PRIVACY NOTICE ON THE PROCESSING OF PERSONAL DATA AND YOUR RIGHTS

under Art. 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC

(the “GDPR“)

In case you are providing your personal data, we as a data controller:

Spaceflow s.r.o., with its registered seat at: Pernerova 676/51, Karlín, 186 00 Praha 8, ID: 05184142, registered by the Commercial Register maintained by the Municipal Court in Prague, File No. C 259630,

would like to inform you about the processing of your personal data and of your rights related to the said processing.

All terms used in Terms of use of the Application [“Terms“; https://spaceflow.io/en/terms], starting with a capital letter, have the same meaning here, in this Privacy notice. For cookies we use a cookie policy on our web pages which pops up.

What are our purpose and legitimate interests for the processing of your personal data?

  1. Selection of potential employees and talents.
  2. Mutual communication.
  3. Promotion of our events and our products.
  4. Targeted communication in social media and product promotion.
  5. Targeted communication through our website and product promotion.
  6. Cooperation with our business partners.

Description of our purpose and legitimate interests:

  1. In case of vacant position at Spaceflow, we look for the best fit to fill this vacancy. When doing that, we collect the CVs from the applicants directly or from the third persons recommending the potential applicant. After reviewing the CVs of the applicants, we invite them for personal interviews after which we send the follow-up information. In case there is no vacant position at the time or if the applicant has not been successful at the particular job opening, we may, upon consent, store the CVs of these persons to contact them in the future regarding the job opening.
  2. Our philosophy is to be open and transparent at all times. This includes being open to communication from any person interested in Spaceflow and the Application. Additionally, we have also published email, so you can contact them at any time with any question related to our Application and business you may have. However, to ensure such effective, flawless and clear communication, we process some of your personal data (including unstructured personal information – contained in email correspondence). If you send us your personal data based on a web-form on our pages, the processing is wider, therefore based on a consent.
  3. Furthermore, we may process your personal data by taking the photographs and audio-visual recordings, name and surname, email contact which are used for the purpose and legitimate interests of promotion of our events and services (e.g. via our newsletter), and product news with respect to the Application and to help us improve our brand and goodwill by providing you with our newsletters and follow-up marketing materials related to our events and publishing the photographs (where you can appear) and audio-visual recordings on our social media profiles such as LinkedIn and Facebook and via other channels such as our website. In a case you subscribed to our newsletter and you are not our current/past customer, we send you our marketing materials under consent granted by you.
  4. We may also use social media marketing tools such as LinkedIn to process your personal data that you voluntarily submit to us, to the extent: name, surname, position in the company, email contact, for the purpose of promoting under C. or for further contact to support the sale of our products.
  5. In order to develop our business, we are looking for new prospective clients, in order to do so – in addition to the points above, our website also uses a third-party services (such as LeadFeeder) to identify potential business partners and collect contact personal data to promote the sale of our products.
  6. If we cooperate with you as our business partner, we need both your personal information to enter into an agreement with you and be with you in functional business relationship. These personal data will appear on a particular contract and may appear on tax documents, invoices, business cards, in an unstructured form in email (internal) communication and in our CRM systems.

What is our legal basis for the processing of your personal data?

  1. If you send us your CV regarding the specific vacant position, we process your personal data on the basis of the performance of a contractual relationship and your request prior to entering into a contract under Article 6 (1) (b) of GDPR (in case of failure to provide us with the personal data, we cannot enter into a contract with you). If you want us to keep your CV after the recruitment process or without applying for any particular position, we process your personal data on the basis of a consent under Article 6 (1) (a) of GDPR.
  2. If you contact us or any particular employee via email, we process your personal data with respect to such reply on the basis of legitimate interests under Article 6 (1) (f) of GDPR. If you contact us through web-form on our webpage, we process your personal data for purposes of reply and further sending marketing material on a basis of a consent under Article 6 (1) (a) of GDPR.
  3. In case of promoting our events and services provided by us, we process your personal data on the basis of the legitimate interests under Article 6 (1) (f) of GDPR and non-customers based on consent under Article  6 (1) a of the GDPR.
  4. In case you send us a filled form with your personal data, we process your personal data on the basis of the legitimate interests under Article 6 (1) (f) of GDPR.
  5. In the case you visit our website, we process your personal data on the basis of the legitimate interests under Article 6 (1) (f) of GDPR.
  6. In case of contractual relationship and your request prior to entering into a contract, we process your personal data on the basis of under Article 6 (1) (b) of GDPR (in case of failure to provide us with your personal data, we cannot enter into a contract with you).

What kind of personal data do we process?

