As of January 30, 2024, Regulation 679/2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as “GDPR”) comes into force, ensuring the protection of the fundamental rights and freedoms of individuals, especially their right to the protection of personal data.
We, SC HamHam Rentals SRL, pay special attention to the confidentiality of personal data and the protection of the rights of our clients and partners.
Therefore, we wish to communicate certain relevant information regarding the processing of personal data carried out by our company:
Understanding certain terms:
To ensure clarity in the information provided in this document, we explain below the meaning of certain terms used, as defined by applicable law:
“Personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person;
“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
“Controller” means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data;
“Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
“Recipient” means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed.
Data controller:
SC HamHam Rentals SRL, headquartered in Bucharest, Barbu Vacarescu Street 164D, sector 2, Unique Registration Code RO 40268364, registered with the Trade Register under no. J40/17482/2018, bank account no. RO40 INGB 0000 9999 0847 7700 opened at ING Bank Floreasca, represented by Catalin Moraru – ADMINISTRATOR, as the personal data controller.
The processing of personal data is carried out in accordance with and in compliance with the provisions of applicable law, and especially Regulation 679/2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (GDPR).
Categories of processed data:
Our company carries out various types of processing of personal data. The processed information, the method of collection, and the other conditions of data processing vary depending on the purpose of each processing operation and its legal basis.
In general, we process the following categories of personal data:
– Names, contact details, signature, position, and organization in which you work (especially in the case of representatives and employees of partner companies – clients, suppliers, other business partners);
-address, identification data (ID series and number, personal identification number), including supporting documents;
– Professional experience, studies and qualifications, other data commonly included in CVs (especially if you apply for a position within our organization);
– Technical and professional knowledge and skills, professional qualifications, information about training/professional development courses and competitions organized by the Controller in which you participate;
– Date of birth (information usually requested for age confirmation, i.e., that you are over 18 years old, so you can participate in events, activities, and/or competitions organized by us);
– Data about the contractual relationship between you and our company;
– Data related to or necessary for fulfilling our legal obligations – including, if applicable, data regarding income earned and/or prizes received from the Controller and towards which our company has fiscal obligations (such as filing tax returns, withholding and paying taxes, contributions to the state budget or other public budgets, etc.);
– We process the image of individuals who visit our video-surveilled locations.
It is possible that, on a case-by-case basis or in occasional situations, we may process other personal data, as we will inform the data subjects in each specific situation.
Purposes and legal bases of data processing:
In this section, we present the purpose for which we use personal data and identify the legal bases for each processing of personal data.
Our company processes personal data mainly for the following purposes:
– Advertising, marketing, and publicity, public relations;
– Sale of products and provision of services offered by our company (including qualification/performance improvement courses);
– Conclusion of contracts and monitoring of contracts with contractual partners (clients, suppliers, etc.), including maintaining contact with them;
– Your participation in events, activities, and/or competitions organized by us;
– Fulfillment of our obligations under applicable law, court judgments, and orders, decisions, and provisions of public authorities;
– Protection of the Controller’s property, as well as protection, respect, and exercise of the Controller’s rights.
Processing of personal data is carried out only on the basis of a legal basis, in accordance with the provisions of the GDPR. The legal bases for the processing of personal data may be as follows:
– Fulfillment of legal obligations of the Controller (fulfillment of tax obligations, maintenance of records required by law, etc.);
– Your freely given consent (in the case of participating in events, activities, and/or competitions organized by us, subscribing to our newsletter, as well as in other specific situations, when your consent is expressly and unequivocally given);
– The legitimate interest of the Controller (advertising, marketing, and publicity for the products and services we offer, public relations and promotion of the Controller’s image, sale of products and provision of services offered by our company to other persons, protection of the Controller’s property and protection, respect, and exercise of our rights);
– Execution of a contract to which you are a party or the performance of actions, at your request, prior to the conclusion of a contract.
Categories of recipients:
In general, we use your personal data in our interest. However, there are situations in which personal data will be disclosed to certain categories of recipients, in accordance with the purpose of each processing operation.
Personal data may be communicated to our business partners (including banks or other credit institutions), as well as to our service providers acting as authorized persons by the Controller. Some of them may be based in other member states of the European Union.
The names of winners of contests organized by us are publicly announced at the respective event, as well as by publication on our websites, on pages and channels on social networks, in our magazine and newsletter, as well as through any other means of communication. The personal data of winners will also be transmitted to the competent public authorities for the fulfillment of tax obligations, in accordance with applicable legal provisions.
