POPP Logo

Privacy Policy

Personal Data Processing Information

POPP s.r.o, ID: 25507869, with its registered office at náměstí Okružní 828, 696 15 Čejkovice, Czech Republic, entered in the Commercial Register maintained by the Regional Court in Brno, file ref. C 27268, acting as the controller of personal data (hereinafter the "Controller"), hereby informs data subjects, pursuant to Act No. 110/2019 Coll., on the processing of personal data, as amended (hereinafter the "Act"), and in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter the "Regulation"), about the processing of personal data that the Controller may process about data subjects.

Data Controller Contact Details

The Controller can be contacted either in writing at the registered office address or electronically:

  • by e-mail: info@popp.cz
  • via Czech data box (datová schránka): uaft4i6

The Controller is entitled to request proof of identity from the contacting person in order to ensure the protection of personal data; for the same reason, all communication between the Controller and the contacting person may be monitored.

Processed Data and Scope of Processing

The Controller will process the provided personal data in accordance with the Act and the Regulation to the extent to which they were provided to the Controller and only in connection with the purpose of processing.

In particular, the following personal data will be involved:

  • contact details — e.g. e-mail address, telephone number, bank details, contact address, etc.,
  • data provided beyond the scope of relevant legal regulations, processed on the basis of the data subject's consent to the processing of personal data.

Purpose of Personal Data Processing

The personal data provided to the Controller may be processed for the purpose of:

  • performance of a contract concluded between the Controller and the data subject,
  • mediation or preparation of legal documents necessary for the execution of a contract between the Controller and the data subject or contractual obligations arising from such a contract,
  • fulfilment of the Controller's legal obligations and legitimate interests,
  • communication between the Controller and the data subject, sending newsletters and other commercial communications with updates on the Controller's activities or activities and events related to the Controller's services, sending promotional e-mails, all in writing and by electronic means (in particular e-mail, SMS, telemarketing) pursuant to Act No. 480/2004 Coll., on certain information society services, as amended,
  • offering goods and services of the Controller or other entities whose services or products relate to the Controller's services,
  • other marketing activities of the Controller.

Legal Basis for Personal Data Processing

Personal data are thus processed by the Controller on the basis of the following legal titles:

  • consent of the data subject,
  • necessity of processing personal data for the performance of a contract concluded between the Controller and the data subject, if such a contract has been concluded,
  • necessity of processing personal data for compliance with a legal obligation applicable to the Controller,
  • necessity of processing personal data for the purposes of the Controller's legitimate interests.

In the case of granting consent to processing, such consent is entirely voluntary; there is no legal obligation to provide it and there is no penalty for not providing it.

Duration of Personal Data Processing

Personal data will be processed for the duration of the contractual relationship and subsequently for a further 10 years, or for a period in accordance with the applicable legal regulations of the Czech Republic on document archiving (if such a period is longer).

Personal data provided to the Controller on the basis of the data subject's consent will be processed for an indefinite period, until the consent to their processing is withdrawn.

Persons Authorised to Process Personal Data

The processing of personal data is carried out by the Controller, or by third parties who provide means and guarantees of appropriate and proper processing of personal data, data security and protection of your rights (hereinafter the "Processors"). The Processors will have direct access to your personal data only for the time strictly necessary and only to the extent strictly necessary for the implementation of processing. The Processors are:

  • IT system administrators and software service providers,
  • external partners — providers of payroll and accounting services, financial, tax and legal advisory services, etc.

Recipients of Personal Data

The Controller informs that the data subject's personal data may be transferred to third parties on the basis of a legal obligation. These third parties are in particular:

  • public authorities, administrative bodies, courts, the Czech Social Security Administration, health insurance companies,
  • external partners — providers of payroll and accounting services, financial, tax and legal advisory services, etc.

Data Subject Rights

In relation to personal data that are subject to processing, the data subject has in particular the following rights:

  • the right to be informed about the processing of their personal data,
  • the right of access to personal data,
  • the right to have personal data corrected or supplemented,
  • the right to erasure of personal data (the so-called "right to be forgotten"),
  • the right to request restriction of processing,
  • the right to request data portability to another controller,
  • the right to object to the processing of personal data,
  • the right not to be subject to automated individual decision-making with legal or similar effects, including profiling,
  • the right to be informed of a personal data breach in certain cases,
  • other rights set out in the General Regulation.

Consent to the processing of personal data may be withdrawn at any time during the period of processing. The withdrawal of consent must be delivered in writing or by electronic communication (e-mail, data box) to the Data Controller. The effects of the withdrawal of consent begin from the day the withdrawal is delivered to the Data Controller and do not apply to the processing of personal data that is necessary and takes place on the basis of a legal ground other than such consent.

Right to Lodge a Complaint with a Supervisory Authority

If the data subject has doubts about compliance with the principles contained in this document or in the General Regulation, or suspects that the activities of the Data Controller are violating their rights, they have the right to lodge a complaint against the Data Controller with the relevant supervisory authority (the Office for Personal Data Protection).

Objections to Personal Data Processing

Objections to the processing of personal data may be filed for the reasons stated in the Act and the Regulation. In cases where the option to file an objection is exercised, the Controller shall no longer process the personal data, unless it has a legitimate interest or the processing of personal data serves the public interest.

Personal Data Security

Personal data provided for processing will be secured by security procedures and technologies determined by the Controller for this purpose, which have been assessed as appropriate and adequate.

In the event of a security breach and possible disclosure of the data subjects' personal data, the Controller will immediately inform the data subject as well as the relevant supervisory authority, in accordance with the obligations set by legal regulations.

Consent granted in electronic form (in particular by confirming or "clicking" consent via the internet or another electronic network) is considered unambiguous, specific and genuine consent, granted by its provider in a form equivalent to written consent.

