What constitutes as "personal data"? "Personal data" means any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
What is data processing? "Processing" means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Who is the data controller? "Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
Who is the data processor? "Processor" means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Who is a third party? "Third party" means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
Who is a recipient? "Recipient" means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.
What is a consent? "Consent" of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
What is a data breach? "Personal data breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
BASIC INFORMATION ABOUT THE DATA CONTROLLER
NXLog's contact details for data protection and privacy related matters are as follows: Name: NXLog Ltd. Email address: email@example.com Postal address: 2315 Szigethalom, Süllő köz 3., Hungary
Designation of data protection officer
Please note that NXLog examined the need to appoint a data protection officer according to Article 37 of the GDPR (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, GDPR ) and drew the conclusion that NXLog is not required to do so in light of the mandatory appointment criteria, in particular, NXLog's core activities do not include processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale. However, since NXLog has always added considerable weight to the privacy of personal data, NXLog appoints dedicated sufficient staff, resources to ensure that it is able to discharge its obligations under the GDPR.
Personal data shall be:
- processed lawfully, fairly and in a transparent manner in relation to the data subject ('lawfulness, fairness and transparency')
- collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with GDPR, not be considered to be incompatible with the initial purposes ('purpose limitation');
- adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed ('data minimisation');
- accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay ('accuracy');
- kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject ('storage limitation');
- processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures ('integrity and confidentiality'). The data controller shall be responsible for, and be able to demonstrate compliance with the above principles ('accountability').
LEGAL BASIS OF THE DATA PROCESSING – LAWFULNESS
Processing shall only be lawful if at least one of the following applies:
- the data subject has given consent to the processing of his or her personal data for one or more specific purposes – i.e. if you signed a consent form or given your consent via electronic means (pressing consent button or link, or giving consent over recorded telephone etc.).
- processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract – i.e. in case you are or want to be in a contractual relationship with NXLog and the processing of your data is necessary for the performance of the contract. Please note that in such case your separate consent is not required, and your data is processed as long and to the extent as required for the performance of the contract.
- processing is necessary for compliance with a legal obligation to which the controller is subject – i.e. in case a EU or national piece of legislation prescribes for NXLog to process your data (data of invoices, data of customer complaints etc.). Please note that in such case also your separate consent is not required, and your data is processed as long and to the extent as required and prescribed by law.
- processing is necessary in order to protect the vital interests of the data subject or of another natural person;
- processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
IF YOU ARE USING OUR WEBSITES
Please note that the below description is a general guideline and advisory and specifics of each data process are detailed on the relevant Website.
WHAT INFORMATION DOES NXLog COLLECT ABOUT YOU?
In case you are using our Websites, NXLog collects several types of personal, aggregated and anonymous data about you, which may include the following:
- Aggregated Data including statistical, demographical or other data which is related to you, but may not be used to directly or indirectly identify you, and which therefore does not fall as personal data.
- Contact Data includes postal address (city, ZIP code, state and country), billing address, delivery address, location, company name, e-mail address, phone number, contact preferences, job and position definition.
- Eligibility Data includes information about your location, company name, user status, NXLog partner data, title, purchase timeframe, purpose, used software and company size data, school data, school website.
- Financial Data includes credit card and bank account information, details about your payments and payment defaults, VAT/TAX ID number.
- Identity Data includes your full name, position, company name, user status.
- Marketing and Communications Data includes your preferences in receiving marketing from NXLog and its affiliates and also upon your consent from third parties, and your communication preferences.
- Profile Data includes your username, password, NXLog ID (you must create it when contacting to us and using a license, registering to use NXLog website and application), purchases or orders made by you, your interests, preferences, feedback and survey responses and other similar interactions, data collected from and via e-mails and phone calls and other communications, and other personal data derived from such data and decisions made on the basis of Profile Data.
- Technical Data includes referral URL, internet protocol (IP) address, connection IP address, WIFI network (SSID), your login data, browser type and version, time zone setting and location, operating system and platform and other technology on the devices you use to access our websites indicated above.
