Privacy policy
We, iComp Limited Liability Company Subotica, with our registered office at Vuka Karadzica 13/1, 24000 Subotica, Republic of Serbia, and company ID number 21521213 (hereinafter: iComp), respect your right to privacy and your right to personal data protection.
In order to align its registered business activity with the provisions of the Personal Data Protection Act („Official Gazette of the RS“, no. 87/18), iComp informs employees and otherwise engaged persons, potential employees – candidates for engagement at iComp, buyers of iComp products, users of other iComp services and other persons whose data iComp processes about all the relevant aspects of personal data processing.
This Privacy Policy lets you find out how iComp, as the controller, processes your personal data and what rights you have regarding the processing of your personal data.
CONTENTS OF THE PRIVACY POLICY
For easier understanding, this Privacy Policy consists of the sections listed below, which together provide comprehensive and complete information about the processing of your personal data and the rights you have regarding that processing under the Personal Data Protection Act:
- Predmet i svrha Politike privatnosti
- Meaning of individual terms
- Primena Politike privatnosti
- Informacije o rukovaocu
- Informacije o Povereniku
- How personal data is collected
- Types of personal data collected and processed
- Processing of special categories of personal data
- Automated processing of personal data
- Principles of personal data processing
- Legal basis for the collection and processing of personal data
- Purpose of personal data processing
- Personal data retention period
- How personal data is stored, data security and processing security
- Rights of the data subject regarding personal data processing and how to exercise them
- Entrusting processing operations and use of personal data by recipients or third parties
- Transfer of personal data to users and third parties
- Transfer of personal data to other countries
- Personal data collected in business with legal entities
- Use of personal data on social networks
- Data protection impact assessment
- Evidencija radnji obrade
- Notification of a personal data breach
- COOKIE POLICY
- Izmene i dopune Politike privatnosti
- Entry into force of the Privacy Policy
1. PREDMET I SVRHA POLITIKE PRIVATNOSTI
iComp adopts and publishes this Privacy Policy on its website https://icomp.rs/ in order to establish the principles applied when iComp processes personal data, as well as the rules for collecting, processing and protecting personal data and the way data subjects exercise their rights, with the aim of aligning its business and activities with the provisions of the regulations governing personal data protection, with best practice and with internationally accepted standards in the processing and protection of personal data.
The purpose of this Privacy Policy is to ensure, through consistent application, the protection of the fundamental rights and freedoms of natural persons, and in particular their right to personal data protection.
This Privacy Policy sets out the rules for protecting natural persons when personal data is collected and processed, and the rules governing the free flow of that data.
2. MEANING OF INDIVIDUAL TERMS
In this Privacy Policy, certain abbreviations have the following meaning as given in the Definitions:
Short name:
Definicija:
Personal data
any data relating to a natural person whose identity is determined or determinable, directly or indirectly, in particular on the basis of an identifier such as a name and identification number, location data, an identifier in electronic communication networks, or one or more features of their physical, physiological, genetic, mental, economic, cultural and social identity
The data subject
the natural person whose personal data is processed
Profilisanje
any form of automated processing used to evaluate certain personal aspects, in particular to analyse or predict a natural person work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements
Pseudonimizacija
processing in a way that makes it impossible to attribute personal data to a specific person without using additional data, provided that this additional data is kept separately and that technical, organisational and staffing measures have been taken to ensure that the personal data cannot be attributed to an identified or identifiable person
Rukovalac
iComp Limited Liability Company Subotica, with its registered office at Vuka Karadzica 13/1, 24000 Subotica, Republic of Serbia, and company ID number 21521213
Processor
a natural or legal person who processes personal data on behalf of iComp
Primalac
a natural or legal person, or a public authority, to whom personal data is disclosed, whether or not it is a third party, except for public authorities which, in accordance with the law, receive personal data in the framework of an investigation into a particular case and process that data in accordance with the personal data protection rules relating to the purpose of the processing
Consent of the data subject
any freely given, specific, informed and unambiguous indication of that person will, by which they, through a statement or a clear affirmative action, consent to the processing of personal data relating to them
Special categories of personal data
all data revealing racial or ethnic origin, political opinion, religious or philosophical belief or trade union membership, as well as the processing of genetic data, biometric data for the purpose of uniquely identifying a person, data concerning health or data concerning the sex life or sexual orientation of a natural person, in accordance with Article 17 of the Act.
