Enquire

PRIVACY POLICY

The Privacy Policy forms an integral part of the Terms and Conditions of the company BOMI SHIP d.o.o. and they describe the purposes and goals of collection, processing and mode of managing the personal data within the company.
The company Bomi Ship appreciates your privacy and adequately protects all personal data that are collected and processed in its daily operation in compliance with the General Data Protection Regulation (EU) 2016/679 of the European Parliament and the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (Official Journal of the European Union, L 119/1, 04.05.2016), Act on Implementation of the General Data Protection Regulation (Official Gazette 42/2018, hereinafter “Act”), as well as other applicable laws concerning the protection of personal data.

In order to ensure fair and transparent processing, with this Privacy Policy the company Bomi Ship d.o.o. wants to clearly inform its users, business partners, employees and other interested parties:

  • which personal data we collect and process, and which we do not process;
  • which are the grounds for processing and which are the principles relating to processing personal data;
  • the period for which the data are stored and with whom we share them;
  • which are your rights as a data subject and how we protect your data;
  • data on the controller and contact data if you want to exercise any of your rights

 

CONTROLLER AND CONTACT DATA

The Data Controller is BOMI SHIP d.o.o., Marasovica 22, Split; OIB: 06631807697.

You can submit your right to access, rectification, erasure, restriction, portability, object and information personally in our registered office, by mail to the address Bomi Ship d.o.o., Marasovica 22,  21000 Split or electronically to the address data.protection@bomiship.com

 

PRINCIPLES RELATING TO PROCESSING

BOMI SHIP d.o.o. processes the personal data in accordance with the following principles of processing:

  • Lawfully, fairly and in a transparent manner – as regards the data subjects and their rights, Bomi Ship shall process the personal data of data subjects in accordance with the valid laws, contractual obligations or legitimate interests by respecting all rights of the data subjects.
    In order to ensure the transparent processing of personal data, Bomi Ship shall provide the data subjects with all necessary information and at request enable the data subject to have insight into the data, explanation of processing, grounds of processing and all other rights in accordance with the relevant regulations.
  • With the purpose restriction – personal data are collected and processed only for the specific, explicit and legal purposes, and are not further processed in the way that is not compliant with these purposes.
  • With the data quantity reduction – we use only the data of the data subjects that are appropriate and necessary to achieve specific legal purposes.
  • With the storage period reduction – all personal data have a life span, and we store the personal data of data subjects in compliance with it in an identifiable form not longer than necessary, after which the data are erased from all records.
  • Your data are accurate, full and updated – We take all reasonable measures to guarantee that your recorded personal data are accurate, complete and updated. Bomi Ship d.o.o. applies the transparent communication process with data subjects through which the rectification or erasure of inaccurate data can be requested.
  • Your data are complete and confidential – we collect and process the data in a safe way, including the protection against unauthorized or unlawful processing and against accidental loss, destruction or damage by applying the appropriate technical and organizational measures. The data of data subjects are accessed by authorized employees, as well as other legal persons exclusively based on legitimate interests or valid contractual obligations. Bomi Ship d.o.o. applies the appropriate technical and organizational measures of protection, it has implemented systems aimed at detection and prevention of data leaking and their loss, as well as the method of supervising data access etc.

 

WHICH PERSONAL DATA ARE COLLECTED AND PROCESSED

Bomi Ship d.o.o. processes the following categories of data in relation to the categories of data subjects:

Users of our services:

  • contact data – name, surname, phone number, e-mail address etc.,
  • data needed for contract conclusion – name, surname, phone number, e-mail address, OIB, address etc.,
  • data needed for contract execution – name, surname, phone number, e-mail, address, OIB, IBAN etc.

Employment candidates:

  • contact data – name, surname, phone number, e-mail address etc.,
  • data from CV/job application – data on education, former employment, years of service, photo etc.

Employees, former and current:

  • all the data are processed in compliance with the legal obligations, and they refer to labour and legal relations, accounting and bookkeeping regulations - name, surname, address, OIB, JMBG, birth year, health data, etc.,
  • contact data – name, surname, phone number, e-mail address, address
  • data needed to perform the tasks of the workplace, the exercise of the benefits related to the employment etc. - name, surname, employment, passport number, driver’s license number, number of children etc.

