GDPR – Privacy policy of personal data processing

  • Home
  • GDPR – Privacy policy of personal data processing

SC TRIPLAST SRL processes the personal data of employees as well as candidates for positions within the company, customers and suppliers, by manual or automated means. In order to carry out this processing, SC TRIPLAST SRL, alone or together with other natural or legal persons, public authorities, agencies or other bodies, establishes the purposes and means of processing personal data. Considering these things, in accordance with RGPD, art. 4, par. (7), SC TRIPLAST SRL is the OPERATOR of personal data.

As a personal data operator, SC TRIPLAST SRL undertakes to protect and respect the confidentiality of personal data. This Privacy Policy is based on the legislative framework established by Regulation no. 2016/679 on the protection of personal data and their free movement, as well as the applicable national provisions, seeking to ensure compliance requirements by referring to the principles governing the protection of personal data.

 

Company contact details:

 

Name of the company (Operator): SC TRIPLAST S.R.L.
Registered office: Târgu Mureș, Str. Gh. Doja, no. 197, Mureș county, J26/198/2002; CUI 14516495

Company data: Registration number at the Trade Register J26/198/2002, tax code RO1451645,

Bank account RO40 BRDE 270S V049 3204 2700, opened at BRD-GSG

Web: www.triplast.ro
Email: dpo@ triplast.ro

 

1. PURPOSE

 

The purpose of this policy is to establish the necessary measures and the responsibilities of the employees of SC TRIPLAST SRL, to fulfill the obligations related to guaranteeing and protecting the fundamental rights and freedoms of natural persons, regarding the processing of personal data.

In addition to this Privacy Policy, please also read the “Cookie Policy”, to find out how www.triplast.ro uses cookies, but also the “Terms and Conditions” Section regarding the sales process for the site www.triplast.ro.

 

 

 

 

2. FIELD OF APPLICATION

 

This policy applies to the processing of personal data within the activities of SC TRIPLAST S.R.L., carried out to fulfill the company’s mission to produce material goods, to develop new solutions but also to continuously improve existing ones.

 

3. TERMS AND DEFINITIONS

 

Nr.crt. The term The definition and/or, if applicable, the act that defines the term
5. Personal data Means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more many specific elements, specific to his physical, physiological, genetic, psychological, economic, cultural or social identity;
6. Processing of personal data It means any operation or set of operations performed on personal data or sets of personal data, with or without the use of automated means, such as collection, recording, organization, structuring, storage, adaptation or modification, extraction, consultation , use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, deletion or destruction
7 Restriction of processing It means marking stored personal data in order to limit their future processing
8. Creating profiles It means any form of automatic processing of personal data that consists in the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects of work performance, economic situation, health , the personal preferences, interests, reliability, behavior, location or movements of that individual;
9. Pseudonymisation It means the processing of personal data in such a way that it can no longer be attributed to a specific data subject without the use of additional information, provided that this additional information is stored separately and subject to measures of a technical nature and organization that ensures the non-assignment of said personal data to an identified or identifiable natural person;
10. Data record system It means any structured set of personal data accessible according to specific criteria, whether centralized, decentralized or distributed according to functional or geographical criteria;
11. Operator It means the natural or legal person, public authority, agency or other body that, alone or together with others, determines the purposes and means of processing personal data; when the purposes and means of processing are established by Union law or domestic law, the operator or the specific criteria for its designation may be provided for in Union law or domestic law;
12. Person authorized by the operator It means the natural or legal person, public authority, agency or other body that processes personal data on behalf of the operator;
13. Consignee It means the natural or legal person, public authority, agency or other body to whom (to whom) personal data is disclosed, whether or not it is a third party.
14. Third part It means a natural or legal person, public authority, agency or body other than the data subject, the operator, the person authorized by the operator and the persons who, under the direct authority of the operator or the person authorized by the operator, are authorized to process personal data;
15. Consent Of the data subject means any manifestation of free, specific, informed and unambiguous will of the data subject by which he accepts, through a statement or an unequivocal action, that the personal data concerning him be processed;
16. Breach of personal data security Means a breach of security that results, accidentally or unlawfully, in the destruction, loss, alteration, or unauthorized disclosure of, or unauthorized access to, personal data transmitted, stored, or otherwise processed
17. Genetic date Means personal data relating to the inherited or acquired genetic characteristics of a natural person, which provides unique information regarding the physiology or health of that person and which results in particular from an analysis of a sample of biological material collected from the person concerned;
18. Biometric data Means personal data resulting from specific processing techniques relating to the physical, physiological or behavioral characteristics of a natural person that allow or confirm the unique identification of that person, such as facial images or dactyloscopic data;
19. Health data Means personal data relating to the physical or mental health of an individual, including the provision of healthcare services, which discloses information about the individual’s health;