Personal data breach
a breach of personal data security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed
Poverenik
an independent and autonomous public authority responsible for supervising the implementation of the Personal Data Protection Act and performing other tasks prescribed by that Act
Zakon
Personal Data Protection Act (“Official Gazette of the RS”, no. 87/2018)
3. PRIMENA POLITIKE PRIVATNOSTI
This Privacy Policy applies to all processing of personal data of employees, potential employees – candidates, customers and users of other iComp services, as further defined below in this Privacy Policy.
This Privacy Policy applies to all processing of personal data at iComp, except where anonymised data is processed from which the person concerned cannot be identified.
iComp emphasises that it collects, processes and keeps only the minimum of personal data prescribed by the Act, through appropriate technical and organisational measures. iComp does not collect, process or keep personal data of minor users (under 14 years of age), unless there is prior written consent from the parent or guardian of such a user.
4. INFORMACIJE O RUKOVACU
In most business activities related to its operations, iComp acts as a controller and, alone or jointly with other controllers, determines the purpose and manner of data processing, while in some activities it may be a processor that processes personal data on behalf of a controller. Where iComp acts as a processor, the data is processed in accordance with a contract or another legally binding act governing the processing and protection of personal data, all in accordance with the Act.
The key information about iComp as the controller of your data is as follows:
- with its registered office at Vuka Karadzica 13/1, 24000 Subotica, Republic of Serbia, and company ID number
- Business name: ICOMP LIMITED LIABILITY COMPANY SUBOTICA
- Company ID number: 21521213
- Registered office and mailing address: Vuka Karadzica 13/1, municipality of Subotica, city of Subotica, Republic of Serbia
- E-mail adresa: office@icomp.rs
- Phone: +381 63 8 100 500
- Internet prezentacija: www.icomp.rs
5. INFORMACIJE O POVERENIKU
- Name: Commissioner for Information of Public Importance and Personal Data Protection
- Registered office and mailing address: Bulevar kralja Aleksandra 15, Belgrade, Republic of Serbia
- E-mail adresa: office@poverenik.rs
- Phone: +381 11 34 08 900
- Internet prezenticija: www.poverenik.rs
6. HOW PERSONAL DATA IS COLLECTED
iComp collects personal data directly from the data subjects, namely from employees and persons engaged on another legal basis in accordance with the Labour Act, job candidates at iComp, buyers of iComp products, users of iComp service, participants in workshops organised by iComp, recipients of the iComp newsletter and users of the iComp website, and indirectly from people who follow iComp accounts on social networks.
In the case of indirect collection of personal data, iComp first checks whether the person providing the data is authorised to pass it on to iComp. The person providing the data must inform the data subjects about all the relevant aspects of the processing, in accordance with Article 24 of the Act.
7. TYPES OF PERSONAL DATA COLLECTED AND PROCESSED
iComp, in line with the principle “purpose limitation” and the principle “data minimisation”, as laid down in Article 5 of the Act, processes only the minimum amount of personal data necessary to achieve the specific purpose:
- from Employees, the data prescribed by the applicable law governing employment relations, employment records and the laws governing social and health care is collected and processed; the purpose of such processing is the fulfilment of legal obligations and it is necessary in order to comply with the legal obligations of iComp within the meaning of Article 12(1)(3) of the Act, as well as other data the employee shares with iComp for another purpose and on another legal basis (for example data needed to arrange supplementary health insurance);
- from job candidates, data such as first and last name, personal identification number, gender, date and place of birth, address of residence, home address, phone number, email address, education and qualifications is collected and processed, as well as other data the person shares about themselves. Such processing is necessary for taking steps at the request of the data subject before concluding a contract, in order to contact them if there is a need for engagement, within the meaning of Article 12(1)(2) of the Act. After a specific vacancy closes, persons who are not engaged may decide that their data remains available in the electronic records of iComp in case a need for their engagement arises in the future. This means that, from the closing of the specific vacancy, personal data is processed on the basis of informed consent within the meaning of Article 12(1)(1) of the Act. If a job candidate is engaged, further processing of their data is carried out as for the “Employees” category above,
- from buyers of iComp products, users of iComp service and participants in workshops organised by iComp, the personal data necessary for performing the agreed services is collected and processed, namely first and last name, email address, address of residence and phone number, depending on the category of persons whose data iComp collects and processes, within the meaning of Article 12(1)(2) of the Act,
- from recipients of the iComp newsletter, personal data is collected and processed, namely the email address and first and last name, which are necessary in order to pursue the legitimate interests of iComp, such as promoting new iComp products and services, on the basis of informed consent within the meaning of Article 12(1)(1) of the Act, that is, within the meaning of Article 12(1)(6) of the Act. Clients using the services are offered the option to decide whether they wish to be on the mailing lists used for marketing campaigns.