Business partners:

  • contact data – name, surname, phone number, e-mail address etc.,
  • data needed for contract conclusion – name, surname, phone number, e-mail address, OIB, IBAN etc.

 

THE DATA THAT ARE NOT COLLECTED AND PROCESSED

Bomi Ship d.o.o. does not process the data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, data concerning health or data concerning a natural person’s sex life or sexual orientation.

The processing of the above stated special categories of personal data may be carried out only in the following conditions:

  • processing is necessary for the purposes of carrying out the obligations and exercising specific rights of Bomi Ship d.o.o. or the data subject in the field of employment and social security and social protection law in so far as it is authorized by the European Union law, Republic of Croatia law or a collective agreement pursuant to the Republic of Croatia law providing for the appropriate safeguards for the fundamental rights and the interests of the data subject;
  • the data subject has given explicit consent to the processing of those personal data for one or more specified purposes;
  • processing is necessary to protect the vital interests of the data subject or another natural person;
  • the processing relates for personal data which are manifestly made public by the data subject;
  • processing is necessary for the establishment, exercise or defence of legal claims.

 

HOW PERSONAL DATA ARE COLLECTED

Bomi Ship d.o.o. may collect personal data in various ways, including;

  • directly from you when it is relevant for your needs as the user of our services, or for our operation, and when meeting our legal obligations or obligations from the sales contract of our services or the services in which we participate in the Contract;
  • by your filling out of our surveys or online questionnaires;
  • when you visit our internet page;
  • during your direct communication with our employees, including personal communication and online communication by the internet page or e-mail;
  • by your application for a job advertisement;
  • we collect your personal data from publicly available data records (such as the court register).

 

FOR WHICH PURPOSES PERSONAL DATA ARE COLLECTED

Bomi Ship d.o.o. processes your personal data for the following purposes:

  • when the processing of your personal data is necessary to contract the services provided by Bomi Ship d.o.o. or the services in which Bomi Ship d.o.o. participates in the Contract;
  • when executing the obligations resulting from the sales contract of services and products of Bomi Ship d.o.o. or the services in which Bomi Ship d.o.o. participates in the Contract;
  • in order to offer our services and products to the market;
  • in order to align our operation with the legal and regulatory regulations within and outside the territory of the Republic of Croatia;
  • in order to analyse and administer the internet page and monitor its use;
  • to improve business processes, services and products, in order to measure satisfaction with the services;
  • to manage relations with data subjects (users of the internet pages and/or services) and other persons in the performance of their operation;
  • in order to educate employees;
  • in order to select candidates for employment;
  • for marketing activities such as various events and newsletter distribution.

 

WHICH ARE THE GROUNDS TO PROCESS PERSONAL DATA


Bomi Ship d.o.o. processes your personal data on the basis on the following grounds:

  • execution of the service sales contract;
  • meeting of legal obligations of Bomi Ship d.o.o., in particular, based on accounting, bookkeeping, labour law regulations and other legal obligations;
  • legitimate interest – provision of services and information by internet page and its management, for statistical purposes, to process your inquiries, for employment needs;
  • explicit consent of data subjects to receive marketing messages, newsletters, e-mail notifications on services or surveys for service satisfaction measuring.

 

HOW LONG DO WE STORE YOUR PERSONAL DATA

Your personal data shall be stored by Bomi Ship d.o.o. with complete respecting of the principles of necessity, minimalization, storage restriction, adoption of technical and organizational measures suitable to ensure appropriate safety level, and in relation to the processing risk degree, only while we need them for the purposes for which we collect them, or to fulfil the contractual relations or legal obligations, and at the latest according to the following criteria:

  • personal data collected for the purpose of meeting the legal and regulatory obligations we store according to the prescribed legal deadlines;
  • personal data collected for the purpose of selling products and services we collect within a reasonable period of a legitimate interest duration;
  • ​personal data collected for the purpose of providing services we store in the duration of the contractual relationship and the deadlines stipulated by law for it;
  • ​personal data collected for the purpose of marketing activities we store until you withdraw your consent, cancel the subscription or request erasure of subscription, or after a specified period of inactivity.

