PERSONAL DATA PROTECTION STATEMENT – PRIVACY POLICY
1. Introduction
RTC Krvavec places special emphasis on the security of your personal data. All provided personal data are treated confidentially and are used only for the purpose for which they were obtained or provided. We manage your personal data with the utmost care, considering the applicable legislation and the highest standards of their treatment. Among other things, we ensure the security of your personal data with appropriate organizational measures, work procedures, and advanced technological solutions, as well as external experts, in order to protect your personal data as effectively as possible. In this, we use an appropriate level of protection and reasonable physical, electronic, and administrative measures to protect the collected data from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of personal data, or unauthorized access to personal data that have been transferred, stored, or otherwise processed.
This personal data protection statement defines how RTC Krvavec processes your personal data, which you provide us directly or indirectly, or which we obtain via our website, and about the rights you have in connection with the processing of personal data. This privacy statement was last changed in September 2018. We may occasionally amend this privacy statement, along with past versions, and publish it on our website.
In the Personal Data Protection Statement, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: "General GDPR Regulation"), we include the following information:
- contact information of the personal data controller,
- purposes, bases, and types of processing of various personal data,
- retention period of individual types of personal data,
- rights of individuals in relation to the processing of personal data,
- the right to lodge a complaint in connection with the processing of personal data,
- validity of the personal data protection statement.
2. Basic information about the controller – RTC Krvavec
Company name: Recreational Tourist Center Krvavec, d.d.
Company headquarters: Grad 76, 4207 Cerklje na Gorenjskem
Short name: RTC Krvavec, d.d.
Company registration number: 5097517
Company tax number: 75861127
Activity code: 49.392 Operation of cableways
Registration: District Court in Kranj, file number 10006000, dated 30.06.1977
Business accounts:
BANKA INTESA SANPAOLO d.d.: IBAN SI56 1010 0005 6446 235, SWIFT (BIC code) BAKOSI2X
SKB BANKA: IBAN SI56 0310 0100 3548 229, SWIFT (BIC code) SKBASI2X
SAVINGS BANK LON: IBAN SI56 6000 0000 0136 065, SWIFT (BIC code) HLONSI22
Company's capital: 9,343,123 EUR
Number of shares 1,119,493
Ownership structure: Alpine Investment Company d.o.o. 98.56%
Minor shareholders: 1.44%
Legal representative: Janez Janša
Chairman of the Supervisory Board: Aleš Vehar
3. The personal data we process
What is personal data?
Personal data is any data related to a specific or identifiable individual, such as: name and surname, home address, location (phone can emit location), web identifier (IP address), email address, phone number, etc.
What does the processing of personal data mean and when can personal data be processed?
Processing of personal data means any action or set of actions performed in relation to personal data or sets of personal data, whether automated or not, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Personal data can only be processed if specified by law or if there is an appropriate legal basis. We process personal data of individuals who use or have used RTC Krvavec services, as well as personal data of visitors to our websites and visitors to RTC Krvavec social networks.
Among other things, we process the following personal data about an individual:
- identification data of the individual (name, surname, address, temporary address, email address, date of birth, tax number, mobile phone number, your photograph, credit card number).
Users of the RTC Krvavec website may always voluntarily decide whether they will contact us via the web form and which potential free interactive tools they will use on the website. When using free interactive tools, users cannot be identified. Individuals can also send electronic messages to the email addresses published on our website. In this case, you voluntarily decide which personal data you want to entrust to us.
Upon each visit to the websites managed by RTC Krvavec, a server log file is automatically stored on the web server (e.g., IP address - a number that identifies an individual computer or other device on the Internet; browser version, visited subpage, time and duration of visit, page from which the file was requested, date and time of request, time spent on the website, amount of data transferred, access status - whether the file was downloaded or not found, etc.). The contractual processor (provider of web server hosting) processes personal data only for the purpose of providing website maintenance services at the company's website address.
As part of these website purposes, cookies are used, the nature of which is further explained in the Cookie Usage Policy on the website. This data is processed for the purpose of keeping statistics of visits to our website, improving the operation of websites, and ensuring the security of information systems.
RTC Krvavec communicates with individuals and the general public via digital social networks Facebook, Twitter, Youtube, making it important for individuals to also familiarize themselves with the rules of these networks or their privacy policies and privacy settings.
When accessing a Facebook account or RTC Krvavec's web services via digital social networks or connecting to the service via a digital social network, data about you may also include user identification and/or username associated with a particular digital social network, all data or content that you allow the digital social network to share with us, such as displayed photos, email address, or list of friends, and all data you have publicly posted regarding a particular social network.
More detailed information on the purposes and scope of processing personal data by providers of digital content can be obtained directly from the providers of these services, administrators of these social digital networks, or directly within these digital social networks. RTC Krvavec assumes no responsibility for the protection of your personal data within the aforementioned social networks, web services, and all associated websites.
In the context of scientific research, additional personal data may be processed in addition to the above for each research or study. The type and scope of personal data may vary in these cases; additional information on this will accompany the relevant research or study.