Processing of Personal Data in the POPP Service Mobile Application

The following part concerns exclusively the POPP Service mobile application (package name cz.erokotech.popp_go), which is developed and published on Google Play by ErokoTech, s.r.o. The application is operated by the Controller, who determines the purposes and means of the processing of personal data. ErokoTech, s.r.o. processes personal data to the extent necessary for the development, operation, maintenance and technical support of the application and acts, to that extent, as a processor.

Who the application is intended for

POPP Service is an internal work tool intended exclusively for the Controller's installers and for its contracted partners who carry out the installation and servicing of pool enclosures.

The application is not intended for the general public or for the Controller's end customers. Access to the application is granted only to persons who have an existing employment or partner relationship with the Controller.

The user of the application is therefore an installer or a contracted partner. However, personal data of the Controller's customers may also be processed through the application as part of the data on individual jobs.

What data the application processes

The application processes the data necessary for its function, in particular:

  • identification and login details of the user — in particular the e-mail address and access credentials. The password is not stored in the application; the login details are passed to the Controller's internal NER CRM system, where the user is authenticated,
  • job data — information relating to a specific installation or service visit, including the data needed to organise and record the work carried out,
  • customer data — personal data of customers held in the NER CRM system and made available to the user of the application to the extent necessary to carry out the job,
  • photographs and other files — in particular photographs taken or selected by the user in connection with an installation, servicing or other performance of a job.

The application processes only the data needed for its work purpose. It does not use the data for advertising purposes and does not create user profiles.

Access to photographs and the camera

The application allows the user to create photographic documentation of the installations and service visits carried out. The camera is used only in connection with the photo-taking function in the application, and the application does not take photographs without the user's knowledge and active action.

Where the application allows photographs already stored on the device to be selected, it may access the photographs selected by the user, to the extent necessary, in order to attach them to the relevant job. The application does not access the user's photographs for any other purpose.

Purpose of processing

Personal data processed through the POPP Service application are used in particular for the following purposes:

  • verifying the user's identity and securing access to the application,
  • organising, recording and managing installations and service visits,
  • making available the data needed to carry out a specific job,
  • creating and maintaining photographic documentation of the work carried out,
  • evidencing the course and outcome of an installation or service visit,
  • handover and acceptance of the work,
  • handling complaints and asserting or defending legal claims,
  • ensuring the proper operation and security of the application.

Legal basis for processing

The legal basis for the processing may differ according to the specific type of personal data and the purpose of their processing.

In the case of data of application users, the processing is carried out in particular in connection with the employment or contractual relationship with the Controller and for the purpose of meeting employment and contractual obligations.

In the case of customer data and data relating to specific jobs, the processing is carried out in particular for the purpose of performing contractual obligations towards customers, complying with the Controller's legal obligations, and on the basis of the Controller's legitimate interest in the proper recording, documentation and evidencing of the work carried out, including the protection of its rights and legal claims.

Access to the data and their storage

The following may have access to the data processed through the application, to the extent necessary to perform their tasks:

  • authorised employees of the Controller,
  • the Controller's installers and contracted partners, to the extent of the data needed to carry out a specific job,
  • ErokoTech, s.r.o. as the provider of development, technical administration and support of the application,
  • Amazon Web Services (AWS) as the provider of the cloud infrastructure and storage that the Controller uses to store data and photographs.

The data used by the application are linked to the Controller's internal NER CRM system. The user's login details are passed to NER CRM, where their access authorisation is verified.

Photographs and files relating to jobs are stored using the Amazon S3 service.

Neither ErokoTech, s.r.o. nor Amazon Web Services use the personal data for their own marketing purposes. Personal data are not sold or rented to third parties.

Retention period

Data of application users are processed for the duration of their employment or contractual relationship with the Controller, or for the period during which their access to the application is authorised. Once the relationship ends, the Controller deactivates the user's access.

Customer data, job data and photographic documentation are retained for the period necessary to fulfil the Controller's contractual and legal obligations, in particular for the period needed to settle warranties, complaints and any legal claims.

Once the relevant period has elapsed, the personal data are erased, anonymised or otherwise processed in accordance with legal regulations and the Controller's internal data retention rules.

Account closure and data deletion

User accounts in the POPP Service application are created and administered by the Controller.

A user may request the closure of their account or the exercise of their rights in connection with the processing of personal data at the e-mail address info@popp.cz.

The closure or deactivation of a user account does not necessarily result in the immediate deletion of all data relating to specific jobs. Data that the Controller is required to retain under legal regulations, or that are necessary to protect its rights and legal claims, may be retained for the period strictly necessary.

Data security

Data are transmitted between the application, NER CRM and the Controller's other systems by means of secure data transfer.

Access to the application is protected by user authentication and is granted only to persons with valid authorisation. Access to data in the Controller's internal systems is restricted according to the employment or contractual authorisation of each individual.

The Controller and its processors adopt appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or destruction.

Rights of users and other data subjects

Users of the application and other persons whose personal data are processed through it have the rights provided by the applicable personal data protection legislation, in particular the right of access to personal data, to their rectification or, where applicable, erasure, to restriction of processing, to object to the processing, and the right to data portability, provided that the statutory conditions for exercising them are met.

These rights can be exercised using the contact details given in the "Data Controller Contact Details" section.

A data subject also has the right to lodge a complaint with the Czech Data Protection Authority (Úřad pro ochranu osobních údajů).

Note on the mobile application and Google Play

The information provided in this part corresponds to the intended functioning of the POPP Service application. The Controller will also keep the information on data processing in the application, and the details given in the Data safety section on Google Play, up to date so that they correspond to the actual functioning of the application and the technologies used.