- from people who follow iComp accounts on social networks, the personal data marked as publicly available in accordance with the privacy policy of the particular social network is collected and processed, and such processing is carried out on the basis of the informed consent of the data subject, given by agreeing to use a particular social network and by liking, following (or a similar action on) the accounts on social networks, within the meaning of Article 12(1)(1) of the Act; such data is processed for the purpose of promoting iComp products and services;
8. PROCESSING OF SPECIAL CATEGORIES OF PERSONAL DATA
As a rule, iComp does not collect or process personal data revealing racial or ethnic origin, political opinion, religious or philosophical belief or trade union membership, and does not process genetic data, biometric data for the purpose of uniquely identifying a person, data concerning health or data concerning the sex life or sexual orientation of a natural person.
By way of exception, the collection and processing of personal data is allowed in the following cases:
- the data subject has given explicit consent to processing for one or more processing purposes;
- the processing is necessary for the performance of obligations or the exercise of the legally prescribed powers of the controller or the data subject in the field of employment, social insurance and social protection, if such processing is prescribed by law or by a collective agreement providing for appropriate measures to protect the fundamental rights, freedoms and interests of the data subject. iComp may process special categories of personal data for the purpose of processing such data in order to fulfil legal obligations relating to employment, to the extent that the processing of that data is prescribed by the applicable regulations, the law governing employment records and the laws governing social and health care, for the performance of obligations or the exercise of the legally prescribed powers of the controller or the data subject in the field of employment, social insurance and social protection, in accordance with Article 17(2)(2) of the Act.
- For example, the Act on Employment Records (“Official Gazette of the FRY”, no. 46/96 and “Official Gazette of the RS”, no. 101/2005 – other act) requires employment records to be kept which may contain special categories of data:
- information on whether the employee is a disabled worker or a pension beneficiary (Article 5(1)(19) of the Act on Employment Records);
- data on the exercise of rights during temporary incapacity or inability to work (Article 5(1)(21) of the Act on Employment Records);
- data on the total hours not worked for which salary compensation is received for hours of temporary incapacity or inability to work, total hours not worked for which salary compensation is received from health insurance funds, hours of temporary incapacity or inability to work, hours of maternity leave and reduced working hours for a parent with a child, data on the net income of the employee: solidarity aid; severance pay, separate living allowance)
- the processing is necessary in order to protect the vital interests of the data subject or another natural person;
- personal data is processed which the data subject has manifestly made public;
- the processing is necessary for the establishment, exercise or defence of a legal claim, or where a court acts within its jurisdiction.
9. AUTOMATED PROCESSING OF PERSONAL DATA
The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, if that decision produces legal effects concerning them or significantly affects their position, unless that decision is:
- necessary for the conclusion or performance of a contract between the data subject and the controller;
- based on the law, if that law prescribes appropriate measures to protect the rights, freedoms and legitimate interests of the data subject (for example, to prevent fraud, money laundering and terrorist financing);
- based on the explicit consent of the data subject.
iComp applies appropriate measures to protect the rights, freedoms and legitimate interests of the data subject, at least the right to obtain human intervention under the control of the controller in the decision-making, the right of the data subject to express their point of view on the decision, and the right of the data subject to contest the decision before an authorised person of iComp as the controller.
