Privacy Policy
Introduction
The VERSO ALTIMA Group conducts business in several countries and processes personal data in accordance with applicable data protection laws.
Pursuant to Articles 13 and 14 of Regulation (EU) 679/2016 (hereinafter: GDPR), this Privacy Policy aims to inform data subjects about how the VERSO ALTIMA Group (hereinafter: Company) processes their personal data in the context of providing its services. It is also intended to help data subjects understand how they can exercise their rights under the GDPR.
- Data holder (“Controller” in the context of Article 4 (7) of the GDPR)
VERSO ALTIMA d.o.o.
City Island
Buzinski krči 3B
HR-10010 Zagreb, Croatia
Telephone: +385 1 6596 600
Fax: +385 1 6536 873
E-mail: info@versoaltima.com
- DATA PROTECTION OFFICER
Telephone: +385 1 6408 036
E-mail: gdpr@versoaltima.hr
Requests regarding the processing of personal data should be submitted to the DPO Contact Information; responses will comply with GDPR deadlines.
- Principles applicable to the processing of personal data
The Company’s processing of data subject personal data is based on the principles of correctness, lawfulness, transparency, and the protection of confidentiality and fundamental rights, in compliance with the GDPR and the guidelines issued by the Privacy Authorities in the respective countries (hereinafter jointly referred to as “Privacy Legislation”).
- The categories and types of personal data processing
The personal data of data subjects that may be processed by the Company primarily depends on how they use the Company’s services and how such data, either directly or indirectly, is provided to the Company.
For more details, the DPO should be contacted.
- Purpose and legal basis of the data processing
The Company processes the personal data of data subjects to:
- prevent, detect, and mitigate fraud, security breaches, and potentially prohibited or illegal activities;
- resolve disputes with data subjects;
- identify and resolve problems that users/customers may encounter when using the website (e.g., blocked or non-functioning pages) and to provide a better experience for users/customers;
- send notifications of any disruptions related to the services;
- publish and manage feedback issued by users/customers;
- carry out marketing activities;
- to manage the business relationship, communication of updates, or risk management with business partners;
- to take professional photographs of employees for marketing and employer branding purposes;
- to protect persons and property via video surveillance (more details about personal data processing can be found under point 5.2 of this policy);
- for keeping records of visitors to the Company.
The processing carried out for the mentioned purposes, according to Art. 6 (1) (f) of the GDPR, is based on the legitimate interest of the Company or of third parties, while respecting the interests, rights, and fundamental freedoms of the data subject.
The Company processes the personal data of data subjects for:
- responding to requests for exercising data subjects’ rights;
- fulfilling legal obligations towards third parties;
- employment.
Pursuant to Article 6 (1) (c) of the GDPR, the processing carried out for the mentioned purposes is based on a legal obligation to which the Company is subject.
The Company processes the personal data of data subjects:
- for the purposes of performing contractual obligations under the business cooperation agreement.
Pursuant to Article 6 (1) (b) of the GDPR, the processing carried out for the mentioned purposes is based on the performance of a contract to which the data subject is a party.
The Company processes the personal data of data subjects:
- after the recruitment process ends;
- for the purpose of responding to the inquiry on the website.
Pursuant to Article 6(1)(a) GDPR, the processing carried out for the mentioned purposes is based on specific consent expressed by the data subject.
5.1 Recruitment
During the recruitment process, the Company may collect and process the following categories of personal data: identification details (name, date of birth, contact information); CV, cover letter, and employment history; education; qualifications; references; interview notes; assessment results any other information you voluntarily provide
Personal data are processed for:
- assessing your suitability for the role;
- communicating with you during the recruitment process;
- conducting background and reference checks (where applicable).
The legal bases for processing are:
Article 6(1)(b) GDPR – processing necessary for entering into a potential employment contract;
Article 6(1)(f) GDPR – legitimate interest in selecting suitable candidates.
During the recruitment process, your data may be shared with third-party recruitment agencies.
5.2 Processing personal data via video surveillance
Purpose of video surveillance
Video surveillance is implemented to ensure:
- the safety of staff, visitors, and contractors;
- protection of the company’s property and information;
- prevention, detection, and investigation of unauthorized access, theft, or other criminal activities;
- support of emergency and evacuation procedures.
The system is not used for monitoring employee performance or non-security purposes.
Lawful Basis for Processing
Processing personal data via video surveillance is based on Legitimate interests Art. 6(1)(f) of the GDPR.
Categories of Data Collected
- video footage capturing individuals in monitored areas;
- date and timestamp of recordings;
- potential environmental information relevant to security events.
Special categories of personal data (e.g., biometrics, racial/ethnic information) are not collected.
Scope and Location of Surveillance
Cameras monitor:
- entry and exit points;
- critical areas containing IT infrastructure or sensitive assets;
- common areas relevant for security purposes.
Data Retention and Deletion
- footage is stored for 72 hours, and a maximum of 6 months with documented justification;
- footage related to incidents may be retained longer, but only as necessary for investigation, with documented justification;
- data is permanently deleted or overwritten after the retention period.
Data Access and Disclosure
Authorized access:
- DPO, Security Personnel, System Administrator, and external maintenance providers.
Disclosure to third parties:
- law enforcement or regulatory authorities in case of criminal investigations;
- internal investigations related to unauthorized access or security breaches;
- viewing real-time or recorded footage;
- copying, downloading, or deleting footage as authorized.
Security Measures
- restricted access for authorized personnel only;
- physical security controls for CCTV infrastructure;
- encryption of stored and transferred footage where feasible;
- security audits and training for all personnel with CCTV access.