 

 

4

. REFERENCE DOCUMENTS

 

Regulation (EU) 679/2016 (“GDPR”), on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
Law no. 190 of July 18, 2018 on measures to implement Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation).
Law no. 682 of November 28, 2001 on the ratification of the Convention for the protection of individuals against automated processing of personal data, adopted in Strasbourg on January 28, 1981
Law no. 506 of November 17, 2004 regarding the processing of personal data and the protection of private life in the electronic communications sector
LAW no. 363 of December 28, 2018 regarding the protection of natural persons regarding the processing of personal data by the competent authorities for the purpose of prevention, discovery, investigation, prosecution and combating of crimes or the execution of punishments, educational and safety measures, as well as regarding the free movement of these data
Law no. 365/2002 regarding electronic commerce;
Methodological rules of November 20, 2002 for the application of Law no. 365/2002 regarding electronic commerce
Decision of the National Supervisory Authority for the Processing of Personal Data no. 99 of May 18, 2018 regarding the termination of the applicability of some normative acts of an administrative nature issued in application of Law no. 677/2001 for the protection of individuals regarding the processing of personal data and the free movement of such data.
Other decisions of the president of the National Authority for the Supervision of the Processing of Personal Data

 

 

 

 

5. SPECIFICATIONS:

 

5.1. GENERAL RULES

 

Minimum security requirements mean a complex of technical, IT, organizational, logistical measures, procedures and security policies to ensure the minimum level of security provided for in Regulation (EU) 2016/679 (hereinafter referred to as “Regulation”), in accordance with the minimum security requirements for the processing of personal data.

 

TRIPLAST has adopted adequate technical and organizational measures to protect personal data against accidental or illegal destruction, loss, modification, disclosure or unauthorized access. In this sense, at the TRIPLAST level, persons responsible for complying with the provisions of the Regulation were appointed.

 

TRIPLAST has taken measures to safely store information regarding personal data, so that an adequate level of protection and security is ensured, in the sense of the Regulation.

 

In order to fulfill the related legal provisions and in order to satisfy the requirements for the safe keeping of data and information, the institution has developed and implemented organizational and technical measures oriented towards certain directions of action:

– User identification and authentication

– Type of access

–             Data collection

–             Execution of safety copies

– Computers and access terminals

– Staff training

5.2. SPECIFIC PROCEDURES

 

5.2.1 User identification and authentication

 

To have access to personal data, users must log in to TRIPLAST’s IT systems. Authentication within the computer systems is done by entering the unique and non-transmissible authentication credentials obtained following the process of enrollment and electronic identity management, governed by the security policies in force.

 

Each user has his own identification code (username). The same identification code is never assigned to several users and it cannot be shared by several people.

 

Identification codes (or user accounts) unused for a longer period are deactivated and destroyed after a prior check. The period after which the codes must be deactivated and destroyed is established by the company’s internal policies.

 

Any user account is accompanied by an authentication method, by entering an authentication key, respectively a password.

