Information clause for TAURON Polska Energia S.A. Contractors and their employees/co-workers.

In fulfilment of the legal obligation imposed on the data Controlleri pursuant to the provisions of Articles 13 and 14 of the GDPRii, we inform that:
1. The Controller of your personal data is TAURON Polska Energia S.A. with its registered office in Katowice (post code: 40-114), at ul. Księdza Piotra Ściegiennego 3, www.tauron.pl

2. We have appointed a Data Protection Supervisor whom you can contact in writing: 
a) at the email address: tpe.iod@tauron.pl
b) at the correspondence address: IOD TAURON Polska Energia S.A., ul Ks. Piotra Ściegiennego 3, 40- 114 Katowice.

3. If you are a TAURON Contractoriii, we will process your personal data for the purpose of: 
a) performance of a contract over the period preceding the conclusion of the contract and the period of its performance [legal basis: Article 6(1)(b) of GDPR - conclusion and performance of the agreement],
b) performance of activities related to the conclusion of contracts  or the selection of contractors, in connection with your participation in these activities as the TAURON Contractor [legal basis: Article 6(1)(b) or (c) (statutory proceedings) of GDPR - conclusion and performance of a contract/on the basis of legal regulations] for the duration of such proceedings and for the period of archiving of documentation resulting from legal regulations. In the case of consolidated proceedings conducted by TAURON Group companiesiv, we may act as the Joint Controller  of your data together with other individual TAURON Group companies. 
c) potential determining and pursuit of claims or defence against claims, including the sale of receivables for the duration of the proceedings and the limitation period of potential claims [legal basis: Article 6(1)(f) of GDPR - exercising the legitimate interests of the Controller], 
d) verification of the contractor's reliability, i.e. the implementation of necessary actions in the form of risk assessment (legal, financial, image and reputation) before concluding a contract, after concluding a contract, during the performance of the contract or extending the scope of the contract. In pursuit of this objective, we may additionally acquire your data from business information registers, credit bureaus and other generally available information sources. The personal data referred to in the previous sentence will relate to your settlement of the liabilities and your business activities for the period necessary for such an assessment [legal basis: Article 6(1)(f) of GDPR - exercising the legitimate interests of the Controller], 
e) creation of analyses of the results of our business activities for internal purposes for the period indicated in points a, b and c [legal basis: Article 6(1)(f) RODO - of GDPR - exercising the legitimate interests of the Controller].

4. In the event that you are an employee/ a co-worker of the TAURON Contractor, we shall process the following of your personal data: a) identification data (e.g. name, surname), b) contact data (e.g. e-mail address, telephone number and/or fax number), c) data relating to your profession or business activity, your participation in a civil partnership, your employment with the TAURON Contractor or your cooperation with the TAURON Contractor (e.g. company name, position).
4.1 Your personal data have been provided (made available) to us by your employer or the person (company) with whom you cooperate (TAURON Contractor) in connection with the conclusion of a contract with us, including the participation of the TAURON Contractor in the bidding process or other contract conclusion or contractor selection procedure as well as the performance by the TAURON Contractor (including as a subcontractor) of the contract concluded with us.
4.2 We will process your personal data for the following purposes: 
a) the conclusion, execution and monitoring of the performance of the contract with the TAURON Contractor, for the period preceding the conclusion of the Agreement and the period of its performance [legal basis: Article 6(1)(f) of GDPR - exercising the legitimate interests of the Controller]. 

b) performance of activities related to the conclusion of contracts  or the selection of contractors, in connection with your participation in these activities as a representative/ employee of the TAURON contractor [legal basis: Article 6(1)(f) or (c) (statutory proceedings) of GDPR - exercising the legitimate interests of the Controller/on the basis of legal regulations] for the duration of such proceedings and for the period of archiving of documentation resulting from legal regulations. In the case of consolidated proceedings conducted by TAURON Group companies, we may act as the Co-controllerv of your data jointly with other individual TAURON Group companies. 

c) potential determining and pursuit of claims or defence against claims, including the sale of receivables for the duration of the proceedings and the limitation period of potential claims [legal basis: Article 6(1)(f) of GDPR - exercising the legitimate interests of the Controller], d) creating the analyses of results of our business activities for internal purposes for a period indicated in points a, b and c [legal basis: Article 6(1)(f) RODO - of GDPR - exercising the legitimate interests of the Controller].