10. PRINCIPLES OF PERSONAL DATA PROCESSING
The processing principles are the basic rules iComp follows when collecting and processing personal data.
iComp and all iComp employees are obliged to ensure the full application of the processing principles when collecting and processing personal data.
iComp is responsible for applying these principles when collecting and processing personal data.
iComp collects and processes personal data with the mandatory application of the following principles:
- Principle of lawfulness, fairness and transparency
Personal data must be processed lawfully, fairly and transparently in relation to the data subject, in accordance with the regulations governing the processing.
iComp undertakes to provide the person, at the time of collecting the data, with information about the procedure for collecting and processing their data, as well as other information concerning lawfulness, the purpose of the processing, how to exercise their rights and other necessary information, all in accordance with the provisions of the Act. - Purpose limitation principle
iComp collects data for purposes that are specified, explicit, justified and lawful, and the data collected in this way cannot be further processed in a manner incompatible with those purposes.
iComp will not process the collected data for any other purpose, unless there are other processing operations required by law or necessary for providing a quality service. - Data minimisation principle
The personal data collected must be adequate, relevant and limited to what is necessary in relation to the purpose of the processing.
- Accuracy principle
Personal data must be accurate and, where necessary, kept up to date. Taking into account the purpose of the processing, iComp takes all reasonable steps to ensure that inaccurate personal data is erased or updated without delay.
Data is kept up to date through procedures of regular checks on the accuracy and currency of the personal data collected and through communication with the persons concerned, in which corrections can be made when a person notifies iComp of a change in their data or notices that some of the data is inaccurate. - Storage limitation principle
iComp keeps personal data in a form that allows identification of the person only for the period necessary to achieve the purpose of the processing. Personal data may be kept longer in order to comply with a legal obligation of iComp requiring the processing, or where there is a legitimate interest (such as the establishment, exercise or defence of a legal claim).
- Integrity and confidentiality principle
Personal data is processed in a way that ensures appropriate protection of the data, including protection against unauthorised or unlawful processing, as well as in the event of loss, destruction or damage, through the application of appropriate technical, organisational and staffing measures.
iComp applies measures aimed at preventing unauthorised disclosure of data, monitoring access to data, restricting access to data according to job requirements and similar.
11. LEGAL BASIS FOR THE COLLECTION AND PROCESSING OF PERSONAL DATA
In accordance with the Act, processing is lawful, that is, data is collected from a person when one of the following conditions for lawful collection and processing is met:
- the processing is necessary for compliance with iComp legal obligations. Where the regulations oblige or authorise iComp to carry out certain processing, iComp will collect and process personal data (such as under the Act on the Prevention of Money Laundering and Terrorist Financing, etc.),
- the processing is necessary for the performance of a contract concluded with the data subject, or for taking steps at the request of the data subject before concluding a contract,
- the processing is necessary in order to pursue the legitimate interests of iComp or a third party, unless those interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, in particular where the data subject is a minor. A legitimate interest of iComp exists in processing carried out to improve processes, develop services and inform clients about business improvements, as well as in the case of resolving court disputes. Processing of personal data necessary to prevent fraud and abuse in the conduct of the iComp business and the provision of services by iComp constitutes a legitimate interest of iComp as the data controller.
- the data subject has consented to the processing of their personal data for one or more specific purposes, whereby iComp must be able to demonstrate that the person consented to the processing of their personal data, and the request for consent must be in an understandable and easily accessible form, using clear and plain language. The data subject may withdraw consent at any time, whereby the withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of consent before the withdrawal,
- the processing is necessary in order to protect the vital interests of the data subject or another natural person,
- the processing is necessary for the performance of tasks in the public interest or the exercise of iComp powers laid down by law
In this specific case, iComp collects and processes personal data:
- for the performance of a contract concluded with the data subject, or for taking steps at the request of the data subject before concluding a contract, within the meaning of Article 12(1)(2) of the Act, in respect of buyers of iComp products and users of iComp service;
- the informed consent of the data subject, within the meaning of Article 15 of the Act, in respect of job candidates at iComp and recipients of the iComp newsletter, in which case you have the right to withdraw it at any time in accordance with Article 16 of this Privacy Policy;
- in order to fulfil legal obligations, within the meaning of Article 12(1)(3) of the Act, in respect of iComp employees;
- in order to pursue the legitimate interests of the controller or a third party, within the meaning of Article 12(1)(6) of the Act, all depending on the category of personal data processed and the purpose of the processing;
12. PURPOSE OF PERSONAL DATA PROCESSING
In accordance with the provisions of this Privacy Policy, iComp collects and processes the personal data of employees, job candidates, buyers of iComp products, users of iComp services, participants in workshops organised by iComp and recipients of the iComp newsletter, which these categories of persons provide in connection with the performance of work tasks and obligations, engagement at iComp, the conclusion and performance of contracts for the sale of iComp products, servicing of iComp products, participation in workshops organised by iComp and receiving the iComp newsletter, for the following purposes:
- performance of obligations under a concluded employment contract or another type of contract engaging a person outside employment, relating to persons employed or otherwise engaged at iComp,
- entering into employment or another type of engagement outside employment, and relates to job candidates until the specific vacancy closes,
- contacting job candidates at iComp after a specific vacancy has closed, relating to candidates who agree that their data may be processed after the vacancy closes,
- fulfilment of legal obligations laid down by the Labour Act, the Act on Employment Records and the laws governing social and health insurance, relating to persons employed or otherwise engaged at iComp,
- performance of obligations under contracts for the purchase of iComp products, use of iComp service, participants in workshops organised by iComp,
13. PERSONAL DATA RETENTION PERIOD
iComp stores and processes personal data for the period necessary to fulfil the specific purpose of the processing.