 

​Personal data are erased upon the end of a contractual or labour relation, and no later than upon the expiry of all legal obligations of storage, except in the case that a judicial procedure is initiated or other similar procedure requesting the data storage.

Upon the expiry of the storage deadline, we remove them from the systems and archives or render them anonymous so that you are no longer identifiable.

 

WITH WHOM YOUR PERSONAL DATA ARE SHARED

Bomi Ship d.o.o. may share your personal data with the third parties exclusively in the following cases:

  • if there is a legal obligation or an explicit authorization based on the law;
  • ​if we hire another person called as a subcontractor, i.e. the processor, to perform particular tasks, who acts exclusively as ordered by Bomi Ship d.o.o., whereby Bomi Ship d.o.o. provides for all measures of data protection as if these tasks were performed by itself;
  • ​if the data need to be forwarded to the third parties to conclude and execute a contract with the data subject;
  • based on the data subject’s consent.

Such third parties include:

  • public administration, to perform institutional functions, within the restrictions specified the law and ordinances;
  • competent institutions and pension and health funds, as well as the companies and insurances in charge of social and health protection;
  • competent physician in compliance with the law;
  • tax administration;
  • consultancy firms to manage and keep the administration of personnel;
  • banking and credit system to pay salaries to employees and/or issue credit cards of the company and/or approve loans and/or issue an administrative injunction (loans that are withdrawn from the salary);
  • companies and institutions specialized in personnel training;
  • other public, legal and/or private subjects to which data need to be submitted to meet the contractual or legal obligations;
  • professionals and/or third companies used by Bomi Ship d.o.o. for its own purposes;
  • state bodies and institutions and based on legal and bylaw provisions.

 

When transferring the data of data subjects, Bomi Ship d.o.o. strictly respects the principle of processing restriction by transferring the minimum quantity of data that is needed to perform a requested service and by respecting all other relevant principles of data protection.

Bomi Ship d.o.o. has regulated all relations with partners by the contracts on data processing execution, whereby at least equal level of personal data protection is requested from the partners.

We process personal data in the Republic of Croatia. We can exceptionally also process them in other countries (e.g. when for the provision of a specific service or a part of the service that includes personal data processing a subcontractor from another country is hired), and this is as a rule in the European Union Member States. We can exceptionally also process them in the third countries, but in such situations the appropriate measures personal data protection is always applied, at least in the way that personal data are processed in the Republic of Croatia (e.g. by applying so-called EU Standard Contractual Clauses for processors established in third countries, by other legally obliging and enforceable instruments, obliging corporative rules, certification etc.

AUTOMATED DATA PROCESSING

Bomi Ship d.o.o. does not carry out the automated data processing.

YOUR RIGHTS AND HOW TO EXERCISE THEM

You can exercise your specific rights at any time, including:

  1. right to obtain confirmation as to whether or not your personal data are being processed;
  2. right of access personal data and the following information referring to you (purpose of the processing that requires personal data, data sources, data categories, data receivers, storage period etc.);
  3. right to request rectification or restriction of processing the personal data referring to you;
  4. right to request the erasure of the personal data referring to you if there are reasons for it;
  5. right of data portability;
  6. right to object to the supervisory authority.

 

You can exercise the stated rights personally in our registered office, by mail to the address Bomi Ship d.o.o., Marasovica 22, 21000 Split or by e-mail to the address data.protection@bomiship.com

Your rights are exercised free of charge, and only exceptionally by paying an administrative cost. We shall inform you about the administrative cost that we are entitled to charge pursuant to the General Regulation (GDPR) before it is incurred and if the prerequisites for its charging are met.

You can also send your complaint to the supervisory authority – Personal Data Protection Agency (Agencija za zaštitu osobnih podataka), Zagreb, Marticeva 14, and the supervisory authority within the EU.

In case of failure to provide the necessary personal data required by Bomi Ship d.o.o. to conclude contracts and exercise the rights from the contract between Bomi Ship and the data subject or provision of our service, there is a possibility that it shall not be possible to conclude the contract or provide a service, that you will not be able to access particular contents.