Personal data are communicated to public authorities or other third parties when there is a legal obligation to do so, if a decision/administrative order with mandatory character for the Controller has been issued, as well as when such communication is necessary for the establishment, exercise, or defense of a legal right.
Data retention period:
Your personal data will be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which
the personal data are processed.
– Data necessary for compliance with legal obligations (e.g., accounting records) will be kept for as long as necessary to comply with such obligations;
– Data processing operations based on your consent will be carried out until the consent is withdrawn or until the moment you object to the processing;
– Data processed based on our legitimate interest will be kept for a period of time deemed appropriate to achieve the purpose for which they were collected (e.g., 10 years from the date of termination of the contractual relationship, in the case of contracts, or a shorter or longer period depending on the nature of the contract and/or the related rights/obligations);
– Data necessary to establish, exercise, or defend a legal right will be kept for the entire duration of the exercise of such rights and/or until the end of the relevant judicial proceedings, including any appeal.
Rights of data subjects:
You have the following rights regarding the processing of your personal data:
– The right of access: you can obtain from us a confirmation that we process personal data concerning you, as well as details about the processing (e.g., purposes, categories of data, recipients, etc.).
– The right to rectification: you have the right to obtain from us, without undue delay, the rectification of inaccurate personal data concerning you. Depending on the purpose of the processing, you also have the right to obtain the completion of incomplete personal data, including by providing a supplementary statement.
– The right to erasure: you can request the erasure of personal data concerning you if the data are no longer necessary for the purposes for which they were collected or processed, if you have withdrawn your consent (if the processing is based on your consent), if you have objected to the processing (if the processing is based on our legitimate interest), if the data have been processed unlawfully, or if there is a legal obligation to erase the data.
– The right to restrict processing: you can obtain from us the restriction of processing if you contest the accuracy of the personal data (for a period enabling us to verify the accuracy of the data), if the processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead, if we no longer need the personal data for the purposes of the processing but they are required by you for the establishment, exercise, or defense of legal claims, or if you have objected to processing (if the processing is based on our legitimate interest) for the period until it is verified whether our legitimate grounds override yours.
– The right to data portability: you have the right to receive the personal data concerning you which you have provided to us, in a structured, commonly used, and machine-readable format and have the right to transmit those data to another controller without hindrance from us, where technically feasible. This right applies only to the personal data you have provided to us, if the processing is based on your consent or is necessary for the performance of a contract, and is carried out by automated means.
– The right to object: you have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on our legitimate interest or on performance of a task carried out in the public interest or in the exercise of official authority vested in us, including profiling based on those provisions. In this case, we will no longer process the personal data unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms or for the establishment, exercise, or defense of legal claims.
– The right to withdraw consent: where the processing of personal data is based on your consent, you have the right to withdraw your consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
– The right to lodge a complaint: if you consider that the processing of personal data infringes applicable legal provisions, you have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP), headquartered in B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, postal code 010336, Bucharest, Romania.
Exercise of rights:
You can exercise your rights by submitting a written request to SC HamHam Rentals SRL, headquartered in Bucharest, Barbu Vacarescu Street 164D, sector 2, Romania, or by email at office@hamham.ro.
The request will be analyzed by our company within the legal term provided by law, and a response will be communicated to you accordingly.
In order to verify your identity, we may request additional information from you (such as a copy of an identity document), information that will be used only for the purpose of verifying your identity.
If you exercise any of your rights under the GDPR, we will take all necessary measures to communicate any rectification, erasure, or restriction of processing to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort.
Security measures:
We have implemented appropriate technical and organizational measures to ensure an appropriate level of security for the personal data we process. These measures are intended to prevent accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed.
These measures include:
– Data encryption (in transit and at rest);
– Anonymization and pseudonymization of personal data, where possible;
– Access control, including limiting access to personal data only to those employees who need it for the performance of their duties;
– Regular monitoring and testing of the effectiveness of security measures.
In the case of certain categories of data, additional measures may be implemented, depending on the risk assessment and the technical and organizational resources available.
Concluding remarks:
This document represents the Data Protection Information Note of SC HamHam Rentals SRL. We may update this document periodically, as necessary, to reflect changes in the processing of personal data or changes in applicable legal provisions.
You are encouraged to regularly consult this document to stay informed about the way we process personal data.
If you have any questions about the processing of personal data by our company or if you need additional information about any aspect related to this topic, please contact us using the contact details provided above.
Thank you for your trust and collaboration!
SC HamHam Rentals SRL
Catalin Moraru
Administrator