CATEGORIES OF PERSONAL DATA
For the purposes of the Processing stipulated in point III below, we process your personal data, hereinafter referred to as the “Personal data”. The personal data will include, as appropriate, both your Personal information, and the Special categories of personal data, as defined hereinafter. The “Personal information” means: your name and surname, date and place of birth, job title and name of the company/ entity you belong to, postal address including home address, business address, telephone number, mobile phone number, fax number and email address and other similar data in respect to you, payments carried out, requests and projects, information collected from public sources and databases, information on relevant and important litigation or other court actions initiated against you or by you against one of your third party affiliates, IP address, other personal data regarding your preferences, which may be relevant for any purposes regarding the performance of our services, details and information about your visits to our offices, as well as other data related to interaction with us.
In addition, in the course of our activities, we may process the following Special categories of personal data about you, such as: personal identification number, Identity Card series and number, data on your political opinions, data on your health, data on union membership and data relating to criminal convictions and offences.
We shall collect your Personal data directly from you, in certain circumstances, including:
In certain circumstances, we collect your Personal data from a third party source. For example, we can collect Personal data from your employer, other companies or individuals with which/whom you are connected, governmental agencies, credit bureaus, information or services providers or from public archives.
PURPOSES OF PROCESSING
We process of your Personal data to the extent allowed or required by the applicable law for the following purposes:
In respect of the marketing related communications, we will make available to you, if required by the law, such information only after you select this option to receive such communications and we will provide you the possibility to unsubscribe at any time, if you no longer want to receive marketing related communications from us. We will not use your Personal data when making automated decisions which may affect you or create profiles, other than those described above.
GROUNDS FOR YOUR PERSONAL DATA PROCESSING
Any operation which is the equivalent of a Processing of your Personal data shall be carried out based on one or several of the legal grounds described below:
The Processing is required for the legitimate interests of Fortim Trusted Advisors or of a third party, unless your interests and rights and freedoms prevail over such interests. We use your Personal data for our legitimate interests, namely, to exercise our obligations and rights deriving from an agreement concluded with your company/ entity, in order to improve our performance and the working method and for administrative .
If the applicable legal provisions required your prior and explicit consent for the Processing of some Special categories of personal data, we shall process such data only based on your prior and explicit consent.
We may choose to withdraw your consent in respect of the marketing materials at any time, simply by accessing the “unsubscribe” link in the foot note of every newsletter or invite to events.
DATA TRANSFERS, RECIPIENTS AND LEGAL GROUNDS FOR SUCH TRANSFERS
Furthermore, we may transfer your Personal data to our processors, mainly to the service providers within or outside Fortim Trusted Advisors , with a view to the Processing of your Personal data for the authorised purposes, on our behalf and strictly based on our instructions. Fortim Trusted Advisors will maintain the control over your Personal data and will use appropriate safeguards, as provided under the applicable law, to ensure the integrity and security of your Personal data in relation with those processors.
Otherwise, we will transmit your Personal data only when instructed or authorized by you in this respect or when this is required under the applicable law or by requests from the judicial or public authorities.
We may transfer your Personal data abroad. Certain recipients of your Personal data may be located in countries for which the European Commission has not issued a decision regarding the provision of an adequate level of data protection, namely: the United States of America or some of the countries outside Europe.
Certain recipients outside the European Economic Area (“EEA”) are certified under the privacy agreement concluded between Europe and USA called “EU-US Privacy Shield”, while others are located in countries for which the European Commission issued compliance decisions [Andorra, Argentina, Canada (for private organizations subject to the Personal information protection and electronic documents act), Switzerland, Faroe Islands, Guernsey, Israel, Isle of Man, Jersey and New Zealand]. In each case, the transfer is recognized as providing an adequate level of data protection from the perspective of the European data protection law (Article 45 of GDPR).
We may conclude data transfer agreements based on the Standard Contractual Clauses (European Commission Decision 2010/87/EU and/or European Commission Decision 2004/915/EC) pursuant to Article 46 (5) GDPR or by using other appropriate means, making sure that all other recipients outside the EEA will provide an adequate level of data protection for Personal data and that there are adequate technical and organizational security measures to protect Personal data against accidental or unlawful destruction, accidental loss or alteration, unauthorized disclosure or access and against all other unlawful Processing methods.
SECURITY OF YOUR PERSONAL DATA
Fortim Trusted Advisors has implemented appropriate technical and organizational measures in order to maintain the privacy and security of your Personal data in line with the internal procedures on storage, dissemination and access to Personal data. The Personal data may be kept either stored on our Personal data technological systems or on paper.
Personal data processed for the purposes specified herein shall be retained only as long as it may be necessary during your relation with Fortim Trusted Advisors , as well as subsequently for the retention periods required under the applicable law. Should any legal proceedings be initiated, the Personal data are retained until the end of such proceedings, including throughout any period of appeal or extraordinary appeal, and subsequently erased or archived, as provided under the applicable law.
In principle, your Personal data will be kept for as long as it is required or permitted under the applicable law. Subsequently, after the expiry of such periods or upon your exercise of one of your rights, as provided under the law, we will remove/erase your Personal data from our systems and records and/or will take any actions for their redaction so that you may no longer be identified based thereon.
YOUR LEGAL RIGHTS
If you expressed your consent with respect to the Processing activities, you may withdraw such consent at any time with future effects. Such withdrawal will not affect the legality of the Processing prior to the withdrawal of your consent. As a general rule, if you withdraw your consent, Fortim Trusted Advisors will no longer allow the Processing of your Personal data and will take any appropriate actions to erase any records containing your Personal data. However, if the Processing is mandatory for the provision of Fortim Trusted Advisors services and the Processing may be performed on other legal bases stipulated by the applicable legal provisions, Fortim Trusted Advisors shall proceed to such Processing and will notify you in this respect.
Under the applicable laws, you have the following rights:
You have the right to object, on grounds relating to your particular situation, at any time to the Processing of your Personal data by us and we can be required to no longer process your Personal data. If you have a right to object and you exercise this right, your Personal data will no longer be processed for such purposes by us. Exercising this right will not incur any costs.
Such right may be cancelled, in particular, if the Processing of your Personal data is necessary to take steps prior to entering into a contract or to perform a contract already concluded
You may exercise any of the abovementioned rights and receive more information on such rights by submitting to us, in our capacity as data controller, a written application at the address: Fortim Trusted Advisors , America House, West Wing, 2nd floor, 4-8 Nicolae Titulescu Blvd., Bucharest, 011141, Romania, or via e-mail at [email protected] .
You also have the right to file a complaint with the National Authority for the Supervision of Personal Data Processing.