​You can revoke the consent provided by you for the individual purpose of processing at any time, in which case your personal data collected based on the consent shall no longer be used by us for the stated purposes.

Bomi Ship d.o.o. as the controller ensures that in case of violating the personal data, no later than 72 hours after becoming aware of that violation, shall inform the supervisory authority of that personal data violation, and shall without unnecessary delay notify the data subjects of the personal data violation. The report submitted to the supervisory authority contains all information in accordance with the Regulation.

SECURITY OF PERSONAL DATA

Bomi Ship d.o.o. implements the following technical and organizational measures to ensure an appropriate level of security, more specifically:

  • pseudonymization and encryption of personal data
  • ensuring the ongoing confidentiality, integrity, availability of personal data and access to them in case of a physical or technical incident
  • ensuring a process for regular testing, assessing and evaluating the effectiveness of technical and organizational measures to ensure the security of the processing.

 

Bomi Ship d.o.o. also implements measures to ensure that any natural person acting under the authority of the controller, and who has access to personal data, does not process them except on instructions from Bomi Ship d.o.o.

Taking into account the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Bomi Ship d.o.o. implements appropriate technical and organizational measures to ensure and be able to prove that the processing is implemented in compliance with the General Regulation, and that the measures are reviewed and updated if necessary.

Organizational and technical measures also include the measures of physical protection of deeds and documents.

Deeds and documents from the previous paragraph are stores in that way that access to these documents is not enabled to unauthorized persons, but these documents have ensured access also in case of technical or other similar incidents.

Organizational measures also include the provision of confidentiality statement of all persons that collect or process personal data or are entitled to access these data.

A confidentiality statement contains the confirmation of a natural person acting under the authority of Bomi Ship d.o.o. that personal data are processed in compliance with the instructions, as well as the statement on acceptance of material liability and liability due to violation of labour obligations for actions that are not in accordance with the instructions. The confidentiality statement is valid and obliges even after the termination of employment with the Bomi Ship d.o.o.

Bomi Ship d.o.o. also during the period of specifying the means of processing and during the processing itself implements appropriate technical and organizational measures, such as pseudonymization, to enable efficient change of the data protection principles, such as reduction of data quality and inclusion of protective measures into processing in order to meet the requirements from the General Regulation and protect the rights of data subjects.

Bomi Ship d.o.o. implements appropriate technical and organizational measures to ensure that, by default, only personal data that are necessary for each specific purpose of the processing are processed. This measure applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. Such measures ensure that by default personal data are not made accessible without the individual’s intervention to an indefinite number of natural persons.

Bomi Ship d.o.o. ensures technical measures of data protection in accordance with the Security Policies of Bomi Ship d.o.o. Security Policies of Bomi Ship d.o.o. contain in particular:

  • training of employees and administrators before the use of IT services
  • defined rules for the use and mandatory use of passwords
  • rules for the use of internet browsers
  • rules for the transfer of sensitive data
  • rules regarding the files downloading
  • e-mail addresses of employees
  • data encryption
  • virus protection
  • defined procedures in case of security incidents
  • additional provisions for mobile devices
  • general safety measures.

 

All subcontractors, partners or processors that Bomi Ship d.o.o. hires shall guarantee the implementation of appropriate technical and organizational measures in the way that the processing is carried out in compliance with the requirements from the General Regulation and that it protects the rights of data subjects.

The processor shall not hire another processor without previously obtained special or general written approval of Bomi Ship d.o.o.

The processing carried out by the processor shall be regulated by a contract between Bomi Ship d.o.o. and the processor. The contract shall contain the subject and duration of processing, nature and purpose of processing, type of personal data and category of data subjects, as well as obligations and rights of the controller. The contract shall be in written and/or electronic form.

USE OF COOKIES (cookies)

Bomi Ship d.o.o. web pages and their on-line services may use cookies to improve the services.
The decision to allow the use of cookies on the web page is completely yours.

It needs to be pointed out that the web page functions optimally if the use of cookies is made possible.

What are cookies?

