Date of issue of the Privacy Notice, August 20, 2019
Purpose of notification.
Caring for personal data and transparency in our work are the values on which we base our business. This Privacy Notice (Notice) is issued in order to comply with the new Law on Personal Data Protection.
We process your personal data so that you can register on mycase.hr and so that you can make a purchase through our Site (online shopping). The purpose of this notice is to acquaint you with the way My Case uses your personal information. It provides information on how we collect, use, store and otherwise process the personal information we need, so that you can make online purchases through the Site.
My Case supports the rights that the Law on Personal Data Protection provides. We are confident that this is a major step in securing your right so that you fully control your personal information as a registered member of the Site.
Personal data is any data that refers to an individual whose identity has been determined or is determinable. Personal data is any data about you that enables us identify you (e.g. name, surname, but also work status or e-mail address).
Processing is any action or set of actions performed with personal data or their collections (e.g. collection, storage, use, duplication, publication, deletion, or destruction).
This is the latest version of the Notice (January 20, 2020). If this Notice is amended or supplemented, we will enter the date of the latest version of the document. We will notify you in a timely manner of any change to the Notice.
In this Notice, “My Case”, “we” and “ours” refer to My Case Ltd, 36 Silvije Strahimir Kranjčević Street, 10000 Zagreb, Croatia. My Case determines the purpose and manner in which collects, uses and otherwise processes personal data.
Questions, complaints, requests for exercising your rights and additional information about the Privacy Notice and the protection of personal data at My Case can be obtained by sending an e-mail to firstname.lastname@example.org.
The person for the protection of personal data in My Case is the lawyer Maja Šutalo and her e-mail address is email@example.com
Types of personal data.
My Case offers products to individuals and legal entities through the Site, and in that sense we make a difference in terms of the type of personal data. In order to make your online purchases through the Site, we process the following types of personal data:
Personal identification data, such as name and surname;
Contact information, such as mobile phone number, address and e-mail address;
Transaction data, such as number and details of product orders through the Site.
Personal identification data, such as name and surname;
Business contact information, such as your business mobile phone number, business address, and business email address;
Information about the company you are employed in, such as its name;
Purpose of processing and legal basis for processing.
We process your personal data based on:
We process your personal data based on the consent you have given us in order to be periodically informed about news from our offer.
If you have given us consent to the processing, you can revoke it at any time. In case that you revoke your consent, we will stop further processing of your personal data and delete that personal data within a maximum of 90 days from the day you sent the revocation of consent. Revocation of consent is free and you can email it to firstname.lastname@example.org
In certain situations, our legitimate interest that Online shopping works in the most efficient way requires us to process your personal data (e.g. in order to maintain your user account).
Our legal obligations
We may process your personal data if required to do so by law.
Protection of your vital interests
We may also process your personal data if the processing is necessary in order to protect your vital interests.
If we process your personal data on the basis of our legal obligations or in order to protect your vital interests, we will inform you about it.
We use only those personal data that are necessary for a specific purpose and we always try to limit the processing of personal data in relation to what is necessary for that purpose. The purpose of processing your personal data is to register on the Site and make online purchases.
Legitimate interest of the operator
In order to achieve our business purpose, we process your personal data based on a legitimate interest. Of course, we do this only if your interest or your fundamental rights and freedom do not prevail over our legitimate interest. We use a legitimate interest to:
Maintain your user account, respond to your requests and possible complaints;
Protect our business and provide support to our colleagues;
Identify and prevent fraud and other illegal activities;
Test and develop new products and services to improve existing ones.
In order to preserve your safety, the safety of the premises / products and the safety of the business itself within My Case company, we use video surveillance in certain situations. We perform video surveillance based on legitimate interest. The recordings are kept for 7 days, after which they are deleted. Access to recordings is strictly limited to persons authorized by internal acts to do so.
You can make an objection to this type of processing of your personal data at any time by sending an e-mail to email@example.com. For more information about your rights, we refer you to the ‘Your Rights’ section below.
Recipients of personal data
Your personal data is shared internally within My Case, in order to achieve the purpose of your online purchase.