 

Passwords are strings of characters, suitable from the point of view of security in terms of length and composition. When entering passwords, they are not clearly displayed on the monitor. Passwords are changed periodically according to TRIPLAST’s internal policies. The periodic change of passwords is done only by authorized users.

 

Any user who receives an identification code and a means of authentication is obliged by the job description to keep their confidentiality and to answer in this regard to the operator.

 

An own procedure for the administration and management of user accounts is established. The persons within the NETALL SRL company as IT administrators are authorized to revoke or suspend an identification and authentication code, if their user resigned or was fired, concluded his contract, was transferred to another service and the new tasks do not require access to personal data, he abused the received codes or if he will be absent for a long period established by the entity.

 

5.2.2. Access type

 

Users must access only the personal data necessary to fulfill their job duties. For this, the types of access must be established according to functionality (administration, input, processing, saving, etc.) and according to actions applied to personal data (writing, reading, deleting), as well as the procedures regarding these types of access.

 

NETALL, which provides technical support, may have access to personal data to resolve incidents and problems arising in the use of IT systems.

 

Other specific measures implemented for access control are:

– anti-burglary alarm systems are installed in the spaces intended for carrying out the institution’s activity;

– in the space related to the entrance to the institution’s perimeter, in the area of ​​the production hall and parking lots, video surveillance systems are installed;

– monitoring and intervention in case of alarm is provided by a protection and security company;

 

5.2.3. Data collection

 

TRIPLAST designates authorized users for the operations of collecting and entering personal data into the information systems.

 

Any modification of personal data is performed only by designated authorized users.

 

5.2.4. The execution of safety children

 

The backup copies of the databases containing personal data, as well as of the programs used for automated processing are carried out once a day, outside the daily work schedule, the period being preset by NETALL, automatically, through an IT system of the type Automatic Back-Up, system maintained by NETALL, responsible for the security of IT systems.

 

The backup copies are stored in a server with restricted access, located in a room monitored by video and protected by the company’s anti-burglary system.

 

The systems that manage personal data are protected by the periodic backup process against the loss or destruction of the data or the computer system.

 

5.2.5. Computers and access terminals

 

The computers and other personal data access terminals located in the TRIPLAST headquarters are installed in rooms with restricted access. At the same time, the luru stations are installed in rooms that can be locked and/or are video monitored.

 

If personal data appear on the screen and are not acted upon for a given period, established by the management (usually 2 minutes), the work session will be closed.

 

The access terminals used in the relationship with the public, on which personal data appear, are positioned so that they cannot be seen by the public even after a short period, established by TRIPLAST (usually 2 minutes), in which no action is taken on them, they will be hidden or the working session will be closed.

 

Servers hosting personal data can only be accessed in a controlled manner, based on access rights, according to TRIPLAST’s security policies;

 

It is not allowed to remove from the institution mobile storage media (CD/DVD, USB Stick, Portable HDD) that contain personal data, except with prior approval from the institution’s management.

 

5.2.6. Telecommunications systems

 

TRIPLAST periodically reviews the user accounts and the privileges granted in order to detect dysfunctional information systems.

 

Informational systems are designed so that personal data cannot be intercepted or transmitted from any location.

 

Through telecommunications systems, personal data are transmitted through a secure channel.

 

5.2.7. Staff training

 

TRIPLAST staff is informed about the provisions of the Regulation for the protection of individuals regarding the processing of personal data and the free movement of such data, about the minimum security requirements for the processing of personal data, as well as about the risks involved processing of personal data.

 

Users who have access to personal data are trained on their confidentiality. Users are obliged to close their work session when they leave the workplace.

 

 

 

5.2.8. Use of computers

 

In order to maintain the security of personal data processing (especially against computer viruses), measures are taken regarding:

– prohibiting the use by users of software programs that come from unverified sources;

– informing users about the danger of computer viruses;

– the implementation of automatic anti-virus and malware protection systems and computer system security;

 

5.2.9. Data printing

 

Printing of personal data will only be done by users authorized by TRIPLAST for this operation.