4. For what purposes do we process your personal data?
Krvavec is considered one of the best maintained and most visited ski resorts in Slovenia. With a forward-looking perspective, we will remain and become attractive both in winter and summer to domestic and foreign guests, individuals, and families by investing in new additional offer programs and investing in new employee knowledge. Our goal is to become the most developed ski center in Slovenia, comparable to similar centers in Europe.
Personal data of individuals are processed for the following purposes:
- operation of the RTC Krvavec company;
- information regarding the implementation of programs and activities, informing about benefits and novelties;
- for the preparation and dissemination of publications;
- information on current events and sending newsletters, invitations to participate, information on competitions;
- sampling, surveying, statistical and market analysis;
- user segmentation.
Personal data obtained from visitors to our websites are processed for the following purposes:
- for the preparation of statistical data about users,
- promoting security and improving our websites,
- to improve our services.
RTC Krvavec also processes personal data to fulfill legal obligations.
5. What is the legal basis for processing personal data?
In order to process your personal data, there must be a legal basis for it, as specified in the General Data Protection Regulation (GDPR). Processing is lawful only if at least one of the following conditions is met:
- the individual to whom the personal data relates has consented to the processing of his or her personal data for one or more specific purposes;
- processing is necessary for the performance of a contract to which the individual to whom the personal data relates is party or in order to take steps at the request of such individual prior to entering into a contract;
- processing is necessary for compliance with a legal obligation to which the controller is subject;
- processing is necessary to protect the vital interests of the individual to whom the personal data relates or of another natural person;
- processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the individual to whom the personal data relates, which require protection of personal data, in particular where the individual is a child.
In the company RTC Krvavec, the legal basis depends on the type of personal data, whether it is processed to perform a contract or legal relationship, processed to fulfill a legal obligation, processed for the purposes of legitimate interests, or processed based on your consent.
a. Processing to perform a contract or legal relationship
Within the framework of executing contractual and legal rights and obligations of the company RTC Krvavec towards individuals.
b. Processing to fulfill legal obligations:
We must process certain data about individuals based on legislation, such as the Occupational Health and Safety Act, the Act on the Protection of Documented and Archival Material and Archives, etc.
c. Processing for the purposes of legitimate interests:
Due to the balance of interests, we may process your personal data for the purpose of protecting our legitimate interests or those of third parties. In any case, data processing is carried out for the protection of legitimate interests in the following cases:
- measures for managing and further developing our services and products;
- maintaining records of users' personal data to improve services for all users;
- measures to protect against unlawful conduct;
- within legal proceedings.
This means that your data is processed for purposes such as the following:
- providing, maintaining, and improving our services for user needs,
- developing new services useful for visitors,
- understanding how individual service users use our services to ensure and improve the efficiency of our services,
- customizing our services to provide visitors with a better user experience,
- informing about events, news, and other activities of RTC Krvavec,
- providing advertising so that some of our services are also available for free,
- detecting, preventing, or otherwise addressing fraud, abuse, and security or technical issues in our services,
- conducting research that improves our services for visitors and benefits the wider public,
- fulfilling obligations to our partners, such as developers and rights holders,
- enforcing legal claims, including investigating potential violations of applicable terms of service.
d. Processing personal data based on consent
If none of the aforementioned legal bases for processing personal data is applicable, we will ask for your consent for the processing of certain personal data. Your consent enables us to create personalized and segmented notifications about events, benefits, the provision of magazines, brochures, and advertising material from RTC Krvavec and our contractual partners.
You can withdraw your consent at any time.
Unsubscribe from receiving postal newsletters; send an email to: [email protected]
Unsubscribe from receiving email newsletters; in the email newsletters you receive, there is a "Unsubscribe" link at the bottom of the message, click on it and follow the unsubscribe process.
Unsubscribe from receiving SMS newsletters; you subscribed to receiving SMS newsletters with one of the keywords listed below. To unsubscribe from receiving SMS newsletters, send the keyword + STOP to 041 174 174.
Keyword for subscription / Keyword for unsubscribe
KRVAVEC / KRVAVECSTOP
RATRAK / RATRAKSTOP
SENIOR / SENIORSTOP
VP / VPSTOP
INFO1 / INFO1STOP
SEASONAL / SEASONALSTOP
For example, to unsubscribe from the keyword KRVAVEC, send KRVAVECSTOP to 041 174 174.
Occasionally, RTC Krvavec conducts image recording at events, which includes photographing participants or video recording of the event. RTC Krvavec notifies participants in advance and obtains separate consent from them for such processing of their data. In image recording of events, RTC Krvavec reserves the right to visually record participants even without their explicit consent if it involves recording a larger number of participants where the individual is not the central focus of the image, and therefore it cannot be argued that the photograph represents their personal data.
The company conducts video surveillance. Every visitor entering the area under video surveillance is informed through notices about the implementation of video surveillance. Video surveillance recordings are kept for up to 60 days.
6. Limitations on the disclosure of personal data
If necessary, we will authorize other companies and individuals to perform certain tasks that contribute to our services. In such cases, RTC Krvavec may also disclose personal data to carefully selected external processors, who will enter into a data processing agreement or substantively equivalent agreement or other binding document with RTC Krvavec (hereinafter: "Data Processing Agreement"). We will only disclose or make such data accessible to external processors to the extent required for a specific purpose. External processors may not use this data for any other purpose, while meeting at least all standards of personal data processing required by applicable law. External processors are contractually obligated by RTC Krvavec to maintain the confidentiality of your personal data.
