Personal Data
INFORMATION FORM PREPARED IN ACCORDANCE WITH THE LAW ON THE PROTECTION OF PERSONAL DATA
This Disclosure Form covers the basic and legal entities whose personal data are processed by Zen Management DOO or its subsidiaries and affiliates (hereinafter collectively or separately, ‘Zen Management DOO’) within the scope of the Personal Data Protection Law (GDPR). It has been prepared by API Investment Doo, based on the Personal Data Protection and Processing Policy, which has been accepted and implemented by API Investment Doo, in order to inform people about the rules followed in their sharing and sharing, and the rights they have in this regard, and has been approved and put into effect by the General Manager of Zen Management DOO.
Definitions
Personal data: Any information relating to an identified or identifiable person.
Special category personal data: Personal data of entities such as race, ethnic origin, political opinion, philosophical belief, religion or other beliefs, disguise, association, foundation or union membership, health, sexual life, criminal conviction and data on security measures, biometric and genetic data.
Processing of personal data: Obtaining, recording, storing, preserving, changing, rearranging, disclosing, transferring, taking over, making available personal data by fully or partially automatic or non-automatic means provided that it is a part of any data recording system, all kinds of operations carried out on the data, such as the classification or prevention of its use.
Data processor: The basic or legal person who processes personal data on behalf of the data controller, based on the authority given by the data controller.
Data registration system: The registration system in which personal data is processed and structured according to certain criteria.
Data controller: It refers to the natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system. Under the law, legal entities included in Nomio Nomad Paradise & Hub act as separate data controllers.
Purpose for Which Personal Data Will Be Processed
Personal data may be processed for the purposes of fulfilling legal and administrative obligations by Nomio Nomad Paradise & Hub, carrying out all necessary work to enter into contractual relations, determining suitable products, projects, and services for customers, ensuring security, compliance with the legislation, making necessary notifications, conducting advertising and marketing activities, carrying out birthday celebrations, lotteries, competitions, promotions, campaigns, investigating and preventing violations of the contract and the law, reporting to authorities, resolving legal disputes, and executing recruitment processes, among other legitimate purposes.
Data Collection Methods
The data comes directly from interviews, call centers, websites, social media channels, mobile applications, written, verbal, and electronic means, as well as institutions and legal entities (business partners, suppliers, agencies, subcontractors, consultants, etc.). Data may also be obtained during training, seminars, or events organized by Nomio Nomad Paradise & Hub.
Your personal data may be retained for the period accepted in the relevant policies of our Company or stipulated in the valid legislation.
To Whom and for What Purpose the Processed Personal Data Can Be Transferred
Collected personal data may be shared with relevant entities, business partners, affiliates, suppliers, agencies, consultants, or public institutions within the framework of GDPR regulations. Your personal data may also be transferred abroad to legal entities, business partners, suppliers, or public institutions where necessary.
Method and Legal Reason for Personal Data Collection
Your personal data may be collected by fully or partially automatic means or non-automatic methods provided that they are part of the data recording system, depending on the nature of the means of supply specified in this document. Data processing and transfers are carried out in accordance with GDPR regulations.
Rights of Data Owner under Article 11 of GDPR
As Zen Management DOO, the rights of personal data owners within the scope of Article 11 and all of the GDPR are stated below:
Learning whether personal data is processed or not.
If personal data has been processed, requesting information about it.
Learning the purpose of processing personal data and whether they are used in accordance with its purpose.
Knowing the third parties to whom personal data is transferred at home or abroad.
Requesting correction of personal data in case of incomplete or incorrect processing.
Requesting deletion, destruction, or anonymization of data when the purpose of processing no longer exists.
Objecting to unfavorable outcomes through automated processing.
Requesting compensation in case of unlawful data processing.
To exercise the above-mentioned rights, a written request must be sent to 21.Novembra, P.O: 85320 Tivat, Montenegro, or to hello@livenomio.com, addressing the official title of the relevant member of Zen Management DOO, together with the necessary information identifying the claimant and explanations regarding the right to be exercised.
Application Procedure
Requests must be sent in writing through a notary public, via registered email (KEP), secure electronic signature, mobile signature, or through an authorized online system. Requests should be made in Montenegrin using the provided form, with identity and relevant documents attached.
Applications on behalf of someone else must include the identity and address information of the requester along with legal documents proving authorization.
Applications will be finalized within a maximum of 30 days. If additional costs arise, a fee determined by the Personal Data Protection Board may be charged.
Responses may be sent in writing to the requester’s address or email address at the discretion of Zen Management DOO.
This disclosure form is an integral part of any written or verbal agreement you have with Nomio Nomad Paradise & Hub.
Additionals
· Statement on the Protection and Collection of Personal Data and Its Use
Nomio is committed to protecting customers’ personal data by collecting only the necessary, basic customer/user information required to fulfill our obligations. We inform customers about the way their collected data is used and regularly provide them with options regarding the use of their data, including the option to decide whether or not they want their name removed from marketing campaign lists. All user data is strictly kept and is only available to employees who need it to perform their work. All employees of Nomio and business partners are responsible for respecting privacy protection principles.
· Statement on the Protection of Personal Data Transmission
“The protection of personal data is in accordance with the General Data Protection Regulation of the European Parliament and Council No. 2016/679 and the implementation of the General Data Protection Regulation.
Monri WSPay, as the entity responsible for processing credit card authorization and payment transactions, handles personal data as a data processor and processes personal data in compliance with the General Data Protection Regulation of the European Parliament and Council No. 2016/679, as well as in accordance with the strict PCI DSS L1 regulatory standards for data entry and transmission security.”
· Statement on the Use of Monri WSPay
“Nomio uses Monri WSPay for online payments.
Monri WSPay is a secure system for online payments, real-time payments using credit and debit cards, and other payment methods. Monri WSPay ensures the secure entry and transmission of card data for both customers and merchants, as confirmed by the PCI DSS certification held by Monri WSPay. Monri WSPay utilizes a 256-bit SSL certificate and the TLS 1.2 cryptographic protocol as the highest levels of security for data entry and transmission.
Website: www.livenomio.com