SK

Privacy notice on the processing of personal data and your rights

In case you are providing your personal data, we as a data controller Nivy Tower s. r. o., having its registered seat at Mlynské nivy 5, 821 09 Bratislava, Slovak Republic, ID No.: 50 733 931, registered with the Commercial Register maintained by the City Court Bratislava III, Section: Sro, File No.: 117440/B (hereinafter referred to as the “HB Reavis” or “we”) would like to inform you about the processing of your personal data and of your rights related to the said processing.

HB Reavis is part of the HB Reavis Group, which consists of all entities consolidated under the group holding HB Reavis Holding S.A. and HB Reavis Investments Holding S.A. with its headquarters in Luxembourg due to which the reference to HB Reavis Group may be found in the Privacy Notice (hereinafter referred to as the “HB Reavis Group “).

This notice applies to current and former employees, tenants, visitors, and contractors. This notice does not form a part of any contract of employment or other contract to provide services. This Privacy Notice may be updated from time to time. We encourage you to periodically review this Privacy Notice for the latest information on our privacy practices. Your continued use of our services after the posting of changes to this Privacy Notice will mean that you accept those changes.

It is important that you read and retain this notice, together with any other privacy notice we may provide on specific occasions when we are collecting or processing personal information about you, so that you are aware of how and why we are using that information and what your rights are under the data protection legislation.

If you are in Nivy Tower, in its immediate vicinity (as a visitor, employee or for any other purpose) or visit websites or social media related to Nivy Tower, your personal data may be processed for the following purposes:

  1. Ensuring the safety of visitors and users of Nivy Tower as well as the protection of Nivy Tower and property
  2. The acceptance, processing, and handling of emergency calls
  3. The issuing of entry cards
  4. Mutual communication
  5. Promotion of our brand, good name, services, and events
  6. The operation of the “Help desk” platform
  7. The administration of insurance claims in Nivy Tower
  8. Organisation and administration of an event
  9. Evaluation of client satisfaction
  10. Use of the More application
  11. Sending of marketing materials
  12. Management of building – daily report
  13. Exercise of the data subject’s rights under the GDPR

 

A more detailed specification of the individual purposes:

  1. Ensuring the safety of visitors and users of Nivy Tower as well as the protection of Nivy Tower and property

What is our purpose for and legitimate interest in processing your personal data?

The protection of Nivy Tower and the safety of the people using the premises of Nivy Tower are the number one priority in our business activities. For us to be able to ensure the proper level of protection and safety, we installed a video monitoring system (CCTV) in the Nivy Tower.  Whenever you enter Nivy Tower, the parking garage, or its immediate surroundings, whether as a visitor or an employee, one or more of the following methods of recording and capturing may apply to you:

 

Ways of processing your
personal data Description of our purpose and legitimate interests
 What kind of personal data do we  process? How long do we store your personal data?
We scan your vehicle licence plate number (LPNo) and store records, if the LPNo recognition technology for the automatic opening on the ramp for authorised vehicles is used in conjunction with the vehicle or when entering the garage using an entry card. Digital image of the vehicle LPNo, recording of the LPNoin alphanumeric format We store your personal data for 6 months from the date of the record
We collect data regarding the entry card or QR code upon entry and departure through contact points in the building, i.e., from the public part to the private part of the building, so that we ensure access for authorised persons only. Card number, place, and entry time We store your personal data for 6 months from the date of the record
We produce your visual images by means of an installed CCTV camera system, which records the internal spaces of the building, the parking lot and part of the area outside the building. A visual image of you We store your personal data captured by cameras located in the building or in the parking lot and on the outside of the building for 15 days
In case you are visiting the premises of the building or attending an event organized by one of the tenants at the building we need to register you at the reception for safety and protection purposes. Moreover, either we or our tenant will issue you with a temporary entry card in the form of a QR code at the reception or via email, if you are a guest of our tenant. While registering you at the reception or sending out the QR code we need to process your personal data so we can fulfil our purpose and legitimate interests to the fullest. Name, surname, e-mail, identification of the tenant (if attending a tenant’s event) and date and time of the entry We store your personal data for 90 days

What is our legal basis and legitimate interest for the processing of your personal data?

