Personal Data Processing Policy | Yacht Club Montenegro
Personal Data Processing Policy
1. General provisions
1.1. This Personal Data Processing Policy (the "Policy") of [Operator legal name] has been drawn up to meet the requirements of the Law of Montenegro on Personal Data Protection and of Regulation (EU) 2016/679 (the General Data Protection Regulation, the "GDPR"), in order to protect the rights and freedoms of individuals when their personal data is processed, including the right to privacy and to personal and family confidentiality.
1.2. The Policy applies to all personal data processed by [Operator legal name] (the "Operator").
1.3. The Policy covers personal data processing relationships that arose for the Operator both before and after this Policy was approved.
1.4. This Policy is published in open access on the Internet, on the Operator's website.
1.5. Key terms used in the Policy:
personal data - any information relating to a directly or indirectly identified or identifiable natural person (the data subject);
operator (controller) - a legal entity or natural person which, alone or jointly with others, organises and carries out the processing of personal data and determines the purposes of processing, the categories of personal data to be processed and the actions performed with that data;
processing of personal data - any action or set of actions performed with personal data, with or without the use of automated means. Processing includes, among other things:
- collection;
- recording;
- organisation;
- accumulation;
- storage;
- adaptation (updating, alteration);
- retrieval;
- use;
- transfer (disclosure, provision, access);
- anonymisation;
- restriction;
- erasure;
- destruction;
automated processing of personal data - the processing of personal data by means of computing technology;
dissemination of personal data - actions aimed at disclosing personal data to an indefinite group of people;
provision of personal data - actions aimed at disclosing personal data to a particular person or a particular group of people;
restriction of personal data - the temporary suspension of the processing of personal data (except where processing is necessary to update the data);
destruction of personal data - actions that make it impossible to restore the content of personal data in an information system, or that result in the destruction of the physical media on which the personal data is held;
anonymisation of personal data - actions that make it impossible, without the use of additional information, to attribute personal data to a specific data subject;
personal data information system - the combination of personal data held in databases together with the information technologies and technical means that process it;
international transfer of personal data - the transfer of personal data to the territory of a foreign country, to a foreign authority, a foreign natural person or a foreign legal entity.
1.6. Main rights and obligations of the Operator.
1.6.1. The Operator has the right to:
1) independently determine the set of measures necessary and sufficient to fulfil the obligations set out in the applicable data protection law, unless otherwise provided by law;
2) entrust the processing of personal data to another party, with the data subject's consent and on the basis of a contract concluded with that party. A party processing personal data on the Operator's instructions is obliged to comply with the principles and rules of processing laid down in the applicable data protection law;
3) where the data subject withdraws their consent to processing, continue processing without that consent if there are grounds for doing so under the applicable data protection law.
1.6.2. The Operator is obliged to:
1) organise the processing of personal data in accordance with the requirements of the applicable data protection law;
2) respond to approaches and requests from data subjects and their legal representatives in accordance with the applicable data protection law;
3) provide the supervisory authority, the Agency for Personal Data Protection and Free Access to Information of Montenegro, with the information it requests, within the time limits set by law.
1.7. Main rights of the data subject. The data subject has the right to:
1) obtain information about the processing of their personal data, except in cases provided by law. The information is provided to the data subject by the Operator in an accessible form and must not contain personal data relating to other data subjects, unless there are lawful grounds to disclose such data;
2) require the Operator to correct, restrict or erase their personal data where it is incomplete, out of date, inaccurate, unlawfully obtained or not necessary for the stated purpose of processing, and to take the measures provided by law to protect their rights;
3) object to the processing of their personal data for direct marketing purposes and require prior consent for such processing;
4) request data portability, and lodge a complaint with the supervisory authority or go to court against unlawful acts or omissions by the Operator in processing their personal data.
1.8. Compliance with this Policy is monitored by the person responsible for organising the processing of personal data at the Operator.
1.9. Liability for breaching the law of Montenegro and the Operator's internal rules in the field of personal data processing and protection is determined in accordance with the law of Montenegro.
1.10. The data subject's consent to the processing of personal data is expressed by ticking the corresponding box on the Operator's website.