5. Moreover, we will process your data in order to: 
a) ensure or improve the work organisation of TAURON Group entities with TAURON Contractors until the end of the cooperation;  for this purpose we shall act as Co-Controller jointly with the remaining companies of  TAURON Group [legal basis: Article 6(1)(f) of the Regulation - exercising the legitimate interests of the personal data Controller], b) in the event that internal IT Servicesvi are made available to you , including services of intranet portal nature, personal data shall be processed for the following purposes: statistics, maintenance and security of IT Services. Data shall be processed until the termination of cooperation with the TAURON Contractor and for a period resulting from the characteristics of individual IT Services. For the above purpose, the Co-Controller of your personal data is: TAURON Polska Energia S.A, TAURON Obsługa Klienta sp. z o.o. and each of the individual companies of TAURON Group separately [legal basis: Article 6(1)(f) of the Regulation -  exercising the legitimate interests of the personal data Controller]

6. In connection with the processing of your personal data, you shall also have the following rights:
a) right of access to personal data,
b) right of data rectification, 
c) right of data erasure,
d) right of limiting personal data processing, 
e) right of data portability,
f) right to lodge a complaint.
g) right of access to fundamental arrangements between Co-Controllers,
h) right of access to the conclusions of the balancing test carried out to verify the existence of the controller's legitimate interest in personal data processing.

7. Should you wish to exercise your rights or obtain further information about them, you may do so: a) in writing to the following address: TAURON Obsługa Klienta sp. z o.o. ul. Lwowska 23, 40-389 Katowice, b) by electronic mail to the address: daneosobowe.wnioski@tauron.pl.

8. If you decide to exercise your rights, we will send you our position on the matter no later than one month after receipt of the request.

9. If you believe that we violate any legal regulations by processing of your personal data, you have the right to lodge a complaint to the supervisory authority, the President of the Office for Personal Data Protection.

10. Processing of data outside the European Economic Area (EEA).
Your personal data may be transferred outside the EEA. Such situation may arise in connection with the outsourcing of certain services/activities to entities established outside the EEA or processing data outside the EEA. Your personal data may only be transferred to such third countries (countries outside the EEA) or entities in third countries for which an adequate level of data protection has been confirmed by the decision of the European Commission, standard data protection clauses have been applied in contracts with these entities or appropriate other safeguards have been applied, as referred to in generally applicable laws.

In connection with the transfer of data outside the EEA, you may request further information on the relevant safeguards in this regard, obtain a copy of these safeguards or information on the pace where they are available by contacting the Data Protection Supervisor as indicated in this notice.

11. The provision of personal data is a necessary condition for the performance of the contract or for taking action prior to the conclusion of the contract. In the case of failure to provide personal data, it will not be possible to conclude and perform the Contract or to take steps prior to contract, including those aimed at its conclusion. 

12. The expected recipients (only to the extent necessary for processing purposes) of your personal data shall include: a) entities which are authorised to receive your personal data on the basis of relevant legal provisions, b) entities which carry out postal or courier activities, c) entities which carry out payment activities (banks, payment institutions - in order to perform mutual settlements, including payments to your benefit), d) entities which purchase receivables and debt collection entities - in the event that you fail to fulfil your obligations under the contract, (e) entities which cooperate with us in handling accounting matters to the extent to which they become data controllers, f) entities belonging to TAURON Group, g) entities that operate ICT systems and provide IT Services, h) entities that provide us with advisory, consulting, audit services, legal, tax, and accounting assistance, i) entities that provide document archiving services, j) our subcontractors, i.e. entities that perform other services on our behalf or deliver goods covered by contracts or agreements with our clients, the performance of which is related to the contract.


Glossary

iController - means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law; - Article 4(7) of GDPR
iiGDPR - means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC. The text of the Regulation is available at www.tauron.pl/rodo.
iiiTAURON Contractor - means an entity with which the TAURON Group company has concluded or plans to conclude a contract
ivTAURON Group - means TAURON Polska Energia S.A. with its registered office in Katowice and its subsidiaries or affiliates. The list of TAURON Group entities is available at: www.tauron.pl/rodo/spolki-grupy
vCo-controller - a controller that determines the purposes and methods of processing jointly with at least one other controller.
viIT Services - mean tools that enable the execution of defined business processes and allow for simultaneous, efficient and fast communication of many people employed or cooperating in TAURON Group Entities that use access to IT Services and consequently ensure the required cooperation between people employed or cooperating in TAURON Group Entities that use access to IT Services. The processing of users’ data in the IT Services is necessary for their due performance of their duties.