In relation to special categories of data subjects:
- employee data is kept permanently in line with the obligations of the law governing employment records;
- data about job candidates at iComp is kept until the specific purpose of the processing is exhausted, that is, until consent is withdrawn within the meaning of Article 15(3) of the Act. If employment or another form of engagement under the Labour Act is established, the data is kept in accordance with the retention period for employee data;
- data collected for the performance of a concluded contract with buyers of iComp products, users of iComp services or participants in workshops organised by iComp is kept for a period of 10 years (the general limitation period for claims under the law governing obligations), or for another period, if a different period is prescribed by law or in the specific notice on the processing of personal data;
- data collected about recipients of the iComp newsletter is kept until the specific processing purpose is exhausted or until consent is withdrawn within the meaning of Article 15(3) of the Act;
- data collected from people who follow iComp accounts on social networks (users) is kept in accordance with the policy of the particular social network;
- data collected through video surveillance on iComp premises is kept for a period of one and a half months from the date of collection;
14. HOW PERSONAL DATA IS STORED, DATA SECURITY AND PROCESSING SECURITY
iComp stores and keeps personal data in paper or electronic form, to which all the necessary organisational, technical and staffing protection measures are applied in accordance with the requirements laid down by the Act.
iComp keeps records of processing operations for each category of data subject in accordance with the requirements of Article 47 of the Act, which describes the processing operations, as the recording of processing is laid down in Article 23 of this Privacy Policy.
Taking into account the state of the art and the cost of its implementation, the nature, scope, circumstances and purpose of the processing, as well as the likelihood and severity of the risk to the rights and freedoms of natural persons arising from the processing, iComp applies appropriate technical, organisational and staffing measures, which in particular include:
- pseudonymisation and encryption of personal data;
- the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services, by means of:
- restricting physical access to the system where personal data is stored, which in particular means that personal data is available only to authorised persons;
- access control: physical and electronic access is available only to authorised persons, and only to those whose work tasks require access to the records and to the extent those tasks require. Access to the data is granted only to authorised persons who know the password and follow the applicable industry recommendations for creating passwords (a combination of lower and upper case letters, characters, appropriate length, etc.);
- data entry control, meaning that only an authorised person collects personal data and stores it in the records, under the supervision of a supervisor;
- ensuring that availability of and access to personal data is restored as quickly as possible in the event of a physical or technical incident;
- a procedure for regularly testing, assessing and evaluating the effectiveness of the technical, organisational and staffing measures for processing security.
By continuously applying the appropriate technical, organisational and staffing measures listed above, iComp must ensure that only the personal data necessary for each individual purpose of the processing is processed. That obligation applies to the amount of data collected, the extent of its processing, its storage period and its accessibility.
iComp undertakes to protect the privacy of all its customers. We collect only the necessary, basic data about customers/users and the data needed for business and for informing customers, in line with good business practice and in order to provide a quality service. All customer data is kept strictly and is available only to employees who need it to do their job. All iComp employees (and business partners) are responsible for observing the privacy protection principles.
All card details are are not stored on iComp servers; they are processed on the banks pages instead.