 

5.2.10. Manual processing of personal data

 

Documents containing personal data are kept in files or cabinets locked with a key or another security mechanism. Documents containing personal data, used to carry out certain operations, will be handed over to authorized persons or will be closed immediately after their completion.

 

5.3. The principles underlying the processing of personal data

 

The processing of personal data is carried out in compliance with legal requirements and under conditions that ensure security, confidentiality and respect for the rights of the persons concerned.

 

The processing of personal data is done in compliance with the following principles:

 

Legality: The processing of personal data is done based on and in accordance with the legal provisions;
Well-defined purpose: Any processing of personal data is done for well-defined, explicit and legitimate purposes, adequate, pertinent and not excessive in relation to the purpose for which they are collected and subsequently processed;
Confidentiality: The persons who process, on behalf of TRIPLAST, personal data have provided in the job description, annex to the individual employment contract, a confidentiality clause;
Consent of the person concerned: Any processing of personal data, with the exception of processing that concerns data from the categories strictly mentioned in the Regulation, can only be carried out if the person concerned has given his express and unequivocal consent for that processing;
Information: The persons concerned are aware of the fact that their personal data will be processed;
Protection of data subjects: The rights of data subjects are presented in point 5.6.
Security: Personal data security measures are established in such a way as to ensure an adequate level of security of processed personal data.

 

5.4. The processing of personal data having an identification function of general applicability, including their disclosure to third parties, is done only under the following conditions:

a) the person concerned has expressly given his consent; or
b) the processing is expressly stipulated by a legal provision; or
c) in other cases, with the approval of the National Authority for the Supervision of the Processing of Personal Data and only on the condition of the establishment of adequate guarantees for the respect of the rights of the persons concerned.

 

TRIPLAST respects the principle of appropriateness, relevance and non-excessive character, as well as the confidentiality and security measures of processing. In the case provided for in point c) above, the following aspects are taken into account:

  • the purpose of processing must be determined, explicit and legitimate;
  • the establishment and application of measures to ensure the exercise of the rights of the persons concerned;
  • the duration of data storage should be for the period strictly necessary to fulfill the purpose, after which the data will be deleted or destroyed, as the case may be;
  • establishing the means of access to the record systems in order to collect data, according to which appropriate technical and organizational measures for data protection will be established and respected;
  • use of data only within the limits of the established purpose;
  • disclosure to other recipients is prohibited, with the exception of the situation in which there is the consent of the person concerned or an express legal provision;
  • the designation, in writing, of the person/persons who will/will process the data and who must assume responsibility for maintaining their confidentiality, the list containing the record of these persons being updated whenever necessary;
  • the appointment, in writing, of a person specialized in information security to oversee data processing, including the proper functioning of the IT systems used in this activity;
  • establishing an information security plan that includes, mainly, technical IT security and the security of the spaces where the data is processed, taking into account the minimum security requirements;
  • establishing, in writing, the rights and obligations of the operator who transmits the data and of the operator who receives them.

 

The collection and processing of personal data having an identification function of general applicability, including their disclosure, by making and retaining copies of the identity card or of the documents that contain them, are prohibited, with the exception of the situations provided for in points a) , b) and c) above.

 

5.5. Processing of personal data through the use of video surveillance systems

 

The processing of personal data through the use of video surveillance systems is carried out in compliance with the general rules provided by the Regulation, with subsequent modifications and additions.

Video surveillance cameras are mounted in visible places.

 

The processing of personal data by means of video surveillance is done for the realization of legitimate interests, without prejudice to the fundamental rights and freedoms or the interest of the persons concerned. It is not allowed to process employees’ personal data by means of video surveillance inside the premises/offices where they carry out their work, with the exception of the situations expressly provided by law or the ANSPDCP notice.

