed personal data.
THE RIGHTS YOU HAVE REGARDING THE DATA WE PROCESS
Right to Access to Data
Any person concerned has the right to obtain from the ECOTIC ASSOCIATION and / or ECOTIC BAT, when acting as an operator, on request and free of charge for the first request per year, confirmation that the data concerning the person are processed or not and, if so, the following information will be provided: the purposes of the processing; the categories of data concerned; the recipients or categories of data recipients, in particular recipients from third countries or international organizations, as well as the appropriate safeguards offered in the case of such data transfer; where possible, the period for which personal data is expected to be stored or, if that is not possible, the criteria used to determine that period; the existence of the right to request ECOTIC ASSOCIATION and / or ECOTIC BAT to rectify or delete data or restrict their processing or the right to oppose processing; the right to lodge a complaint with ANSPDCP; if the data are not collected from the data subject, any available information on their source; the existence of an automated decision-making process including profiling, as well as relevant information on the logic used, the significance and the expected consequences of such processing for the data subject.
Right to rectification
The person concerned has the right to obtain, without undue delay, from ECOTIC ASSOCIATION and / or ECOTIC BAT, as a data controller, the rectification of inaccurate personal data concerning it.
Taking into account the purposes for which the data were processed, the data subject has the right to obtain the incomplete personal data, including by provision of an additional statement.
Right to delete data (“the right to be forgotten”)
The data subject has the right to obtain the deletion of the personal data concerning him / her without undue delay and ECOTIC ASSOCIATION and / or ECOTIC BAT will have the obligation to delete the data without undue delay if:
- (a) the data are no longer required for the purposes for which they were collected or processed;
- b) the person concerned withdraws their consent on the basis of which the processing takes place and there is no longer any other legal basis for the processing;
- c) personal data has been processed illegally
- d) the person concerned exercises the right to opposition under GDPR conditions;
- (e) data must be erased in order to comply with a legal obligation on the part of the operator;
- f) personal data were collected in connection with the provision of information services to minors under GDPR conditions;
- g) personal data were collected in connection to the provision of information to children under GDPR conditions.
ECOTIC ASSOCIATION and / or ECOTIC BAT, as data controller, may refuse the request for data deletion under the following conditions:
- (a) processing is necessary for the exercise of the right to freedom of expression and information;
- (b) processing is necessary to comply with a legal obligation applicable to the operator;
- (c) processing is necessary for reasons of public interest in public health, under the conditions imposed by GDPR;
- (d) processing is necessary for purposes of archiving in the public interest for purposes of scientific or historical research or for statistical purposes under GDPR conditions, to the extent that the exercise of the right may make it impossible or seriously affect the achievement of the objectives of that processing ;
- e) Processing is necessary for the establishment, exercise or defense of a right in court.
The right to restrict the processing
The data subject has the right to obtain from ECOTIC ASSOCIATION and / or ECOTIC BAT, as a data controller, the restriction of processing in the following cases:
- (a) the data subject contests the accuracy of the data for a period which allows the controller to verify the accuracy of the data;
- b) processing is illegal and the data subject opposes the deletion of personal data, but instead calls for restriction of their use;
- c) ECOTIC Association and / or ECOTIC BAT no longer require personal data for processing, but they are necessary for the establishment, exercise or defense of a right in court;
- d) the data subject opposed to the processing for the period of time during which it is verified that the legitimate rights of the controller prevail over those of the data subject.
- e) the person concerned who has obtained the restriction of the processing is informed by ECOTIC ASSOCIATION and / or ECOTIC BAT before lifting the processing restriction.
The right of opposition
The person concerned is entitled to the following in regards to ECOTIC ASSOCIATION and / or ECOTIC BAT:
- (a) to oppose at any time, on grounds relating to his / her particular situation, that the data concerning him / her are subject to processing justified on grounds of public interest or legitimate interest. In the case of opposition, the processing may only relate to the data in question only if there are legitimate and compelling reasons justifying processing and which prevail over the rights of the data subject or whether the purpose is to establish, exercise or defend a right in court.
- b) to oppose at any time, free of charge and without any justification, that the data concerning him/her be intended to be processed for direct marketing purposes, including the creation of profiles for this purpose.
The right to data portability
The person concerned has, in regards to ECOTIC ASSOCIATION and / or ECOTIC BAT, the right to receive – in a structured, commonly used and readable form – personal data that concern him/ her and that him/her has provided to the Organization and to convey it to another operator if:
- (a) processing is based on consent or on a contract; and
- (b) processing is carried out by automatic means.
In exercising its right to data portability, the data subject is entitled to transmit his/ her data directly from ECOTIC ASSOCIATION and / or ECOTIC BAT to another operator when technically feasible.
The right not to be subject to an automatic decision (including profiling)
In this respect, in regards to ECOTIC ASSOCIATION and / or ECOTIC BAT, the person concerned has the right to not be subjected to a decision based solely on automated processing (including profiling) and which would produce legal effects for the data subject or would affect it significantly.
This right will not apply in the following exceptional situations in which the automated decision:
- (a) is required for the conclusion or performance of a contract between the person concerned and ECOTIC ASSOCIATION and / or ECOTIC BAT;
- b) is authorized by European Union or national law applicable to ECOTIC ASSOCIATION and / or ECOTIC BAT and which also provides for appropriate measures to protect legitimate rights, freedoms and interests of the data subject; or
- c) is based on the explicit consent of the person concerned.
In the cases of articles a) and c) of this paragraph, ECOTIC ASSOCIATION and / or ECOTIC BAT are required to implement appropriate measures to protect the legitimate rights, freedoms and interests of the data subject, at least its right to obtain human intervention from parte of the operator, to express their point of view and to challenge the decision.
The right to withdraw their consent
If your data processing is based on your consent, you can withdraw your consent, in which case we will immediately cease processing your personal data. Withdrawal of consent will not affect the processing up to that point.
In order to exercise any of these rights, please contact the Data Protection Officer of ECOTIC ASSOCIATION and ECOTIC BAT at email@example.com or by sending a request to firstname.lastname@example.org, correspondence address: Splaiul Unirii, Nr. 86, 4th floor, District 4 Bucharest, phone 0318055743, Fax 021 3323238.
Right to address the court and / or ANSPDCP
The person whose personal data is processed by ECOTIC ASSOCIATION and / or ECOTIC BAT has the following rights:
- a) the right to lodge a complaint with ANSPDCP (National Supervisory Authority for Personal Data Processing, headquarters: Bucharest, 28-30 Gheorghe Magheru Blvd., district 1, CP 010336, Phone: +40.318.05.92.11, Fax: +40.318.05.96.02 email: email@example.com, website: dataprotection.ro) if the data subject considers that the processing of his data is done in violation of GDPR;
- b) the right to bring legal proceedings if the data subject considers that the processing of his data is done in violation of GDPR.