Contractors

I.

Controller

 

For the Processing of Your personal data, Controller is Aurubis Bulgaria AD, a joint stock company, registered in the Company Register with the Registry Agency under uniform ID code 832046871, having its registered seat and management address in:

 

Aurubis Bulgaria AD

            Industrial zone

            2070 Pirdop

            Bulgaria

 

Aurubis Bulgaria AD is represented by Tim Kurt, Executive Director.

 

II.

Contact details of the Data Protection Officer

 

Data Protection Officer, Security and Risk Management department, Aurubis Bulgaria AD, Industrial zone, 2070 Pirdop

Tel.:        +359 7286 2280

Fax:        + 359 7286 2646

E-mail:   d.temelkova(at)aurubis.com

 

III.

Collection and processing of personal data of Contractors employees, who work on the territory of Aurubis Bulgaria

1.

 

 

 

 

 

 

 

 

 

2.

 

 

 

 

3.

 

 

3.

 

 

5.

 

 

 

 

 

 

6.

When issuing an access card, as part of the security and safety measures, review and transfer of the personal data from the identity document is performed, via reader, into the access control system, or the personal data is entered manually into the system. We collect and process the following data:

  • Name;
  • Personal identification No or date of birth;
  • Photo;
  • Registration plate No of the vehicle (only in case access with vehicle in needed)

 

Video Surveillance – on the territory of the company are located cameras for 24-hour video surveillance designed for security and operational purposes; on the entrances of the company are located cameras for 24-hour body temperature measurement that aim is to prevent epidemic/ pandemic disease spreading.

 

Photos - on the territory of the company, contractors employees are shot for proving violations.

 

Copies of qualification, driving license  and training certificates, as required by the OHS procedures and work instructions in Aurubis Bulgaria AD and form FM-HNSD-006-B/E.

 

Communication details, namely:

  • Names;
  • one or more valid e-mail addresses
  • address     
  • phone number (landline and/or mobile)

·         fax number

 

Personal data collected directly from the employees in written or verbal, generated by the Health service department throughout pandemics periods, in case the person has symptoms or direct contacts with infected people:

·         Identification data: names, personal address, position, phone number;

·         Contacts within Aurubis Bulgaria: names, positions, companies;

·         Results of pandemic’s specific tests;

·         Body temperature.

 

The processing of personal data in p. III (1- 6) is necessary for the following purposes:

·         Security management – including but not limited to activities related to access control, video surveillance, ensuring security of the premises, assets and information held by the company, and for the purposes of preventing and investigating theft, fraud, abuse, conflict of interest, audits and controls. The processing of personal data for these purposes is based on the legitimate interests of the company to ensure the safety and security of its assets as well as its employees against any possible risks;

  • Operational management – including but not limited to establishment, implementation and management of the business activities of the company, for example: maintenance and monitoring of the use of internal networks and information systems, exchange of written correspondence or other communication, health and safety management, protection against serious cross – border threats to health. The processing of personal data for these purposes is based on the legitimate interests of the company to manage its material resources and workforce, including providing network and information security in its organization, issuing  invoices as well as managing its budget effectively;

·         Compliance with regulatory requirements and settling of legal disputes - including, but not limited to, the processing of personal data in accordance with regulatory requirements (e.g tax, social, health, trade, labor and other applicable legislation). The processing of personal data for these purposes is done on the basis of compliance by the company with applicable legal obligations.

 

Personal data entered into the access control system is processed and stored for up to 3 years from the termination of the contract with Aurubis Bulgaria AD or a notice from the Employer that the person is no longer its employee.

Video records are processed and stored for up to 2 months of creation in compliance with the Private Security Services Legislation. The video records of sites under the Waste Management Act are processed for up to 1 year.

 

Photos of contractor’s employees are processed for a period of 5 years from committing a violation, unless they have become necessary within that period to establish, exercise or protect of any legal claims or administrative proceedings against Aurubis Bulgaria AD. In this case they will be stored until the end of the relevant legal procedure.

Personal data which is processed in case of work accidents, is stored for up to 5 years after the event.

 

Video records and indicators of body temperature measurements are processed for up to 2 weeks.

 

Contractor’s employees provide their personal data to the Company on a voluntary basis. If they do not provide their personal data, the company will not be able to allow them to work on the territory because it will not be able to fulfill its legitimate interests and/ or legal obligations or will not be able to perform its obligations towards the public interest in the area of public health, such as protecting against serious cross-border threats to health.

The grounds for processing the personal data under p. III are based on Regulation (EU) 2016/679 as follows: Article 6 (1) (b) of Regulation (EU) 2016/67 and Article 6 (1) (c) of Regulation (EU) 2016/679 and/ or Article 6 (1) (f) of Regulation (EU) 2016/679 and Article 6 (1) (d) of Regulation (EU) 2016/679, in relation with Article 9 (2) (h) of Regulation (EU) 2016/679 and Article 9 (2) (i) of Regulation (EU) 2016/679.

 

IV.

Collection and processing of Personal Data in other cases

 

In other cases, different than the mention in p. III, personal data is collected and processed only if provided voluntarily, as follows:

 

1.

If the employee is communicating with us while acting in a professional capacity for one of our business partners, we store and process professionally used contact data, as follows:

  • business partner for whom you are working
  • title, first name, last name
  • position in the organization of our business partner
  • one or more valid e-mail addresses
  • address     
  • phone number (landline and/or mobile)
  • fax number

 

The processing of the above mentioned personal data serves for the following purposes:

  • in order to be able to identify you as our contact with our business partner;
  • for business correspondence with You;
  • in order to inform you about the products, services, and Aurubis Group companies;
  • in order to offer you Aurubis Bulgaria’s products and services;
  • to initiate, execute, and terminate contracts in connection with the business relationship;
  • to maintain the business relationship with Aurubis Bulgaria;
  • for invoicing;
  • to fulfill legal obligations, especially for the prevention of fraud and money laundering.