Transparency and public information
- signage: clear notices displayed at entrances and monitored areas indicating CCTV operation;
- policy availability: video surveillance policy is accessible on the Company’s website.
- additional information may be provided in request forms for further clarification.
- The Cookies
Cookies are small text files that your browser saves on your device (e.g., computer, phone, or tablet) when visiting a website.
The Company uses cookies that may be stored on or read by your device to recognize it each time you visit the Company’s website (hereinafter “Website”). This allows the Website to recognize your device the next time you visit us, to offer you a personalized experience when moving through it.
The cookies Company uses on this site are technical cookies that are necessary for the functioning of the Website and that enable basic functions (e.g., login, security), which is why Company cannot disable them, and Company does not need your consent to use this type of cookie.
Cookies on the Website are not intended to spy on users; they do not follow everything the user does, and are not malicious code or a virus. They are also not connected to spam and are not intended exclusively for advertising. The Website cannot access your personal information and files on your device.
You can set your browser to block these cookies or to warn you about them, but in that case, some parts of the site will not work. It should be noted that the Company Website only functions optimally if cookies are enabled.
- Data retention
The Company retains your personal data collected through the contact form on the website until your inquiry is resolved, and for a maximum of one month.
Personal data collected during the recruitment process will be deleted after the process ends, unless you agree for us to keep it longer for future opportunities.
The Company’s internal document regulates retention and deletion periods of employee portrait photos.
Employment data is stored in accordance with the provisions of Art. 9. Rulebook on the content and method of keeping records of workers employed by the employer (Official Gazette No. 55/24), the duration of storage varies by type of document.
The data collected for the performance of a contract will be retained only as long as necessary for the purposes. Retention periods will be determined based on contractual and legal obligations.
Data collected based on the consent is retained for the duration of the consent, and may be revoked at any time, in whole or in part, by submitting a written statement to gdpr@versoaltima.hr.
The data collected based on the Company’s legitimate interests is retained only as long as necessary to fulfill these purposes. The Company periodically assesses the retention of personal data to ensure that it remains necessary and proportionate to the legitimate interests identified in the Company’s balancing test. The data subject is guaranteed the right to object in accordance with Article 21(1) of the GDPR in relation to data collected based on the legitimate interests of the Company or third parties.
All data collected pursuant to legal obligations is stored in accordance with applicable legal requirements.
Upon expiry of the retention period, the data subject’s data is deleted or permanently anonymized.
- Recipients of personal data
The personal data collected may be processed by subjects or categories of subjects acting as data processors according to Article 28 of the GDPR, or by subjects authorized to process personal data according to Article 29 of the GDPR.
In the exercise of its activities, the Company transmits the data subjects’ personal data according to Article 6 (1) (b) of the GDPR, for the performance of a contract to which the data subject is a party or to take steps at the request of the data subject before entering into a contract in compliance with their respective contractual or legal obligations.
Except for the aforementioned cases, personal data will not be disclosed to any persons, entities, or authorities, unless disclosure is required by law or regulation.
- Transfer of personal data to a third country or international organization
Personal data may be transferred outside the European Union. Any transfer of data outside the European Union or the EEA will be conducted in full compliance with the measures outlined in Articles 45 and 46 of the GDPR (e.g., the Standard Contractual Clauses).
- Rights of the data subject
The data subject has the right to request at any time:
- the confirmation of the existence or non-existence of personal data concerning the data subject, even if not yet registered, provided in a concise, transparent, intelligible, and easily accessible form, using simple and clear language;
- the personal data that the Company is processing, and the access to the personal data, with the following information:
- the origin of the personal data,
- the purposes and methods of processing,
- the legitimate interests pursued by the Company or by third parties,
- the information on any recipients or categories of recipients of the personal data,
- the Company’s intention, if any, to transfer personal data to a third country or an international organization,
- the retention period of the personal data,
- the logic applied, as well as the importance and expected consequences of such processing for the data subject, in the event of processing carried out with electronic instruments as part of an automated collection and/or profiling process,
- the identification details of the Company, the data processors, the designated representative (if any), and the data protection officer (if any),
- the subjects and categories of subjects to whom the personal data may be communicated, or who may become aware of the data in their capacity as designated representative in the territory of the State, data processors, or persons in charge of data processing.
- the possibility of lodging a complaint with a supervisory authority,
- the update, recalibration, or, where interested in it, integration of the data,
- the cancellation, anonymization, or blocking of data processed in violation of the law, including data whose storage is no longer necessary for the purposes for which it was collected or subsequently processed,
- the restriction of processing,
- the portability of personal data to another data controller,
- the withdrawal of consent to the processing,
- the right to oppose, in whole or in part, the processing of personal data for legitimate reasons, even if it is relevant to the purpose of collection.
To exercise these rights, the data subject may contact the Company at any time by phone, email, or by submitting a written request to the contacts listed in point 2 of this Policy.
The Company will address the data subject’s requests within one month of receipt.
Depending on the complexity and number of requests received by the Company, this period may be extended by up to two months. In such a case, the Company will inform the data subject of the deadline extension and the reasons for it within one month of receiving the request.
If the response is considered unsatisfactory, or if the processing of the data subject’s personal data is believed to violate data protection law or if their data protection rights have been violated in any other way, the data subject has the right to lodge a complaint with a supervisory authority in accordance with Article 77 of the GDPR, particularly in the Member State of habitual residence, place of work, or location of the alleged infringement.
- Review and Updates
This Privacy Policy will be reviewed at least annually or following:
- changes in data processing operations;
- updates to GDPR, national privacy laws, or guidance;
- due to significant incidents or risks impacting personal data processing.