2. Purposes of collecting personal data
2.1. The processing of personal data is limited to achieving specific, predefined and lawful purposes. Processing that is incompatible with the purposes of collection is not allowed.
2.2. Only personal data that matches the purposes of its processing is processed.
2.3. The Operator processes personal data for the following purposes:
- ensuring compliance with the law of Montenegro;
- carrying out its activities in accordance with the Operator's governing documents;
- keeping personnel records;
- assisting employees with employment, education and career development, ensuring their personal safety, monitoring the quantity and quality of work performed and safeguarding property;
- attracting and selecting candidates for employment with the Operator;
- registering employees in the compulsory social and pension insurance system;
- completing and submitting required reporting forms to the competent authorities;
- carrying out civil law relations;
- keeping accounting records;
- managing access to premises.
2.4. The personal data of employees may be processed solely to ensure compliance with the law.
3. Legal bases for processing personal data
3.1. The legal basis for processing is the body of laws and regulations under which and in accordance with which the Operator processes personal data, including:
- the Constitution of Montenegro;
- the Civil Law of Montenegro;
- the Labour Law of Montenegro;
- the tax legislation of Montenegro;
- the legislation of Montenegro on companies and business activity;
- the accounting legislation of Montenegro;
- the legislation on compulsory social and pension insurance;
- other laws and regulations governing relations connected with the Operator's activities.
3.2. The legal basis for processing also includes:
- the Operator's governing documents;
- contracts concluded between the Operator and data subjects;
- the consent of data subjects to the processing of their personal data.
4. Volume and categories of personal data processed,
categories of data subjects
4.1. The content and volume of the personal data processed must match the stated purposes of processing set out in Section 2 of this Policy. The personal data processed must not be excessive in relation to those purposes.
4.2. The Operator may process the personal data of the following categories of data subjects.
4.2.1. Candidates for employment with the Operator:
- first name, last name and any patronymic;
- gender;
- citizenship;
- date and place of birth;
- contact details;
- information about education, work experience and qualifications;
- other personal data provided by candidates in their CVs and cover letters.
4.2.2. Employees and former employees of the Operator:
- first name, last name and any patronymic;
- gender;
- citizenship;
- date and place of birth;
- image (photograph);
- identity document details;
- registered place of residence;
- actual place of residence;
- contact details;
- tax identification number;
- social insurance number;
- information about education, qualifications, professional training and development;
- marital status, children and family ties;
- information about employment history, including any rewards, awards or disciplinary measures;
- marriage registration details;
- military service records, where applicable;
- information about disability;
- information about the withholding of maintenance payments;
- income from a previous place of work;
- other personal data provided by employees in accordance with labour law.
4.2.3. Family members of the Operator's employees:
- first name, last name and any patronymic;
- degree of kinship;
- year of birth;
- other personal data provided by employees in accordance with labour law.
4.2.4. Clients and counterparties of the Operator (natural persons):
- first name, last name and any patronymic;
- date and place of birth;
- identity document details;
- registered place of residence;
- contact details;
- position held;
- tax identification number;
- bank account number;
- other personal data provided by clients and counterparties (natural persons) that is necessary to conclude and perform contracts.
4.2.5. Representatives (employees) of the Operator's clients and counterparties (legal entities):
- first name, last name and any patronymic;
- identity document details;
- contact details;
- position held;
- other personal data provided by representatives (employees) of clients and counterparties that is necessary to conclude and perform contracts.
4.3. The Operator does not process biometric personal data (information about a person's physiological and biological characteristics from which their identity can be established), in accordance with applicable law.
4.4. The Operator does not process special categories of personal data concerning racial or ethnic origin, political views, religious or philosophical beliefs, health or sex life, except in the cases provided by law.
4.5. Concluding and performing contracts may require the identification of the client. The information needed to identify the client may include the IP address, data in web storage when recent browser versions are used, information from cookies, information about the client's browser, and the date and time of visits to the Operator's website. The client personally provides their personal data when registering and updating their details. The Operator has the right to check the accuracy of the information entered by clients on the Operator's website in accordance with its terms of service and public offer.