 

TRIPLAST, as an operator that processes personal data through means of video surveillance, is obliged to provide the information provided by the Regulation, with subsequent changes and additions, including regarding:

a) the existence of the video surveillance system and the purpose of data processing by such means;
b) identity of the operator;
c) the existence of the registration of the images and the categories of their recipients;
d) the rights of the persons concerned and the manner of their exercise.

The information mentioned above must be brought to the attention of the persons concerned, clearly and permanently.

The existence of the video surveillance system is signaled by means of an icon that contains a representative image with sufficient visibility and positioned at a reasonable distance from the places where the video surveillance equipment is located.

 

The processing of personal data by means of video surveillance can only be carried out by persons authorized by TRIPLAST (its own staff or persons authorized by the operator), trained in the legislation relating to the protection of personal data and obliged to obey it.

 

The duration of storage of the data obtained through the video surveillance system is proportional to the purpose for which the data is processed, but no longer than 30 days, with the exception of situations expressly regulated by law or thoroughly justified cases.

 

At the expiration of the established term, the recordings are destroyed or deleted, as the case may be, depending on the medium on which they were stored.

 

5.6. The rights of the persons whose personal data are collected and/or processed

 

5.6.1. The right to be informed

 

(1) If the personal data are obtained directly from the data subject, TRIPLAST is obliged to provide the data subject with at least the following information, except for the case where this person already possesses the respective information:

 

a) the purpose for which the data is processed;
b) additional information, such as: recipients or categories of data recipients; if providing all the requested data is mandatory and the consequences of refusing to provide them;
c) the existence of the rights provided by law for the data subject, in particular the right of access, intervention on data and opposition, as well as the conditions under which they can be exercised;
d) any other information, the provision of which is imposed by the order of the supervisory authority, taking into account the specifics of the processing.

 

(2) The Privacy Policy is posted on the TRIPLAST website (www.TRIPLAST.ro);

 

(3) Before completing the personal data, the consent of the concerned persons is requested for their processing;

 

(4) The registration number of the notification communicated by the National Supervisory Authority is mentioned in any document through which personal data is collected, stored or disclosed;

 

(5) Buildings that are monitored by video will have, at the entrance, displayed in a visible place, the information regarding the retrieval and storage of images.

 

5.6.2. Right of access to data

 

Any data subject has the right to obtain from TRIPLAST (as operator), upon request and free of charge, confirmation of the fact that the data concerning him or her are or are not being processed by him.

 

TRIPLAST is obliged, in the situation where it processes personal data concerning the applicant, to communicate to him, together with the confirmation, at least the following:

a) information regarding the purposes of the processing, the categories of data considered and the recipients or categories of recipients to whom the data is disclosed;
b) communicating in an intelligible form the data that are the subject of processing, as well as any available information regarding the origin of the data;
c) information on the principles of operation of the mechanism through which any automatic data processing is carried out that targets the respective person;
d) information regarding the existence of the right of intervention on the data and the right of opposition, as well as the conditions under which they can be exercised;
e) information on the possibility to submit a complaint to the supervisory authority, as well as to address the court to challenge the operator’s decisions, in accordance with the provisions of the law.

 

Nota:

(1) Persoana vizata poate solicita de la TRIPLAST informatiile prevazute de lege, printr-o cerere intocmita in forma scrisa, semnata si inregistrata la registratura companiei. In cerere solicitantul poate arata daca doreste ca informatiile sa ii fie comunicate la o anumita adresa, care poate fi si de posta electronica, sau printr-un serviciu de corespondenta care sa asigure ca predarea i se va face numai personal.

(2) TRIPLAST este obligat sa comunice informatiile solicitate, in termen de 15 zile de la data primirii cererii, cu respectarea eventualei optiuni a solicitantului.

 

5.6.3. The right to intervene on the data

 

Any data subject has the right to obtain from the operator, upon request and free of charge:

a) as the case may be, rectifying, updating, blocking or deleting data whose processing is not in accordance with the law, especially incomplete or inaccurate data;
b) as the case may be, the transformation into anonymous data of data whose processing is not in accordance with the law.

