1. Introduction
1.1. This Privacy Policy describes the data collected by NeoKingdom in connection with the Website and how these data are used. The Privacy Policy also explains your rights regarding the administration of your data.
1.2. The Privacy Policy does not set out a comprehensive list of all the legal bases which enable authorities or persons to request data from NeoKingdom and process these data, as these bases derive from various legislation and cannot be presented as an exhaustive list.
1.3. Please take your time to read the Privacy Policy.
2. Definitions
2.1. The data subject means an identified or identifiable natural person whose personal data are being processed. You are a data subject only if you are identified or identifiable on the basis of the personal data which are being processed.
2.2. Personal data are any data concerning an identified or identifiable natural person (data subject).
2.3. Processing of personal data means any operation which is being performed on personal data (e.g., collection, alteration, viewing, erasure).
2.4. NeoKingdom means the company NeoKingdom DAO OÜ (registry code 16638166), with its address at Laki 11/1, 12915 Tallinn, Estonia, being which is the owner and administrator of the Website.
2.5. The Website is the website https://www.neokingdom.org including all its subdomains and aliases, with all of its components, contents and software required for its functioning.
2.6. The User is every person who uses the Website, including only visits.
3. NeoKingdom as a personal data processor
3.1. The Privacy Policy sets out information regarding the processing of personal data by NeoKingdom. NeoKingdom processes personal data on the basis of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, (GDPR), Personal Data Protection Act and other legislation regulating data protection in Estonia.
3.2. NeoKingdom can be contacted with regard to any issues concerning data protection by e-mail [administration@neokingdom.org] or by posting a letter to the address Laki 11/1, 12915 Tallinn, Estonia.
3.3. With regard to the User, the processor means the providers of hosting, development and maintenance services.
4. Legal bases for and purposes of processing of personal data, categories of data and retention of data
4.1. NeoKingdom processes all personal data which have become known to it or disclosed to it while communicating with the data subject. Personal data are processed and retained only during a specified term, and are thereafter erased or destroyed. The staff of NeoKingdom has the right to process personal data only to the extent needed for performing the duties assigned to them and for achieving the purpose of processing of personal data
4.2. The processing of personal data takes place on the following legal bases:
4.2.1. You have provided your consent for the processing of your personal data;
4.2.2. NeoKingdom as an enterprise has a legitimate interest in the data processing.
4.3. The processing of personal data may take place also on other legal bases, e.g., upon issue of data to law enforcement authorities to enable them to perform their duties (e.g., the police or court).
4.4. NeoKingdom processes personal data for the following purposes:
4.4.1. Making direct marketing offers and display of adapted contents or advertisements to the User on the Website;
4.4.2. Development and administration of the Website;
4.4.3. Responding to the inquiries and requests of the Users;
4.4.4. Compliance with the requirements deriving from legislation;
4.4.5. Processing on the basis of other legitimate interests.
4.5. NeoKingdom processes the following personal data and data related thereto:
4.5.1. With regard to the User:
4.5.1.1. The name, e-mail address and country of residence of the subscribers of newsletters;
4.5.1.2. Feedback on the Website;
4.5.1.3. Automatically collected data from the User’s web browser, including the type of the browser, type of the device, operational system, selected language, IP-address, information on the visits to the websites of the Website and other website traffic data;
4.5.1.4. Operations carried out by the User on the Website (recording the use of the Website) and operation logs (information on the operation, date and time);
4.5.1.5. Other personal data made known to NeoKingdom by the User.
4.6. Personal data are retained in accordance with the purpose of processing as follows:
4.6.1. Upon analysis and enhancement of the Website, personal data are retained for up to 1 year after the moment of their collection;
4.6.2. Upon development and administration of the Website, personal data are retained for up to 1 year after the moment of their collection;
4.6.3. Upon responding to the inquiries and requests from the Users, personal data are retained for up to 1 year after responding to the inquiry or request;
4.6.4. Upon processing on other legal bases or on the basis of legitimate interest, during the term provided for by law or should there not be such term, then for a minimum term until the need ceases to exist.
4.7. Personal data are anonymised not later than at the end of the term of retention of personal data, and their processing will continue as statistical information regarding the services of NeoKingdom and the functioning of the Website.