 

The grounds for processing this personal data are based on Regulation (EU) 2016/679 as follows: 1) Article 6 Paragraph 1(b) GDPR (General Data Protection Regulation) and Article 6 Paragraph 1(f) GDPR (General Data Protection Regulation) in order to maintain and conduct the business relationship for the length of the business relationship or until the Aurubis Bulgaria business partner communicates that You are no longer employed by them; 2) In cases when we are obligated to store the data for a longer period of time pursuant to Article 6 Paragraph 1 Sentence 1(c) GDPR (General Data Protection Regulation) due to storage and documentation obligations according to legal tax, commercial regulations and other applicable regulations; 3) In cases when You have consent to a longer storage period pursuant to Article 6 Paragraph 1 Sentence 1(a) GDPR (General Data Protection Regulation).

2.

If Aurubis Group companies provide personal data of the type described above to us as allowed for the purposes mentioned above, especially for cases in which You have contacted an affiliated company of ours with an issue that relates to us and not that affiliated company.

 

V.

Provision of personal data to third parties         

 

Aurubis Bulgaria AD uses service providers, who process and store personal data ("Personal Data Processors" pursuant to Article 28 of Regulation (EC) 2016/679). In particular, this is applicable to the security company and its employees, legal advisers and other third parties. These processors work only on contractual basis with Aurubis Bulgaria AD and store and process personal data according to the company's instructions.

If You contact Aurubis Bulgaria regarding issues that concern a company affiliated with Aurubis Bulgaria, in individual cases we will provide this affiliated company with your personal data.

 

The information for confirmed infected employees, in relation with p. III (6), shall be disclosed only in case it is necessary to assess whether employees of Aurubis Bulgaria AD or employees of other contractors had been in contact with the infected person, and respectively are infected too.

 

Out of these three circumstances, data will only be provided in individual cases and in a volume that is in accordance with a specific legal obligation of Aurubis Bulgaria AD, as well as in cases where You submitted consent to provide your data.

 

VI.

Your rights as Data Subject

 

·         Right to withdraw consent at any time (Article 7 (3) of Regulation (EC) 2016/679). As a consequence, the company will not be able to continue processing this data if it was based on consent.

·         Right to request confirmation whether the company processes personal data, and if so, information on the storage and processing (Article 15 of Regulation (EC) 2016/679). In particular, information may be requested about the purposes of processing; categories of personal data; the categories of recipients to whom personal data will be or have been provided; storage period; the right to request correction, erasure and / or limitation of processing, to object to such processing and to lodge a complaint with a supervisory authority; information about the source from which the company have received personal data when it was not collected by the subject; information on the availability of automated decision making (including profiling) and, if applicable, relevant detailed information.

·         Right to request immediate rectification of the personal data (Art. 16 of Regulation (EU) 2016/ 679).

·         Right to request erasure of the personal data, unless its processing is necessary:

1) For exercising the right of freedom of expression and information;

2) For compliance with a legal obligation;

3) For reasons of public interest;

4) For the establishment, exercise or defense of legal claims (Art. 17 of Regulation (EU) 2016/ 679).

·         Right to request restriction of the processing of the personal data if: contest their accuracy; the processing is unlawful; the company does not need the personal data any more, but the data subject require them for establishment, exercise or defense of а legal claim; if the data subject has objected to processing pursuant to Article 21 (1) of Regulation (EU) 2016/ 679 (Art. 18 of Regulation (EU) 2016/ 679).

·         Right to receive the personal data in a structured, widely used and machine readable format or request the transfer of this data to another Administrator (Article 20 of Regulation (EC) 2016/679).

 

When exercising the right to receive personal data or to transfer it to another Controller, more than once within 24 months, Aurubis Bulgaria AD reserves the right, according to Ch. III, Art. 12 par. 5 (a) of Regulation (EU) 2016/679, to require payment of administrative costs of BGN 20 per set of paper copy and BGN 20 per electronic carrier.

 

In order to exercise his rights under the above points, the data subject must contact the Data Protection Officer designated by Aurubis Bulgaria AD:

 

              Address:                   2070. Pirdop, Industrial zone,

              Tel :                         + 359 886 131 999

              E-mail:                      d.temelkova(at)aurubis.com

 

Contractors employee/ Data subject has the right, under Article 77 of Regulation (EC) 2016/679, to lodge a complaint to the Commission for Personal Data Protection (CPDP) by the ways described in the Commission's website. The contact details of CPDP are:

 

Address:                      1592 Sofia, Prof. Tsvetan Lazarov Blvd. 2

Fax:                             02 9153525

E-mail:                          kzld(at)cpdp.bg

 

Aurubis Bulgaria AD will cooperate to CPDP in the handling of such complaints and will comply with all recommendations and/ or instructions issued by the supervisory authority.

Contractors employee/ Data subject also has the right to lodge a complaint at Aurubis Group Headquarters by sending an email to dataprotection(at)aurubis.com .

VII.

Right to object

 

If the personal data is processed on the basis of a legitimate interest of the company pursuant to Article 6 (1) (f) of Regulation (EC) 2016/67, the employee/ data subject has the right to object the processing of these data under Article 21 (1) of Regulation (EC) 2016/679. In this case, the company will not continue the processing of the personal data, unless there are convincing legal grounds for the processing that take precedence over the interests of the data subject, his rights and freedoms or are necessary for the establishment and/ or the defense of legal claims.

 

If the data subject wants to use the right to object, it is enough to send an email to d.temelkova(at)aurubis.com