- Transaction Data includes details about payments made by you and other details of products and services you have purchased from NXLog such as the date of acceptance of the product/service specific terms and conditions.
- Usage Data includes information about how you use our or our partners' websites, products and services (including data generated during user interactions on NXLog and third party websites, such as registrations, likes and comments, and also data collected automatically via normal IT environment operations (such as crash reports etc.). NXLog always indicates whether the provision of a certain data is mandatory or optional. Where the pro vision of a data is mandatory and you fail to provide it, NXLog may not be able to provide the requested service or product, in which case you will be informed accordingly.
- Support information includes all details sent or uploaded to us containing name, user ID , e-mail address, location, time, time zone, activity type.
HOW AND WHERE DOES NXLog COLLECTS THIS INFORMATION?
REGISTRATION ON NXLOG WEBSITES AND CUSTOMER SUPPORT – NXLOG ID
In order to be able to use our Products You must sign up and have a valid NXLog ID. When you register to use a NXLog Website or application, provide your NXLog ID, or contact us for support or other offerings or submit a claim, NXLog collects Identity Data about you. For obtaining certain special (for example student and teacher) licenses of our applications, further Eligibility Data is required. When you contact us for support, we may request from you to provide us with copies of your files, photos, documents or other data (although that might not constitute as personal data). Please note that we use your GS ID for statistical purposes identifying the number of actual users logged in at the same time.
NXLOG SUPPORT LINES
Being subject to individual agreement you may contact us for support in technical issues and other service questions by a designated telephone line or e-mail address. When you call this support line NXLog collects Identity Data about you. Based on the type of your request additional information might be required to provide the best solution. In order to further improve NXLog service, we would like to measure your satisfaction and the performance of the service via a satisfaction survey. Your feedback is processed and retained based on your consent till withdrawal. Please note that in most cases such support lines are operated by our third party vendors as data processors.
NXLOG WEBSITES AND APPLICATIONS
For certain products and developments NXLog provides platforms for users/consultants to share their ideas, thoughts, questions etc. While you are participating in the Forums your information is collected via several ways. Firstly, by browsing the relevant program will cause to create a number of cookies.. Other way in which we collect your information is by what you submit to us. This can be, and is not limited to: posting as an anonymous user (hereinafter "anonymous posts"), registering on the relevant program (hereinafter "your account") and posts submitted by you after registration and whilst logged in (hereinafter "your posts").
Emails we send you, on the basis of your prior written (including electronic means) consent if you are an individual, usually include technologies that tell NXLog whether you have received or opened the email, or clicked a link within the email. If you do not want us to collect this information from NXLog marketing emails, you may withdraw your consent at any time and can either opt out of receiving NXLog marketing emails either from the website or application you are using, or by clicking "unsubscribe" at the end of the message or just simply writing an email to the email address(es) highlighted at point 9.8. Also for more detailed description of your rights, please also refer to clause 9.
NXLOG ONLINE ADVERTISING
NXLog advertises online in a variety of ways, including displaying NXLog ads on websites and in apps. We collect your Technical and Usage Data on our websites, including information about which ads are displayed, which ads are clicked on, and on which web page the ad was displayed, and which campaign has generated certain user actions – such as web page views and web page interactions, mobile app interactions, mobile app purchases, file downloads, contact form submissions or registration to NXLog's online services.
BUTTONS, TOOLS, AND CONTENT FROM OTHER COMPANIES
THIRD-PARTY SITES AND SERVICES
NXLog websites, products, online services, documentation and applications may contain links to third-party websites, products, and services. Our products and services may also use or offer products or services from third parties − for example, a third-party MSP. NXLog will not transfer any of your data while you are using these links or navigate to third-party website, in such case it will be these third parties who will advise you on their data processing and collect information from you, which may include such things as Contact Data, these data processing are governed by the privacy practices of these third parties. We encourage you to learn about the privacy practices of those third parties. We are also working closely with third parties (including, for example, business partners, sub-contractors in technical, delivery services, advertising networks, analytics providers, search information providers, credit reference agencies, such as Google, Twitter, Linked In based inside or outside the EU) and may receive Technical Data or information about you from them that we usually combine with other information we have about you.
