GDPR

Introduction

The purpose of this notice on the protection of personal data is to fulfill our obligation to provide you with information about the processing of your personal data in connection with the use of our website – https://www.kardi-ai.com/ (hereinafter referred to as the “website”) and the services offered .Below is set out in more detail what information we collect about you, how we use and protect that information, with whom we may share it and what rights you have as a data subject.We may update this privacy notice from time to time and will post any changes on our website pages. Please review our Privacy Notice regularly. This privacy notice was last updated on 07/29/2022.

Who is the data controller?

The data controller is the company KARDI AI Technologies, s.r.o., registered in the commercial register in Ostrava, Czech Republic, with registered office at 28. října 11, Olomouc, Czech Republic 779 00. All references to “we”, “us”, “our”, KARDI AI”, KARDI-AI” and “Kardi AI” refer to KARDI AI Technologies.

Who is the data subject?

A data subject is any person whose personal data is collected, stored or processed (e.g. website visitors, job applicants, clients, suppliers and partners).

What does personal data mean?

“Personal data” or “personal information” means any information relating to an identified or identifiable natural person (“data subject”), such as name, address, age, contact details, identification number, location data, online identifier, etc.

Does KARDI AI process children’s personal data?

Our services are not intended for children under the age of 14. We do not intentionally collect, use, provide or otherwise process personal data of children under the age of 14. Therefore, we also ask that if you are under 14 years old, do not send us your personal data. If you are under 14 years of age and still wish to ask a question or use our website or services in any way that requires the provision of your personal information, please ask your parent or guardian to do so on your behalf.

How does KARDI AI collect data?

Kardi AI collects personal data from various sources, but primarily directly from you – the data subjects. You can provide this information directly to Kardi AI, send it by email or enter it in the contact or job application form on our website.

What personal data does KARDI AI process and why? How long does KARDI AI keep my data?

Website visitors

As a visitor, you do not need to provide any personal information to use our website. However, if you complete a contact form or a job application form, our website will collect standard internet protocol information, including:

  • your IP address
  • browser type
  • country, region and city
  • access times and addresses of referring websites

If you choose to contact us, including by completing a contact form on our website, we will collect certain personal information about you, such as:

  • names
  • email and/or phone number
  • any other information you choose to share with us.

In your inquiry, withhold or delete any personal information that is not relevant or that you do not want to share with us.

We will only use this data to answer your inquiry and will not process it for other purposes.

Job seekers

If you apply for any job vacancy at Kardi AI, including by completing the job application form on our website, we will process the following categories of personal data that you or your potential candidate provide to us, such as:

  • names
  • contact details (e.g. phone number, address, e-mail)
  • professional experience
  • education
  • qualifications
  • any other information you choose to share with us.

We will only process this data for recruitment purposes and we will keep the data you provide for a period of six months from the end of the recruitment process. Kardi AI will store assessment data (tests, interview reports, etc.) for a period of three years from the end of the recruitment process.

Customers and suppliers

If you are our client, supplier or partner, we may collect the following information:

  • names
  • identification number (personal identification number or other identifier used as a VAT number for an invoice issued to a natural person).
  • Data from a national identity card or passport
  • contact details (address, e-mail, telephone number).
  • registration data (country of registration, registration number)
  • Bank account

The processing of your personal data is necessary for the performance of the contract between you and Kardi AI and for the fulfillment of legal obligations applicable to Kardi AI.

We will keep your personal data for a maximum of 5 (five) years after the termination of the contract.

In all cases described above, it is our policy to retain your personal data for as long as is necessary for the specific purpose or purposes for which it was collected. However, we may be required to retain some personal data for a longer period of time, taking into account the following factors:

  • legal obligations under applicable laws to store data for a certain period of time.
  • (potential) disputes
  • instructions issued by competent data protection authorities

While we will continue to process your personal data, we will ensure that it is handled in accordance with this Privacy Policy. Otherwise, we will securely delete your data as soon as it is no longer needed.

Do we share your personal data with third parties?

Your personal data will only be shared as necessary with third parties, such as service providers (cloud service providers, insurance companies, bankers, lawyers, auditors, investors, consultants and other professional advisors and other service providers) and affiliates.

If these third parties act as “data processors”, they perform their tasks on our behalf and at our direction for the above purposes. In these cases, your personal data will be made available to these third parties only to the extent necessary to provide the requested services.

Where is my data transferred?

Your personal data is processed within the European Economic Area (EEA). However, if our service providers are based or use servers outside the EEA and it is necessary, we may transfer your data outside the EEA. In these cases, we will ensure that adequate safeguards are in place to protect your personal data and that the requirements of the GDPR and all other applicable data protection laws are met before such a transfer takes place.

Rights of the data subject

What are my data subject rights and how can I use them?

As a data subject, you have many choices over the information we hold about you; these rights and how to exercise them are explained below. If you have any questions, need additional information or instructions, please contact info@kardiai.com.

Access to my data

You can request access to the information we hold about you and we will also share it with you:

  • what data we process about you
  • why we process it
  • lawful basis for processing
  • with whom we share it and whether the information is transferred to a country that is not considered to have adequate privacy protection.
  • how long we will keep your data
  • the source of the information unless it was obtained directly from you.
  • if we use your data for automated decision-making or profiling.

Correction of inaccuracies

If you believe that the information we have about you is inaccurate, you can ask us to correct or update it.

The right to be forgotten

You can also request the erasure of your data. However, this may not always be possible if it would mean that we cannot fulfill the contract with you, or if we have a legal obligation or legitimate interest to retain the data. We will explain the consequences of deleting your data.

Restrict processing

If you believe that we are processing your data illegally or with inaccurate data, you can ask us to restrict processing. If personal data is subject to such a restriction, we will only process it with your consent or for the purpose of establishing, exercising or defending legal claims or for the purpose of protecting the rights of another natural or legal person or for reasons of important public interest. If the processing is limited, we will continue to store the data.

Objection to processing

If you do not agree with any legitimate interest or public interest that we have invoked when processing your data, you can object to the processing. In such a case, we will stop processing the data unless we demonstrate a serious legitimate reason that overrides your rights, or if the processing is not necessary for the determination, exercise or defense of a legal claim.

Data portability

If we rely on your consent as a legal basis for processing or the fact that the processing is necessary for the performance of a contract to which you are a party, and such personal data is processed automatically, you have the right to obtain all such personal data that you have provided to Kardi AI have provided, in a structured, commonly used and machine-readable format, and also to request that we pass it on to another controller if technically feasible

File a complaint

We are committed to protecting your data and respecting your rights, but if you feel that we have not done so, please contact us via info@kardiai.com. In addition, you have the right to file a complaint with the relevant supervisory authority of the Czech Republic at https://www.uoou.cz/

Thank you for your interest

We will contact you shortly.