GDPR Compliance
Our comprehensive commitment to data protection and your privacy rights under the General Data Protection Regulation.
Our GDPR Commitment
ngCommit s.r.o. is committed to complying with the General Data Protection Regulation (GDPR) and protecting the privacy rights of all individuals. As a Czech Republic-based enterprise technology company, we implement comprehensive data protection measures across all our services.
Data Controller Information
130 00 Prague, Czech Republic
Your Rights Under GDPR
As a data subject, you have the following rights under GDPR:
- Right to Information: You have the right to be informed about how we collect and use your personal data. This information is provided in our Privacy Policy.
- Right of Access: You can request copies of your personal data. We will provide this information within one month of your request.
- Right to Rectification: You have the right to request correction of any inaccurate or incomplete personal data we hold about you.
- Right to Erasure ("Right to be Forgotten"): You can request deletion of your personal data when it's no longer necessary for the original purpose or you withdraw consent.
- Right to Restrict Processing: You can request limitation of processing in certain circumstances, such as when you contest the accuracy of the data.
- Right to Data Portability: You can request your data in a structured, commonly used, and machine-readable format for transfer to another service.
- Right to Object: You have the right to object to processing based on legitimate interests, direct marketing, or processing for research purposes.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us using the information below. We will respond to your request within one month.
Contact Methods
- Subject Line: "GDPR Rights Request"
- Post: Jičínská 226/17, Žižkov, 130 00 Prague, Czech Republic
Please include sufficient information to verify your identity and specify which right you wish to exercise.
Data Security Measures
We implement appropriate technical and organizational measures to ensure data security:
- Encryption of data in transit and at rest
- Access controls and authentication
- Regular security assessments and updates
- Staff training on data protection
- Secure backup and recovery procedures
- Incident response procedures
Data Processing Activities
Website Visitors
Purpose: Website functionality and improvement
Legal Basis: Legitimate interests
Data Types: IP address, browser information, usage patterns
Retention: 24 months
Consultation Requests
Purpose: Providing enterprise consultation services
Legal Basis: Consent and legitimate interests
Data Types: Name, email, company details, project information
Retention: 3 years from last contact
Client Projects
Purpose: Contract performance and service delivery
Legal Basis: Contract performance
Data Types: Project data, technical specifications, business information
Retention: 7 years from project completion
Data Breach Procedures
In the event of a data breach, we will:
- Notify the relevant supervisory authority within 72 hours
- Inform affected individuals without undue delay if there is a high risk to their rights
- Document all breaches and remedial actions taken
- Implement additional security measures to prevent future occurrences
International Data Transfers
We primarily process data within the European Union. Any international transfers are conducted in accordance with GDPR requirements, including appropriate safeguards such as adequacy decisions or standard contractual clauses.
Complaints and Supervisory Authority
If you have concerns about our data processing activities, you can file a complaint with the Czech supervisory authority:
Úřad pro ochranu osobních údajů
(Office for Personal Data Protection)
Pplk. Sochora 27, 170 00 Prague 7, Czech Republic
Phone: +420 234 665 111
Website: www.uoou.cz
Updates to GDPR Compliance
We regularly review and update our GDPR compliance measures. Any significant changes will be communicated through our website and to affected individuals where required.
Exercise Your Data Rights
Have questions about data processing or want to exercise your GDPR rights? Our data protection officer is here to help.