To help keep our databases current and to provide you the most relevant content and experience, we may combine information from you with information from public sources and our trusted partners, in accordance with applicable law.
To update you about our products and services, industry relevant news, we either organize, sponsor or participate in certain events. To build up and improve business relation with you, we may collect your contact information verbally or via business cards on various Events either held by us or others. Also, when we sponsor industry specific events, we can gather your registration information from the organizers in compliance with the applicable regulations.
We use different social media platforms to interact with you, answer and support your queries and questions. We might collect and use your personal data for such interactions with you. We use the general social media platforms (like Facebook, LinkedIn, WhatsApp, etc) and some development and support forums. We also operate BlogPost, to publish relevant and actual information with respect to NXLog's products and services, events and industry specific news, where you have the option to comment on them.
NXLOG CLASSROOM OR ONLINE TRAININGS, SEMINARS
NXLog offers different services:
- train the trainer trainings aimed at NXLog PARTNERS;
- trainings to Building Information Modeling managers and end users using NXLog Products.
- professional seminars available for the public – some of only after after registration.
These training services may be offered free of charge or in consideration of certain reimbursement as specified in the relevant terms and conditions. NXLog collects and uses the following personal data:
- first name;
- last name;
- nick name;
- full mail address;
- phone number;
- company name;
- country and
- face and voice of online training participants (if participant approves such functions by enabling their operation) during the training and storing the recording of face and voice after the training for a limited period of time.
Purpose of data processing:
- registering to participation;
- issuing / re-issuing certificate / confirming that certificate has been issued;
- issuing targeted newsletters about new trainings (if consent has been given);
- issuing targeted emails for training feedback and follow up;
- statistical purposes; and
- online trainings might get recorded for the purpose of supporting the participants in their learning and enabling to re-watch the training
Legal base of the data processing:
- if you as natural person enter into the agreement with NXLog then performance of contract (GDPR point b) Article 6(1)) and if your company enters into the contract then the legitimate interest of NXLog (GDPR point f) Article 6(1)).
- consent in case of marketing inquires (GDPR point a) Article 6(1)).
Data retention periods: Save for the data relating to certificates issued for NXLog classroom trainings (either online or classroom), the data retention period is not defined. The recorded trainings may be published via YouTube or other public video or training sharing platforms. In case date subject revokes consent (see Section 9.) NXLog may re-edit the published video to remove the relevant information. The data retention period for data relating to certificates is 10 years after issuance of the certificate. This time period is needed to ensure that NXLog can re-issue certificates if someone lost it or to verify the training certifications on request. Data transfers: Personal data of training participants are shared with NXLog PARTNER(s) as well as with certified external trainers acting according to NXLog's instructions as NXLog's data processors if the participant is registered for local trainings. The purpose of the data transfer is to provide the training to the participant and follow-up on the course and other trainings. The training recordings are shared with the participants of the same training course for a limited time period not longer than 7 weeks after the end of the course. The purpose of the data transfer is providing the training to the participant by also enabling the participant to review the course during a limited period of time. Data transfer activities between NXLog, and NXLog PARTNERS are contractually agreed. The collected personal data is shared with the relevant NXLog PARTNERS(s) for the purposes of verifying the training certifications on request. For managing the registrations from technical point of view, NXLog might use certain external service platforms (e.g. Eventbrite).
NXLog does not offer any of its products or services to children under the age of 16 and does not allow children under the age of 16 to register on the Websites.
When you apply for a job advertised by NXLog, personal data provided by you will be processed for the purposes of managing our recruitment related activities, which include setting up and conducting interviews and tests for applicants, evaluating and assessing the results thereto, and as is otherwise needed in the recruitment and hiring processes. NXLog collects and uses your contact, identity and profile data, until you withdraw your consent but maximum for the period specified by the consent. Legal basis of data processing: consent of the data subject (Article 6(1)(a) of the GDPR) Your personal data will be shared with cloud services provider located in several countries that we engaged to help manage our recruitment and hiring process. Furthermore, your personal data will be stored in a cloud storage provided by Digital Ocean Inc, Microsoft Inc, Linked In Inc. Accordingly, if you are located outside of the United States, your personal data will be transferred to the United States once you submit it through this site. Because the European Union Commission has determined that United States data privacy laws do not ensure an adequate level of protection for personal data collected from EU data subjects, the transfer will be subject to appropriate additional safeguards under the standard contractual clauses or the Privacy Shield. You can obtain a copy of the standard contractual clauses by contacting us at info@NXLog.com.
