Who are we?
The controller that has determined the purposes and means of processing your personal data is the company:
Name: NEOSHIP s. r. o.Registered office: Miletičova 23, Bratislava – mestská časť Ružinov 821 09
Company ID (IČO): 50 286 820
Registration: Obchodný register Mestského súdu Bratislava III, odd. Sro, vložka č. 193803/B
Glossary of terms
For a better understanding of the information contained in this document, we explain the following terms.
- What is personal data?
- Personal data means any information relating to an identified or identifiable natural person (hereinafter referred to as the "data subject"). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- What is the processing of personal data?
- Processing means an operation or set of operations performed on personal data or on sets of personal data. For example, collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction, whether or not carried out by automated or non-automated means.
- Who is the controller?
- The controller is a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
- Who is the processor?
- The processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
- Who is the recipient of personal data?
- The recipient is a natural or legal person, public authority, agency or another body to which personal data is disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law are not regarded as recipients. The processing of such data by those public authorities is carried out in compliance with the applicable data protection rules according to the purposes of the processing.
- Who is a third party?
- A third party is a natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and persons who, under the direct authority of the controller or the processor, are authorised to process personal data.
- What is consent to the processing of personal data?
- Consent of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
- What is a personal data breach?
- A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
Principles of personal data protection
When processing your personal data in accordance with the requirements of the General Data Protection Regulation, we observe the following principles:
Lawfulness, fairness and transparency
We process personal data lawfully, fairly and in a transparent manner in relation to the data subjects, so that their rights are not infringed.
Purpose limitation
Personal data collected for specified, explicit and legitimate purposes is not further processed in a manner that is incompatible with those original purposes. Further processing for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes is not, in accordance with Article 89(1) of the GDPR, considered incompatible with the original purposes.
Data minimisation
We collect and process only personal data that is adequate, relevant and limited to what is necessary in relation to the purposes for which we process it.
Accuracy
We process only accurate and, where necessary, up-to-date personal data. To fulfil this principle, we take every reasonable step to ensure that personal data which is inaccurate, having regard to the purposes for which it is processed, is erased or rectified without delay.
Storage limitation
Personal data is kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data is processed. Personal data may be stored for longer periods insofar as it will be processed solely for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes in accordance with Article 89(1), subject to the implementation of the appropriate technical and organisational measures required by this General Data Protection Regulation (GDPR) in order to safeguard the rights and freedoms of data subjects.
Integrity and confidentiality
We process personal data in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures, in particular in the area of information and cyber security.
Accountability
As the controller, we are aware that we are responsible for complying with the principles of personal data processing, for ensuring that the processing of personal data complies with the processing principles under the General Data Protection Regulation (GDPR), and that we are obliged to demonstrate such compliance at the request of the competent supervisory authority.
Legal bases for the processing of personal data
We process your personal data only on the basis of the following legal bases under the General Data Protection Regulation (GDPR):
- Article 6(1)(a) the data subject has given consent to the processing of their personal data for at least one specific purpose.
- Article 6(1)(b) processing of personal data is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract.
- Article 6(1)(c) processing of personal data is necessary under a specific regulation or an international treaty by which the Slovak Republic is bound.
- Article 6(1)(f) processing of personal data is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or rights of the data subject which require protection of personal data, in particular where the data subject is a child.
If we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. For example, by sending a request to the address info@neoship.sk.
Purposes of the processing of personal data
Depending on which category of data subjects you belong to, we process your personal data for the following purposes:
- Information on the purposes of processing for website visitors and social media followers
- Information on the purposes of processing for business partners and their employees
- Information on the purposes of processing for job applicants
- Information on the purposes of processing for employees
Cookies and analytics tools
Our website uses cookies and similar technologies. On your first visit you can choose which optional cookies to allow. You can change your choice at any time via the "Cookie settings" link in the website footer.
