Profil Management Consulting d.o.o.  Information security and data privacy policy

1) Introduction

Profil Management Consulting d.o.o. is committed to protecting the private information of the data subjects. To ensure that your personal data remains secure we are regularly communicating our information security and data privacy policy to all Profil Management Consulting d.o.o. employees, and we strictly enforce privacy safeguards within the firm. We use personal data collected based on your consent in a responsible and secure way to provide our consulting services.

This information security and data privacy policy describes our privacy practices regarding the collection, and processing of personal data collected in relation to the provision of consultancy projects.
Profil Management Consulting d.o.o. is a wholly owned company and is the sole controller of all information collected by Profil Management Consulting d.o.o. company, and we are committed to protecting the privacy of your personal data. In this statement we announce our policies regarding the collection, use and transfer of your personal data, the security methods Profil Management Consulting d.o.o. uses to protect such data and your rights in relation to the processing of your personal data. By sharing your personal data with us, you state your agreement to the terms and conditions set out within this Policy. If the terms set forth within this information security and data privacy policy are not acceptable for you for any reason, please do not share your personal data with us.

2) Personal Information collected

Profil Management Consulting d.o.o. is an consulting firm, and for these purposes we collect a variety of personal data necessary to provide consulting services in a secure and highly confidential database accessible only by Profil Management Consulting d.o.o..

Profil Management Consulting d.o.o. treats all personal data in a manner consistent with the requirements of GDPR and Personal Data Protection Agency in Bosnia and Herzegovina.

We collect your data to provide our consulting services based on your explicit consent which you may submit through our company mail profil@profil.ba. All data subjects have the following rights: to access and adjust your personal data; to file a written, motivated request to cease processing or to object against the processing of your personal data or for the erasure of your personal data; to receive the information which you have provided to Profil Management Consulting d.o.o. which you may transmit to another entity; and the right to withdraw consent at any time. We process your data for the period of providing services to you and/or to our clients. If you granted us consent to process your data but decided that you no longer want your data to be processed, please reach out to Profil Management Consulting d.o.o. at profil@profil.ba. Data subjects are also entitled to lodge a complaint with their respective supervisory authority.

We may process personal data based on our legitimate interest as an consulting company; however, we comply with principles of data minimization and carefully consider the legitimate interest of the data subjects. The legal basis intent for which Profil Management Consulting d.o.o. collects, processes, and retains your personal data throughout the term of your (prospective) relationship with us in consulting projects, correlates with consulting projects for our clients, and your prospective participation in these consulting projects. We retain the data for a period of our engagement by the client and/or until you withdraw your consent to ours processing your data.

Our records may include your: personal address and contact details; marital status; educational background; job application; past and/or current CV; areas of expertise and interests; details of expected compensation/fees; comments and communication.

We may obtain the content of our records either directly from you, from our client or via relevant social media platforms, reference interviews executed during the consulting process, or during the interview and interaction process you have had with a Profil Management Consulting d.o.o. employee, with your conveyed consent.

It is important to differentiate between the non-sensitive data required for consulting purposes which may be submitted to Profil Management Consulting d.o.o. and the sensitive data which are not required or requested additionally, unless legally required to do so with a consent at a later stage of the consulting process. Data that is deemed non-sensitive, may include personally identifiable information such as: professional experience, career history, education history, resume/CV, and contact information. By choosing to provide your personal information to Profil Management Consulting d.o.o. data base, you indicate your acceptance and willingness to disclose this information to Profil Management Consulting d.o.o. and to be considered, when appropriate, for one of Profil Management Consulting d.o.o. confidential consulting mandates.

If you choose not to disclose personal information to Profil Management Consulting d.o.o., then Profil Management Consulting d.o.o. will be unable to provide you the consulting services offered or consider your relevance for our consulting process. Should you wish to remain in Profil Management Consulting d.o.o. consulting process but do not submit your personal information to Profil Management Consulting d.o.o., then you are recommended to contact someone within our office by email with your information and/or to set up an appointment. Email addresses of the office can be found on www.profil.ba;

Profil Management Consulting d.o.o. recommends that you do not provide data defined by the laws as sensitive to Profil Management Consulting d.o.o.; however, we do not forbid the submission of such data when done with your prior and unambiguous consent. Your choice to provide such data and your eligibility for a Profil Management Consulting d.o.o. confidential consulting projects remains a personal decision and requires you to express unambiguous consent as provided to Profil Management Consulting d.o.o.. This data is not required by Profil Management Consulting d.o.o. for eligibility, and data deemed sensitive could be, but is not limited to, information related to race or ethnicity, political views, religion, philosophical beliefs, trade union memberships, physical and/or mental health impairments, sexual orientation, or criminal record. If, for any reason, you do wish to provide such information deemed as sensitive data, Profil Management Consulting d.o.o. accepts your explicit and unambiguous consent to use that information in the methods described throughout this information security and data privacy policy.