FOR WHAT PURPOSES AND ON WHAT BASES DOES NXLog USE THE INFORMATION IT COLLECTS ABOUT YOU?
IN MOST CASES, NXLOG WILL USE YOUR PERSONAL DATA ON THE FOLLOWING LEGAL BASES:
Consent : when NXLog, or NXLog PARTNERS send you marketing communications via electronic means, such as e-mail, text messages, personal messages (point a) Article 6(1) GDPR).
Legitimate interest : where processing is necessary for our legitimate interests (or those of a third party), and your interests and fundamental rights do not override those interests, and we may verify that a favourable balance of interest test has been carried out (point f) Article 6(1) GDPR).
Performance of contract : where NXLog needs to perform the contract we are about to enter into or have entered into with you as natural person (point b) Article 6(1) GDPR).
Legal obligation : where NXLog needs to comply with a legal obligation, such as tax or other regulatory obligations and requirements (point c) Article 6(1) GDPR). By way of background information, in general, legitimate interest means the interest of our business in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). Please be advised if you need further information on the summary of the balance of interest tests carried out by NXLog in relation to the activities set out in the below table, please contact us. Of course, you can always obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us.
Performance of contract means processing your data where it is necessary for the performance of a contract to which you as a natural person are a party or to take steps at your request before entering into such a contract.
Legal obligation means processing your personal data where it is necessary for compliance with a legal or regulatory obligation that we are subject to.
WHAT ARE COOKIES AND HOW DOES NXLog USE THEM?
A cookie is a small piece of information that will be stored on your hard disk until you delete it. Like most websites and applications, we use our own cookies and those of third parties, together with similar technologies, to make our websites and applications work, to offer you customized and personalized service, and to learn more about our users and their likely interests. Cookies themselves don't hold personal information. They only have a unique alphanumeric identifier that sits on your browser. And in many cases, we won't be able to link the information we collect by using a cookie back to you. They can, however, enable us to link that information back to you and your personal information, for example, when you log in, or choose to register for a service, product or newsletter. NXLog and third-party vendors (including Microsoft and Linked In, etc.) use first-party and third-party cookies and related user behaviour tracking technologies to measure desktop software, mobile application and website usage; record different user activities in its software and on its web sites; and display advertisements based on the user's previously recorded activities. NXLog does not disclose any personally identifiable information to these third-party vendors. However, third-party vendors automatically receive IP addresses when activity tracking occurs. NXLog may connect user activity data gathered by third-party vendors with information collected by its websites and applications and such data may therefore become Profile or Usage Data. You can set your browser so that the browser informs you about cookies or automatically prevents their storage. If you do not store our cookies, you will still be able to visit our website or use our services; however, the use of individual offers or features might be limited.
DOES NXLog SHARE/DISCLOSE MY PERSONAL DATA?