15. RIGHTS OF THE DATA SUBJECT REGARDING PERSONAL DATA PROCESSING AND HOW TO EXERCISE THEM
At the moment of collecting personal data, iComp will provide the person with all the information required by the Act, that is, information on:
- identitetu rukovaoca,
- the purpose of the intended processing and its legal basis;
- the existence of a legitimate interest of the controller or a third party;
- the recipient of the personal data (especially if the data is transferred to another country or an international organisation);
- the personal data retention period;
- the type and manner of exercising the rights of the data subject,
- the right to object;
- the right to withdraw consent at any time, and that withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal;
- the right to lodge a complaint with the Commissioner;
- whether providing personal data is a legal or contractual obligation or a necessary condition for concluding a contract, as well as whether the data subject is obliged to provide their personal data and the possible consequences of not providing it;
- the existence of automated decision-making, including profiling (information about the logic involved, as well as the significance and expected consequences for the data subject),
- the source of the data (where the data is not collected from the data subject).
iComp enables the person to exercise the following rights:
- Right of access – the data subject has the right to request from iComp information on whether it processes their personal data, access to that data, a copy of that data, as well as information on the purpose of the processing, the types of personal data processed, the recipient, and in particular a recipient in other countries or international organisations, the envisaged retention period, and other information relating to the processing.
- Right to rectification and completion – the data subject has the right to have inaccurate personal data about them corrected without undue delay. Depending on the purpose of the processing, the data subject has the right to complete incomplete personal data, which includes providing a supplementary statement.
- Right to erasure – the data subject has the right to have their personal data erased, and iComp must erase it without undue delay under the following conditions:
- the personal data is no longer necessary for the purpose for which it was collected or otherwise processed;
- the data subject has withdrawn the consent on which the processing was based and there is no other legal basis for the processing;
- the data subject has objected to the processing and there is no other legal basis for the processing that overrides the legitimate interest, right or freedom of the data subject,
- the personal data has been processed unlawfully;
- the personal data must be erased in order to fulfil the legal obligations of the controller;
- the personal data was collected in connection with the use of information society services
- Right to restriction of processing – the data subject has the right to have iComp restrict the processing of their personal data if one of the following applies:
- the data subject contests the accuracy of the personal data, for a period enabling iComp to verify the accuracy of the personal data;
- the processing is unlawful and the data subject opposes the erasure of the personal data and instead requests a restriction of its use;
- iComp no longer needs the personal data for the purpose of the processing, but the data subject has requested it for the establishment, exercise or defence of a legal claim;
- the data subject has objected to the processing and it is being assessed whether the legal basis for iComp processing overrides the interests of that person.
Where processing has been restricted, that data may be further processed only with the consent of the data subject, except for storage or for the establishment, exercise or defence of a legal claim, or for the protection of the rights of other natural or legal persons, or for reasons of important public interest.
If the processing has been restricted, iComp must inform the data subject that the restriction is ending, before it ceases to apply.
- Right to portability – the data subject has the right to receive from iComp the personal data they previously provided, in a structured, commonly used and machine-readable format, and has the right to transfer that data to another controller without hindrance from iComp, where the processing is carried out by automated means on the basis of consent or a contract.
- Right to object – the data subject has the right at any time to lodge an objection with iComp to the processing of their personal data carried out for the performance of tasks in the public interest or the exercise of legally prescribed powers, or necessary in order to pursue the legitimate interests of iComp or a third party, including profiling related to such processing. iComp must stop processing the data of the person who lodged the objection, unless iComp demonstrates that there are legal grounds for the processing which override the interests, rights or freedoms of the data subject, or which relate to the establishment, exercise or defence of a legal claim. The data subject has the right at any time to object to the processing of their personal data carried out for direct marketing purposes, including profiling to the extent that it is related to direct marketing. If the data subject objects to processing for direct marketing purposes, the personal data may no longer be processed for such purposes.
- Right to object to automated decision-making and profiling – the data subject has the right not to be subject to a decision based solely on automated processing, including profiling, if that decision produces legal effects concerning them or significantly affects their position, unless that decision is necessary for the conclusion or performance of a contract between the data subject and iComp, is based on the law (where that law prescribes appropriate measures to protect the rights, freedoms and legitimate interests of the data subject), or is based on the explicit consent of the data subject.
