UHY Axon Audit SA considers the security of your data and the protection of the confidentiality of the information it manages as part of its professional services to be of primary importance. Therefore, it fully follows the legislation of the European Union, the General Data Protection Regulation 2016/679 (hereinafter GDPR), processes personal data only to the extent permitted by law and in accordance with the legal conditions, has taken the technical and organizational measures which is necessary to ensure the secure processing and subsequent deletion of data.
For a complete understanding of our Policy, we list the basic definitions relating to the protection of personal data.
Definitions
- What is “personal data”
The term “personal data” refers to information of natural persons, such as name, postal address, e-mail address, contact telephone number, etc., which can be used to determine the identity of a customer, partner, supplier or visitor.
In fact, according to the GDPR, it is any information that concerns an identified or identifiable living natural person (according to the Regulation “data subject”). That is, any type of information that can lead, alone or in combination, to the identification of a living natural person, constitutes personal data.
What constitutes “processing” of personal data?
The term “processing” includes a broad set of operations performed on personal data, with or without the use of automated means, such as collection, recording, storage, alteration, use, disclosure by transmission, dissemination or any other form of disposal, association or combination, restriction, deletion or destruction.
Who is the “Controller“?
It is the natural or legal person, public authority, agency or other entity that, alone or jointly with others, determines the purposes and manner of personal data processing.
In this case, the Data Controller is: “ UHY Axon Audit SA”
Who is the “processor“?
It is the natural or legal person, public authority, agency or other body that processes personal data on behalf of the data controller.
Who do you consider a “third party” under the GDPR?
Any natural or legal person, public authority, agency or body, with the exception of the data subject, the controller, the processor and persons who, under the direct supervision of the controller or the processor, are authorized to process personal data.
- What is “personal data”
What categories of data do we process?
In the context of its business activity and service provision, the company as Data Controller processes:
- Identification Data such as: name, surname, identity card or passport details.
- Contact details such as: email address and landline/mobile phone numbers.
- Work data such as: job title and company name.
- Financial Data: this consists strictly of data necessary for the fulfillment of the provision of our services (execution of a contract) and the invoicing of said services.
- Closed video surveillance system data such as visitor image for the purpose of protecting persons and goods located in our offices. You can read more about this processing in the Update on the processing of personal data through a video surveillance system
Legal bases and purposes of use of personal data.
“UHY Axon Audit SA” mainly processes only personal data that is necessary for the provision of our services based on the contract you have entered into, the legal basis of this processing is the “execution of the contract”.
Other cases where we process personal data are when the processing is necessary for us to comply with a “legal obligation”, such as keeping records for tax audit purposes, or where we have a “legitimate interest” in carrying out a lawful activity, to the extent that we do not outweighs your own legitimate interest and does not contravene your fundamental rights and freedoms. In exceptional cases, and where none of the above lawful processing grounds apply, we may ask for your “consent” to process some of your personal data. In this case you have the right to refuse to provide it to us or if you choose to provide it to us, to revoke it at any time by sending us an e-mail at data.protection@axon-group.eu Withdrawal of consent does not affect the lawfulness of processing that was based on consent prior to its withdrawal.
Data transmission to third parties
We may transmit data that is necessary for the purposes of the respective processing to the following categories of recipients within the EU:
- To “processors” who provide services to us. In this case, the transfer of data always follows the signing of a contract on the protection of personal data which, among other things, ensures that the persons authorized to process the personal data have undertaken an obligation of confidentiality and process the personal data only on the basis of our recorded instructions .
- To national regulatory, tax or public bodies or courts, where required by law.
- To third parties who carry out audits on us in the context of our legal obligations.
Your Rights and How You Can Exercise Them
In accordance with the provisions of the General Data Protection Regulation 679/2016/EU, you have the following rights:
Right of Access.
You have the right to receive a copy of your personal data processed by us. After reviewing your personal data, where you believe it is inaccurate or incomplete, you can request that it be amended accordingly by exercising your “right to rectification” of your personal data.
Right to rectification.
You have the right, if you find that the personal data processed by our Company on your behalf is inaccurate, to request that it be amended accordingly. Bearing in mind the purposes of the processing carried out by where it is considered that the personal data held are incomplete you have the right to request their completion through a supplementary statement. If the correction you request requires the verification of your identity, “ UHY Axon Audit SA ” may ask you to provide additional information necessary to confirm your identity, or to verify the information you request correction of. Your personal data can be updated on a case-by-case basis by sending an email to our email address.
Right to erasure (“right to be forgotten”).