( A ) DISCLOSURE TO DATA PROCESSORS NXLog as a business entity is subject to tax related obligations and also is subject to authority reviews, the course of which we could be obliged to share your data with the authorities. These obligations are imposed on NXLog by laws and regulatory decisions, we are legally bound to fulfil these requirements. NXLog also works with companies that help us run our business. Among these are the subsidiaries of NXLog and also companies that are not linked to NXLog providing services for us. These services vary in subject and term: external consultants, professional advisers such as lawyers or auditors, technical support functions (IT and document storage providers, professionals delivering customer support and sending emails on our behalf). These are called data processors are engaged in all cases based on written contract with appropriate guarantees to safeguard the security of the data and the rights of the data subjects. In some cases, these companies have access to some of your personal information in order to provide services to you on our behalf. They are not permitted to use your information for their own purposes and we ensure by data processing contracts (including electronic format) that your data are being processed in accordance with the legal regulations. Currently, NXLog is using the following data processors:
Name Accessibility Activity Salesforce.com, Inc.www.salesforce.com CRM software service provider/licensor, marketing automation The Rocket Science Group, LLC d/b/a MailChimp www.mailchimp.com Assistance with the conduct of e-mail marketing campaigns, webinars GitLab www.gitlab.com Software & Tech Services Google, Inc. www.google.comDescriptionTwitter Inc. www.twitter.comProcessing of user dataMicrosoft Corporationwww.microsoft.comData hosting, mailing system, voice, video, pictures Digital Ocean, Inc. www.digitalocean.com
Data hosting Linked In Inc www.linkedin.comProcessing of user data
It is NXLog's legitimate interest to prevent and respond to fraud, to defend our Websites and applications against attacks, to protect the property and safety of NXLog, our customers, users, the public. That is why NXLog PARTNERS and specific companies are retained as data processors to assist us to combat piracy. Please note that it is NXLog's legitimate interest from the above reasons not to identify our service providers. We share Your IP address, MAC address, software version and language with them exclusively for the above purposes. Further to the above as indicated earlier NXLog provides its services in close cooperation with its subsidiaries therefore it is frequent that a NXLog subsidiary acts as data processor on behalf of NXLog. ( B ) DISCLOSURE TO OTHER DATA CONTROLLERS In other cases, we provide your data to other entities to use such data under their own name and for their own benefit. Sometimes we may need to do this to comply with a legal obligation (such as when we need to provide certain Transaction, Technical or Identify Data to the police or other authorities), and in other cases, we rely on other legal grounds, such as our legitimate interests or your written (including electronic means) consent. Accordingly, if you consent to the sharing, as indicated above in the table, NXLog may also share your Identity Data, Contact Data and Marketing and Communications Data with our partners. Please note that we do not share your personal data for their own marketing purposes unless the consumer agreed to that sharing. We may share or publish Aggregate Data that doesn't specifically identify you, such as statistical information about visitors to our websites or statistical information about how customers use our applications. We require all third parties to respect the security of your personal data and to treat it in accordance with the law and the data processing contract if any. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
( C ) MAKING YOUR DATA PUBLICLY AVAILABLE BY YOU There are several places on NXLog's websites and applications that allow you to post comments, upload pictures, or submit content for others to see. Sometimes you might be able to limit who can see what you share, but there are some places where what you share can be seen by the general public or other members of the website or application. Please be careful when you share your personal information. Do not share anything you do not want publicly known unless you are sure you are posting it within a website or application that allows you to control who sees your post. Please note that when you post messages on certain user forums on our websites and applications, your email address or name may be included and displayed with your message. To remove content you have shared on our websites and applications, please use the same website or application feature you used to share the content. If another user invites you to participate in shared viewing, editing, or commenting of content, you may be able to delete your contributions, but usually the user who invited you has full control. If you have questions or concerns about this, please contact us.INTERNATIONAL TRANSFERSAs indicated above, we share your personal data within the NXLog PARTNERS as follows:
- You provide us with certain personal data when registering at our Websites. In such case, if you consent to the sharing, as indicated above in the table, NXLog as data controller may also share your Identity Data, Contact Data and Marketing and Communications Data with NXLog PARTNERS too.
- NXLog PARTNERS use the online ordering system of NXLog and when using it may fill in certain personal information about you. This is always the decision of the given NXLog PARTNER. In such case the NXLog PARTNER is the data controller and NXLog is only data processor of the partner in order to provide the electronic ordering system. These transfers will involve transferring your data outside the European Economic Area ( EEA ). Also, since many of our external third parties are based outside the European Economic Area ( EEA ) (such as Microsoft, Inc., Digital Ocean, Inc., Salesforce.com, Inc.), so their processing of your personal data will involve a transfer of data outside the EEA.
