PRINCIPLES OF PROCESSING AND PROTECTION OF PERSONAL DATA OF WOMEN FOR WOMEN, o.p.s.

This document was prepared by the charitable trust WOMEN FOR WOMEN, o.p.s. ID No: 24231509, registered office: Vlastislavova 152, 140 00 Prague 4 – Nusle, (hereinafter referred to as “W4W”), registered in the Commercial Register at the Municipal Court in Prague, Section B, File 1003, in order to provide complete information on the methods and conditions of personal data processing by the charitable trust. This document is designed to help you better navigate personal data protection issues and is a tool to easily exercise your rights and address your requirements.

• Legal framework of processing
W4W processes your personal data always and exclusively in accordance with the applicable legislation, i.e. Act No. 110/2019 Coll., on the protection of personal data, as amended, and Regulation (EU) No. 2016/679 of the European Parliament and of the Council (GDPR Regulation). W4W places special emphasis on the security of the processing and protection of your personal data, the protection of your personal data is an absolute priority for us.

In the performance of its business activities, W4W is obliged to comply with Act No. 110/2019 Coll., or the GDPR Regulation, in particular with the following legal regulations, which also set out the obligations affecting the processing of personal data and are binding on W4W:

• Act. No. 262/2006 Coll., Labor Code, as amended
• Act. No. 187/2006 Coll., on Sickness Insurance, as amended
• Act No. 155/1995 Coll., on Pension Insurance, as amended
• Act No. 582/1991 Coll., on the Organization and Implementation of Social Security, as amended
• Act No. 563/1991 Coll, on Accounting, as amended
• Act No. 337/1992 Coll., on the Administration of Taxes and Fees, as amended
• Act No. 586/1992 Coll., on Income Tax, as amended
• where appropriate, with supplementary, amending or replacing legislation,

W4W is subject to the supervision of the Office for Personal Data Protection of the Czech Republic, to which you can file a complaint if you are not satisfied with W4W’s procedures for exercising your rights or processing your personal data.

Office for Personal Data Protection
Pplk. Sochora 27
170 00 Praha 7

• Who the data is processed by
The administrator of your personal data is the charitable trust WOMEN FOR WOMEN, o.p.s. ID No.: 24231509, registered office: Vlastislavova 152, 140 00 Praha 4 – Nusle, registered in the Commercial Register at the Municipal Court in Prague, Section O, Insert 1003 (hereinafter also referred to as “W4W”). You can exercise all your rights against this administrator and direct your questions to it.

W4W processes your personal data through its authorized employees and selected associates, in each case, the following persons:

• are thoroughly selected and audited, are of good repute and capable of ensuring the proper protection of your personal data,
• are bound by the obligation of confidentiality under strict sanctions,
• are bound by strict processing rules and are obliged to ensure all the security standards set by W4W and regularly checked by W4W,
• to only process the extent of your personal data that is necessary for the fulfillment of the given processing task, and only for the necessary period of time,
• They only ever process your personal data in the secure environment of the W4W information system on secure computing resources,
• are obliged to record all personal data processing activities carefully,
• are subject to regular and continuous monitoring of compliance with processing obligations and W4W security standards,

• Data Protection Officer
W4W has appointed a Data Protection Officer in accordance with the GDPR, who is Mgr. Kristýna Černá, based at Vlastislavova 152/4, Prague 4, email: legal@prague-lofts.cz

• What personal data W4W processes
In accordance with the relevant legislation, W4W processes only such personal data as are required by the relevant legislation and such data as are necessary for the performance of W4W’s charitable activities, i.e. only data that are necessary for your participation in W4W programs or for the decision to include you in one of W4W’s programs. W4W also processes the personal data of its employees, associates and third parties that are necessary for the proper performance of W4W’s obligations under applicable law and specific contracts (employment, collaboration, consultancy, etc.). For this purpose, W4W processes the following categories of data:

•identification data – personal data used to identify you (name, surname, maiden name, title, personal number, date of birth, ID number, Company Registration number, etc.),
•contact information – personal information used to contact you (permanent address, mailing address, telephone number, e-mail address),
•information about your family and social situation – marital and health status, social circumstances, employment, receipt of social security benefits, your current housing conditions, etc.
• personal data of employees, associates and third parties – W4W processes the personal data of such persons to the extent required by applicable law or to the extent necessary to exercise the rights and obligations under the applicable contractual document, including the health status of employees (e.g. data on incapacity for work, accidents at work, etc.).

W4W is also obliged to process the personal data listed above without your consent, because W4W is obliged to process them in accordance with the relevant legal regulations, or W4W is entitled to process them in connection with the performance of a contractual obligation or on the basis of a legitimate interest (see below). However, it remains your sole choice whether or not to provide your personal data to W4W. However, if you do not provide personal data to the extent requested, one of the following situations may occur. W4W:

• must not provide the service, if so specified in a special regulation; or
• is entitled not to include you in the program, or not to conclude a contract for participation in the program or another contract, or not to provide you with a charitable service.

