{"id":19641,"date":"2020-04-20T14:45:41","date_gmt":"2020-04-20T13:45:41","guid":{"rendered":"https:\/\/www.spinalis.com\/protection-of-personal-data\/"},"modified":"2020-04-20T14:45:41","modified_gmt":"2020-04-20T13:45:41","slug":"protection-of-personal-data","status":"publish","type":"page","link":"https:\/\/www.spinalis.com\/en\/protection-of-personal-data\/","title":{"rendered":"Protection of personal data"},"content":{"rendered":"\n<p>On the basis of Articles 24 and 25 of the Personal Data Protection Act (ZVOP-1) and Regulation (EU) 2016\/679 of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation or GDPR), the Director of the company Ham, d.o.o., Gerbi\u010deva ulica 102, 1000 Ljubljana, registered number 5376491000, tax number SI 70000891 (hereinafter referred to as the company), Toma\u017e Ham, hereby accepts the following:  <\/p>\n\n\n\n<p><strong>REGULATIONS<\/strong><\/p>\n\n\n\n<p><strong>ON PROCEDURES AND MEASURES TO<\/strong><\/p>\n\n\n\n<p><strong>PROTECTION OF PERSONAL DATA<\/strong><\/p>\n\n\n\n<p><strong>I. GENERAL PROVISIONS<\/strong><\/p>\n\n\n\n<p>Article 1<\/p>\n\n\n\n<p><strong>Content and purpose of the Regulations<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li>This policy lays down the technical and organisational measures for the protection of personal data in the company in order to protect the rights and freedoms of the data subject. The purpose of the Company is to prevent accidental or intentional unauthorised destruction, alteration or loss of data, as well as unauthorised access, processing, use or disclosure of personal data to third parties. <\/li><li>Employees and external contractors who process and use personal data in the course of their work must be familiar with the Personal Data Protection Act (PDPA-1) and the General Data Protection Regulation, as well as with the content of this policy.<\/li><li>In matters not covered by these Rules, the provisions of the Personal Data Protection Act (ZVOP-1) and the General Data Protection Regulation shall apply directly.<\/li><\/ol>\n\n\n\n<p>Article 2<\/p>\n\n\n\n<p><strong>Meaning of terms<\/strong><\/p>\n\n\n\n<p>(1) As used in this Regulation, the following terms shall have the following meanings:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>&#8220;national legislation&#8221; means the national legislation currently in force (ZVOP-1 &#8211; Personal Data Protection Act (Official Journal of the Republic of Slovenia, No. 86\/04, 113\/05, 51\/2007. 67\/2007 and 94\/2007);<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>EUR General Data Protection Regulation (2016\/679) or GDPR; <\/li><li>&#8216;personal data&#8217; means any information relating to an identified or identifiable natural or legal person (hereinafter referred to as &#8216;data subject&#8217;); an identifiable natural or legal person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural or legal person;<\/li><li>&#8220;processing&#8221; means any operation or set of operations which is performed upon personal data or upon sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;<\/li><li>&#8216;collection&#8217; means any structured set of personal data which are accessible in accordance with specific criteria and which may be centralised, decentralised or dispersed on a functional or geographical basis;<\/li><li>&#8216;controller&#8217; means the natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing; where the purposes and means of the processing are determined by Union law or by the law of a Member State, the controller or the specific criteria for its designation may be determined by Union law or by the law of a Member State;<\/li><li>&#8216;processor&#8217; means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;<\/li><li>&#8216;user&#8217; means the natural or legal person, public authority, agency or other body to whom the personal data have been disclosed, whether or not a third party. However, public authorities which may receive personal data in the context of an individual enquiry in accordance with Union or Member State law shall not be considered as users; the processing of those data by those public authorities shall be carried out in accordance with the applicable data protection rules in relation to the purposes of the processing; <\/li><li>&#8216;data subject consent&#8217; means any voluntary, explicit, informed and unambiguous indication of the data subject&#8217;s wishes by which he or she, by a statement or by a clear affirmative action, signifies his or her agreement to the processing of personal data concerning him or her;<\/li><li>&#8220;data medium&#8221; means any type of medium on which data are recorded or reproduced (documents, deeds, papers, files, computer equipment including magnetic, optical or other computer media, photocopies, audio and visual material, microfilms, data transmission devices, etc.).<\/li><\/ul>\n\n\n\n<p><strong>II. PRINCIPLES <\/strong><\/p>\n\n\n\n<p>Article 3<\/p>\n\n\n\n<p><strong>Principles relating to the processing of personal data<\/strong><\/p>\n\n\n\n<p>1. Personal data are:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>processed lawfully, fairly and in a transparent manner in relation to the data subject (&#8216;lawfulness, fairness and transparency&#8217;);<\/li><li>adequate, relevant and limited to what is necessary for the purposes for which they are processed (&#8220;minimum data scope&#8221;), which means that forms with fields are predefined and we do not collect or store unnecessary personal data;<\/li><li>kept in a form which permits identification of data subjects for as long as is necessary for the purposes for which the personal data are processed;<\/li><li>they are processed in a way that ensures adequate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, by appropriate technical or organisational measures (&#8220;integrity and confidentiality&#8221;);<\/li><li>pseudonymised in certain business processes to avoid the risk of disclosure. At points in business processes where decryption of pseudonymisation is necessary for the performance of a contractual duty, authorised persons have access to extended data about the individual &#8211; based, of course, on a unique username and password that determines the level of authorisation &#8211; thereby ensuring &#8220;data protection by default&#8221;. We ensure the protection of personal data by default on the basis of organisational and technical measures. Each processing method has a different content of the individual&#8217;s personal data by default, so that only the data that is strictly necessary for the specific processing method and purpose is processed.  <\/li><\/ul>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\" start=\"4\"><li>Member<\/li><li>&nbsp;<\/li><\/ol>\n\n\n\n<p>Article 4<\/p>\n\n\n\n<p><strong>Lawfulness of processing<\/strong><\/p>\n\n\n\n<p>Only personal data that have a relevant legal basis under the provisions of the GDPR and ZVOP-1 and are demonstrable by the controller are processed in the personal data file:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>the processing is necessary for compliance with a legal obligation to which the controller is subject;<\/li><li>the processing is necessary for the performance of a contract to which the data subject is a party or for the performance of measures at the request of such data subject prior to the conclusion of the contract;<\/li><li>legitimate interest;<\/li><li>the data subject has consented to the processing of his or her personal data for one or more specified purposes.<\/li><\/ul>\n\n\n\n<p><strong><\/strong><\/p>\n\n\n\n<p><strong>III. INDIVIDUAL RIGHTS <\/strong><\/p>\n\n\n\n<p>Article 5<\/p>\n\n\n\n<p><strong>Transparency of the information provided and of the means of exercising individual rights<\/strong><\/p>\n\n\n\n<p>The controller shall provide the following information to the individual in a concise, transparent, comprehensible and easily accessible form and in clear and plain language:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>the identity and contact details of the controller,<\/li><li>the purposes for which the personal data are processed, as well as the legal basis for the processing,<\/li><li>the period of retention of the personal data or the criteria used to determine the period, <\/li><li>the existence of a right to obtain from the controller access to personal data and to have personal data concerning the data subject rectified or erased or to have processing restricted, or the existence of a right to object to processing,<\/li><li>the existence of a right to withdraw consent at any time without affecting the lawfulness of the processing carried out on the basis of the consent until its withdrawal,<\/li><li>the right to lodge a complaint with the supervisory authority.<\/li><\/ul>\n\n\n\n<p>Article 6<\/p>\n\n\n\n<p><strong>Right of access of the individual<\/strong><\/p>\n\n\n\n<p>The data subject shall have the right to obtain from the controller confirmation as to whether personal data concerning him or her are being processed and, where this is the case, access to the personal data and the following information:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>the purposes of the processing,<\/li><li>the type of personal data concerned,<\/li><li>if possible, the intended retention period of the data,<\/li><li>the existence of a right to require the controller to access and rectify or erase personal data or to restrict processing in relation to the data subject, or the existence of a right to object to processing,<\/li><li>the right to lodge a complaint with the supervisory authority,<\/li><li>where the personal data are not collected from the data subject, any available information concerning their source.<\/li><\/ul>\n\n\n\n<p>The controller will provide the requested information without undue delay and in any event within one month of receipt of the request.<\/p>\n\n\n\n<p>The controller shall provide a copy of the personal data processed free of charge. For additional copies requested by the data subject, the controller may charge a reasonable fee, taking into account legal costs. <\/p>\n\n\n\n<p>Article 7<\/p>\n\n\n\n<p><strong>Procedure for exercising your rights<\/strong><\/p>\n\n\n\n<p>Personal data shall only be disclosed to those users who provide the relevant legal basis or the written request or consent of the data subject. <\/p>\n\n\n\n<p>For each transfer of personal data, the individual must submit a written application and each transfer is recorded in a transfer register (which data, to whom, when and on what basis). Original documents shall never be disclosed, except in the case of a written order from a court. The original document shall be replaced by a copy in the Company&#8217;s absence.  <\/p>\n\n\n\n<p>The controller shall communicate to each user to whom personal data have been disclosed any rectification or erasure of personal data or restriction of processing, unless this proves impossible or involves a disproportionate effort.<\/p>\n\n\n\n<p>The controller shall inform the data subject of these users if the data subject so requests.<\/p>\n\n\n\n<p>Article 7a <\/p>\n\n\n\n<p><strong>Procedure for providing information on processing<\/strong><\/p>\n\n\n\n<p>Upon oral or written request and identification of the data subject, the following information shall be provided to the data subject in printed or pdf form: the purpose of the processing of his\/her personal data, the types of personal data concerned, the envisaged retention period (if possible), the existence of the right to request rectification or erasure or restriction of processing or to object to the processing of personal data, the existence of the right to lodge a complaint with a competent authority. The controller shall provide a copy of the personal data processed free of charge. For additional copies requested by the data subject, the controller may charge a reasonable fee, taking into account legal costs.  <\/p>\n\n\n\n<p>Article 7b <\/p>\n\n\n\n<p><strong>Procedure for exercising the right of rectification<\/strong><\/p>\n\n\n\n<p>Following an oral or written request and identification of the data subject, inaccurate data collected by the controller shall be rectified without undue delay. The data subject shall have the right, having regard to the purposes of the processing, to have incomplete personal data completed. <\/p>\n\n\n\n<p>Article 7c <\/p>\n\n\n\n<p><strong>Procedure for exercising the right to erasure (&#8220;oblivion&#8221;)<\/strong><\/p>\n\n\n\n<p>Upon oral or written request and identification of the data subject, the data collected by the controller shall be deleted without undue delay if:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>the personal data collected is no longer necessary for the purposes for which it was collected or otherwise processed,<\/li><li>the individual withdraws the consent on the basis of which his or her data are processed and where there is no other legal basis for the processing,<\/li><li>the data subject objects to the processing (under GDPR Section 4, Article 21 (1) or (2)), no other legal basis exists for the processing,<\/li><li>they must be erased in order to comply with a legal obligation under Union or national law to which the controller is subject.<\/li><\/ul>\n\n\n\n<p>The data will be permanently removed from the database. In the X and Y collections &nbsp;<a>a &#8220;delete&#8221; function that will anonymise personal data at the request of the individual, leaving the data we need for <\/a>annual financial or business analysis. The process is carried out by an authorised person of the controller. The Z file is a personnel file which is permanent and the data is not deleted. Collections A, B and C allow the deletion of data. This shall be carried out by an authorised person of the controller, who shall, if necessary, seek the cooperation of the contract administrator of the sub-processor. The video file shall delete the recordings after 12 months, but if a recording needs to be deleted earlier, the controller&#8217;s authorised person shall do so.      <\/p>\n\n\n\n<p>Article 7c <\/p>\n\n\n\n<p><strong>Procedure for exercising the right to restriction of processing<\/strong><\/p>\n\n\n\n<p>Upon oral or written request and identification of the data subject, the processing of the data collected by the controller shall be restricted without undue delay if:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>the data subject contests the accuracy of the data for a period which allows the controller to verify the accuracy of the personal data,<\/li><li>the data subject objects to the erasure of personal data and requests instead the restriction of processing,<\/li><li>the controller no longer needs the personal data for the purposes of the processing, but the data subject needs them for the exercise of. Exercise or defence of legal claims, <\/li><li>the data subject has lodged an objection to the processing, pending verification whether the legitimate grounds of the controller override those of the data subject.<\/li><\/ul>\n\n\n\n<p>Article 7d <\/p>\n\n\n\n<p><strong>Procedure for exercising the right to data portability<\/strong><\/p>\n\n\n\n<p>Upon oral or written request and identification of the individual, the information provided to the controller shall be provided to the competing company designated by the client. The competing company shall receive it in a structured, commonly used and machine-readable format (*.pdf). It has the right to transmit this information to another controller without hindrance, where the processing is based on the consent of the data subject or on a contract and where the processing is carried out by automated means.  <\/p>\n\n\n\n<p>Article 7e <\/p>\n\n\n\n<p><strong>Procedure for exercising the right to object<\/strong><\/p>\n\n\n\n<p>Upon oral or written request and identification of the data subject, the controller shall terminate the processing of personal data, including profiling, if any, and direct marketing. An exception shall be made where the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims. <\/p>\n\n\n\n<p>If the data subject objects to the purpose of direct marketing, his or her data shall no longer be processed for that purpose or for any other purpose to which the data subject objects. The individual shall be explicitly reminded of this right at the latest at the time of the first communication &#8211; clearly and separately from other information.  <\/p>\n\n\n\n<p><strong>IV. OBLIGATIONS OF THE CONTROLLER AND THE PROCESSOR <\/strong><\/p>\n\n\n\n<p>Article 8<\/p>\n\n\n\n<p><strong>Controller&#8217;s responsibility and retention period<\/strong><\/p>\n\n\n\n<p>The controller shall take technical and organisational measures to ensure and be able to demonstrate that processing is carried out in accordance with the applicable Regulation.<\/p>\n\n\n\n<p>At the time of determining the means and at the time of the processing itself, the controller shall implement appropriate technical and organisational measures for the effective implementation of the data protection principles, such as the principle of data minimisation, and shall include in the processing the necessary safeguards to meet the requirements of the applicable Regulation and to protect the rights of data subjects. In particular, it shall ensure that personal data are not automatically accessible to an indeterminate number of individuals without the intervention of the individual concerned.  <\/p>\n\n\n\n<p>Personal data will be stored and processed for a minimum period of time determined by law according to the purpose for which the data were collected. Otherwise, the storage will be indefinite or until the consent of the data subject is withdrawn. After withdrawal of consent, the data will be effectively and permanently deleted or anonymised.   <\/p>\n\n\n\n<p>If the purposes for which personal data are stored and processed by the controller change, the databases with the changed purposes will be effectively and permanently erased or anonymised. <\/p>\n\n\n\n<p>Article 9<\/p>\n\n\n\n<p><strong>Responsibilities of the processor<\/strong><\/p>\n\n\n\n<p>Where processing is carried out on behalf of the controller, the controller shall only cooperate with processors who provide sufficient guarantees to implement the appropriate technical and organisational measures in such a way that the processing satisfies the requirements of the applicable Regulation and ensures the protection of the data subject&#8217;s rights.<\/p>\n\n\n\n<p>The processor shall not employ another processor without the prior specific or general written consent of the controller.<\/p>\n\n\n\n<p>The processing by the processor shall be governed by a contract in accordance with Union law, which shall specify the content and duration of the processing, the nature and purpose of the processing, the type of personal data and the obligations and rights of the controller.<strong><\/strong><\/p>\n\n\n\n<p><strong>V. WHAT PERSONAL DATA WE COLLECT AND FOR WHAT PURPOSE<\/strong><\/p>\n\n\n\n<p>Article 10<\/p>\n\n\n\n<p>For business processes, we collect the following information about users and employees at specific points (sometimes all of them, but for individual processes only some of the information recorded):<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>name and surname,<\/li><li>Company<\/li><li>Title,<\/li><li>a telephone number, and<\/li><li>e-mail address,<\/li><li>Notes,<\/li><li>&#8230; .<\/li><\/ul>\n\n\n\n<p>This data is used to perform the following activities for each business process:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>communication about the purchase,<\/li><li>sending newsletters and promotional content from the company,<\/li><li>direct marketing,<\/li><li>sending out ordered e-print, physical print or quiz results,<\/li><li>keeping you informed about events,<\/li><li>Statistical analysis: tracking clicks (on the website and in emails) and email opens to improve the content of emails,<\/li><li>sending emails with offers, information about news, promotions and benefits from the Company and its partners,<\/li><li>phone calls, SMS messages and regular mail.<\/li><\/ul>\n\n\n\n<p><strong>Annex 1<\/strong> describes each of the Company&#8217;s data collections, outlining the categories of individuals, the types and origin of the data, the purpose of the processing, the legal basis for the processing, to whom they are disclosed, the intended retention period, how the overview of the flow of personal data is achieved and where the collection is kept.<\/p>\n\n\n\n<p><strong>Annex <\/strong>2 lists all the sites on the websites where data is collected, such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>sign up for the newsletter;<\/li><li>order catalogues;<\/li><li>Submitting a request for quotation;<\/li><li>order products;<\/li><li>etc. &#8230; &#8230; . <\/li><\/ul>\n\n\n\n<p><strong>VI. INVENTORY OF BUSINESS PROCESSES THAT ARE IN CONTACT WITH PERSONAL DATA <\/strong><\/p>\n\n\n\n<p>Article 11<\/p>\n\n\n\n<p>The nature of our work brings us into contact with individuals&#8217; personal data. By business area and business process, the contact is broken down into &nbsp;<strong>Annex 3.<\/strong><\/p>\n\n\n\n<p><a><strong>VII. DESCRIPTION OF THE SYSTEM <\/strong><\/a><\/p>\n\n\n\n<p>Article 12<\/p>\n\n\n\n<p><strong>System infrastructure<\/strong><\/p>\n\n\n\n<p>The infrastructure of an IT system consists of the following elements: hardware, network equipment and the connections between them.<\/p>\n\n\n\n<p>The hardware consists of a local server, a communication hub and individual computers in the offices.<\/p>\n\n\n\n<p>The network equipment consists of a local server, a provider router and a wireless router for the internet. Data is stored centrally on the local server in encrypted format &#8211; &nbsp;<a>backups are made on it and in encrypted form.<\/a><\/p>\n\n\n\n<p>Maintenance, upgrades and other necessary interventions in the information system are regular and traceable (from the records). Only authorised repairers, organisations or individuals who have a contract with the company are allowed. Contractors must document changes and additions to system or application software. An authorised employee of the Company must also be present at all times during the servicing to ensure that no unauthorised handling of personal data takes place.    <\/p>\n\n\n\n<p>Article 13<\/p>\n\n\n\n<p><strong>Information Security Policy<\/strong><\/p>\n\n\n\n<p>We have an Information Security Policy. To this end, two policies have been drawn up, which each existing and new employee reads and signs to agree to: <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Code of Conduct,<\/li><li>Privacy Policy.<\/li><\/ul>\n\n\n\n<p><strong>VIII. ACCESS TO THE SYSTEM <\/strong><\/p>\n\n\n\n<p>Article 14<\/p>\n\n\n\n<p><strong>User authentication<\/strong><\/p>\n\n\n\n<p>The company uses user authentication with a username in combination with a password.<\/p>\n\n\n\n<p>Identification to the different databases varies, and users must log in to each one with their own unique username and password. The username is assigned to individuals and the password is set by the individual. <\/p>\n\n\n\n<p>There are rules for choosing a password, so that it is strong enough and not easily guessed. Passwords must be at least 6 characters long, and there must be a structure so that the password contains at least one number and one character. In addition, employees are encouraged to use upper and lower case letters. Passwords cannot be repeated.   <\/p>\n\n\n\n<p>The password remains the same until the responsible person decides to change the password. Passwords themselves do not expire and we do not use automatic system password changes. <\/p>\n\n\n\n<p>Article 15<\/p>\n\n\n\n<p><strong>Authorisation of users<\/strong><\/p>\n\n\n\n<p>Staff duties and responsibilities are assigned and established at the start of the job and at induction.<\/p>\n\n\n\n<p>For each personal data collection, a responsible person and the users who have the right of access to each personal data collection are identified.<\/p>\n\n\n\n<p>When accessing the system, there is a division of roles between users and administrators, where the latter have different authorisations from the users.<\/p>\n\n\n\n<p>The granting, modification and revocation of user authorisations is the responsibility of the administrators. When a new employee joins and the onboarding process is completed, the individual receives their own user authorisation, which is actively changed during the course of the work when the user&#8217;s access needs change. This includes removing user privileges and locking them when the employee leaves.  <\/p>\n\n\n\n<p>In many cases, the checking of user authorisations is already set by default for each add-on collection, so the checking is not difficult and can be done quickly.<\/p>\n\n\n\n<p>Article 16<\/p>\n\n\n\n<p><strong>Traceability of data access<\/strong><\/p>\n\n\n\n<p>Every access to data is logged, both user and administrator, even if it was just to log in and view the data. It is also possible to trace changes made to the data, i.e. what was changed and by which user. <\/p>\n\n\n\n<p>Audit trails of data accesses are stored in the individual database and are not accessible to all users, but only to administrators. Modification, deletion and deactivation of audit trails in individual collections are not possible &#8211; not even for administrators. <\/p>\n\n\n\n<p>Accesses to audit trails are also recorded like all other accesses. Regular audits are not on our schedule, but we have the possibility to review and investigate internally if any problem or suspicion arises. As these are small and not frequently used personal data collections, we do not use specific tools to manage audit trails.  <\/p>\n\n\n\n<p>Access control to the data and, more importantly, to the system, is arranged so that access to the databases can only be logged on company computers. Remote access by staff users on company computers is done using VPN technology, which applies exclusively to the company&#8217;s technical sector. <\/p>\n\n\n\n<p><strong>IX. PHYSICAL AND TECHNICAL SECURITY OF PREMISES AND PROTECTION AGAINST ENVIRONMENTAL INFLUENCES <\/strong><\/p>\n\n\n\n<p>Article 17<\/p>\n\n\n\n<p><strong>Physical access<\/strong><\/p>\n\n\n\n<p>The premises where the personal data media, hardware and software are located are protected by technical and organisational measures to prevent unauthorised access to the data. Access is only possible during regular working hours and outside these hours only with the authorisation of the legal representative. Secured areas must not be left unattended and must be locked in the absence of the employees who otherwise supervise them.  <\/p>\n\n\n\n<p>The most important parts, the server and the communication hub, are under lock and key. They can only be accessed by an authorised hardware maintenance person and by contracted service technicians in case of updates and troubleshooting. <\/p>\n\n\n\n<p>Keys to secure rooms are used and stored in accordance with the house rules and are not left in the lock.<\/p>\n\n\n\n<p>We use an alarm system, security locks, mechanical barriers on windows and video surveillance to control access (see&nbsp;<em>Video surveillance rules<\/em>). Employee access is controlled by an alarm system, each of whom has their own personal password. <\/p>\n\n\n\n<p>The aforementioned burglar and security surveillance systems are maintained by external maintenance personnel who are aware of their duties and responsibilities with regard to the protection of our data and have an appropriate contract with the Company. Any interference with them is only permitted in the presence of a legal representative. <\/p>\n\n\n\n<p>Outside working hours, cabinets and desks with personal data carriers must be locked and computers and other hardware must be switched off and physically or programmatically locked. No one shall have access to the premises outside working hours, much less to the personal data files. <\/p>\n\n\n\n<p>In customer-facing areas, data carriers and computer displays must be installed in such a way that they cannot be accessed by customers and other unauthorised persons.<\/p>\n\n\n\n<p>Article 18<\/p>\n\n\n\n<p><strong>Protection against environmental impacts<\/strong><\/p>\n\n\n\n<p>We also protect personal data collections with mechanisms to counteract the impact of the environment. We use a fire alarm system and smoke detectors. <\/p>\n\n\n\n<p><strong>X. DATA PROTECTION<\/strong><\/p>\n\n\n\n<p>Article 19<\/p>\n\n\n\n<p><strong>Controls against malicious code<\/strong><\/p>\n\n\n\n<p>We use ESET ENDPOINT ANTIVIRUS + FILE SECURITY antivirus and firewall software on all computers in the company, which is regularly updated. New versions are installed on an annual basis and licences are renewed annually. <\/p>\n\n\n\n<p>A password-based intrusion detection system is used, where all login attempts are logged and intrusion attempts are blocked.<\/p>\n\n\n\n<p>The contents of network drives and local workstations containing personal data are checked daily for the presence of computer viruses. If a computer virus is detected, it should be eliminated as quickly as possible with the help of the appropriate professional service, while at the same time identifying the cause of the virus in the computer information system. <\/p>\n\n\n\n<p>All personal data and software intended for use in a computer information system and arriving at the Company on computer data transmission media or through telecommunications channels must be checked and tested for the presence of computer viruses before use.<\/p>\n\n\n\n<p>Staff members must not install software without the knowledge of the person responsible for the operation of the computer information system. Nor shall they remove software from the Company&#8217;s premises without the approval of the head of the organisational unit and the person responsible. <\/p>\n\n\n\n<p><a>Article 20<\/a><\/p>\n\n\n\n<p><strong>Backups<\/strong><\/p>\n\n\n\n<p>All databases and the contents of the network server and local stations shall be backed up, if the data is located there, for the purposes of the continuity and uninterrupted operation of the Company and for the purposes of restoring the computer system. Backups shall be made daily during night-time hours when the Company&#8217;s system is idle and not being updated. Copies shall be made in triplicate and shall be located in three different, geographically separated locations that are fireproof, floodproof, EMI-proof, temperature-proof and securely locked.  <\/p>\n\n\n\n<p>Copying is automatic and takes place locally on the server and via cloud connections, so no personal transfer is necessary. Backups are stored on disks and are managed by an authorised person, who is always only one. The original copy is updated daily and does not become outdated, so there is no destruction process for old copies, as there is one copy and it is always up-to-date.  <\/p>\n\n\n\n<p>Article 21<\/p>\n\n\n\n<p><strong>Handling of data media<\/strong><\/p>\n\n\n\n<p>After each use, employees securely format the media to ensure that no personal data remains on it. They should also be stored securely for as long as the data is on them, so that unauthorised access is not possible. Secure storage means in a cabinet and under lock and key.  <\/p>\n\n\n\n<p>Article 22<\/p>\n\n\n\n<p><strong>Data destruction<\/strong><\/p>\n\n\n\n<p>Before a data medium is destroyed, all data on it must be permanently destroyed. In the case of digital media, we ensure that it is permanently erased so that restoration of all or part of the data on it is impossible. Data on traditional printed media (documents, files, lists, registers, etc.) shall be destroyed by means of a document shredder which makes all or part of the data unreadable. Ancillary material shall be destroyed in the same way.   <\/p>\n\n\n\n<p>It is forbidden to dispose of waste data carriers containing personal data in the bins. The transfer of personal data carriers to the destruction site and their destruction shall be supervised by a special internal committee, which shall draw up an appropriate record of the destruction. <\/p>\n\n\n\n<p>Article 23<\/p>\n\n\n\n<p><strong>Handling sensitive personal data<\/strong><\/p>\n\n\n\n<p>We do not collect data that falls under the category of sensitive personal data. Therefore, we do not collect data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, nor do we process genetic or biometric data for the purpose of uniquely identifying an individual, or data relating to health or data relating to an individual&#8217;s sex life or sexual orientation. <\/p>\n\n\n\n<p><strong>XI. SECURITY INCIDENT MANAGEMENT <\/strong><\/p>\n\n\n\n<p>Article 24<\/p>\n\n\n\n<p>It concerns the management of security incidents that have an impact on the level of protection of personal data. The reporting protocol for employees is: <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>the reporting method is primarily oral,<\/li><li>information reaches the responsible person in the company as soon as possible,<\/li><li>reported by the person who detected the security incident,<\/li><li>a report must be made as soon as an employee becomes aware of the possibility of unauthorised access to a personal data collection or when he or she discovers the unauthorised destruction, appropriation, alteration or corruption of a personal data collection or of individual data contained therein,  <\/li><li>doing everything in its power to prevent such activity,<\/li><li>When reporting, you should tell the person responsible which personal data set the incident relates to, how it occurred, when it occurred and any other relevant information that could help to resolve the incident more quickly,<\/li><li>the responsible person immediately reports the incident to the Information Commissioner after becoming aware of it.<\/li><\/ul>\n\n\n\n<p><strong>XII. HUMAN RESOURCES <\/strong><\/p>\n\n\n\n<p>Article 25<\/p>\n\n\n\n<p><strong>Staff<\/strong><\/p>\n\n\n\n<p>Employees are required to follow and comply with this Policy on Procedures and Measures for the Protection of Personal Data, which is adapted to the realities of the Company.<\/p>\n\n\n\n<p>Each staff member shall be made aware of the provisions and shall sign a declaration to that effect, which shall form part of this policy<strong>(Annex 4<\/strong>). The policy shall be published and available at all times on the common drive and in hard copy from the line manager. <\/p>\n\n\n\n<p>We include and discuss personal data protection education in regular company meetings (briefings) so that the information and rules are not forgotten and are regularly implemented.<\/p>\n\n\n\n<p>Anyone processing personal data is obliged to implement the procedures and measures prescribed for data protection and to protect the data which he\/she has learned or become aware of in the course of his\/her work. The obligation to protect data shall not cease upon termination of the employment relationship.  <\/p>\n\n\n\n<p>Staff members are liable for disciplinary action for breaches of the provisions, former staff members are liable for criminal action, and external contractors are liable on the basis of their contractual obligations.<\/p>\n\n\n\n<p>Article 26<\/p>\n\n\n\n<p><strong>Clean desk policy<\/strong><\/p>\n\n\n\n<p>A clean desk policy is very important in society and means that documents with personal data (printed, data media, etc.) are never &#8220;on display&#8221; on the desk, but are always in locked drawers\/cabinets when we are not around.