 

5.6.4. The right of opposition

 

The data subject has the right to object at any time, for well-grounded and legitimate reasons related to his particular situation, to the processing of his data, with the exception of cases where there are legal provisions to the contrary. In case of justified opposition, the processing can no longer concern the data in question.

 

5.6.5. The right not to be subject to an individual decision

 

(1) Any person has the right to request and obtain the withdrawal/cancellation/reevaluation of any decision that produces legal effects regarding him, adopted exclusively on the basis of a processing of personal data, carried out by automatic means, intended to evaluate some aspects of his personality, such as professional competence, credibility, behavior or other similar aspects.

 

(2) Respecting the other guarantees provided by law, a person may be subject to a decision of the nature referred to in paragraph (1), only in the following situations:

a) the decision is taken within the framework of the conclusion or execution of a contract, provided that the request for the conclusion or execution of the contract, introduced by the person concerned, has been satisfied or that some appropriate measures, such as the possibility to support his point of view , to guarantee the defense of its own legitimate interest;
b) the decision is authorized by a law that specifies the measures that guarantee the protection of the legitimate interest of the person concerned.

 

5.6.6. The right to go to justice

 

(1) Without prejudice to the possibility to complain to the supervisory authority, the persons concerned have the right to go to justice for the defense of any rights guaranteed by the law, which have been violated.

(2) Any person who has suffered damage as a result of an illegal processing of personal data, may apply to the competent court for its reparation.

 

5.7. Communication of personal data

 

(1) Personal data can be communicated between TRIPLAST and its proxies or between TRIPLAST or its proxies and other institutions or public bodies or entities under public or private law in one of the following situations:

a) if the person concerned has given his express and unequivocal consent for the communication of his data;
b) without the consent of the person concerned in the cases provided by law.

 

(2) Communication of personal data in the situations provided for in para. (1) can be done if one of the following conditions is met:

a) the communication is carried out on the basis of a contract or, as the case may be, a cooperation document which must include at least: the registration number of the notification, the legal basis of the processing and its purpose, the maximum term of processing, the rights and obligations of the parties, the methods of ensuring the security of processing and respecting the rights of the data subject, as well as the mention that the data can only be used by the beneficiary structure and only for the purpose for which they were requested;
b) the communication is carried out based on a written request, which must include the legal basis, the purpose of the processing and the requested data, as well as, if applicable, the number assigned to the beneficiary by the National Supervisory Authority.

 

(3) Communication of personal data can also be done online, in compliance with the provisions of para. (1) and (2) and ensuring the security of personal data communication systems.

 

(4) The personal data on which the data subjects exercised and were recognized the right of opposition cannot be the subject of processing.

 

(5) Requests for the communication of personal data addressed to TRIPLAST must contain the applicant’s identification data, as well as the motivation and purpose of the request, according to the legal provisions.

 

(6) Applications that do not contain these elements are returned for completion, and those that do not meet the conditions provided by law are rejected, mentioning the reasons why the communication of personal data is not possible.

 

(7) Before communicating personal data, TRIPLAST checks whether they are accurate and, if necessary, updated.

 

(8) In the event that it is found that incorrect or out-of-date data has been transmitted, TRIPLAST has the obligation to inform the recipients of the respective data about their non-conformity, mentioning the data that have been modified.

 

(9) When communicating personal data, TRIPLAST warns the recipients about the prohibition to process the data for purposes other than those specified in the communication request.

 

5.8. Technical measures regarding the processing of personal data

 

All documents containing personal data are registered and follow the rules of preservation, processing, multiplication, transport, transmission, destruction and archiving established by the National Archives Law and by internal procedures.

 

Note 1: This document is completed with the entire set of security policies/procedures approved by TRIPLAST management and in force.

Note 2: The list of personal data, their registration, processing, storage and disclosure mechanism are presented in the Annexes to this document.

No products in the cart.