At Espera X, a brand operated by AITAC Ltd., we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your personal data when you interact with the Espera X website.
This data processing notice outlines how we handle data that can directly or indirectly identify you as an individual ("personal data"). All processing of personal data is carried out in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws through appropriate legal, technical, and organizational measures.
The data controller for all personal data collected via the Espera X website is:
AITAC d.o.o.Although Espera X is presented as a standalone brand, it is not a separate legal entity and operates under the full responsibility of AITAC.
This Privacy Policy applies to:
It does not apply to other websites or services of AITAC unless specifically stated.
AITAC has appointed a Data Protection Officer (DPO) responsible for overseeing privacy and data protection compliance. You may contact the DPO regarding any concerns about your data:
By post:
AITAC d.o.o.By email:
When interacting with Espera X, a brand of AITAC Ltd., we may collect the following personal data through various communication channels (such as through our website, email inquiries, contract negotiations, tenders, and events):
We may also collect non-personal data, including but not limited to:
Your personal data are processed only when legally justified. The legal bases for processing include:
We process your data to fulfill requests, respond to inquiries, provide support, and deliver goods or services as part of our legitimate and contractual obligations. This includes:
Marketing communications will only occur with your explicit prior consent, and you may withdraw it at any time by emailing us at zastitapodataka@aitac.nl.
We may process your data for the following purposes based on legitimate interest:
You can object to such processing at any time by contacting zastitapodataka@aitac.nl.
We request your consent for specific cases, including:
You can withdraw consent at any time without affecting previous processing, by emailing zastitapodataka@aitac.nl. Certain services or benefits may no longer be available after withdrawal.
We collect data:
We retain personal data only as long as needed to:
After the retention period ends, your data is securely deleted or anonymized.
Our website and services are not intended for individuals under 16 years of age.
Your personal data is processed within the European Economic Area (EEA). The only exception is for our use of MailChimp for email marketing, whose provider is based in the U.S.:
The Rocket Science Group LLC (MailChimp)This transfer is permitted under GDPR via the Adequacy Decision and Privacy Shield mechanisms (Article 45, GDPR).
You have the right to:
Submit any requests to zastitapodataka@aitac.nl. We will respond within 30 days, and may require identity verification. In rare cases, a fee may be charged if the request is excessive.
You also have the right to know:
We do not use automated decision-making or profiling in any way that affects your rights or services.
You may submit a complaint to the Croatian supervisory authority:
Personal Data Protection AgencyWe apply physical, technical, and organizational safeguards to protect your data from unauthorized access, alteration, or loss. Our security measures include:
When browsing our web pages, the Company may collect information through various technologies such as cookies, web beacons, and similar tools. In this document, the term "cookies" encompasses all such technologies.
Cookies are used to:
These technologies help improve user experience, analyze usage patterns, enhance site security, and tailor our communications and services to better suit your interests.
When you browse our website or interact with us via any platform using programmatic support, we automatically collect and store certain data in server logs. This includes:
This data is used exclusively for system maintenance, security analysis, troubleshooting, and service improvement.
Our website may contain links to external websites owned or managed by third parties. These websites are not governed by this Privacy Policy.
The Company assumes no responsibility for the privacy practices, content, or security of such third-party sites. We recommend reviewing the privacy policies of all external sites you visit.
The Company implements comprehensive technical and organizational security measures to protect the personal data of individuals. These measures apply during data entry, transmission, processing, and storage.
Access to personal data is restricted solely to employees who require such access to perform their work duties and company activities.
All individuals have the right, at any time, to request:
Requests can be submitted in writing to the Personal Data Protection Representative at the Company.
This section outlines how the Company collects and processes personal data during the candidate selection and employment process. Personal data will be handled in accordance with the rules set forth below.
Voluntary Submission of Personal Data
By submitting personal data for employment or business registration purposes, you voluntarily provide your personal information to the Company.
The Company collects the following categories of information:
In addition, the Company may verify information provided by the candidate through third-party sources (e.g., to confirm educational credentials, employment history, or references).
The Company does not request or process sensitive personal information unless legally required. This includes information related to:
All personal data provided during the employment process is given voluntarily. The Company will only request information necessary to ensure a lawful and fair recruitment process and will not collect excessive or unrelated personal data.
The Company may use your personal data for the following purposes:
If selected for employment, your data may be further used for onboarding, employee administration, and internal organizational management.
The Company may share your personal information:
All third parties are bound by confidentiality agreements and must use the data solely for the purposes disclosed.
The Company implements robust technical and organizational measures to protect personal data. Only employees who need access to personal data for work purposes are granted such access and are bound by confidentiality obligations.
Security procedures may include surveillance of premises and monitoring of IT systems. Such activities are carried out in accordance with applicable laws and are designed to safeguard the Company's assets and data.
Candidates are responsible for ensuring that:
This Privacy Policy is reviewed and updated regularly to reflect changes in how the Company processes personal data. The most current version is always available on AITAC's website.
In the event of significant changes that may affect your rights or freedoms, the Company will inform you promptly and clearly, using appropriate communication channels.