At Borgdirect we, just like everybody else, process personal data of our customers and business partners. We are committed to protecting the privacy of visitors of our website, and our customers (hence also referred to as “Data Subjects”).
- Personal Data we collect
From visitors of our web pages we automatically collect data based on their web browsing activity, just like almost every other webpage. All such collected data is only processed for the purpose of analysis of our webpage effectivity and possible improvements, so that we are able to provide our visitors and customers with better service, and as such it is processed on the legal basis of our legitimate interests.
A wider range of data about browsing activity of our visitors may be collected so that we can get detailed statistics and more information about our visitor’s preferences to improve our services and to target our marketing better. Such data, however, are collected only after we get our visitors consent to do so, therefore, in this case, the legal basis for processing of personal data is the consent.
Our visitors may contact us or request newsletters using forms on our website. Data provided in these forms will be used only to reply or send newsletters. This processing is based on data subject’s consent (point a of article 6 paragraph 1 of GDPR).
We also collect and process data provided to us by the visitors directly in the process of them becoming our customers. This includes name, phone number, email, and monthly spend on Facebook (not personal information, but also important). This set of data is crucial for us entering into contract with the visitor, meaning it falls under the point b of article 6, paragraph 1 of GDPR (“contract processing”).
From our customers we only collect a little more – data about their activity inside the application. Such logs mostly won’t contain any personal data, though. Still it is worth mentioning that the logs also fall under above mentioned point b of article 6, paragraph 1 of GDPR.
None of the personal data mentioned above are sensitive (special categories of personal data).
The data is stored securely, i.e. behind firewalls and, where applicable, encrypted. We have taken multiple organizational and technical measures to make sure the data will be stored securely.
- Disclosure of Personal Data
Personal Data may be transferred outside the European Union and the European Economic Area (“EU/EEA”), including but not limited to, the United States of America, China, Australia, Singapore and Argentina as well as other locations and jurisdictions in which we conduct our business. Such transfers outside the EU/EEA are performed subject to appropriate safeguards such as standard data protection clauses adopted or otherwise approved by the EU Commission in accordance with the GDPR.
- Retention Period
We strive to retain Data Subjects’ data only for the period we need them. If a customer decides to stop working with us, we will only retain the customer’s personal data inside the application for 2 months. Logs about customers’ activities are automatically deleted even faster – within one month. If the processing of personal data is based on consent, we may process the data until the consent is withdrawn.
- Data Subjects’ Rights
Data Subject has a right to request from us:
- Access to and rectification or erasure of Data Subject’s Personal Data
- For restriction of processing concerning the Data Subject or to object to processing
- To receive, under certain preconditions, Data Subject’s Personal Data in a structured, commonly used and machine-readable format and to transmit those data to another controller
- Data Subject may exercise the aforementioned rights by contacting our support or client partners. We shall endeavor to comply with legitimate requests by Data Subjects as quickly as possible.