- Right to complain – the data subject has the right to lodge a complaint with the Commissioner if they believe their personal data has been processed contrary to the regulations.
iComp must provide the data subject with information on the action taken on a request to exercise the rights listed above without delay, and at the latest within 30 days of receiving the request, whereby that period may be extended by a further 60 days (if necessary, taking into account the complexity and number of requests). iComp must inform the data subject of the extension and the reasons for it within 30 days of receiving the request.
If iComp does not act on the request of the data subject, it must inform that person of the reasons without delay, and at the latest within 30 days of receiving the request, as well as of the right to lodge a complaint with the Commissioner or a lawsuit with the court.
iComp provides information on the collection and processing of data, and information relating to the exercise of rights, free of charge. If a request by the data subject is manifestly unfounded or excessive, in particular if the same request is repeated frequently, iComp may charge the necessary administrative costs of providing the information or acting on the request (for example in the case of a request for a copy of the data) or may refuse to act on the request.
In the event of a violation of the rights guaranteed to them by the applicable regulations of the Republic of Serbia and by this Privacy Policy, the person has the right to contact the Commissioner using the contact details given in Article 6 of this Privacy Policy.
16. ENTRUSTING PROCESSING OPERATIONS AND USE OF PERSONAL DATA BY RECIPIENTS OR THIRD PARTIES
As a controller, iComp may also disclose personal data to third parties, some of whom are processors, data recipients or third parties.
iComp may designate as a processor only a person that fully guarantees the application of appropriate technical, organisational and staffing measures, in a way that ensures the processing is carried out in accordance with the regulations and that the rights of the data subject are protected.
A processor may entrust processing to another processor only if iComp authorises it to do so, that is, if it agrees to the choice or replacement of the other processor.
Processing by a processor is governed by a contract or another legally binding act which binds the processor towards iComp as the controller and which regulates the subject matter and duration of the processing, its nature and purpose, the type of personal data and the type of data subjects, the obligation of confidentiality and similar.
The categories of processors that may have access to personal data can be:
- companies providing IT services (maintenance of iComp information and communication systems or development of the iComp website);
- other persons who carry out certain processing operations on behalf of and for the account of the controller (companies that select candidates in recruitment procedures at iComp, accounting agencies that process salaries).
17. TRANSFER OF PERSONAL DATA TO USERS AND THIRD PARTIES
iComp transfers personal data when there is a legal obligation to provide it at the request of an authorised body or regulator of the Republic of Serbia (the National Bank of Serbia, the Ministry of Finance of the Republic of Serbia – the Administration for the Prevention of Money Laundering and the Tax Administration of the Republic of Serbia, the external auditor of iComp and other bodies).
iComp may also disclose personal data to its business partners where this is necessary for the performance of business relations (for example IT support, debt collection, legal assistance, consulting services, assignment of receivables and similar), on the basis of a contract which, in accordance with the regulations and iComp internal acts, governs the obligation and the measures for keeping the data confidential.
18. TRANSFER OF PERSONAL DATA TO OTHER COUNTRIES
The transfer of personal data to other countries or international organisations is allowed in accordance with the regulations governing personal data protection.
iComp is part of a group of companies in accordance with the Act and other regulations governing companies, and may accordingly transfer personal data to other countries and/or international organisations where an adequate level of personal data protection is ensured, namely to countries and international organisations:
- which are parties to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data;
- which the European Union has determined provide an adequate level of protection;
- with which the Republic of Serbia has concluded international agreements on the transfer of personal data; and
- which are on the list determined by the Government of the Republic of Serbia on the basis of the criteria and rules laid down by the Act and published in the „Official Gazette of the Republic of Serbia“.
19. PERSONAL DATA COLLECTED IN BUSINESS WITH LEGAL ENTITIES
iComp collects and processes data about legal entities (public authorities, local self-government units, other legal entities and natural persons carrying out a registered activity), transactions, product purchases and the use of services, as well as personal data of natural persons connected with the legal entity (members and shareholders, members of management bodies, legal representatives, procurators, proxies and other natural persons whose personal data the legal entity has provided to iComp), in order to establish and maintain a business relationship.
Personal data collected in business with legal entities is processed in accordance with this Privacy Policy.
20. USE OF PERSONAL DATA ON SOCIAL NETWORKS
For how personal data is used on social networks, please see the privacy rules of those social networks.