 3) Use and disclosure of personal information

The data collected is encrypted, controlled and securely stored on our IT Systems internally administered by Profil Management Consulting d.o.o. at Husrefa Redzica Street no.3, 71000 Sarajevo, Bosnia and Herzegovina.

Our systems are constantly monitored and have restricted access granted only to our own employees and consultants. The data stored within our IT systems is available only to our own employees and consultants.

We do not trade or otherwise commercially share the data collected to gain any benefit from it. We only share the data as consented by the data subjects with our clients for particular consulting projects. We may need to share some data with our services providers, such as computing providers or financial institutions, and we always do this in line with the laws of a particular jurisdiction with the highest standards of professional care and legal compliance.

As required by Profil Management Consulting d.o.o. clients, we may need to present your data for consulting projects to potential Profil Management Consulting d.o.o. clients. As a result, your personal data may be securely shared with clients.

In most standard situations, we provide personal information to our clients or reference sources only if the candidate has authorised us to do so.  However, on the rare occasions that we are engaged to conduct highly confidential consulting services personal information may be provided to the client without the candidate’s prior request or knowledge.

Below is a non-exhaustive list of various ways in which we may use and/or disclose supplied sensitive and/or non-sensitive personal data that was transmitted to Profil Management Consulting d.o.o.:

  • Profil Management Consulting d.o.o. may use personal data collected regarding potential candidates to identify professional opportunities that we deem relevant and of interest for the candidate and the prospective employer/our client. We then provide this personal information to the prospective employer/our client as per agreed search requirements. We reserve the right to contact potential candidates regarding such opportunities.
  • The information obtained by Profil Management Consulting d.o.o. in regard to our clients, including business contact information, is kept and used as part of the provision of our consultancy services.
  • Other situations that could involve the use of personal information may  include, but are not limited  to: the updating of data; responding to inquiries; other communications; modification, improvement,  refinement and validation of intellectual property and technology; accounts and records; responding  to complaints and other inquiries; personal data can also be used for proposals, engagement letters,  presentations, research surveys, white papers, advertising, marketing and public relations.

Profil Management Consulting d.o.o. can use personal data submitted to us for the purposes stated above but are not limited to the purposes stated above.  Profil Management Consulting d.o.o. remains responsible for how the personal information will be used. Profil Management Consulting d.o.o. reserves the right to disclose or transfer, any and all personal information that we collect in connection with the provision of our services,  to a third party in connection with a strategic alliance with such a third party, or in the event of a sale of our company, a merger or consolidation involving Profil Management Consulting d.o.o.

Personal information collected by Profil Management Consulting d.o.o. is used only for the intended purposes stated at the time of collection. Profil Management Consulting d.o.o. does not sell or share your personal information for unrelated purposes to third parties, unless otherwise stated at the time of collection or required by law. If at any time we decide to use personal data in a manner different from that stated at the time it was collected, we will notify you and give you a choice as to whether or not we use your information in this different manner. No notification and choice will be sought, however, if Profil Management Consulting d.o.o. is compelled or required by applicable law, statute, regulation, ordinance, or court order to disclose personal data.

4) Information security

To prevent unauthorised access, maintain the accuracy of data, and ensure proper use of information, Profil Management Consulting d.o.o. has put in place appropriate physical, electronic and managerial security procedures to safeguard all information collected. All sections of the IT system in which personal information is submitted or exchanged employ encryption.
Profil Management Consulting d.o.o. will not process, use or transfer personal data in such a way that is not in line with that which is outlined in this information security and data privacy policy. We will use our best efforts to ensure that data is accurate, complete, current, and reliable for its intended use. We also will use our best efforts to protect your information from loss, misuse, unauthorised access, disclosure, alteration, and destruction.

We constantly train our associates on data protection related matters and frequently review our policies and systems in place in order to make sure that we process personal data with the highest standards of professional care and legal compliance.

5) Changes to our Privacy Policy

Profil Management Consulting d.o.o. reserves the right to modify or amend the information security and data privacy at any time and for any reason. If there are material changes to the information security and data privacy, we will post those changes here.  Please revert to this information security and data privacy from time to time to be informed.

Nothing contained in this information security and data privacy is intended to create a contractual agreement or legal relationship between Profil Management Consulting d.o.o. and any user providing identifying information in any form.

Date of last revision: June 03, 2022

6) Questions

If you have any questions about your personal information, please e-mail Profil Management Consulting d.o.o. at profil@profil.ba