www.tenus.sk
This privacy policy (hereinafter the „Policy“) contains information about the processing of your personal data by tenus s. r. o., with its registered office at Robotnícka 109, 905 01 Senica, Slovakia, Company ID: 47 417 196, registered in the Commercial Register of the District Court Trnava, section: Sro, insert no. 32883/T (hereinafter the „Controller“), which takes place through the website www.tenus.sk (hereinafter the „website“).
Through this Policy the Controller provides you with information about why your personal data are processed, how they are processed, how long the Controller retains them, what your rights are in connection with the processing of your personal data and other relevant information about the processing of your personal data.
The Controller processes your personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter the „Regulation“), with the applicable Slovak legislation, in particular Act No. 18/2018 Coll. on the Protection of Personal Data and on amendments to certain acts (hereinafter the „Act“) and with other personal data protection legislation (the Regulation, the Act and other personal data protection legislation hereinafter jointly the „Data Protection Legislation“).
You may contact the Controller in matters concerning the processing and protection of personal data at Robotnícka 109, 905 01 Senica, Slovakia, or by e-mail at tenus@tenus.sk. The Controller has not appointed a data protection officer.
The Controller obtains your personal data through the website or through a social network profile directly from you, if you provide them yourself (whether through a message or by another automated means). The provision of personal data for all the processing purposes set out below is voluntary and is not a statutory and/or contractual requirement.
INFORMATION ON PROCESSING OPERATIONS (categories of personal data, purposes of processing, legal bases and retention periods)
The Controller processes your personal data strictly in accordance with the principle of data minimisation, which means that the Controller does not require personal data from you that are not necessary for a specific and justified purpose of processing. The Controller processes personal data only where a legal basis for their processing exists, and therefore processes them in accordance with the principle of lawfulness. The specific purposes for which the Controller processes your personal data, together with the legal basis and retention period, are set out in the table below.
| Purpose of processing | Responding to messages and handling queries / requests from messages delivered to the Controller through the contact form on the website, by e-mail communication or by telephone |
| Legal basis | Article 6(1)(f) of the Regulation |
| Categories of personal data | first name, surname, e-mail, telephone number, other data stated in the message |
| Retention period | 60 days from the date the request is delivered or until the request is handled (the purpose is fulfilled), whichever occurs first |
| Purpose of processing | Taking photographs of data subjects and publishing them on the Controller’s websites and on the Controller’s other communication channels, including publication in brochures, presentations and on noticeboards at the Controller’s premises, together with the data subject’s first name, surname, title and position with the Controller in the course of its presentation activities |
| Legal basis | Article 6(1)(a) of the Regulation |
| Categories of personal data | Photograph, first name, surname, position, specialisation, other personal data depending on the consent granted (within the scope of ordinary personal data) |
| Retention period | 5 years from the date consent was granted or until it is withdrawn, whichever occurs first |
| Purpose of processing | Keeping records of job applicants |
| Legal basis | Article 6(1)(a) of the Regulation |
| Categories of personal data | First name, surname, e-mail, data on work experience, other personal data stated in the CV and / or cover letter |
| Retention period | We delete the applicant’s data no later than 90 days after the application has been successfully transferred to the RECRU system, and in any event no later than 1 year from the granting of consent — whichever occurs first. We delete the CV immediately after a successful transfer. |
| Purpose of processing | Carrying out the selection procedure (ensuring the selection of new employees) |
| Legal basis | Article 6(1)(b) of the Regulation |
| Categories of personal data | first name, surname, e-mail, data on work experience, other personal data stated in the CV and / or cover letter |
| Retention period | for the duration of the selection procedure (i.e. no later than 90 days from the date the CV and / or cover letter is delivered, if no employment or similar labour-law relationship arises) |
| Purpose of processing | Handling the exercised rights of data subjects |
| Legal basis | Article 6(1)(c) of the Regulation – the processing of personal data is carried out in the fulfilment of legal obligations |
| Categories of personal data | Ordinary personal data that form part of the data subject’s request and are necessary for handling it under the relevant legislation |
| Retention period | Until the exercised rights are handled under the relevant provisions of the Regulation (a maximum of 120 days) |
| Purpose of processing | Keeping records of the exercised rights of data subjects |
| Legal basis | Article 6(1)(f) of the Regulation – the processing of personal data is carried out on the basis of the Controller’s legitimate interest, which is to keep records of the exercised rights of data subjects in order to demonstrate compliance with obligations arising from legislation |
| Categories of personal data | Ordinary personal data that form part of the data subject’s request and are necessary for handling it under the relevant legislation |
| Retention period | 5 years following the day on which the exercised right or the request submitted by the data subject was handled |
| Purpose of processing | Processing of personal data for the purpose of measuring website traffic and targeting the Controller’s advertising (through cookies) |
| Legal basis | Article 6(1)(a) of the Regulation |
| Categories of personal data | IP address, data on activity on the Controller’s website, data on preferences in the online environment, data on the type of browser and type of device used, data on the device’s operating system, data on the network and subnet used |
| Retention period | No longer than 2 years from the date consent was granted or until it is withdrawn, whichever occurs first |
In order to ensure the protection of your personal data, the Controller has adopted appropriate security measures, which it has documented, at both the organisational and the technical level.
To whom does the Controller disclose your personal data?
In certain cases the Controller has an obligation to disclose your personal data to public authorities that are entitled to process your personal data, e.g. courts, law enforcement authorities and supervisory and oversight authorities (e.g. the Office for Personal Data Protection in the event of an inspection) (third parties).