•Personal data for W4W’s marketing activities – personal data that W4W processes for the purpose of marketing activities, in particular sending commercial communications or advertising (name, surname, telephone number, e-mail address, mailing address),
•photographs/videos – these are photographs/videos from events organized by W4W, the taking of which requires separate consent, photographs and videos may be used as part of the marketing promotion of W4W by publishing them on social networks, in W4W web presentations, in flyers, etc.

W4W is entitled to process the personal data referred to above only with your consent, and always for the necessary period of time, but no longer than the duration of such consent. Granting of consent to processing is completely voluntary. The above applies with the exception of sending commercial communications by e-mail, which is possible in relation to W4W’s clients in accordance with Section 7 of Act No. 480/2004 Coll., On Certain Information Society Services and on Amendments to Certain Acts, as amended , to also send without prior express consent until such time as the data subject objects to such sending.

W4W only processes personal data to the extent necessary for the fulfillment of a given purpose; personal data obtained for one purpose may not be used for another purpose unless these purposes are compatible with each other.

As a rule, W4W only processes personal data that you have provided to it.

• For what purpose W4W processes personal data
W4W processes your personal data for the following purposes:

• the performance of its own charitable activities consisting in the provision of charitable services within the framework of individual W4W programs or projects,
• fulfillment of legal obligations,
• fulfillment of legal obligations, performance of contractual obligations,
• protection of persons, property, data, trade secrets and legitimate interests of persons, including proper identification and authentication of acting persons,
• establishing, enforcing and defending W4W’s legal claims,

for the purposes set out in a) to e) above, W4W is entitled to process your personal data in accordance with the GDPR, possibly without your consent.

• W4W marketing and promotional activities – sending marketing offers, advertising, W4W events, events to raise awareness of W4W and to support and develop W4W, promotion within the internet environment,
• possibly other purposes.

For the purposes set out in (f) and (g) above, W4W processes personal data only with your consent. The above applies with the exception of sending commercial communications by e-mail, which is possible in relation to W4W’s clients in accordance with Section 7 of Act No. 480/2004 Coll., On Certain Information Society Services and on Amendments to Certain Acts, as amended , to also send without prior express consent until such time as the data subject objects to such sending.

W4W is also entitled to process personal data (if applicable) for the purpose of identifying, exercising and defending its own legal claims, even though the personal data were obtained for another purpose. W4W is entitled to do so if the original purpose and the purpose of defending the legal claims are in any way connected or related to each other.

• On what legal basis and for how long W4W processes personal data
W4W processes personal data within the meaning of Article 6 or Article 9 of the GDPR on the following legal bases:

• data subject’s consent – on this legal basis, personal data are processed in the absence of (if it is not possible to apply) another legal basis for processing, always for the duration of the purpose for which the personal data has been collected, however, at the latest until the consent is withdrawn, and in such cases, you always have the right to withdraw your consent (the ways of withdrawing the consent are listed below),
•performance of a contractual obligation – if a contract has been concluded between you and W4W to which you and W4W are parties, W4W is entitled to process the personal data it has obtained in the performance of the contract or which are necessary for the exercise of its rights and obligations under the contract for the duration of the relevant contract,
•compliance with a legal obligation – W4W is obliged to process selected personal data if it is obliged to do so under the applicable law, for the period of time specified in the applicable law. In particular, the following legal provisions are relevant to the activities of W4W in relation to the processing of personal data:
• Act No. 262/2006 Coll., Labor Code, as amended,
• Act. No. 187/2006 Coll., on Sickness Insurance, as amended
• Act No. 155/1995 Coll., on Pension Insurance, as amended
• Act No. 582/1991 Coll., on the Organization and Implementation of Social Security, as amended
• Act No. 563/1991 Coll, on Accounting, as amended.
• Act No. 337/1992 Coll., on the Administration of Taxes and Fees, as amended
• Act No. 586/1992 Coll., on Income Tax, as amended
• where appropriate, supplementary, amending or replacing legislation,
•W4W’s legitimate interest – in this case, W4W processes personal data for the duration of its legitimate interest. If you object to such processing on the basis of your individual situation and W4W accepts this objection after due consideration, then W4W is obliged to terminate the processing.

Legitimate interests of W4W means, in particular, legitimate interests:
• in the performance of its own charitable activities,
for the establishment, exercise and defense of W4W’s legal claims, in which case the scope of the personal data processed is limited to the minimum necessary and access to the personal data is further limited to specified persons only (typically, if a contract has been concluded between you and W4W to which you and W4W are a party, W4W processes certain personal data obtained in the course of activities under such contract even after its termination, since it is after its termination that you and W4W may assert your claims within the statutory limitation periods),
the protection of persons, property, data and legitimate interests of persons, including the interest in proper identification and authentication of persons acting.

Any personal data may be processed on multiple legal bases. Any personal data may be processed provided there is at least one legal basis for its processing. If the last legal basis for the processing of the personal data is omitted, the personal data must be properly destroyed.

• To whom personal data may be passed
W4W is entitled to disclose personal data to the following entities:
to state authorities and other entities in the performance of their statutory obligations under the relevant legislation (e.g. Act No. 187/2006 Coll., on sickness insurance, as amended, Act No. 155/1995 Coll., on pension insurance, as amended, Act No. 582/1991 Coll., on the organization and implementation of social security, as amended, etc.),
personal data processors under a written agreement on the processing of personal data and providing sufficient technical and organizational safeguards to protect personal data (e.g., IT service providers, accountants, etc.),
employees or other persons in a similar contractual relationship with W4W for the purpose of performing their duties on behalf of W4W,
to other entities as necessary to establish, exercise or defend W4W’s legal claims (e.g. courts, bailiffs, attorneys, etc.),
with the consent of the data subject to other persons,

provided that personal data are only provided to the abovementioned recipients only to the extent necessary for the intended purpose and for the necessary period of time.

• Principles of personal data protection
W4W strictly observes all the security and organisational measures it has put in place to protect personal data.

W4W regularly and consistently checks compliance with security and organizational measures to ensure the protection of personal data, regularly evaluates the findings and updates its security and organizational measures as necessary.

Personal data is processed exclusively by authorized persons, who are thoroughly checked by W4W both before and during processing. All persons who have access to personal data are bound by the obligation of confidentiality under strict sanctions.

• What rights you have and how you can exercise them
Articles 15 – 22 of the GDPR set out the rights you can exercise against W4W. To help you exercise your rights, W4W has created a simple form which is available here. Please always use this form to avoid unnecessary delays in the application process and other possible complications.

Please send the completed and signed form to the address:

WOMEN FOR WOMEN, o.p.s
Vlastislavova 152
140 00 Praha 4 – Nusle

In order to protect your personal data, We DO NOT RECOMMEND that you send your signed and completed form via an unencrypted e-mail message.

You may exercise the following rights at your discretion:

•the right of access to personal data – W4W will provide you with an extract (confirmation) of personal data processed about you within the scope of Article 15 of the GDPR upon request (forms) with your officially verified signature,
•the right to rectification of inaccurate personal data – if you find out that W4W processes inaccurate or outdated personal data about you, W4W is obliged to rectify the inaccurate personal data without undue delay after being informed about it, based on a written request (form),
•the right of erasure – in the cases provided for in Article 17 of the GDPR Regulation, W4W will erase the processed personal data (in particular cases where you would withdraw consent to processing and there is no other legal basis for such processing, if you would object to processing and there are no overriding legitimate reasons for W4W processing, when personal data are no longer needed for the given purpose, etc.), based on a written request (forms) or automatically if personal information is no longer needed for the purpose of processing,
• Right to restrict processing – while W4W assesses the legitimacy of your objection to processing, or until W4W verifies the accuracy of personal data where you deny its accuracy, or if processing is illegal and you refuse to delete it and instead apply for restrictions on use, WW4 temporarily restricts the processing of personal data. It is done upon written request (forms), if you request a restriction, or automatically in the event of a right of objection or correction,
•portability right – if the processing of specific personal data is based on consent or on a contract and is also automated, you have the right to obtain and to transfer to another administrator personal data concerning you. It is done upon written request (forms)with your officially verified signature,
• the right to an individual objection – if processing is based on W4W’s legitimate interest, you have the right to object to such processing for reasons specific to your particular situation. The objection will be thoroughly assessed by W4W. The objection will be upheld if your individual interest outweighs the legitimate interests of W4W. It is executed based upon written request (forms)
•the right to object to direct marketing – if personal data are processed for direct marketing purposes, you may object to direct marketing. Unlike the individual objection under letter (f) of this Article, this objection is not considered, but processing for these purposes is automatically terminated. It is done on the basis of a written request (forms) or by clicking on the link provided directly in a specific electronic marketing message,
•the right to withdraw consent to processing – if you have given consent to W4W to process your personal data, you can withdraw it either as a whole or for individual processing purposes. W4W will no longer process personal data whose processing has been revoked unless there is no other legal basis for the processing. Consent may be revoked electronically at the e-mail address info@w4w.cz , or in writing by mail to the registered office of WOMEN FOR WOMEN o.p.s., Vlastislavova 152, 140 00 Praha 4 – Nusle.
The right not to be subject to any decision based solely on automated processing, including profiling, which would have legal effects on you or similarly significantly affect you – this right does not apply, W4W does not carry out any automated decision-making which would have legal or similar effects on you.

In all of the above cases, W4W will provide you with information on how your request has been dealt with without undue delay, but no later than 1 month after receipt of your request. Given the complexity and number of applications, the deadline can be extended by a further 2 months.

In cases where applications are manifestly unfounded or disproportionate, in particular because they are recurring, W4W may refuse to comply or impose an administrative fee for processing the application taking into account the costs of providing the information.

If you disagree with W4W’s handling or protection of your rights or processing of your personal data, or if you have other observations or comments, you can use the email address info@w4w.cz to send us your comments. We will look into each and every one of your comments.