5. Procedure and conditions for processing personal data
5.1. Personal data is processed by the Operator in accordance with the law of Montenegro.
5.2. Personal data is processed with the consent of data subjects, and also without such consent in the cases provided by law.
5.3. The Operator carries out both automated and non-automated processing of personal data.
5.4. Only employees of the Operator whose duties include the processing of personal data are allowed to process it.
5.5. Personal data is processed by:
- obtaining personal data orally and in writing directly from the data subjects;
- obtaining personal data from publicly available sources;
- entering personal data into the Operator's logs, registers and information systems;
- using other methods of processing personal data.
5.6. Disclosure to third parties and dissemination of personal data without the data subject's consent is not allowed, unless otherwise provided by law. Consent to the processing of personal data that the data subject has authorised for dissemination is given separately from any other consent to processing.
5.7. The transfer of personal data to the tax authority, social and pension insurance bodies and other competent public authorities of Montenegro is carried out in accordance with the law.
5.8. The Operator takes the necessary legal, organisational and technical measures to protect personal data from unlawful or accidental access, destruction, alteration, restriction, dissemination and other unauthorised actions, including:
- identifying threats to the security of personal data during its processing;
- adopting internal rules and other documents governing the processing and protection of personal data;
- appointing people responsible for the security of personal data in the Operator's departments and information systems;
- creating the conditions needed to work with personal data;
- keeping records of documents that contain personal data;
- organising the operation of information systems in which personal data is processed;
- storing personal data in conditions that ensure its safety and rule out unlawful access to it;
- training the Operator's employees who process personal data.
5.9. The Operator stores personal data in a form that allows the data subject to be identified for no longer than the purposes of processing require, unless a storage period is set by law or by contract.
5.10. The Operator stores and processes personal data on secure servers located within Montenegro or the European Economic Area, or under the appropriate safeguards required by the GDPR.
5.11. To protect information from unauthorised access while it is being transmitted from the client to the server, the Operator uses a secure SSL/TLS connection. Where online payments are made, additional authentication methods such as 3-D Secure may be used to confirm the transaction.
6. Updating, correcting, erasing and destroying personal data, and responding to data subjects' access requests
6.1. Confirmation that the Operator processes personal data, the legal bases and purposes of processing, and the other information required by the applicable data protection law, are provided by the Operator to the data subject or their representative on request.
The information provided does not include personal data relating to other data subjects, unless there are lawful grounds to disclose such data.
The request must contain:
- the number of the main identity document of the data subject or their representative, with the date of issue and the issuing authority;
- information confirming the data subject's relationship with the Operator (a contract number, the date of the contract, an agreed reference or other information), or information otherwise confirming that the Operator processes their personal data;
- the signature of the data subject or their representative.
The request may be sent in the form of an electronic document signed with an electronic signature in accordance with applicable law.
If the data subject's request does not contain all the necessary information, or the subject does not have the right to access the requested information, a reasoned refusal is sent to them.
The data subject's right to access their personal data may be restricted in the cases provided by law, including where access would breach the rights and lawful interests of third parties.
6.2. If inaccurate personal data is identified following a request from the data subject or their representative, or from the supervisory authority, the Operator restricts the personal data relating to that data subject from the moment of the request, for the period of verification, provided that this does not breach the rights and lawful interests of the data subject or third parties.
If the inaccuracy of the personal data is confirmed, the Operator corrects it within seven working days of being provided with the relevant information and lifts the restriction.
6.3. If unlawful processing of personal data is identified following a request from the data subject or their representative, or from the supervisory authority, the Operator restricts the unlawfully processed personal data relating to that data subject from the moment of the request.
6.4. Once the purposes of processing have been achieved, and also where the data subject withdraws their consent, the personal data is destroyed, unless:
- otherwise provided by a contract to which the data subject is a party, a beneficiary or a guarantor;
- the Operator is entitled to process the data without the data subject's consent on the grounds provided by the applicable data protection law;
- otherwise provided by another agreement between the Operator and the data subject.
Rent a yacht in Montenegro
Leave your contact details and our manager will get in touch with you
Leave a request
Thank you!
Your details have been sent.