Privacy
The controller of personal data is AS OG ELEKTRA (hereinafter also referred to as the company or Grossi Toidukaubad), registry code 10054238, Keskus, Tobia village, Rakvere parish 44416, e-mail info@ogelektra.ee. The current privacy policy terms and conditions are always available on the AS OG ELEKTRA website www.grossitoidukaubad.ee/privaatsus. It is also possible to obtain additional information about the privacy policy by contacting the e-mail address info@ogelektra.ee.
The privacy policy of AS OG ELEKTRA describes the principles on which the company processes personal data. The privacy policy applies to all natural persons who visit the company’s Grossi Toidukaubad stores, other business premises, the website www.grossitoidukaubad.ee, contact the company or apply for a job at the company.
AS OG ELEKTRA processes personal data as little as possible, but as much as necessary to perform its tasks and obligations and to ensure security. We process personal data in accordance with Estonian and European Union legislation. The main legal basis for the protection of personal data is the European Union’s General Data Protection Regulation (GDPR).
Personal data are data that can be directly or indirectly linked to a natural person and that a company collects and processes for the performance of a contract with the person, for the protection of vital interests and the company’s property or persons, or for compliance with legal obligations. Processing of personal data is any operation performed on personal data, such as collection, use, transmission, recording, organization, storage, modification, disclosure, deletion, provision of access to data, and making inquiries and extracts. A data subject is a natural person whose personal data is processed.
What kind of personal data does the company collect and process?
- Basic data – first and last name, personal identification code, date of birth, identity document (ID card, passport) details, residential address, telephone number, e-mail address, language of communication;
- Data collected by video recording – personal data captured on security cameras installed on company premises and outside entrances;
- Data obtained and/or created in the course of fulfilling obligations arising from legal acts – data arising from orders and/or inquiries from the police, tax authorities, bailiffs, and bankruptcy trustees.
For what purposes and on what basis does the company collect and process personal data?
- Organizing the recruitment of AS OG ELEKTRA personnel – when applying for a job, the data disclosed in the data subject’s CV and other documents submitted by him/her are processed, such as first and last name, identity document, postal address, e-mail address, telephone number, information on education and work experience, and other relevant data submitted by the data subject. The said personal data is information with restricted access and is processed based on the data subject’s consent;
- AS OG ELEKTRA personnel records – for the fulfillment of obligations arising from legislation and the employment contract, the personal data includes first and last name, identity document, contact details, bank account for payment of wages, family data (existence of minor children), qualification, further education, employee incapacity for work, occupational diseases and health check-up data. The aforementioned personal data is information with restricted access and is processed on the basis of the data subject’s consent and the concluded contract;
- Calculation of purchase bonuses for the customer card account of the holder of the Grossi Toidukaubad customer card – when applying for a customer card, the customer agrees to the processing of their personal data, including first name, last name, personal identification number and address by county. The customer’s personal data is processed only for the purpose of ensuring the use of the Grossi Toidukaubad customer card. The company does not use personal data for direct marketing and satisfaction surveys;
- Use and improvement of the website grossitoidukaubad.ee – so-called tracking data sent through the company’s website and general online services, such as IP address, web browser, cookies, time and date of visiting the website;
- Protection of AS OG ELEKTRA property, ensuring the safety of employees and visitors, and detecting violations of the law and processing legal claims – personal data that can be used to identify a person will remain on video recordings. The said personal data is information with restricted access and the processing of personal data is carried out on the basis of a legitimate interest assessment carried out by the company;
- Forwarding a request to the company – personal data contained in the request, such as name, e-mail address, telephone number and similar data disclosed by the requester;
- To fulfill obligations arising from the law – when selling products with an age restriction, verifying the customer’s age based on an identity document and responding to inquiries from supervisory, investigative and law enforcement authorities and third parties, if the corresponding obligation arises from the law.
AS OG ELEKTRA processes personal data of the data subject only if he/she provides such information voluntarily or has a legitimate interest in doing so. The company follows the principle of minimization when processing personal data, i.e. it processes only those data and to the extent necessary to achieve a specific purpose. If the company intends to process the collected personal data for purposes not specified, information about the other purpose in question, together with other relevant additional information, will be provided before further processing of the personal data.
Processing of personal data when applying for a job
When applying for a job, the company processes the personal data provided by the candidate for the purpose of assessing the candidate’s professional suitability and compliance with the position applied for. The company may also obtain data about the candidate from other sources such as public registers, recommenders, former employers, etc. The company will only contact the candidate’s recommender or former employer if the candidate has given consent to do so.
Personal data and documents related to the application are only accessible to authorized persons participating in the recruitment process. The data of the selected candidate will be stored in accordance with the Employment Contracts Act, and the personal data of the unsuccessful candidates will become anonymous 1 month after the end of the competition.
Processing of personal data when applying for and using a loyalty card
The personal data of the customers to be processed is collected from the customer himself, which the customer discloses when filling out the Grossi Toidukaubad customer card application form. The legal basis for the processing of ordinary personal data, such as first name, last name, personal identification number, address by county, is the customer’s consent, which he adds as a signature when filling out the Grossi Toidukaubad customer card application form on paper. Ordinary personal data is retained until the customer submits a corresponding application for deletion of the data, after which his personal data is made anonymous, i.e. his name and personal identification number are partially replaced with xxx in the database.
Unused bonuses collected by customers are archived twice a year, i.e. on August 1st and February 1st, after which this data can no longer be processed.
AS OG ELEKTRA does not process personal data related to the Grossi Toidukaubad customer card and purchase statistics for profile analysis.
More detailed information about applying for, using and canceling a loyalty card can be found at www.grossitoidukaubad.ee/kliendikaart/
Processing of personal data on the company website
When visiting the company’s website www.grossitoidukaubad.ee, only so-called tracking data is collected and stored about the visitor: the IP address of the visitor’s computer or computer network, web browser, cookies. The website uses cookies, which help the browser remember the choices made by the user. When using the company’s website, the website visitor is asked to consent to the use of cookies. The website visitor may not agree to cookies, as a result of which several services and functions of our website may be limited to him.
When visiting the website www.grossitoidukaubad.ee, the company may collect non-personal data such as the date and time of visiting the website, information downloaded from the website, information about the browser name and operating system, internet service provider and other similar information. AS OG ELEKTRA processes this data anonymously and the data is used primarily for the purpose of improving the functionality of the website.
Processing of personal data in video surveillance
AS OG ELEKTRA has installed security cameras in the interior of its stores and in the external territories of the entrances, as well as in other business premises of the company, in whose field of view employees, customers and cooperation partners (customers and cooperation partners hereinafter collectively referred to as visitors) may be located, relying on legitimate interest as the legal basis for the processing of personal data (GDPR Article 6(1)(f).
The purpose of processing personal data is to protect the company’s assets, as well as to ensure the safety of the company’s employees and visitors, to identify and, if possible, prevent violations of the law, to promptly obtain information about the safe conduct of work processes, and to quickly resolve any bottlenecks and threats that have arisen, and to resolve any disputes that have arisen. The controller of the video recording resulting from video surveillance and the personal data processed in the video recording is AS OG ELEKTRA. Only persons who have the right to view the video recordings based on their work duties, as defined in the company’s assessment of legitimate interest, have access to all video recordings.
We are required by law to provide the personal data of the data subject in the video recording to law enforcement agencies, national and local government agencies and insurance companies upon request. We may ourselves forward the personal data in the video recording to law enforcement agencies, national and local government agencies and insurance companies in order to fulfill our interests in the preparation, submission and defense of legal claims.
Recordings are retained until the data volume is full, but not longer than 30 calendar days. When the data volume is full or the deadline arrives, whichever occurs first, the video system will automatically start overwriting. In the event of a security incident or dispute, the recording related to the incident will be retained until the incident is resolved.
Individuals are only identified if it is necessary to achieve the company’s objectives. The data subject has the right to object to the processing of personal data based on the company’s legitimate interests. However, due to the nature of video surveillance, the company cannot guarantee that the data subject’s right to object to the processing of personal data can be fully exercised, as the data is collected automatically and the data subject cannot perform his/her tasks and/or receive the company’s services without being subject to video surveillance. The controller has ensured the presence of information signs so that the data subject understands that he/she is being monitored by a camera in the areas owned by the company. Even if the data subject does not notice the information signs, he/she can assume that the processing in question is taking place, as the use of cameras for security purposes is very common today.
Processing of personal data at Grossi Toidukaubad events
AS OG ELEKTRA has the right to make photo and video recordings of the event at events it organizes, including the opening of Grossi Toidukaubad stores, joint events of the company’s employees, customer days, etc., and to use and publish the recordings made at its discretion to a reasonable extent on the company’s intranet, website, social media and public media. If the data subject, as a participant in the event, does not wish his or her personal data to be processed in the aforementioned recordings, we ask that the person who recorded the event be notified.
Processing of personal data when participating in campaign games and/or raffles
We process the personal data of the data subject in order to manage the campaign games and/or raffles organized by Grossi Toidukaubad and/or Grossi Toidukaubad’s cooperation partners, if he/she has expressed a desire to participate in the campaign games and/or raffles (including if he/she has voluntarily disclosed his/her personal data in comments, messages, etc. on social networks). We process the personal data in order to draw and announce the winner, to identify the data subject when issuing the prizes of the campaign games and/or raffles.
If you wish to participate in the campaign game and/or raffles, you must provide us with your personal data. If personal data is not provided, the data subject will not be able to participate in the campaign games and/or raffles, or if they win, we will not be able to award them the prize. Identity will be verified when the prize is awarded, and in case of discrepancies, the prize will not be awarded.
We collect personal data that the data subject provides to us, i.e. with their consent, for example when participating in campaign games and/or raffles or when they give their consent in comments, messages, etc. on social networks. The personal data requested in the campaign game and/or raffle is the first and last name, contact information, e.g. email address, telephone number, address.
If the company’s partners organize campaign games and/or raffles, we may transfer the data subject’s personal data to the partners if they win and publish their personal data on our platforms (website, social networks).
All personal data related to the organization and administration of campaign games and/or raffles and the identification and announcement of the winner will be stored for up to 90 days after the end of the campaign games and/or raffles. The data of the winners of the campaign games and/or raffles will be displayed on the Grossi Toidukaubad website within 3 working days. If a complaint is filed in connection with the campaign games and/or raffles, personal data may be stored for a longer period. In such a case, personal data will be stored until the complaint is resolved.
Deadlines for processing personal data
AS OG ELEKTRA processes the personal data of the data subject at the beginning and during the customer and/or employment relationship and when visiting Grossi Toidukaubad stores, business premises and the website www.grossitoidukaubad.ee. The company processes personal data for as long as necessary to fulfill the customer relationship or other equivalent relationship between the company and the data subject or until the data subject withdraws his/her consent to the processing of personal data or for legal purposes until the deadlines stipulated by law.
- Job applicant data
- Data on unsuccessful candidates 1 month after the end of the competition
- The data of the selected candidate will be stored in accordance with the Employment Contracts Act.
- Customer inquiries and requests, as well as claims and complaints – written requests 3 years after the company sends the final response.
- Customer card details
- Standard personal data is retained until the client submits a request to delete the data.
- Unused bonuses collected by customers are archived twice a year, i.e. on August 1st and February 1st.
- personal data on company video recordings
- up to 30 calendar days
- In the event of a security incident or dispute, the recording related to the incident will be retained until the incident is resolved.
- results of campaign games and raffles – 90 days after the end of the campaign games and/or raffles
- personal data related to the processing of legal claims – 3 years from the date of performance of obligations by the data subject
After the specified deadlines, personal data will be deleted or made anonymous.
Personal data protection and data subject rights
AS OG ELEKTRA uses up-to-date and adequate technical and organizational security measures when collecting, storing and processing personal data, which protect against unauthorized access, modification, disclosure or destruction of personal data. Access to modify and process personal data is only available to authorized persons.
The data subject has the right to request access to their personal data from the controller at any time, to request rectification and portability of their personal data, to restrict the processing of their personal data, to erase their personal data, and to object to the processing of their personal data.
Requests related to the processing of personal data should be submitted electronically to the company’s e-mail address info@ogelektra.ee. In order to ensure the security of personal data processing, the data subject’s request must be digitally signed. The company has the right to respond to the request within one month of receiving the request. As the controller, the company has the right to reject the request if the identity of the applicant cannot be established or the transmission of personal data is not secure or the requests submitted are clearly unfounded or excessive, in particular due to their repetitive nature. The company has the right to refuse to satisfy the data subject’s request to restrict the processing of personal data or to delete personal data if the obligation to process personal data arises from a valid contract, law or is necessary for the establishment, exercise or defence of legal claims relating to the protection of persons and property. If the company is unable to satisfy the data subject’s request, it shall notify the data subject of the reason for rejecting the request without delay and no later than one month from receiving the request.
If the data subject finds that the controller is violating his or her rights when processing personal data, he or she has the right to contact the Data Protection Inspectorate (www.aki.ee) or the court at any time.
Changing the terms of the privacy policy
The controller has the right to change and supplement the terms of the privacy policy at any time. The current terms of the privacy policy are always available on the website www.grossitoidukaubad.ee. It is also possible to familiarize yourself with the terms of the privacy policy by contacting the company at the e-mail address info@ogelektra.ee.