Cookies (cookies) are small files that your browser saves to disk when visiting our web page. This enables our web page to recognize your computer when you visit us the next time so that we could provide you with the personalized experience in compliance with it. Cookies are not aimed at spying of users and do not monitor everything that the user does and are not a malicious code or a virus. In addition, cookies are not linked with unwished messages or spam; they cannot save a passport and are not intended exclusively for advertisements or advertising. Information such as your name or e-mail address shall not be stored - web pages cannot access your personal information and files on your computer.

In order that “cookies” could be used in accordance with the REGULATION (EU) 2016/679 OF EUROPEAN PARLIAMENT AND THE COUNCIL on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), Act on the implementation of the General Regulation, Electronic Communications Act, we need your consent.

Types of cookies

  • Session cookies and persistent cookies
    • Session cookies are temporary cookies that expire after you leave the web page. These cookies are mandatory for the regular operation of specific applications or functionality on this page.
    • Persistent cookies are used to improve the experience of our users (e.g. remembering the details of your sign-in, so that you do not have to enter them every time you visit the web page). These cookies remain in a cookie file of your browser for a longer period of time. This period of time shall depend on the selection of settings on your visit web browser. Persistent cookies enable that data are transferred to the webserver every time you visit the page.
  • First-party and third-party cookies
    • First-party cookies – issued by this Internet page. These cookies frequently serve for the regular operation of the web page and to remember your preferences on the web page.
    • Third-party cookies are cookies placed by another web page or services such as, e.g. YouTube. We have no access or control of these cookies. You need to consult the appropriate privacy rules of these third parties. If you are within the European Union, you can find out more about how the third parties use these cookies on the following link: http://www.youronlinechoices.eu/.
  • Essential and other cookies
    • Essential cookies are necessary for the operation of our web pages and the use of their features and/or services. For example, they enable navigation on the web page and the possibility to sign in into safe areas. By using these Internet pages, you automatically give consent to use essential cookies without which the web pages cannot function. These are PHPSESSID cookies and _exp cookies.
    • Performance cookies collect information about how the users use our web page, for example, which pages they visit most frequently and if they get errors messages from these pages. These cookies do not collect data that identify the visitor. All information that is collected by these cookies is anonymous. They are used only to improve the functioning of this web page.
    • Functional cookies enable our web page to remember selections and adjustment that you have made during the visit and provide improved personal features — for example, remembering the changes in language settings or currency preferences. They can also be used to enable the third parties in order to provide tools for social sharing and remember your preferred sharing services.
    • Marketing cookies are used to monitor visitors through the web page. Their intention is to show advertisements that are relevant and interesting for an individual user and thereby also more valuable for third-party publishers and advertisers.

 

Cookies and other tracking technologies that are used on this Internet page:

The information provided by these cookies helps us understand how our users are using the web site, with the purpose of improving the content quality of users and browsing experience. Optional cookies include Google Analytics cookies (whose cookies track the attendance and analyze the site performance, which is available to Bomiship d.o.o. as statistical data, without personal data of individual users), and social network cookies (eg. Facebook) that allow the user to share certain content by using one’s own social network account.

Other cookies used by this website are:

$_COOKIE['site_lng'] - remembering prefered language for a year

$_COOKIE['fav_ych_id'] - remembering your favourites for 7 days

When you access a website for the first time, a label will appear that warns you of the existence of the cookies and asks for your approval to accept them.

By continuing to browse the web site, you agree to the use of cookies.

A webpage user can always independently control (restrict or disable) receiving cookies by setting one’s web browser. Please note that disabling cookies can affect your functionality and your interaction with the web site, so we exclude any liability for any loss of functionality and/or quality of the website content in all cases of cookies regulation control selecting by the user.

For more information about configuring cookie browser settings, visit the following links:

• learn more about private browsing and cookies settings in Firefox here

• read about the anonymous mode and cookies settings in Google Chrome here

• read the "InPrivate" mode of operating and cookies settings in Internet Explorer here

• for more information about the "Private navigation" mode and cookies settings in Safari here

By using the websites, users will be deemed to be familiar with and comply with the terms of use at any time, including processing and personal data protection and cookies options.

 

 

 

 

 

Enquire