The Controller also discloses your personal data to its processors, i.e. external entities that process your personal data on the Controller’s behalf. Processors process personal data on the basis of a contract concluded with the Controller in which they undertook to adopt appropriate technical and security measures for the secure processing of your personal data. The Controller’s processors include:
- a company providing accounting, HR and payroll services
- an entity providing occupational health and safety and fire protection services,
- an entity or company providing services in the area of web development, programming, the creation and modification of websites and related IT services and online marketing services,
- a company providing hosting services (including mail hosting services).
The recipients of your personal data also include Google Ireland Limited, which provides analytical and marketing services through cookies that the website stores on your device if you grant the Controller consent to the storage of such files. Information on cookies can be found in the cookies section.
That company acts as a joint controller with the Controller in the processing of personal data, and the processing of personal data is in this case governed by a joint controller arrangement under Article 26 of the Regulation, under which the Controller is the point of contact for handling your requests concerning the processing of personal data.
The recipients of your personal data also include RECRU – a recruitment information system in which we keep records of job applicants. We transfer to it the data from the application: first name and surname, e-mail, telephone number, CV and data on residence and work permit.
The recipients of your personal data also include EZ Content Solutions DWC-LLC, operating under the First Principle brand, and Meta Platforms Ireland Limited, which carry out measurements of advertising effectiveness for the Controller. We transfer to them the e-mail address and telephone number in encrypted form and identifiers from advertising cookies, and only where the visitor has consented to marketing cookies. If consent is not granted, we do not transfer any contact data to them.
The cookies we set on the job offer pages:
- tenus_consent – stores your answer to the consent banner (yes or no). Valid for 1 year. It is always set, so that we do not ask again.
The following are set only after consent has been granted:
- _fp_vid, _fp_utm, _fp_consent (FirstPrinciple) – an identifier of the visit and information about which campaign you came from. Valid for 1 year.
- _fbp, _fbc (Meta) – measurement of advertising effectiveness.
TRANSFER to third countries and international organisations
If you grant the Controller consent to the storage of analytical and marketing cookies, your personal data may be transferred to the USA, to Google LLC.
The transfer of your personal data is secured by appropriate means of safeguarding transfers of personal data to third countries in accordance with the Data Protection Legislation, in particular through the use of standard contractual clauses that form part of the terms of use of the services referred to above, and also through additional transfer safeguards adopted by the providers of those services. A transfer may occur only exceptionally, on the basis of the relevant legislation in force in that third country (the USA) that applies to those service providers (FISA).
In all the cases referred to above, the transfer of your personal data is secured through standard contractual clauses which, in accordance with the terms of use of those services, form part of the data processing agreements concluded with the entities referred to above.
What are your rights in connection with the processing of personal data?
In connection with the processing of your personal data you have, as a data subject, the following rights:
| Right of access – As a data subject you have the right to obtain from the Controller confirmation as to whether it processes your personal data and, if so, you have the right to obtain access to those personal data and the information under Article 15 of the Regulation. The Controller will provide you with a copy of the personal data being processed. If you submit the request by electronic means, the Controller will provide the information in a commonly used electronic form, unless you request another means. | Right to rectification – The Controller has adopted appropriate measures to ensure the accuracy, completeness and currency of your personal data. As a data subject you have the right to have the Controller rectify your inaccurate personal data or complete your incomplete personal data without undue delay. |
| RIGHT TO OBJECT You have the right to object to the processing of personal data, for example where the Controller processes your personal data on the basis of a legitimate interest, or in the case of processing that involves profiling. If you object to such processing of personal data, the Controller will not process your personal data further unless it demonstrates compelling legitimate grounds for the further processing of your personal data. | |
| Right to erasure (the „right to be forgotten“) – You also have the right to obtain from the Controller the erasure of your personal data without undue delay where certain conditions are met, for example where the personal data are no longer necessary for the purposes for which the Controller obtained or processed them. This right must, however, be assessed individually, since a situation may arise in which other circumstances prevent the Controller from erasing the personal data (for example a legal obligation of the Controller). This means that in such a case the Controller will not be able to comply with your request for erasure of personal data. | Right to data portability – In certain circumstances you have the right to have your personal data transmitted to another controller designated by you. The right to portability applies only to personal data that the Controller processes on the basis of consent you granted to the Controller, on the basis of a contract to which you are a party, or where the Controller processes personal data by automated means. |
| RIGHT TO WITHDRAW CONSENT If the Controller processes your personal data on the basis of your consent, you have the right to withdraw the consent granted at any time, in the same form in which you granted it. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal of consent. | |
| Right to restriction of processing – You also have the right to have the Controller restrict the processing of your personal data. This will be the case, for example, where you contest the accuracy of the personal data, or where the processing is unlawful and you request the restriction of processing, or where the Controller no longer needs your personal data for the purposes of processing but you need them for the establishment, exercise or defence of legal claims. The Controller will restrict the processing of your personal data if you so request. | Right to lodge a complaint or a submission – If you feel that your personal data are being processed contrary to the applicable legislation, you may lodge a complaint with the supervisory authority, which is the Office for Personal Data Protection of the Slovak Republic, with its registered office at Hraničná 12, 820 07 Bratislava 27; website: dataprotection.gov.sk, tel. no.: 02 3231 3214; e-mail: statny.dozor@pdp.gov.sk |
The Controller will provide a response to the exercise of your rights free of charge. In the case of a repetitive, unfounded or excessive request to exercise your rights, the Controller is entitled to charge a reasonable fee for providing the information. The Controller will provide you with a response within 1 month from the day on which you exercised your rights. In certain cases the Controller is entitled to extend that period, namely in the case of a high number and complexity of data subjects’ requests, but by no more than 2 months. The Controller will always inform you of an extension of the period.
Validity
This Policy is valid and effective from 24 March 2023. Since an update of the information on the processing of personal data contained in this Policy may be required in the future, the Controller is entitled to update this Policy at any time. In such a case, however, the Controller will inform you of this in advance in an appropriate manner.