•
"Data controller": the Company, and furthermore the natural or legal person or any
other body which, alone or jointly with others, determines the purposes and means of
the processing of personal data.
•
•
"Data processor": a natural or legal person, public authority, agency or other body
which processes personal data on behalf of the controller.
"Recipient": a natural or legal person, public authority, agency or another body, to
which the personal data are disclosed, whether a third party or not. Public authorities
that may receive personal data in the framework of a particular inquiry in accordance
with Union or Member State law shall not be regarded as recipients; the processing of
those data by those public authorities shall be in compliance with the applicable data
protection rules according to the purposes of the processing.
•
•
"Third party": a natural or legal person, public authority, agency or body other than
the data subject, controller, processor and persons who, under the direct authority of the
controller or processor, are authorized to process personal data.
"The data subject's consent": any freely given, specific, informed and unambiguous
indication of the data subject's wishes by which he or she, by a statement or by a clear
affirmative action, signifies agreement to the processing of personal data relating to him
or her.
•
•
"Special categories of personal data": personal data revealing racial or ethnic origin,
political opinions, religious or philosophical beliefs, or trade union membership, and
the processing of genetic data, biometric data for the purpose of uniquely identifying a
natural person, data concerning health or data concerning a natural person's sex life or
sexual orientation.
"Data concerning health": personal data related to the physical or mental health of a
natural person, including the provision of health care services, which reveal information
about his or her health status.
•
•
"Data transfer": making personal data available to a specific recipient.
"Personal data breach": a breach of security leading to the accidental or unlawful
destruction, loss, alteration, unauthorized disclosure of, or access to, personal data
transmitted, stored or otherwise processed.
Other terms defined by the GDPR are contained in Article 4 thereof.
3. The Scope, Limitations, and Basic Principles of Data Processing
The Company processes the personal data of Data Subjects only to the extent and for the
duration necessary for the purposes defined above. Only personal data that is essential for the
purpose of data processing and is suitable for achieving that purpose may be processed.
The Company takes all necessary measures to ensure the accuracy, completeness, and up-to-
date nature of personal data.However, considering that the Data Subjects are responsible for
the authenticity of the data provided, Data Subjects are obliged to report any changes to their
data as soon as possible after the change, but no later than within 3 working days, providing
the new data to the Company at the contact details indicated in this Notice.
The Company does not perform automated data processing or profiling.
3.1. The source of the data: The Company receives the data of the Data Subjects either
directly from the Data Subjects or from its Clients who provide the data of their contributors,