5. Use of cookies
5.1. NeoKingdom uses the co-called cookies on the Website. Cookies are text files which are sent to the User’s browser by the web server and are recorded on the data medium of the User’s device.
5.2. The cookies are used for identification of the User, analysis of the use of the Website and for marketing purposes, enabling to make the work of the Website more efficient and provide better user experience to the User on the Website.
5.3. NeoKingdom uses cookies also for monitoring the web traffic and statistics on the use of the Website and the operations carried out on the Website in an aggregated form. The information obtained is used for improving the user convenience and contents of the Website.
5.4. The cookies collect the automatically collected data referred to in clause 4.5.1.3.
5.5. While using the Website, you provide your consent for recording cookies on your device.
5.6. You will be entitled to prohibit the use of cookies any time, but in such case all the functions of the Website may not work properly.
6. Principles of personal data processing
6.1. Personal data are processed in accordance with legislation and the principles specified in the Privacy Policy:
6.1.1. Transparency
6.1.1.1. NeoKingdom processes your personal data in a fair and transparent way and only if NeoKingdom is entitled to process your personal data pursuant to law.
6.1.2. Limited purpose
6.1.2.1. NeoKingdom collects your personal data for accurately and clearly determined and legitimate purposes. NeoKingdom does not process your personal data in any manner which is inconsistent with the initial purposes. If your personal data are being processed for any other purpose than the initial purpose of personal data processing, NeoKingdom shall rely on the legal bases deriving from law (for example, while responding to inquiries from courts or law enforcement authorities, NeoKingdom does not process your personal data only for the purpose of providing its own services) or requests your prior permission to process your personal data for a purpose that differs from the initial purpose of personal data processing.
6.1.3. Collection of minimum data
6.1.3.1. NeoKingdom aims to ensure that the personal data being processed are sufficient and relevant for the purposes of processing and are limited to what is needed for processing. NeoKingdom does not collect any excessive or unnecessary information.
6.1.3.2. Should you or a third person disclose more personal data than needed, NeoKingdom will take all reasonable measures to prevent further processing of excessive personal data, and return the quantity of the processed personal data to the minimum.
6.1.4. Accuracy
6.1.4.1. NeoKingdom aims to ensure that your personal data are accurate and up to date. NeoKingdom takes all reasonable measures to ensure that inaccurate personal data will be immediately erased or rectified.
6.1.4.2. If your personal data are incorrect, you will be entitled to request the rectification and/or erasure of the data from NeoKingdom. NeoKingdom shall not rectify or delete such personal data which NeoKingdom is obliged to retain for the purpose of complying with a legal obligation (e.g., to meet any requirements deriving from tax laws).
6.1.5. Limited retention
6.1.5.1. NeoKingdom will retain your personal data in a form which enables identification of the data subject only for as long as it is necessary for the purpose of personal data processing and for compliance with the requirements deriving from law. NeoKingdom will process personal data only for as long as it is required pursuant to laws or binding agreements.
6.1.6. Reliability and confidentiality
6.1.6.1. NeoKingdom shall ensure the protection of personal data and process your personal data in a manner ensuring the required security, including protection against unauthorised or unlawful processing. NeoKingdom will make reasonable efforts to prevent loss or destruction of or damage to data.
6.1.6.2. Technical and organisational measures are implemented for enhanced security upon the processing of personal data. In order to increase awareness and knowledge of personal data protection, relevant trainings are organised for the staff processing your personal data. In addition, the protection of personal data is ensured through the confidentiality obligation applicable to the staff and processors of NeoKingdom.
6.1.6.3. NeoKingdom does not process any special categories of your personal data (i.e., sensitive data like data concerning health, or data revealing racial or ethnical origin, political views, religious or philosophical beliefs).
6.1.7. Data protection by design and by default
6.1.7.1. In the development and administration of the Website, NeoKingdom will take into account the data subject’s right to the protection of personal data and privacy. The processes of personal data processing and development thereof will be based on the development of science and technology, and measures will be taken to mitigate risks related to the processing of personal data in accordance with the development of science and technology as far as possible. It will be ensured that the processes of personal data processing are protected according to the type, extent, context and purposes of personal data processing.