 In all cases of processing for the purpose of ensuring the safety of visitors and users of Nivy Tower and protecting the building and property, your personal data is processed based on a legitimate interest pursuant to Article 6(1)(f) of the GDPR.

 

  1. The acceptance, processing, and handling of emergency calls

What is our purpose for processing your personal data?

In each lift in the building, there are voice communicators through which it is possible to contact the central security desk of the building in real time should a problem arise. These calls are not recorded. However, we may process your personal data during the call if it is necessary to protect your life, physical safety, or the life or physical safety of another person.

What is our legal basis and legitimate interest for the processing of your personal data?

During the handling of emergency calls, the legal basis is justified under your or another individual’s ‘vital interest’, we process your personal data under Article 6 (1) (d) of GDPR.

What kind of personal data do we process?

Personal data provided during an emergency call.

How long do we store your personal data?

We process your personal data during the call.

 

  1. The issuing of entry cards

What is our purpose for and legitimate interest in processing your personal data?

For us to permit you to enter the premises of your employer, we will issue you an entry card that allows you access to the restricted premises of the building.

What is our legal basis and legitimate interest for the processing of your personal data?

We process your personal data based on the legitimate interests under Article 6 (1) (f) of GDPR to issue entry cards.

What kind of personal data do we process?

Name, surname, and the business name of your employer

How long do we store your personal data?

For the duration of your contractual relationship with our tenant or the duration of the rental relationship, whichever occurs first.

 

  1. Mutual communication

What is our purpose for and legitimate interest in processing your personal data?

Our philosophy is to always be open and transparent. This includes being open to communication with any person interested in Nivy Tower. To achieve this goal, we created several types of contact forms that can be used for direct communication with a team of people managing the operation of Nivy Tower, or to receive more information about the building. Additionally, we have also published the email addresses of specific employees you can contact at any time with any questions. However, to ensure effective, flawless, and clear communication, we must process some of your personal data.

Moreover, when executing the sales/leasing process with our (potential) clients we strive to create an effective and transparent communication channel. To achieve this purpose, we use the CRM database that consists of contact data (including personal data) of our (potential) clients or their employees. We create this database to ensure effective and flawless communication with the (potential) clients and to build a database consisting of all our business partners.

What is our legal basis and legitimate interest for the processing of your personal data?

If you contact us or any employee via email or a web-based form, we process your personal data based on the legitimate interests under Article 6 (1) (f) of GDPR.

What kind of personal data do we process?

Name, surname, email address and phone number. For the purposes of the CRM database, in addition to the aforementioned data, we also process job title and employer identification data.

How long do we store your personal data?

We store your personal data until you unsubscribe from our contact database.

 

  1. Promotion of our brand, good name, services, and events

What is our purpose for and legitimate interest in processing your personal data?

Furthermore, we may process your personal data by taking photographs and audio-visual recordings, which are used for the purpose of and legitimate interest in the promotion of our events and services and to help us improve our brand and good name by publishing the photographs (where it is possible that you will appear) and audio-visual recordings on our social media profiles such as YouTube, LinkedIn, Facebook, X (former Twitter) and Instagram, as well as via other channels such as our websites.

What is our legal basis and legitimate interest for the processing of your personal data?

In the case of promoting our events and the services we provide, we process your personal data based on the legitimate interests under Article 6 (1) (f) of GDPR.

What kind of personal data do we process?

Photographs or/and audio-visual images of you. In the case of private events, also your name, surname and email address will be processed.

How long do we store your personal data?

We may process your personal data for the entire duration of the existence of the HB Reavis Group.

 

  1. The operation of the “Help desk” platform

What is our purpose for and legitimate interest in processing your personal data?

