top of page

Personal Data Protection Policy

B P K, spol. s r.o., within the scope of its activities, processes the personal data of its employees, business partners, and other persons.

The processing of personal data by B P K, spol. s r.o. is governed by the rules set out in the relevant legislation, in particular the rules contained in REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 – General Data Protection Regulation (GDPR).

Our goal is to ensure the security of the personal data of employees, business partners, and other data subjects, and to prevent its misuse. Therefore, we perceive the GDPR not only as a mandatory legal regulation but also as a guideline for achieving this goal. In this spirit, we have adopted the following vision:

We protect all personal data entrusted to us within the scope of our activities.

We fulfill this vision primarily through the following measures:

  • GDPR Implementation: We apply GDPR rules as a comprehensive system of management documentation (this GDPR Policy, follow-up directives, and working procedures).

  • Employee Data: We retain the personal data of our employees only when necessary for HR processes and payroll administration. Employees know what information we collect and for what purpose, and grant their consent when necessary.

  • Business Partner Data: We collect the personal data of our business partners and other natural persons (advisors, representatives of state or public administration, etc.) only when necessary for the given activity (purchasing, sales, consulting, inspection activities, etc.). These persons are informed that we comply with GDPR rules.

  • Camera System: We operate a camera system (CCTV) in accordance with the established rules. We ensure direct supervision, recording, and storage of recordings for security and technological purposes.

  • Software Compliance: We assess all software products in terms of compliance with GDPR rules. We require our suppliers to support us in ensuring compliance with these rules, including features that allow us to fulfill the rights of data subjects (data deletion, anonymization, etc.).

  • General Processing: All other processes of processing the personal data of natural persons are managed in such a way as to prevent any breach of GDPR rules.

This GDPR Policy is a commitment by the company's management to adhere to personal data protection principles. It forms the basis for setting specific objectives in the area of personal data protection.

Employees are obliged to familiarize themselves with this GDPR Policy and observe it in their daily work.

This GDPR Policy is issued for an indefinite period and may be reviewed at any time for its timeliness and effectiveness.

In Proseč on June 25, 2025


bottom of page