Information on personal data processing for our employees and associates
Information on personal data processing for employees and associates
Pursuant to Article 13(1-2) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (OJ UE L 119/1, 4.05.2016), hereinafter "GDPR", please be advised that:
I. The Controller of your personal data is PGE Paliwa sp. z o.o. with its registered office in Kraków (31-587), ul. Ciepłownicza 1.
II. With regard to the protection of your personal data, you may contact the Data Protection Officer at the email address iod.pgepaliwa@gkpge.pl or in writing at the address of our registered office indicated in paragraph I above.
III. Objectives and basis of processing.
We will process your personal data:
- On the basis of Article 6(1)(a) of the GDPR (consent), where you voluntarily consent to the processing of data for specific purposes.
- On the basis of Article 6(1)(b) of the GDPR for the purpose of entering into and performing a contract with the Controller.
- On the basis of Article 6(1)(c) of the GDPR (legal obligation to which the Controller is subject), in particular for the purpose of complying with requests from law enforcement authorities and for the purposes of legal proceedings, as well as to comply with other obligations imposed on the Controller under the generally applicable legal regulations (including tax regulations).
- On the basis of Article 6(1)(f) of the GDPR (legitimate interest):
a. for archival (evidential) purposes, being the fulfilment of the Controller's legitimate interest to safeguard information in the event of a legal need to prove facts,
b. for the purpose of establishing, pursuing or defending claims,
c. for the purpose of facilitating communication among PGE Capital Group entities,
d. for the purpose of ensuring security on the employer's premises (including the strengthening of its image),
e. for administrative purposes of the Seller constituting the pursuit of the Seller's legitimate interests (based on Article 6(1)(f) of the GDPR).
IV. Recipients of data.
Your personal data may be transferred to:
a. institutions, entities or persons in cases in which the Controller is obliged to transfer the data in accordance with the legal regulations;
b. entities from the PGE Capital Group, in particular PGE Polska Grupa Energetyczna S.A., to the extent necessary for contact purposes (joint venture, project, exercise of corporate governance);
c. partners and contractors of the Controller to the extent necessary for contractual purposes;
d. processors who provide services to the Controller, including those to whom the data are entrusted, e.g. PGE Polska Grupa Energetyczna S.A., PGE Systemy S.A.
V. Transfer of personal data outside the EEA.
In principle your personal data will not be transferred outside the European Economic Area (hereinafter: EEA). However, taking into account the IT services provided by PGE Systemy S.A. as a Shared Services Centre within the PGE Capital Group, the performance of specific IT activities or tasks by this subcontractor may result in the transfer of data outside the EEA. For more information on possible data transfer and how to secure it, please contact PGE Systemy S.A.
VI. Data retention period.
Personal data will be processed for the following periods of time:
a. data processed for the purpose of contract performance - until the statute of limitations for claims arising under a contract, for the time necessary to pursue or defend such claims;
b. data processed on the basis of a legal regulation - for the period resulting from the generally applicable law;
c. data processed on the basis of the Controller's legitimate interest - for the time necessary to achieve the purpose or for you to make an effective objection;
d. in the case of data processed on the basis of the given consent - until the consent is withdrawn or it is determined that the data have become obsolete.
VII. Rights of data subjects.
According to the GDPR, you are entitled:
a. to request access to your data and to receive a copy of your data,
b. to request the rectification (correction) of your data,
c. to request that your data be deleted or restricted, or to lodge an objection to their processing,
d. to request that your data be transferred,
e. to lodge a complaint with the supervisory authority.
VIII. Information on the voluntary provision of data.
In the case of obtaining data directly from you, the provision of data is:
a. necessary for the conclusion and performance of a contract or for any other purpose related to the processing of data in accordance with paragraph III above,
b. voluntary with regard to the processing of personal data based on your consent (you have the right to withdraw your consent at any time).
IX. Automated decision-making.
Please be advised that we do not make automated decisions for the above purposes and your data is not used for profiling purposes.
X. Data source.
Personal data not obtained directly from you may originate:
a. from your employer/principal who has entered into a contract with the Controller for the provision of a specific service for the performance of which it is necessary to provide your contact details, as well as additional information in the case of the performance of work that requires the provision of such information;
b. from publicly available sources (e.g. CEiDG, KRS registers), from persons representing you on the basis of a power of attorney granted by you.
XI. Consent and information about the possibility of withdrawing your consent.
You have the right to withdraw your consent to the processing of your personal data on the basis of your consent at any time, but the withdrawal of your consent does not affect the lawfulness of the processing performed on the basis of your consent prior to its withdrawal.
Data Protection Officer – Mariusz Lach