We process your personal data to ensure that our contractual obligations arising from the contract with a third party (our tenant and the company/ies on whose behalf you are acting), in which you are in the position of the contact person, are effectively fulfilled. Based on the contract we concluded with the said third party, we provide a “Help desk” platform for reporting issues in connection with the building in which the offices of the third party are situated. To properly use the platform, you or the said third party provided us with your personal data, as you are the designated person for communication in the platform. We need to process your personal data to ensure effective, flawless, and clear communication, as well as to ensure the fulfilment of our obligations towards the company/ies on whose behalf you are acting.

What is our legal basis and legitimate interest for the processing of your personal data?

We process your personal data based on the legitimate interests under Article 6 (1) (f) of GDPR when ensuring the smooth operation of the ‘Help Desk’ platform application for our tenants.

What kind of personal data do we process?

Title, name, surname, job position, place of work, email address, phone number, the identification information of your employer, or companies that listed you as a contact person.

How long do we store your personal data?

During your contractual relationship with our tenant or the duration of the rental relationship, or a change in your job positions, whichever occurs first.

 

  1. The administration of insurance claims in Nivy Tower

What is our purpose for and legitimate interest in processing your personal data?

Your personal data is processed for the purpose of the administration of insurance claims that occur in Nivy Tower, such as car accidents in the parking lot, etc. When such an insurance claim occurs, it is necessary to fill out an incident form for insurance purposes and other legal matters.

What is our legal basis for the processing of your personal data?

 In the case of handling insurance claims, we process your personal data based on legitimate interest in accordance with Article 6 (1) (f) GDPR.

What kind of personal data do we process?

The requested data on the insurance form.

How long do we store your personal data?

We store your personal data only during the time that it is strictly necessary to deal with the insurance claim.

 

  1. Organization and administration of an event

Description of our purpose and legitimate interests:

Your personal data is processed for the purpose of ensuring your attendance at the event (e.g., processing of your personal data during the ticket purchase or for sending the invitation) and administration of matters regarding the event. This purpose includes mainly efficient communication relating to the event, proper performance of the event, providing you with the notices about the event, collecting feedback, notification about the changes, ensuring the examination of your complaint or claim, carrying out our obligations arising from our mutual contract and for verification process.

What is our legal basis for the processing of your personal data?

We process your personal data on the basis of the performance of a contract or pre-contractual relations in accordance with Article 6 (1) (b) of GDPR. The conclusion and the fulfillment of the contract are possible only if we can process your personal data. In case that the personal data is not provided, we will not be able to enter the contract with you and so to provide your attendance at the event.

What kind of personal data do we process?

Name, surname, e-mail, and phone number.

How long do we store your personal data?

We only process your personal data for the time strictly necessary to ensure the organization and administration of our event.

 

  1. Evaluation of client satisfaction

What are our purpose and legitimate interests for the processing of your personal data?

After we lease/sell our offices/buildings we evaluate the clients’ experience and satisfaction with our business relationship and with the leased/sold offices/buildings by collecting surveys from the clients or their employees.

What is our legal basis for the processing of your personal data?

We process your personal data on the basis of the legitimate interests under Article 6 (1) (f) of GDPR.

What kind of personal data do we process?

We process name, surname, e-mail address, phone number, position, and identification of the employer.

How long do we store your personal data?

We only process your personal data for the time strictly necessary to carry out the assessment.

 

  1. Use of the “More” application

For more information on how we process your personal data when you use the More app, please check out the privacy section in your profile at the More app.

 

  1. Sending of marketing materials

What is our purpose for and legitimate interest in processing your personal data?

In the case of a previous business relationship (you have requested more information regarding our projects/available capacities in buildings using our web forms) we may process your personal data to ensure the promotion of our products and services, improving our brand and good name we will provide you with our newsletters, invitations to our events, marketing alerts and follow-up marketing materials via the various available channels such as e-mail marketing communication.

What is our legal basis for the processing of your personal data?

We process your personal data on the basis of the legitimate interests under Article 6 (1) (f) of GDPR.

What kind of personal data do we process?

e-mail

How long do we store your personal data?

We store your personal data until you unsubscribe from our contact database. You can unsubscribe from our contact database electronically by clicking on “unsubscribe” in any of our e-mails sent to you.

 

12. Building management – daily reports

What is our purpose for and legitimate interest in processing your personal data?

The purpose of processing personal data in daily reports is to ensure the building is operated properly, is well managed and maintained, and that emergencies and incidents are resolved. The reports also serve to ensure safety and order in the building. These reports document important events relating to property and tenant safety, as well as the resolution of operational issues.

What is our legal basis for the processing of your personal data?

We process your personal data on the basis of legitimate interests, as defined in Article 6(1)(f) of the GDPR.

What kind of personal data do we process?

First name, last name, e-mail address, telephone number, job title and employer identification details.

How long do we store your personal data?

We store your personal data for a period of three months.

 

  1. Exercise of the data subject’s rights under the GDPR

What are our purposes for the processing of your personal data?

We strive to protect your privacy as much as possible, and therefore we process your personal data in compliance with GDPR and all other relevant laws. However, if you disagree with the way we handle your personal data, you can exercise your rights via our Data Protection Officer, including by filling out a request to exercise rights, which is available at the information desk.

What is our legal basis for the processing of your personal data?

Your personal data is processed while handling your complaint in accordance with Article 6 (1) (c) GDPR, i.e., the processing is necessary for compliance with a legal obligation to which Nivy Tower is subject.

What kind of personal data do we process?

Personal data provided by you when submitting the complaint to ensure effective communication (such as name, surname, email, phone number, etc. according to your own choice).

How long do we store your personal data?

We store your personal data strictly during the time necessary to deal with the complaint.

General statement on the processing of personal data.

Once we no longer need your personal data for the purposes for which we processed it, we will delete your personal data or archive it for the period of time specified by law or the archiving plan.

With whom do we share your personal data?

We may also share your personal data with companies within the HB Reavis Group. We may also be obliged to disclose your personal data to state authorities and public authorities, (courts and law enforcement authorities i.e. (police and prosecutor), and only to the extent necessary as required by applicable and effective law to exercise their power.

Based on several agreements with third parties, which act as our intermediaries or independent operators, we may provide your personal data, in particular to these companies, to the extent necessary to ensure the provision of services specified for individual companies:

  1. WALL & Partners a. s., ., a company organized and existing under the laws of Slovak Republic with its registered seat at Prievozská4, 821 09 Bratislava, Identification No. 36 869 813, registered with the commercial register maintained by the City Court Bratislava III under Section Sa, file No. 5121/B; the company as a processor ensures the operation of the CCTV system;
  2. HB REAVIS Slovakia a. s., a company organized and existing under the laws of Slovak Republic with its registered seat at Mlynské nivy5, Bratislava, 821 09, Identification No. 31 346 065, registered with the commercial register maintained by the City Court Bratislava III under Section Sa, file No. 3429/B; the company as a processor provides marketing services;
  3. HB Reavis Group a. s., a company organized and existing under the laws of Slovak Republic with its registered seat at Mlynskénivy5, Bratislava, 821 09, Identification No. 50 588 427, registered with the commercial register maintained by the City Court Bratislava III under Section Sa, file No. 7791/B; the company as a processor provides marketing services;
  4. HB Reavis Investments Slovakia s. r. o., having its registered seat at Mlynskénivy 5, 821 09 Bratislava, Slovak Republic, ID No.: 44 489 650, registered with the Commercial Register maintained by the City Court Bratislava I, Section: Sro, File No.: 55375/B; the company as a processor provides facility management services “Concierge“;
  5. ISTROCENTRUM s. r. o., a company organized and existing under the laws of Slovak Republic with its registered seat at Mlynskénivy 5, 821 09 Bratislava, Identification No. 31 396 224, registered with the commercial register maintained by the City Court Bratislava III under Section Sro, file No.141730/B; the company as a processor provides various services for the administrator of the building (e.g., reception);
  6. Yardi Systems, Inc., located at 430 South Fairview Avenue Santa Barbara, CA 93117 United States of America, Registration Authority Entity Identifier: 1315897, LEI (Legal Entity Identifier) Number: 549300ON1GNGUQR55L60, the company providing services as a processor in the field of Contactless Door Opening Services and Visitor Management Software (VMS);
  7. ELIMER a.s. a company organized and existing under the laws of Slovak Republic with its registered seat at Srnianska19, Nové Mesto nadVáhom 915 01, Identification No. 36 306 941, registered with the commercial register maintained by the District Court Trenčín under Section Sro, file No. 10592/R; the company as a processor provides various services in the field of CCTV maintenance;
  8. SAYTECH s.r.o., a company organized and existing under the laws of Slovak Republic with its registered seat at Hrachova 14/B, 821 05 Bratislava, IČO: 46 795 049, Identification No. 31 396 224, registered with the commercial register maintained by the City Court Bratislava III under Section Sro, file No. číslo83499/B; the company as a processor provides various services in the field of parking systems maintenance;
  9. KONE s.r.o., a company organized and existing under the laws of Slovak Republic with its registered seat at Galvániho7/B, 821 04 Bratislava, Identification No. 31 359 884, registered with the commercial register maintained by the City Court Bratislava III under Section Sro, file No. 5894/B; the company as a processor provides various services in the field of elevator maintenance.

