Privacy Policy
This privacy policy has been prepared with regard to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL.
We use security measures in our work related to the provision of services to SPS Grupp OÜ clients and the handling of personal data relating to employees.
This privacy policy applies to everyone who uses the company's website or other digital services, submits an enquiry about our services, or otherwise communicates with SPS Grupp OÜ.
SPS Grupp OÜ processes the data of its employees, clients and contact persons in connection with employment or contractual relationships, the provision of services and the other lawful purposes described in this policy.
Definitions
Personal data – means information about a person, i.e., a natural person (data subject), by which they can be identified directly or indirectly: name, personal identification code, location information, network identifiers (identifiers that, in a communication network, help lead to a specific person), as well as physical, economic, cultural, and any other identifying characteristics and combinations thereof.
Processing of personal data – means any operation performed on data: collection, organisation, storage, modification, reading, use, transmission, combination, deletion, etc.
Identification of the Controller and Processor
SPS Grupp OÜ is the controller when processing the personal data of its employees, website visitors and client representatives, and when developing its services. SPS Grupp OÜ's processors are service providers that process data on its behalf.
The processor must process personal data on behalf of and under the instructions of the controller in accordance with all applicable regulations.
The processor has the right to carry out processing operations only with respect to those personal data and to the extent that the controller has authorized the processor.
SPS Grupp OÜ is a processor for its clients with respect to personal data entered/transmitted by its clients into SPS Grupp OÜ's business software (e.g., data of clients' clients). In this situation, the controller of personal data is the respective client of SPS Grupp OÜ.
Purposes and Bases of Personal Data Processing
When collecting client data, we limit collection to the minimum necessary to provide our services and improve customer service.
The basis for processing personal data is the conclusion of a contract, legitimate interest, or the consent of the data subject.
SPS Grupp OÜ does not distribute, transmit, modify, or use personal data entrusted to us in any other way not disclosed at the time of data collection, except where there is a corresponding agreement with the data subject or where the need to disclose information arises from the legislation of the respective country.
SPS Grupp OÜ collects personal data for:
- identifying the data subject;
- fulfilling the employee's work duties and legal obligations (e.g., data submitted to the tax authority, data submitted to the occupational health physician, etc.);
- preparing a client contract and/or invoice;
- fulfilling the terms of the contract concluded with the client;
- contacting the data subject for the provision of the service;
- maintaining client relationships or resolving questions.
Personal Data Collected
The personal data we collect may include the following:
- Your name;
- Your personal identification code;
- Your phone number;
- Your email address;
- Your address;
- Your company name and your position;
- Your bank account details;
- The text of your inquiry;
- other data necessary for the provision of the service.
The categories of personal data processed may vary depending on the employment contract, applicable law, or the contract between SPS Grupp OÜ and the client.
Data Retention
We retain personal data for as long as necessary to achieve the purposes for which the data were collected. The retention period also depends on legal requirements for document retention.
- Personal data related to SPS Grupp OÜ transactions are retained for at least seven (7) years from the end of the financial year, pursuant to the obligation under the Accounting Act to document transactions.
- Data related to employees are retained for at least 10 years after the termination of the employment contract, and occupational health data for at least 55 years in accordance with the legal requirements of the Republic of Estonia.
- Personal data of clients are retained for at least seven (7) years after the end of the client relationship where this is necessary to protect SPS Grupp OÜ's rights in a dispute or in connection with other legal claims.
How We Share and Disclose Information
Personal data processed by SPS Grupp OÜ may be disclosed without the consent of the data subject only to an authority or person who has a justified need or a direct legal right to do so (e.g., a court or pre-trial investigator).
We may transmit your data for processing to third parties who assist us in providing and managing the Services and who provide services related to the management of client inquiries. These parties may include, for example, transport companies, property managers, etc.
In all cases, we transmit to the data processor only the data necessary for the performance of a specific task or the provision of a specific service.
Collection of Visitor Information on the Website
The SPS Grupp OÜ website uses cookies. Cookie information is used to collect statistics on the number of users, as well as to obtain information about the geographical location of our users, in order to adapt the content and service of the website.
Security of Personal Data
SPS Grupp OÜ implements the necessary technical, physical (confidential documents are kept in locked storage) and organisational security measures (including confidentiality agreements with personnel) to protect client and employee personal data against loss and unlawful processing.
SPS Grupp OÜ has established clear and mandatory requirements for everyone who processes personal data on the company's behalf and has communicated those requirements to them.
SPS Grupp OÜ complies with applicable data protection legislation when processing personal data and implements appropriate technical and organisational security measures.
Notification of Personal Data Breach to the Data Subject
If a breach is likely to result in a high risk to the rights and freedoms of individuals, the controller shall notify the data subject without undue delay.
The purpose of the notification is to give the data subject the information needed to take reasonable precautions and mitigate possible risks.
In the notification, we provide essential information about the personal data breach, as well as recommendations to mitigate possible adverse effects.
The notification to the data subject shall include:
- a clear and plain language description of the nature of the personal data breach;
- the name and contact details of the contact person at SPS Grupp OÜ;
- a description of the possible consequences of the personal data breach;
- a description of the measures taken to address the personal data breach.
Rights of the Data Subject
Right to rectification – the right of the data subject to request that inaccurate or incomplete personal data concerning them be rectified without undue delay.
Right to erasure – the right of the data subject to request that their personal data be erased without undue delay, provided certain additional conditions are met.
If there is no longer a legal basis for processing or disclosing personal data, or for providing access to them, the data subject may request that the data no longer be used or be deleted and that their disclosure or accessibility cease. The request must be submitted in a manner that allows the applicant to be identified.
The request will not be granted if:
- it may harm the rights and freedoms of another person;
- it would conflict with a legal or contractual obligation;
- it may hinder the work of law enforcement authorities;
- the requested action is not technically feasible;
- the requester is not legally connected to the data;
- the requester cannot be identified.
Right to restrict processing – the right of the data subject to temporarily or permanently restrict the processing of all or part of their personal data in certain cases.
Right of access – the right to be informed of personal data and to request access to the personal data we process about you.
If the processing of personal data is based on the consent of the data subject, the data subject has the right to withdraw that consent at any time by notifying us by email, without affecting the lawfulness of processing based on consent before its withdrawal.
Privacy Policy and Changes
Where consent is required for processing, it is obtained in a form that can be reproduced in writing, for example as an annex to a contract.
SPS Grupp OÜ reserves the right to amend or supplement this privacy policy where necessary. The current version is available on the SPS Grupp website at spsgrupp.ee/andmekaitsetingimused.
If you believe that SPS Grupp OÜ has infringed your rights when processing personal data, please contact us at our published email address. We will first seek to resolve the matter through discussion. You also have the right to contact the Estonian Data Protection Inspectorate (aki.ee, email: info@aki.ee) or a competent court.
The privacy policy is effective as of 08.12.2021.