7. Rights of data subject
7.1. NeoKingdom shall provide information regarding a specific data subject at the request of the data subject electronically, in writing or orally, considering that the identity of the data subject is previously clear and verified. It means that if there any doubts arise while processing your request, NeoKingdom may ask you to provide additional information. NeoKingdom does it to be sure about the identity of the data subject and to ensure that correct information is submitted to the correct person.
7.2. The right to receive information on the extent and use of processed personal data
7.2.1. You are entitled to access your personal data and receive information on which data regarding you are processed by NeoKingdom and how these data are being processed. This enables you to be informed, as necessary, and verify which personal data are being processed and how these data are being processed by NeoKingdom in connection to you. You may also contact NeoKingdom and ask for which purpose we are processing your personal data, if this remains unclear to you or if you have additional questions.
7.2.2. NeoKingdom will respond to you within a reasonable time but not later than within one month. In case of more complicated inquiries and requests, NeoKingdom will be entitled to extend the response time by two months. In such case NeoKingdom will contact you for extending the response time and explain to you the reasons for such extension.
7.3. Right to rectification of personal data
7.3.1. Should you notice that your personal data are no longer up to date, are incorrect, need rectification or supplementing, you may contact NeoKingdom to change the data. NeoKingdom will change your personal data in case of a reasoned and legitimate request as soon as possible but not later than within 30 days.
7.4. Right to withdraw your consent
7.4.1. In case of personal data processing on the basis of consent, you will be entitled to contact NeoKingdom at any time and withdraw your consent for the processing of personal data. The withdrawal of consent does not have retroactive effect and it shall not retroactively affect the lawfulness of personal data processing during the time when the consent was valid.
7.4.2. If consent is withdrawn, the collected personal data shall be retained during the terms set out in clause 4.6 of the Privacy Policy, whereas the term will be calculated not later than from the day when the consent was withdrawn. Upon a request of erasure of personal data upon withdrawal of consent, NeoKingdom shall act in accordance with clause 7.5 of this Privacy Policy.
7.4.3. The withdrawal of consent may result in limitation of the use of the Website and undergoing online trainings in accordance with relevant contracts.
7.5. Right to erasure of personal data
7.5.1. You are entitled to request erasure of your personal data if the personal data are no longer necessary or suitable in relation to the purposes of their collection or processing. The right to erasure is not an absolute right and therefore your request for erasure of personal data may not mean that all your personal data will be erased after receipt of the request. The law prescribes obligations to retain data in certain cases, and therefore it may not be possible to grant your request in such cases. Furthermore, respective data may be retained for the exercise or defence of legal claims.
7.6. Right to lodge a complaint with a data protection supervisory authority
7.6.1. All data subjects have the right to lodge a complaint with a supervisory authority exercising state supervision of data protection or with a court if they find that the processing of their personal data is not in compliance with legislation regarding data protection. In Estonia, the supervisory authority is the Data Protection Inspectorate, whose contact details can be found here: https://www.aki.ee/et/inspektsioon-kontaktid/tootajate-kontaktid.
8. Safeguards and notification
8.1. NeoKingdom shall maintain confidentiality of personal data and protect them against unlawful disclosure to third persons by implementing relevant IT security measures and organisational and technical measures.
8.2. In the case of a personal data breach, if it involves a probable risk to the rights and freedoms of the data subject, NeoKingdom shall notify the breach to the Data Protection Inspectorate. Additional measures shall be taken to end such infringement as soon as possible.
8.3. If the breach results in a probable major risk to the rights and freedoms of the data subject, NeoKingdom shall notify the data subject about the breach. The purpose of such notification is to enable the data subjects themselves to take precautionary measures to mitigate the potential risks deriving from the situation.
9. Amendments to Privacy Policy
9.1. NeoKingdom will be entitled to amend the Privacy Policy based on the amendments to laws and to the state of the art which ensures high level of protection of personal data. You are required to become acquainted with the amendments.
9.4. Should you continue to use the Website, you thereby confirm that the amendments are suitable, and you will be deemed to have agreed with the amendments.