  1. Personal data included in the CV (such as name, surname, date of birth, address, email, phone number etc.).
  2. Name, surname, email address and phone number, in case of a web-form it is: email, name, surname, phone number, location.
  3. Name, surname, email address, photograph or/and audio-visual image of yourself.
  4. Name, surname, email address, firm position, business name containing personal name.
  5. Name, surname, email address, address, details of activities related to a natural person, and web analytics.
  6. Name, middle name, surname, ID No., Tax ID No., registered office, email address and phone number, business name containing your personal name, job title, source of the contact, business category and market.

How long do we store your personal data?

  1. In case of applying for particular vacant position, we store your personal data until the end of the recruitment process. If you give us your consent to store your CV for future vacant positions, we store it for 3 years.
  2. If you contact us or any employee via email, we store your personal data until you unsubscribe from our contact database, or in case you sent us your personal data through the web-form until you withdraw the granted consent.
  3. We store your personal data during the time strictly necessary to achieve the given purpose and for non-customers based on consent for 10 years.
  4. We store your personal data during the time strictly necessary to achieve the given purpose.
  5. We store your personal data during the time strictly necessary to achieve the given purpose.
  6. We store your personal data for the duration of the contractual relationship and till lapse of tax duty period and time limitation period for defending claims.

As soon as we no longer need your personal data for the processing purposes for which the personal data have been collected, we will delete them unless the statute-barred period applies. Certain details and correspondence may be retained until the time limit for claims, in respect of the pre-contractual or contractual relationship, has expired or in order to comply with regulatory requirements regarding the retention of such personal data.

With whom do we share your personal data?

For a certain reason, we might provide your personal data to personal data recipients, to perform part of our activities through them (meant outsourced activities). Within our business, we use the following categories of personal data recipients:

Google Ireland Limited (Cloud Service Provider, providing platform as services e.g. environment, computing capabilities, for more information see: https://cloud.google.com/terms/), the App runs on the Google Cloud Platform and (E-mailing services out of the App and cloud-storage services, e-mailing services for us), service provider terms are listed here [https://policies.google.com/privacy?hl=en].

Message Systems, Inc. d/b/a SparkPost, Delaware, US, (E-mail service – Sparkpost, sending the email from the Application), for more information see: [https://www.sparkpost.com/policies/DPA/] (the Application uses API of the Sparkpost to send: 1) Addressing, message, 2) email address of the addressee 3) content of email. Message Systems, Inc. d/b/a SparkPost is certified under the EU-U.S. Privacy Shield Framework.

The Rocket Science Group, LLC, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308 USA (Email service Mailchimp, sending from and out of the Application), contractor who provides us with e-mailing services related to the newsletter); service provider terms are listed here [https://mailchimp.com/legal/forms/data-processing-agreement/].

We also may be obliged to provide your personal data to public authorities, in particular courts and law enforcement agencies (police and prosecutors) only to the extent necessary and within the limits of the law.

From whom do we get the personal data?

We get personal data from you and in order not to be so vague in explanation, by “you” we mean:

  1. Job applicants for a position with us.
  2. Interviewers and potential business partners.
  3. Participants in events we organize or participate in.
  4. Leads and business partners.
  5. Visitors to our website.
  6. Potential and current business partners or customers and contractors.

Do we use automated individual decision-making?

No, we do not use automated individual decision-making.

Do we transfer your personal data to third countries?

Your personal data are processed within the territory of the Czech Republic and other states of the European Union. Your personal data can be processed by a country outside of European Union if this third country has been confirmed by the European Commission as a country with an adequate level of data protection or if other appropriate data protection safeguards exist (for example, binding corporate privacy rules or EU standard data protection clauses).

Other information:

Personal data may also, in justified cases, be subject to use (processing) for the purpose of dealing with legal matters, including the performance of public authority obligations and monitoring for possible legal protection. Personal data may also be archived for a given public interest, as well as for scientific, historical or statistical research.

What are your rights?

Your rights as a data subject are stated below. Please note that the exact conditions to exercise these rights are set out in detail in Chapter III of GDPR, while in a particular circumstance not all rights may be exercised. You have the following rights:

How can you exercise your rights?

Spaceflow s.r.o., registered seat at: Pernerova 676/51, Karlín, 186 00 Praha 8, or

Electronically: hello@spaceflow.cz

We strive to protect your privacy as much as possible and therefore we process your personal data in compliance with GDPR and all other relevant laws. However, if you disagree with the way we handle your personal data, you can exercise your rights via our Data Protection Officer at:

Data Protection Officer’s contact: 

JUDr. Theodor Klán, attorney-at-law

Seat at: Nuselská 419/92, 140 00 Praha 4,

E-mail: dpo@spaceflow.cz

or you can file a complaint in supervising authority regarding the processing of your personal data. Your local supervisory authority may be found at: https://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm