This Privacy Policy (hereinafter referred to as the “Policy”) governs the procedure for processing the personal data of users of the website https://pravostandart.com/ (hereinafter referred to as the “Website”).
1.1. The Administrator processes Users’ personal data in accordance with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the applicable laws of the European Union and the countries where services are provided.
1.2. By using the Website and submitting a contact form, the User agrees to the terms of this Policy.
When the User completes a contact form or uses the Website, we may collect the following data:
Your data is processed solely for the following purposes:
4.1. The Website Administrator does not provide legal services and is not a party to any agreement between the User and the Service Provider.
4.2. Once the inquiry has been forwarded to a specialist (Service Provider), the Service Provider becomes an independent data controller with respect to the User’s personal data and bears full responsibility for data processing within the scope of the services provided.
4.3. The Administrator ensures only the technical transfer and initial processing of data necessary to connect the User with a specialist.
Data processing is carried out on the basis of:
Data submitted through the contact form is retained until it is transferred to the Service Provider and for no more than 90 days after the last contact if no agreement is concluded.
If an agreement is concluded, the storage and processing of data are governed by the Service Provider’s Privacy Policy.
Technical logs and analytical data are retained for no longer than 12 months.
Your personal data may be transferred to:
All such parties are required to comply with GDPR requirements and enter into a Data Processing Agreement with the Administrator.
8.1. General principles of protection
The Administrator implements all reasonable technical and organizational measures to protect Users’ personal data from loss, unauthorized access, alteration, disclosure, or destruction. These measures comply with the principles of confidentiality, integrity, and availability established under Articles 5 and 32 of Regulation (EU) 2016/679 (GDPR).
8.2. Technical security measures
The following technologies and methods are used to ensure data security:
8.3. Organizational measures
Access to personal data is granted only to authorized employees and Service Providers who have signed confidentiality agreements and received data protection training.
All individuals with access to personal data are granted access based on the need-to-know principle.
Internal audits and data processing risk assessments are conducted periodically.
A Data Protection Officer (DPO) has been appointed to monitor compliance with this Policy and GDPR requirements.
8.4. Security of data transfers to service providers
User data is transferred to Service Providers through secure communication channels using encryption and security protocols. Service Providers are required to maintain a level of protection equivalent to GDPR standards and to use the data solely for purposes agreed upon with the User.
8.5. Data storage and backup
Data is stored on servers located within the European Union or in countries recognized by the European Commission as providing an adequate level of data protection.
Regular backups are created to prevent data loss resulting from technical failures.
Access to backup copies is restricted and controlled.
8.6. Data protection Impact assessment (DPIA) and risk management
Where data processing is likely to result in a high risk to the rights and freedoms of individuals, the Administrator conducts a Data Protection Impact Assessment (DPIA) and documents measures implemented to mitigate such risks.
8.7. Security breaches (Data Breach Notification)
In the event of an incident involving the leakage of or unauthorized access to personal data, the Administrator shall:
8.8. Log Retention and access monitoring
To ensure transparency, technical access logs are maintained, recording all operations involving personal data. These logs are stored in a secure environment and are used exclusively for internal audits and incident investigations.
8.9. Transfers of data outside the EU
If data processing takes place outside the European Union (for example, where a Service Provider or contractor is located outside the EEA), such transfers are carried out only in compliance with Chapter V of the GDPR, including:
8.10. Accountability and oversight
The Administrator is responsible for ensuring that personal data processing complies with the GDPR principles (Article 5(2)) and for documenting all protective measures. Users may contact the Administrator or the Data Protection Officer (DPO) to obtain information regarding specific security measures.
8.11. User obligations
The User undertakes not to engage in any actions that may compromise the security of the Website or result in unauthorized access (including attempts to hack the Website, interfere with its code, or use malicious software).
The Website uses cookies to ensure proper functionality and for statistical analysis purposes. For more information, see Section 9 “Cookies and Analytics” of the extended version (available upon request). You may manage cookies through your browser settings or the consent banner on the Website.
In accordance with the GDPR, you have the right to:
The Administrator reserves the right to amend this Policy. The updated version will be published on the Website with the date of amendment indicated.
Website administrator:
Email: info@pravostandart.com