NXLog is a worldwide remote company and cannot limit data processing to pre-defined geographical locations. Whenever we transfer your personal data outside of EEA, we contractually ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- we ensure and provide an adequate level of protection for personal data by the European Commission. For further details, see European Commission: Adequacy of the protection of personal data in non-EU countries.
- (b) where we use certain service providers, we may use specific contracts follow the European Commission which give personal data the same protection it has in Europe. For further details, see European Commission: Model contracts for the transfer of personal data to third countries. Please do contact us if you need further information on the specific mechanism used by us when transferring your personal data outside of EEA.
IS MY PERSONAL DATA SECURE, AND WHERE WILL IT BE STORED?
We understand that the security of your personal information is important. We provide reasonable administrative, technical, and physical security controls to protect your personal information. All information you provide us is stored on secure servers. Where we have given you (or where you have chosen) a password which enables you to access certain parts of our websites, you are responsible for keeping this password confidential. We ask you not to share a password with anyone. Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot warrant or guarantee the security of your data transmitted to us; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access. In case your data is provided by registering on our websites than we ensure that this registration is completed on a secured platform where we apply our security measures. In case you would like to have more information on the specific security measures taken in order to save your data than please contact us. Also, we have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality. Finally, we have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so. Your personal information and data files are stored on NXLog's servers and the servers of companies we hire to provide services to us. As shown in clause 6 above, your personal information may be transferred across national borders because we have servers located worldwide and the companies we hire to help us run our business are located in different countries around the world (for example, Germany, Ireland, the United States). As mentioned in clause 6 above, the data that we collect from you may therefore be transferred to, and stored at, a destination outside the European Economic Area ("EEA"). It may also be processed by staff operating outside the EEA who work for us or for one of our suppliers. Such staff maybe engaged in, among other things, the fulfilment of your order and the provision of support services.
HOW LONG WILL NXLog HOLD AND USE MY PERSONAL DATA?
We only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we take into account the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements. More specifically, and without limiting the generality of the foregoing, by law we have to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for at least 5, in certain cases 8 years after they cease being customers for tax, financial auditing, and record keeping purposes. In some applicable circumstances you can ask us to delete your data: see the clause dealing with 'Right To Erasure' below for further information. In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.
YOUR RIGHTS REGARDING YOUR PERSONAL DATA
Your right to access
You have the right to access your personal data, including requesting information on whether NXLog processes your data, which data are processed, and you may also request a copy of the data that you or a third person provided to NXLog and which data is being processed by NXLog. If you request that NXLog confirm whether or not NXLog processes your personal data, then you have the right that obliges NXLog to confirm that it processes your personal data, or does not process your personal data. Your right to obtain confirmation whether NXLog processes (or does not process) your personal data ( a ) does not include data that is anonymous; ( b ) includes the personal data that concern you; ( c ) does not include personal data that does not concern you; and ( d ) includes pseudonymous data that can be clearly linked to you. NXLog shall give you access to your personal data if ( a ) you request NXLog to confirm whether or not it processes your personal data, and ( b ) NXLog confirms that it processes your personal data, and ( c ) you request access to your personal data. NXLog shall provide you with a copy of your personal data if ( a ) you request NXLog to confirm whether or not it processes your personal data, and ( b ) NXLog confirms that it processes your personal data, and ( c ) you request a copy of your personal data. If you request further copies of your personal data, then NXLog may charge you the fee of EUR10 or in equivalent local currency,- based on the administrative costs incurred in relation to the accommodation of such request. Upon your request NXLog will give you access to the following information:
- the purposes of the processing;
- the categories of personal data concerned;
- the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
- where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
- the existence of your right to request from NXLog rectification or erasure of your personal data or restriction of processing of personal data concerning you or to object to such processing;
- the right to lodge a complaint with a supervisory authority;
- where your data are not collected from you, any available information as to their source;
- the existence of automated decision-making, including profiling, and meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for you.
Please also note that many of our websites and applications allow you to access or edit your personal information by accessing thethe website or application you are using. Likewise, you can access files or photos you have stored in our online services by logging in and using the functions they make available.
Your right to rectification
You have the right to the correction of your personal data without undue delay. This enables you to ask that any incomplete or inaccurate data we hold about you be corrected. Your right to obtain rectification of your data that are inaccurate ( a ) does not include data that is anonymous; ( b ) includes the personal data that concern you; ( c ) does not include personal data that does not concern you; and ( d ) includes pseudonymous data that can be clearly linked to you. NXLog shall rectify your personal data if ( a ) NXLog processes your personal data; ( b ) the personal data in question are inaccurate; and ( c ) you request the rectification of your personal data. NXLog shall complete your personal data if ( a ) NXLog processes your personal data; ( b ) the personal data in question are incomplete; and ( c ) you request the completion of your personal data and if necessary you provide supplementary information for completion. NXLog may verify any and all data provided to it. NXLog shall taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to communicate the rectification of your personal data to recipients of such personal data (if any). However, NXLog shall not communicate the rectification of personal data to recipients if the communication to such recipients is either impossible or involves a disproportionate effort. Please also note that many of our websites and applications allow you to edit your personal information by accessing the website or application you are using. Likewise, you can edit files or delete photos you have stored in our online services by logging in and using the functions they make available.
Your right to erasure ('right to be forgotten')
Subject to certain conditions and in certain cases, you have the right to the erasure of your personal data. This means that you may request that we delete your personal data that we may have processed unlawfully or where the use of your data is no longer needed for a purpose. Please keep in mind that NXLog may not be able to meet your request for specific legal reasons that will be notified to you, if applicable. NXLog shall erase your personal data without undue delay if ( a ) NXLog processes your personal data, and ( b ) you request to obtain the erasure of your personal data, and ( c ) the personal data are no longer necessary to the purposes for which NXLog collected them; NXLog shall erase your personal data without undue delay if ( a ) NXLog processes your personal data based on your consent, and ( b ) you request to obtain the erasure of your personal data, and ( c ) you withdraw your consent on which the processing of your data is based, and ( d ) there is no alternative legal basis for the processing of your data any further. NXLog shall erase your personal data without undue delay if ( a ) the processing is based on being necessary for the purposes of the legitimate interests of NXLog or a third party, and ( b ) you object to NXLog's processing of your personal data, and ( c ) the legal ground for the processing of your personal does not override your objection. NXLog shall erase your personal data without undue delay if ( a ) you request to obtain the erasure of your personal data, and ( b ) the processing by NXLog of such data is unlawful, or ( c ) if the erasure is required under applicable law, or ( d ) your data is collected in relation to the offer of an information society service. NXLog shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to communicate the erasure of your personal data to recipients of such personal data (if any). However, NXLog shall not communicate the erasure of personal data to recipients if the communication to such recipients is either impossible or involves a disproportionate effort. Please note that there are certain cases when you may not request erasure of your data. These reasons will be communicated to you if your request for erasure cannot be completed. Please also note that many of our websites and applications allow you to edit or delete your personal information by accessing the website or application you are using. Likewise, you can delete files or photos you have stored in our online services by logging in and using the functions they make available.
Your right to the restriction of processing
You may also request the restriction of the processing of your personal data. For instance, you may request that we suspend the processing of your personal where our use of the data is unlawful but you do not want us to delete it. Your right to request the restriction of the processing of your personal data ( a ) does not include data that is anonymous; ( b ) includes the personal data that concern you; ( c ) does not include personal data that does not concern you; and ( d ) includes pseudonymous data that can be clearly linked to you. NXLog shall restrict the processing of your personal data for a period to verify the accuracy of such data if you request to obtain the restriction of the processing of your personal data, and you contest the accuracy of such data. NXLog shall restrict the processing of your personal data if you request to obtain the restriction of the processing of such data, the processing of which is unlawful, and you opposes the erasure of such data. NXLog shall restrict the processing of your personal data if ( a ) you request to obtain the restriction of the processing of such data, and ( b ) NXLog does not need such data for the purposes of its processing, and ( c ) you require your data for establishment, exercise or defence against a legal claim. NXLog shall restrict the processing of your personal data if ( a ) you object to the processing of your personal data that are necessary for the purposes of the legitimate interests that NXLog pursues, and ( b ) you wait to verify that the legitimate ground of NXLog's processing of your personal does not override your objection. NXLog shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to communicate the restriction of processing of your personal data to recipients of such personal data (if any). However, NXLog shall not communicate such restriction to recipients if the communication to such recipients is either impossible or involves a disproportionate effort. If NXLog restricts its processing of an your personal data, then it may ( a ) store such personal data, ( b ) process such personal data on the basis of your consent, ( c ) process the personal data for establishing, exercise or defend a legal claim, or for protecting the rights of another person. In case you have obtained restriction of processing as per the above than you shall be informed by NXLog before the restriction of processing is lifted.
Your right to data portability
Where the processing of your data is either based on your consent (e.g. in respect of electronic direct marketing), or is necessary for the performance of a contract (e.g. customer registration data and data relating to your orders), and the processing is carried out by automated means, than you may request the provision of your personal data that you have provided to us in a standard format, and you may also request that such data be transferred to another entity. Without prejudice to your rights above, you have the right to receive the personal data concerning you, which you provided to NXLog, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance (where technically feasible) from NXLog, where the processing is based on your consent, or is necessary for the performance of a contract, and the processing is carried out by automated means. Your right to data portability ( a ) does not include data that is anonymous; ( b ) includes the personal data that concern you; ( c ) does not include personal data that does not concern you; and ( d ) includes pseudonymous data that can be clearly linked to you.
Your right to object
**Importantly, when we process your data on the basis of our legitimate interests as indicated in the above table, you may object to such processing and request that any of those activities be stopped. Similarly, you may opt-out of any of our direct marketing activities at any time by contacting NXLog at info@NXLog.org, by adjusting your preferences in the privacy dashboard provided as part of some of our services or by using the 'unsubscribe' function at the end of our messages.
Your rights in relation to automated decision making and profiling
You have the right to request not to be the subject of automated decision-making including profiling where the decision produces legal effects or equally has a significant effect on you, and can insist on human intervention where appropriate. There are exceptions to this right, which are, if the decision: 1. Is necessary for concluding or performing a contract 2. Is authorized by law 3. Is based on the data subject's explicit consent
Your right to withdraw consent
Your right to withdraw consent Also, you have the right to withdraw your consent at any time where we rely on your consent for processing your data (e.g. for certain electronic direct marketing purposes). You may do this at any time by contacting NXLog at info@NXLog.org , by adjusting your preferences in the privacy dashboard provided as part of some of our services or by using the 'unsubscribe' function at the end of our messages. Remember that the withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal and that in some cases we may need time to process request. NXLog shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to communicate your objection/withdrawal of consent to recipients of such personal data (if any). However, NXLog shall not communicate such restriction to recipients if the communication to such recipients is either impossible or involves a disproportionate effort.
Your right to lodge a complaint
Without prejudice to any other administrative or judicial remedy that you may have (such as the right to claim compensation for damages suffered as a result of NXLog's breach of the GDPR), you have the right to lodge a complaint with the Hungarian Data Protection and Freedom of Information Authority ( NAIH ) supervisory authority, or another data protection supervisory authority in the Member State of your habitual residence, place of work or place of the alleged infringement if you consider that the processing of personal data relating to you infringes the GDPR. The contact details of the NAIH are as follows: H-1055 Budapest, Falk Miksa utca 9-11; 1363 Budapest, Pf. 9; phone: +36 1 391-1400; telefax: +36 1 391 1410; e-mail: firstname.lastname@example.org; website: www.naih.hu. In any case, we would highly appreciate the chance to deal with your concerns before you approach the regulatory authority above, so please contact us in the first instance if you have any problems.
Restrictions on the above rights
Please be advised that based on GDPR Member States are allowed to restrict by way of a legislative measure the scope of the rights you may have as per the above. In case such restriction is applicable in your respect, we will advise you accordingly when you contact us on exercising any of your above rights.
If you wish to exercise any of your rights mentioned above, please contact us at the addresses set out in clause 1.2 above.
No fee usually required
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a fee of EUR 30 or in equivalent local currency, if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
Verification of your identify