To make it easier to find and understand the privacy rules of the social networks where iComp has accounts, below are links to the iComp profiles on those social networks, as well as links where the privacy rules of those social networks can be found
Facebook:
iComp account:
Privacy explanations and settings: https://www.facebook.com/privacy/explanation
Twitter:
iComp account:
Politika privatnosti: https://twitter.com/en/privacy
Instagram:
iComp account:
Politika privatnosti: https://help.instagram.com/519522125107875
LinkedIn:
iComp account:
Politika privatnosti: https://www.linkedin.com/legal/privacy-policy
21. DATA PROTECTION IMPACT ASSESSMENT
Where a type of processing, in particular using new technologies and taking into account the nature, scope, circumstances and purpose of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, iComp is obliged under the Act to carry out an assessment of the impact of the envisaged processing operations on the protection of personal data before starting the processing.
A data protection impact assessment is mandatory in the case of:
- a systematic and comprehensive assessment of the situation and characteristics of a natural person carried out through automated processing of personal data, including profiling, on the basis of which decisions are made that are significant for the legal position of the individual or similarly significantly affect them;
- processing of special categories of personal data on a large scale;
- systematic monitoring of publicly accessible areas on a large scale;
- carrying out the processing operations prescribed by the Commissioner.
The impact assessment must contain at least:
- a comprehensive description of the envisaged processing operations and the purpose of the processing, including a description of the legitimate interest of the controller, if any;
- an assessment of the necessity and proportionality of the processing in relation to its purposes;
- an assessment of the risk to the rights and freedoms of the data subject;
- a description of the measures intended to be taken in relation to the existing risk, including safeguards, as well as technical, organisational and staffing measures to protect personal data and to provide evidence of compliance with the provisions of the Act, taking into account the rights and legitimate interests of the data subject and other persons.
22. EVIDENCIJE RADNJI OBRADE
In accordance with the Act, iComp keeps an electronic record of the processing operations for which it is responsible, containing information on:
A data protection impact assessment is mandatory in the case of:
- the name and contact details of the controller, joint controllers, the controller representative and the data protection officer,
- svrsi obrade;
- the type of data subjects and the type of personal data;
- the type of recipients to whom the personal data has been or will be disclosed, including recipients in other countries or international organisations;
- the transfer of personal data to other countries or international organisations, including the name of the other country or international organisation;
- the period after which certain types of personal data are erased, if such a period has been set;
- a general description of the security measures.
23. NOTIFICATION OF A PERSONAL DATA BREACH
iComp must notify the Commissioner of a personal data breach that may create a risk to the rights and freedoms of natural persons without undue delay or, where possible, within 72 hours of becoming aware of the breach.
If iComp does not act within 72 hours of becoming aware of the breach, it must explain the reasons why it did not act within that period.
Where processing has been entrusted, the processor must notify iComp of a personal data breach without undue delay after becoming aware of it.
If a personal data breach may create a high risk to the rights and freedoms of natural persons, iComp must notify the data subject of the breach without undue delay and describe the nature of the breach in clear and understandable terms.
iComp is not obliged to notify the person of a personal data breach if:
- appropriate technical, organisational and staffing protection measures have been taken in relation to the personal data whose security has been breached, in particular if encryption or other measures have made the data unintelligible to all persons not authorised to access it;
- measures have subsequently been taken which ensure that a personal data breach posing a high risk to the rights and freedoms of the data subject can no longer produce consequences for that person;
- notifying the data subject would involve a disproportionate amount of time and resources, in which case the notification must be provided to the data subject through a public announcement or another effective means.
24. COOKIE POLICY
A detailed overview and explanation of cookies can be found on the page Cookie policy.
25. IZMENE I DOPUNE POLITIKE PRIVATNOSTI
All amendments and additions to this Privacy Policy must be made in writing and published on the iComp website.
Any amendments and additions to this Privacy Policy must not reduce the level of personal data protection established and achieved by this Privacy Policy.
26. ENTRY INTO FORCE OF THE PRIVACY POLICY
This Privacy Policy was published on the iComp website on 1 June 2023 and enters into force on the eighth day after publication, that is, on 8 June 2023.
By this, the persons whose personal data is processed by iComp confirm that they have read, understood and accepted the processing of personal data described above in accordance with the provisions of this Privacy Policy.
In Subotica, on 29 May 2023
iComp d.o.o.