You have the right to request the deletion of the processing of personal data concerning you, if: a) the personal data are no longer necessary in relation to the purposes for which they were collected or b) are processed in a different way than that for which it was collected, or c) you withdraw your consent to the processing and there is no other lawful basis for processing, or d) if it is considered that your personal data has been processed unlawfully or if the processing of your personal data is not in accordance to the Regulation in any other way. If you have objections to the processing of personal data concerning you, please send us an email to the address data.protection@axon-group.eu explaining in accordance with the above the reason or reasons why it is considered that “UHY Axon Audit SA” as the Controller to delete your personal data. We will consider your request and the reasons behind it and send you a reasoned response within a reasonable time. Until you receive our above answer, you can submit a reasoned request to UHY Axon Audit SA to limit the processing of your personal data, as detailed below.
Right to restriction of processing.
You have the right to request a restriction of the processing of your personal data, when one of the following applies: a) if you question the accuracy of your personal data, for a period of time that allows “UHY Axon Audit SA” as Processor to verify the accuracy of your personal data, b) if it is considered that the processing is illegal and you wish instead of deleting your personal data, to limit its use, c) in the event that “UHY Axon Audit SA” as a Processor no longer needs the personal data concerning you for the purposes of the processing, but these data are required by you to establish, exercise or support legal claims, d) in the event that you object to the processing for reasons relating to a particular situation of yours, where the processing is based on a legitimate interest of the controller or a third party, pending verification of whether the controller’s legitimate reasons prevail over your own. Where processing has been restricted in accordance with the above, such personal data, apart from storage, are only processed with your consent or for the establishment, exercise or support of legal claims or for the protection of the rights of another natural or legal person or for reasons of significant public interest of the Union or a Member State. If you want to exercise the right to restrict processing, please state with reasons which of the above cases you fall under. “UHY Axon Audit SA” will review your request and respond within a reasonable time.
Right to object.
You have the right to object to the processing of your personal data, in the following cases: a) If the processing is based on the purposes of legal interests pursued by “UHY Axon Audit SA” as a controller or a third party, for reasons related to a particular your status. In this case “UHY Axon Audit SA” as the Processor will no longer submit your personal data for processing, unless it demonstrates compelling and legitimate reasons for the processing that override your interests, rights and freedoms or to establish, exercise or support legal claims. b) If personal data concerning you is processed for the purposes of direct marketing, you have the right to object at any time to the processing for such marketing, including profiling, if related to such direct marketing. When you object to processing for direct marketing purposes, your personal data will no longer be processed for these purposes. c) When personal data concerning you are processed for the purposes of scientific or historical research or for statistical purposes you have the right to object, for reasons related to your particular situation, unless the processing is necessary for the performance of a task carried out for reasons of public interest. If you wish to exercise the right to object to the processing, please state with reasons which of the above cases you fall under. “ UHY Axon Audit SA “ will check your request and respond to you within a reasonable period of time.
Right to withdraw consent.
Where the processing of personal data concerning you is based on your consent, you have the right to withdraw said consent at any time. Withdrawal of consent does not affect the lawfulness of processing that was based on consent prior to its withdrawal. If you wish to exercise the right to withdraw your consent for the processing of personal data concerning you, please indicate specifically the processing for which you have given consent that you wish to withdraw to the email address data.protection@axon-group.eu
Right to data portability.
You have the right to receive the personal data concerning you, which you have provided, in a structured, commonly used and machine-readable format, as well as the right to transmit said data to another controller, when: Processing is based with your consent or when the processing is necessary for the performance of a contract to which you are a party, and is carried out by automated means, and provided that it does not adversely affect the rights and freedoms of others. When exercising the right to data portability in accordance with the above, you have the right to request the direct transmission of your personal data to another data controller, if this is technically possible. The right to portability is exercised subject to article 17 of the GDPR (“right to erasure”). If you wish to exercise this right, please indicate specifically whether you wish to receive or transmit your personal data to another data controller. In the second case, provide the details of the controller to whom you want your data to be transferred. “UHY Axon Audit SA” will examine your request and will respond to you within a reasonable period of time.
Finally, according to the current regulation, in addition to your above rights, you are also entitled to file a complaint with the competent supervisory authority, Hellenic Data Protection Authority, Kifisias Avenue 1-3, 115 23 Athens.
Time interval of data storage
Personal data is kept by “UHY Axon Audit SA” only for as long as it is necessary to fulfill the purposes for which it was collected and according to the time limits set by the applicable legislation. The personal data you enter in the job application form and in your CV to “UHY Axon Audit SA” will be deleted after three months from the date of sending your application.
Contact address
For any further information or clarification regarding the processing of your personal data as well as the exercise of your rights, please send us an e-mail at data.protection@axon-group.eu