In addition to the companies listed above, we use the following categories of intermediaries: data centres, hosting – marketing tools – analysis and tracking tools – events, surveys – business operations / management tools – task management and communication tools.

We use analytical and marketing tools (e.g. Google Analytics, Facebook Pixel, LinkedIn Pixel, Hotjar, Luigi´s Box, HubSpot) that collect third-party cookies. The information about your use of websites (including your IP address) generated by the cookies will be transmitted to and stored by the above-mentioned companies also on servers in the United States. We will use this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. These companies will not associate your IP address with any other data held by them. You may refuse the use of cookies by selecting the appropriate settings on your browser. However, please note that if you do this you may not have full functionality of this website. By using our websites, you acknowledge that the above – mentioned companies may process data in the manner and for the purposes set out above.

From whom do we get the personal data?

We get the personal data from you or from our tenant.

Do we use automated individual decision-making?

No, we do not use automated individual decision-making.

Do we transfer your personal data to third countries?Your personal data are processed within the territory of the Slovak Republic and other states of the European Union. Your personal data can be processed by a country outside of European Union if this third country has been confirmed by the European Commission as a country with adequate level of data protection or if other appropriate data protection safeguards exist (for example, binding corporate privacy rules or EU standard data protection clauses).

What are your rights?

Your rights as a data subject are stated below. Please note that the exact conditions to exercise these rights are set out in detail in Chapter III of GDPR, while in a particular circumstance not all rights may be exercised. You have the following rights:

  1. Access to personal data we process about you
  2. Rectification of incorrect or inaccurate personal data and add incomplete personal data
  3. Restriction, i.e., blocking of processing of your personal data
  4. The deletion of personal data in case the purpose absence or unauthorized data processing
  5. Submission of an objection to the processing of personal data if you believe that our data processing is not justified
  6. Be excluded from automated decision-making
  7. Listing of personal data in a structured and machine-readable format or for another controller
  8. Revocation of consent to the processing of personal data
  9. To lodge a complaint with the supervisory authority

How can you exercise your rights?

Electronically: dataprivacy@hbreavis.com

In writing to the address: Nivy Tower s. r. o., at hands of legal department, Mlynské nivy 5, 821 09 Bratislava, Slovak Republic or at HB Reavis Group a. s., compliance department, Mlynské nivy 5, 821 09 Bratislava, Slovakia.

We strive to protect your privacy as much as possible and therefore we process your personal data in compliance with GDPR and all other relevant laws. However, if you disagree with the way we handle your personal data, you can exercise your rights via our Data Protection Officer at:

HB Reavis Group a. s., at hands of DPO, Mlynské nivy 5, 821 09 Bratislava, Slovak Republic, email: dataprivacy@hbreavis.com

Or you can file a complaint with the supervising authority regarding the processing of your personal data. Your local supervisory authority may be found at: https://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm.