Information about processing personal data

Web application E-ZAK which is running on the https://zakazky.bvk.cz domain is an electronic tool within the meaning of Act No. 134/2016 Coll. on public procurement, as amended (hereinafter referred to as "PPA"). All personal data are processed solely for the purpose of preparing and processing the procurement procedures and the resulting performance in accordance to PPA and the internal directives of the contracting authority, in accordance with regulation No. 2016/679 of the European Parliament and of the Council (EU) on the protection of natural persons with regard to the processing of personal data and the free movement of such data and repealing Directive 95/46/EC (General regulation on the protection of personal data) (hereinafter referred to as "GDPR").

Personal data controller

Brněnské vodárny a kanalizace, a.s.
Pisárecká 555/1a
603 00 Brno
CRN: 46347275
contact e-mail:

Personal data processor

QCM, s.r.o.
Heršpická 813/5
639 00 Brno
CRN: 26262525
contact e-mail:

The purposes of the processing, the category of personal data concerned and the period of retention

In the E-ZAK electronic tool, personal data is processed for purposes of

  • user account creation (signing up) and administration,
  • preparation and realization of procurement procedures and the resulting performance to the extent necessary for the fulfillment of law requirements,
  • sending system e-mail notifications (alerts),
  • protection against access abuse.
The following personal data categories are processed:
  • identification data - firstname, surname, title, role, identification data or identifiers issued by public authorities (CRN of natural person), date of birth of self-employed natural person without CRN, digital certificate (e.g. electronic signature), personal number of the employee,
  • contact / address details - e-mail address, postal address, telephone number, fax number,
  • other potential personal data - IP address of internet requests.

No sensitive personal data is processed within the meaning of GDPR Article 9.

There is no automated decision making, including profiling within the meaning of GDPR Article 22.

Personal data is retained in E-ZAK system

  • 10 years from the last active participation of the data subject in the realization of the procurement procedures or the resulting performance (fulfillment of legal obligation under the PPA),
  • for the period of validity of possible consent for processing personal data.

Personal data sources

The primary source of personal data is the data subject under the registration or activating a user account, within managing subject user profile, or by using an electronic signature.

Other sources of personal data can be:

  • so-called pre-registration, when a validly signed-in user with the appropriate permissions inserts into the system the contact data especially the e-mail address of natural person to which the e-mail with instructions for completing the registration or activating a user account is sent
  • acts of Controller within the preparation and processing procurement procedures and the resulting performance in accordance with the of the PPA and the internal directives of the contracting authority

The recipients of personal data

Personal data may also be processed by other processors for the purposes described above, but only with the consent and on request of the Controller.

Personal data may also be transmitted upon a legal request to third parties, which have the legal authority to request the transmission of the personal data.

Personal data are not transmitted to third countries or international organizations by the E-ZAK system.

Rights of data subject (registered users)

Right of correction is primarily provided by the user account administration - each user can modify or add personal data within his or her user profile. In the case of incomplete pre-registration, it is possible to contact the Controller or the Processor by e-mail (contact is provided at the beginning of this document).

Right to erasure ("right to be forgotten") is primarily provided by the user account administration - each user can use the account deletion functionality within his or her user profile after signing in (users with company administrator permissions can also delete other user accounts within their organization). In case that there is another legal reason for processing (a record of an electronic act performed by this user in the procurement process, where the law requires an unambigous identification of the person who performed the electronic act), personal data will be erased after a specified period of time. Otherwise, the user's personal data will be erased immediately. The right to withdrawal of previously given consent for processing personal data is realized in the same way.

Right to have the processing restricted is primarily provided by the user account administration - each user can delete the selected personal data within his or her user profile after signing in. In the case of incomplete pre-registration, it is possible to contact the Controller or the Processor by e-mail (contact is provided at the beginning of this document).

Right to data portability is primarily provided by the administration of user accounts - each user can use the export functionality in his user profile after signing in.

Right to object against the processing of personal data relating to subject, to the address of the Controller (contact is provided at the beginning of this document).

Right of data subject to have access to personal data is ensured by this document and the above mentioned procedures and functionalities.

Right to lodge a complaint with a supervisory authority, which is The Office for personal data protection.

Cookies

Information is provided in a separate article Cookies.