<\/p>\n\n\n\n<p>Article 27<\/p>\n\n\n\n<p><strong>Clean screen policy<\/strong><\/p>\n\n\n\n<p>The Clean Screen Policy is another rule that we follow consistently in the company. We regularly close open databases when we no longer need them. Computers are locked whenever employees are not present. To provide additional protection, after a certain period of inactivity, a screen saver is activated, which is not only removed by moving the mouse, but also requires a real password that only the user has.    <\/p>\n\n\n\n<p>Article 28<\/p>\n\n\n\n<p><strong>Use of official electronic means<\/strong><\/p>\n\n\n\n<p>The storage of company data, trade secrets and, in particular, any personal data on company electronic devices is prohibited. Company electronic means may only be used for the processing of such data on the Company&#8217;s premises and on a shared protected local area network. <\/p>\n\n\n\n<p>If any corporate electronic device is lost, stolen or damaged, a personal data incident cannot occur as the device does not contain any data, nor does it have direct access to databases without a corresponding internal network, programs, unique usernames and passwords.<\/p>\n\n\n\n<p>Article 29<\/p>\n\n\n\n<p>External contractors &#8211; contract processors of personal data<\/p>\n\n\n\n<p>Outsourcers change over the years and are not permanent. At any given time, the Company will compile a list of all contractual processors of personal data, which will always be up to date. A list of current contract processors is attached to the Policy in  &nbsp;<strong>Annex 5.<\/strong><\/p>\n\n\n\n<p>We have a cooperation and personal data processing agreement with each of our external contractors, which sets out the procedures and measures to be taken to protect personal data in order to ensure the highest possible level of information security. It also defines the services or types of processing of personal data provided by each contractor. They may only ever act in accordance with our mandate and may not process or otherwise use the data for any other purpose. They must have at least the same level of protection of personal data as provided for in this Policy and the signed contract.    <\/p>\n\n\n\n<p>The same applies to external parties who maintain hardware and software and build or install new hardware or software.<\/p>\n\n\n\n<p>We follow the following policies when choosing a contract processor:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Careful choice of processor, in particular with regard to data protection,<\/li><li>a prior review and documentation of the security measures taken by the processor,<\/li><li>written instructions to the processor (contract),<\/li><li>the non-disclosure obligation of the processor&#8217;s employees,<\/li><li>the processor has established a Data Protection Officer,<\/li><li>ensuring the return\/destruction of data after termination of the contract,<\/li><li>a specific right of the controller to control the processor (checking the processor and its activities),<\/li><li>contractual penalties for infringements.<\/li><\/ul>\n\n\n\n<p><strong>XIII. RESPONSIBILITY FOR THE IMPLEMENTATION OF SECURITY MEASURES AND PROCEDURES <\/strong><\/p>\n\n\n\n<p>Article 30<\/p>\n\n\n\n<p>The implementation of the procedures and measures for the protection of personal data and of this Policy shall be the responsibility of the authorised persons designated by the legal representative.<\/p>\n\n\n\n<p class=\"has-text-align-left\"><strong>XIV. FINAL PROVISIONS <\/strong><\/p>\n\n\n\n<p>Article 31<\/p>\n\n\n\n<p>The Rules are a business secret.<\/p>\n\n\n\n<p>The Regulations are available to all staff in physical form from the Director.<\/p>\n\n\n\n<p>The Regulations shall enter into force on&nbsp;<strong>1 October 2020<\/strong>. The information shall be published in the employer&#8217;s usual manner. <\/p>\n\n\n\n<p>Ljubljana, 20 September, 2020 &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  Director Toma\u017e Ham<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On the basis of Articles 24 and 25 of the Personal Data Protection Act (ZVOP-1) and Regulation (EU) 2016\/679 of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation or GDPR), the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-19641","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.spinalis.com\/en\/wp-json\/wp\/v2\/pages\/19641","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.spinalis.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.spinalis.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.spinalis.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.spinalis.com\/en\/wp-json\/wp\/v2\/comments?post=19641"}],"version-history":[{"count":0,"href":"https:\/\/www.spinalis.com\/en\/wp-json\/wp\/v2\/pages\/19641\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.spinalis.com\/en\/wp-json\/wp\/v2\/media?parent=19641"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}