Necessary cookies and technologies
These ensure the basic functioning of the website. They include storing your cookie consent (in the browser’s local storage), protecting forms against spam via the Cloudflare Turnstile service, and anonymous (cookieless) error tracking via Microsoft Azure Application Insights to ensure the stability of the website. We process these on the basis of our legitimate interest (Article 6(1)(f) GDPR) and they cannot be switched off.
Analytics cookies – Google Analytics 4
With your consent we use Google Analytics 4 (provider Google Ireland Limited) to measure traffic and user behaviour. It stores the _ga and _ga_* cookies and processes data such as the IP address (truncated), pages visited and device type. The data may be transferred to Google LLC in the USA on the basis of standard contractual clauses. The legal basis is your consent (Article 6(1)(a) GDPR), which you can withdraw at any time.
Marketing cookies
We currently do not use any marketing or advertising cookies on the website. We list this category for transparency about the future – should we introduce it, we will ask for your separate consent.
Your rights relating to the protection of personal data
The General Data Protection Regulation (GDPR) grants you, as data subjects, rights which we as the controller endeavour to make as easy as possible to exercise. When processing your personal data, we are ready to give effect to your rights.
Right of access to personal data
You have the right to access your personal data, as well as the right to know for what purpose it is processed, who the recipients of your personal data are and what the processing period is.
Right to rectification
You have the right to rectification; if your personal data is inaccurate or has changed, contact us and we will correct it. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
Right to erasure (right to be forgotten)
You have the right to erasure of personal data if it is inaccurate or processed unlawfully. We will erase your personal data without undue delay if one of the following grounds applies: the personal data is no longer necessary for the purposes for which it was collected or otherwise processed, or you withdraw the consent on which the processing is based and there is no other legal ground for the processing, or your personal data has been processed unlawfully, or your personal data must be erased in order to comply with a legal obligation.
Right to restriction of processing
You have the right to restriction of processing if you so wish, in one of the following cases: as a data subject you contest the accuracy of the personal data, for a period enabling us to verify the accuracy of the personal data, or the processing is unlawful and you oppose the erasure of the personal data and request the restriction of its use instead, or we no longer need your personal data for the purposes of the processing but you as the data subject require it for the establishment, exercise or defence of legal claims, or as a data subject you object to the processing, pending the verification of whether our legitimate grounds override your legitimate grounds as the data subject.
Right to data portability
You have the right to data portability; if you wish to transfer your data to another controller, we will provide it to you in a corresponding structured, commonly used and machine-readable format, where the processing is based on consent or on a contract and where the processing is carried out by automated means.
Right to object
You have the right to object at any time to the processing of your personal data on grounds relating to your particular situation, where the processing is carried out for the stated purposes on the basis of the legitimate interest that we pursue as the controller. We will no longer process your personal data unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or grounds for the establishment, exercise or defence of legal claims.
Right to lodge a complaint
If you believe that the processing of personal data is contrary to applicable regulations, you have the right to lodge a complaint with the supervisory authority, which is the Office for Personal Data Protection of the Slovak Republic, with its registered office at Galvaniho Business Centrum II, Galvaniho 7/B, Bratislava, Slovak Republic, Company ID (IČO): 36 064 220, tel. no.: +421 2 32 31 32 14, https://dataprotection.gov.sk/uoou/
Where and how you can exercise your rights
You can exercise your rights in writing at the address: Neoship, s.r.o., Miletičova 23, 821 09 Bratislava – mestská časť Ružinov, e-mail: info@neoship.sk.
We will respond to your request free of charge within 30 days. In the event of complexity or a large number of requests, we are entitled to extend this period by a further 60 days. Should this happen, we will inform you of it and of the reasons.
However, if your request is manifestly unfounded or repetitive, we are entitled to charge a reasonable administrative fee to cover the costs associated with providing this service.
Amendments and changes
Because personal data protection is not a one-off matter for us, we reserve the right to amend and change the information set out in this document at any time. We will notify you of any such change in advance via this website or by e-mail.
Additional information
If you have any questions concerning the protection of personal data, you can contact us. You can ask whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, and also whether you are obliged to provide us with personal data. You can also ask about the possible consequences of failing to provide your personal data.