We may also share your personal data with the following recipients:
Subcontractors, external consultants, lawyers, accountants, commercial banks,
courier services, research and marketing agencies or printing offices;
IT service providers, such as cloud providers, hosting companies, customer support, chat services or software companies;
To a newly established entity or entity acquiring ownership of My Case, if My Case is involved in a merging, acquisition, purchase, sale of shares or other status change;
To any other recipient, if we are obligated by law or by court order;
To any other recipient when reasonably necessary, e.g. in case of danger to life.
All recipients are required to take appropriate technical, organizational and personnel measures to protect your personal information. My Case has signed personal data processing agreements with all recipients.
Transfer of personal data to other countries
The personal data we process about you are transferred to countries that are considered to have an appropriate level of personal data protection - members of the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, i.e. to countries determined by the European Union to provide appropriate level of protection. For example we send your personal data to Germany for storage.
Data retention period
My Case keeps your personal data as long as you have a profile on the Site. After the profile is deleted, the purpose of our processing of this data ceases and we delete it no later than 90 days from the date of termination when you requested the deletion of the profile.
If you have sent us a complaint in terms of the Consumer Protection Law, we keep your contact details as well as your complaint for two years from the date of receipt of the complaint, in order to fulfill the legal obligation to protect you as a consumer. We will delete your complaint and the relevant contact information no later than 90 days from the day when our obligation to keep data on that basis ended.
Security of personal data
My Case continuously takes appropriate security measures in order to protect your personal data in accordance with the Law on Personal Data Protection.
We implement appropriate physical, procedural, technical, organizational and personnel measures in order to achieve the appropriate level of protection of your personal data that we process. My Case applies the best industry standards in data protection. Protection refers to the loss, use against the purpose, unauthorized access and insight, alteration and destruction of such personal data. However, no security measure can guarantee that personal data will be 100% protected, but My Case at all times with its controlled processes and with high responsibility constantly improves all security measures in order to protect your personal data.
You may use certain rights under My Case in relation to the personal data we process about you in connection with your registration on the Site and online shopping. You can apply for these rights at any time.
You have the following rights:
Informing: the right to be informed about how we process your personal data (this right is fulfilled by making this Privacy Notice available);
Access: the right to request from us access to all your personal data that we process. If you submit the request electronically, the information shall be provided in the commonly used electronic form, unless you request otherwise;
Correction / amendment: the right to request to correct incorrect or incomplete personal data about you without delay. Please let us know if you change that personal information or if you learn that any personal information we hold is inaccurate or incomplete;
Deletion: the right to request to delete your personal data without delay (in compliance with the restrictions set by law);
Restriction: the right to request a restriction on the processing of your personal data in certain situations;
Transferability: the right to request the transfer of your personal data: The right to request us to transfer this data to another company, if the processing is based on consent or on the basis of a contract and the processing is done automatically;
Automated decision making: the right not to be subject to a decision made solely on the basis of automated processing, which may include profiling, if that decision produces legal consequences or that decision significantly affects your position;
Objection: the right to object to specific processing of personal data. This includes direct advertising, processing for scientific or historical research purposes or for statistical purposes.
You can exercise your rights in the following way: by sending an e-mail to firstname.lastname@example.org.
We will respond to your request as soon as possible, and no later than 30 days from the date of receipt of the request. In case of complexity or a large number of requests, we may need an additional deadline to respond to the request. This period cannot be longer than 90 days and we will inform you about it separately.
If your request is obviously unfounded or frequently repeated, we may reject it or charge you for it`s realization. It is considered to be a frequent recurrence when you contact us with a request to exercise any of the rights more than once in one year. If you contact us two or more times in one year for the same right, we will only respond to your request if you have a good reason.
If you believe that you have been denied any of the aforementioned rights or if you believe that we are processing your personal data in any way against the law, you may at any time file a complaint with the Commissioner for Personal Data Protection.
Possible consequences in case you fail to provide us with your personal data.
Providing your personal data is a necessary condition to register on the Site and to make an online purchase. If you do not provide us with the personal data we need, we will not be able to register your profile on the Site, nor will you be able to make an online purchase.