Data Controller
We believe it is better to do one activity as well as possible rather than multiple activities averagely. Therefore, in our company, we focus exclusively on network management and security services—both in the Czech Republic and in the member states of the European Union. However, even with this very narrow specialization, we find ourselves in the position of both a controller and a processor of personal data.
If you have any questions or comments, you can contact us at:
PATRON-IT s.r.o. (Company ID: 29279534)
Příkop 843/4
602 00 Brno
gdpr@patron-it.cz
List of Personal Data Processed in the Capacity of Controller
Payroll Administration
To comply with legal requirements and fulfill our obligations toward our employees (hereinafter referred to as "Colleagues"—because this word better expresses the atmosphere and friendly relations that prevail in our company), we maintain the following data about them for a period of 30 years (I am surprised myself by the length of the following list, but everything is truly necessary): name, surname, title, birth number (RČ), date and place of birth, permanent residence, marital status, health insurance company, previous education and employment, conscription/military obligation, private contact details (phone, e-mail), bank account number, working hours data (illness, vacation, hours worked), salary data, health status certificate, data necessary for tax returns (bank confirmation of mortgage interest paid, number of dependent children including their first name, surname, and birth number, personal data of the husband/wife/partner including first name, surname, birth number, amount of housing loan interest, pension data, data on contributions provided to life and pension insurance systems including contractual terms of specific products, data on provided gifts, data on interest provided for housing needs including contractual terms and legally required data on housing needs), type of pension received, category of health disability, affiliation to the social security system of another state, data on wage deductions including ongoing execution/garnishment proceedings, job position, as well as all other personal data necessary for maintaining payroll accounting and fulfilling obligations established by generally binding legal regulations, and all other data necessary for applying tax reliefs and deductions from the tax base of employees.
Some of this data is obtained directly from employees when concluding the contract (e.g., name, surname), and another part is generated during our relationship (e.g., working hours data and salary data). Colleagues inform us about changes in their data.
Access to this personal data is restricted to a limited number of persons: executives, the assistant, the accountant, and the payroll accountant. Outside the company, we make it available only to an external payroll accountant with whom we have concluded a separate data processing agreement, and to the necessary extent to the health insurance companies of our Colleagues and state institutions (tax office, municipal social security administration).
This personal data is kept in our company in electronic form in the "Pohoda" system with an encrypted database unit and in paper form in a lockable cabinet.
Company Representation
Just as inside the company, externally (with customers, suppliers) we strive to maintain warm and honest relationships. We believe that when other parties know who they are communicating with, cooperation is more efficient and trust is built faster. For this reason, in the "legitimate interest of the company," we process the following personal data about our Colleagues obtained from them: name, surname, photographs, job position, company telephone number, company e-mail address, certifications, work achievements.
This personal data is used by colleagues in e-mail communication and by the company on its website and in marketing, advertising, and sales materials.
The personal data is located in the following places:
- E-mail messages – Microsoft provider, Microsoft 365 cloud – contains all the personal data listed above.
- Information systems – ESET Protect, Unifi, PATRAM, Active Directory – contains first and last name as login credentials.
Due to the nature of this personal data, it is shared with third parties.
We retain personal data for the duration of the colleague's employment relationship with the company. Upon its termination, deactivation and termination of sharing of this personal data occur without undue delay. Within 1 year of termination, it is also deleted within our company.
Work Activity Log
For transparency and good relationships with our company's customers, we keep records of our work (legitimate interest of the company, performance of contracts with customers). Based on these work sheets, we subsequently invoice our customers.
Work sheets contain: name and surname of the person performing the service, description of the service (what, when, how, and where), and optionally the name of the person (customer or their representative) who approved, ordered, or participated in the service.
We obtain this data directly from the colleagues themselves, or they record it about each other (e.g., someone enters a bulk operation in the information system in which they participated with others).
Since work sheets are an attachment to tax documents (to substantiate the purposefulness of costs for the tax office) and our company is a VAT payer, we must keep them for a period of 10 years.
Internally, every Colleague has access to this personal data (for the purpose of mutual substitution and tracking past service interventions).
We share this personal data in the form of work sheets with customers. Each customer receives via e-mail only the work sheet containing personal data relating to their employees and our Colleagues. In the network management contract, we oblige customers to properly secure the provided personal data (in accordance with applicable personal data protection regulations).
The personal data is located in the corporate OneDrive account, the PATRAM information system, and e-mails. All systems require a username, password, and second factor for access. Communication is protected against interception during transmission by encryption.
Business Contact Information
In order to carry out business activity and simultaneously fulfill the obligations of the Accounting Act, we must record the following about our business partners: name, company address, Company ID (IČ), VAT ID (DIČ), contact persons, bank account number, information on provided/ordered services and goods, solvency.
We keep this data for a period of 10 years and obtain it directly from the data subject, from bank statements, the Commercial Register, the VAT payers' registry, and the tax office.
This personal data is located in various places: the Pohoda IS, the Office 365 mail server, and in paper form. Even though this is predominantly public data, we use encryption for both the Pohoda IS and Office 365, and we keep the paper form in a locked cabinet with access restricted only to executives, administrative staff, and company accountants. Except for legal obligations, we do not make it available to third parties.
Customer Contact Information
During the provision of services (network management and security), we are in contact with customers, their partners, employees, and potential customers. In the legitimate interest of the company and for the purpose of fulfilling contracts, we process the following personal data: name, surname, telephone number, e-mail address, company name.
The main reason for processing the personal data of these individuals is so that we can communicate with them for the purpose of fulfilling their requests or our obligations toward them (arising from contracts). They provide personal data to us voluntarily.
We share this data within our company and pass it on only to:
- business partners involved in accounting and reporting,
- subcontractors with whom we cooperate on our contracts,
- the "partners" listed below.
Of course, we also have an obligation arising from special legal regulations to hand over requested data to courts, the police, and other public administration authorities.
Personal data is located in Office 365, company computers, and mobile phones. In case of theft/loss of a mobile phone, personal data is protected by encryption, and the contents of the phone can be remotely wiped. Company computers are non-portable and their contents are also protected by encryption.
Recruitment of New Colleagues
From time to time, we look for new colleagues to join our company. In such cases, resumes and cover letters are sent to us via e-mail.
We store this personal data on the company shared drive. Personal data is deleted from e-mail as soon as the position for which a colleague is sought has been filled or the respective round has been closed (approx. 2 months). We do not print this personal data.
We store this personal data on the company drive for 1 year, after which we delete it. Exceptions are cases where the candidate gives us written permission to keep personal data for a longer period (because we would like to contact them regarding an open position in the future).
We do not pass this personal data on anywhere further, and inside our company, only a subset of people have access to it (those responsible for selecting the new colleague).
Sending New Articles
Readers who like our blog https://martinhaller.cz can subscribe to notifications about new articles. To be able to send them these notifications, they provide us with their e-mail address. We do not share this personal data with anyone further and do not use it for any purpose other than sending notifications. Every e-mail we send also contains a link to remove your e-mail from the list. When a reader decides to no longer receive notifications, their e-mail address is immediately deleted from the system.
List of Personal Data Processed in the Capacity of Processor
As the manager of our customers' networks, computers, and servers, we also have access to personal data for which they are controllers or processors. We are obligated to process this data based on the network management contract we have concluded with our customers.
What Personal Data We Process and What We Do With It
Our customers are companies from various fields; therefore, the personal data for which we are processors also varies. Most often, this involves personal data of a business nature (lists of suppliers, customers, overviews), user nature (login credentials, user profiles in e-shops), payroll substrates, health information (examination results, health records). Given the number of customers, however, it is not possible for us to provide an exhaustive list of personal data.
Mostly, we do not have direct access to this personal data (login credentials to information systems), but only access to the underlying systems/infrastructure. As network managers, we access them primarily for the purpose of backing up (e.g., backing up the entire database/server), security (we take care of the systems where personal data is located), and customer support (if a user needs help with a system).
We do not pass personal data on any further, except for exceptions when we are asked in writing by the data controller themselves (e.g., for the purpose of technical support with the manufacturer of the information system where personal data is managed).
How We Ensure Security
Some of our customers are controllers of "special categories of personal data," which have increased security requirements. In our company, we also adhere to the philosophy of standardization (see our article "Standardization – We Do IT Like Baťa's Shoemaker"). For these reasons, we have decided to approach the network management of all customers with an emphasis on the highest possible security.
- We do not create copies of personal data – during the management of our customers' networks (fulfilling obligations from the network management contract), their personal data does not leave their environment (i.e., we do not make copies of it for ourselves).
- Physical security:
- The locations from which we can access our customers' environments are restricted.
- These locations are guarded by an electronic security system or have security guards.
- Electronic security:
- We use a unique set of passwords to access each customer.
- For remote access to the customer, we primarily use RDP, TeamViewer, and VPN connections. All these technologies ensure encryption, authentication, and authorization and are standard in the IT industry.
- We store all access data in software designated for this purpose, which we operate on our own servers and which can only be accessed from PCs with a high level of security (see article "Password Management 2").
- PCs from which customers can be accessed from our end are extra secured. Their users (Colleagues) cannot install anything on the stations and can only run permitted applications (this is a technical restriction). (More about this security in the article "Network Security: Tiering and PAW").
- For all our central systems (allowing access to multiple customers), we use at least two-factor authentication.
- Organizational measures:
- We have an authorization system solved in the company (i.e., not everyone has access everywhere).
- In the field of security, we strive to constantly educate ourselves, improve, and implement new technologies (see articles on our activities at https://martinhaller.cz/).
- All Colleagues are regularly trained in personal data protection so that they know and follow company rules regarding personal data protection.
- Activity logs:
- All connections to customers are automatically logged (who, when, where, and how long).
- At the same time, manual records are kept of all operations, which are submitted to the customer every month (see article "Work Sheets").
Instructions / Rights of Data Subjects
As a personal data subject, you have the right to:
- request information about the categories of your processed personal data, purpose, duration, and nature of processing, and recipients of your personal data;
- request the provision of a copy of the processed personal data;
- request, upon fulfillment of conditions set by relevant legal regulations, that personal data be corrected, supplemented, or deleted, or its processing restricted;
- object to the processing of personal data and the right to file a complaint with a supervisory authority;
- be informed of cases of personal data breaches if such breach is likely to result in a high risk to your rights and freedoms;
- data portability;
- withdraw your consent to the processing of personal data at any time (Here we would like to point out that some personal data necessary for the proper provision of the service or to fulfill our obligations must be processed even if you withdraw your consent. This is so that we can properly provide you with the services we agreed upon, or because the law commands us to do so).
If we receive a request from you regarding personal data, we will inform you of the measures taken without undue delay.
The law permits us to process personal data without the consent of the data subject, but only for the purpose of:
- providing a service or product (when fulfilling obligations arising either directly from the contract or even in a situation where we nod to a task together or shake hands as a sign of agreement—the law defines this as "implied use of the service");
- fulfillment of legal obligations that arise for us from generally binding legal regulations;
- in the public interest (e.g., verification and ensuring the security of services and products provided by us);
- processing necessary for the purposes of legitimate interests (the effect for the customer is higher than for the processor).
Furthermore, we can also process personal data on the basis of consent. The purpose for which we process specific personal data is stated above in this document.
You also have the right to object to the processing of data concerning you (pursuant to Article 21 of the GDPR).
In case of questions or to exercise your rights, send us a message at gdpr@patron-it.cz.