Upon justified request, RTC Krvavec may also disclose personal data to competent state authorities with legal authority for this. RTC Krvavec will, for example, respond to requests from courts, law enforcement agencies, and other state authorities, which may also include state authorities of other EU member states.
7. Data retention period
The data retention period is determined based on the category of individual personal data. We keep data for no longer than necessary to achieve the purpose for which it was collected or further processed, or until the expiration of the limitation periods for fulfilling obligations or the legally prescribed retention period.
- Server log files: 30 days;
- First and last name, address, temporary address, date of birth, tax number: permanently or until revoked or for the period specified by individual legislation (e.g., tax);
- Phone number: permanently or until revoked by its holder;
- Email address: permanently or until revoked by its holder;
- Credit card number: not stored;
- Photograph: 2 years after the last activity;
After the retention period expires, the data is erased, destroyed, blocked, or anonymized unless the law specifies otherwise for a particular type of data.
8. Individual's Rights Regarding Personal Data Processing
We ensure the exercise of your rights regarding the processing of your personal data without undue delay. We will decide on your request within one month of receiving your request. In cases of complexity and a large number of requests, we may extend the deadline by up to two additional months. If we extend the deadline, we will inform you of such extension within one month of receiving the request, along with the reasons for the delay.
You can send requests regarding the exercise of your rights via email to [email protected] or by mail to our address.
When you submit a request electronically, we will provide information electronically, if possible, unless you request otherwise.
If there is reasonable doubt about the identity of the individual submitting a request regarding any of their rights, we may request additional information necessary to confirm the identity of the individual to whom the personal data relate.
If the requests of the individual to whom the personal data relate are manifestly unfounded or excessive, especially because they are repetitive, we may:
- charge a reasonable fee, taking into account the administrative costs of providing the information or communication or taking the requested action, or
- refuse to act on the request.
We provide you with the following rights regarding the processing of your personal data:
(i) the right to access data
(ii) the right to rectification
(iii) the right to erasure ("right to be forgotten")
(iv) the right to restriction of processing
(v) the right to data portability
(vi) the right to object
(i) Right to Access Data
You always have the right to know whether personal data concerning you are being processed and if so, to access personal data and the following information:
- purposes of processing,
- types of personal data being processed,
- recipients or categories of recipients to whom the personal data have been or will be disclosed,
- the envisaged retention period for personal data or, if not possible, the criteria used to determine that period,
- the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of your personal data or to object to such processing,
- the right to lodge a complaint with a supervisory authority,
- where personal data are not collected from you, any available information as to their source.
(ii) Right to Rectification
You have the right to obtain, without undue delay, the rectification of inaccurate personal data concerning you and, taking into account the purposes of the processing, the right to have incomplete personal data completed, including by means of providing a supplementary statement.
(iii) Right to Erasure ("Right to Be Forgotten")
You have the right to obtain from us the erasure of your personal data without undue delay where one of the following grounds applies:
- the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed,
- you withdraw consent on which the processing is based, and where there is no other legal ground for the processing,
- you object to the processing of your data, and there are no overriding legitimate grounds for the processing,
- the personal data have been unlawfully processed,
- the personal data have to be erased for compliance with a legal obligation in EU or Slovenian law.
(iv) Right to Restriction of Processing
You have the right to obtain from us restriction of processing of your personal data where one of the following applies:
- you contest the accuracy of the data, for a period enabling us to verify the accuracy of the personal data,
- the processing is unlawful, and you oppose the erasure of the personal data and request the restriction of their use instead,
- we no longer need the personal data for the purposes of the processing, but you require them for the establishment, exercise, or defense of legal claims,
- you have objected to processing based on legitimate interests of the company, pending the verification whether our legitimate grounds override yours.
When the processing of your personal data has been restricted in accordance with the preceding paragraph, such personal data, except for their storage, shall only be processed with your consent, or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person.
Before lifting the restriction on the processing of your personal data, we are obliged to inform you thereof.
9. Right to lodge a complaint regarding the processing of personal data
You can send any complaint regarding the processing of your personal data via email to [email protected] or by mail to our address.
If we do not respond to your request within the statutory period or if your request is rejected, you have the option to lodge a complaint with the Information Commissioner.
You also have the right to lodge a complaint directly with the Information Commissioner if you believe that the processing of your personal data violates Slovenian laws or EU regulations on the protection of personal data.
If you have exercised the right to access data and after receiving the decision you believe that the personal data you received are not the personal data you requested, or that you have not received all the requested personal data, you can submit a reasoned complaint to the company within 15 days before filing a complaint with the Information Commissioner. We must decide on your complaint as if it were a new request within eight working days.
10. Final provisions
All matters not addressed in this Privacy Statement shall be governed by applicable law.
11. Data Protection Officer
Data Protection Officer for RTC Krvavec: Mag. Bojan Rajer [email protected]
RTC Krvavec