PERSONAL DATA PROTECTION POLICY FOR EMPLOYEES

Personal Data Protection Policy for Employees

The protection of privacy is an essential commitment for UNIVERSAL AFIR, S.A. (“Universal Afir”), which conducts its activities in this area in compliance, in particular, with the General Data Protection Regulation (“GDPR”), Regulation (EU) 2016/679 of 27 April, Law No. 58/2019 of 8 August, which implements the GDPR into Portuguese law, and all other applicable national legislation.

This Personal Data Protection and Privacy Policy (“Employee Policy”) provides detailed information on how Universal Afir processes the personal data of its Employees in accordance with applicable personal data protection and privacy legislation. This Employee Policy does not form an integral part of the employment contract.

In certain cases, this Employee Policy also applies to the processing of data relating to family members, dependants, beneficiaries or other persons who have a relevant relationship with Employees or former Employees.

Although certain Employees have greater responsibility for ensuring that personal data is kept secure and processed lawfully, taking into account the duties they perform, all Universal Afir Employees share this responsibility.

If you have any questions about how personal data should be processed, or any concerns or doubts regarding the operation of, or suspected breaches of, this Employee Policy, you should seek advice from the Human Resources Department.

  1. DATA CONTROLLER

Universal Afir, with registered office at Cova do Frade, parish of Ovar, 3880-020 Ovar, with a share capital of €5,800,000.00, registered under company and legal entity identification number 500 293 473 at the Ovar Land and Commercial Registry Office, is the entity responsible for processing Employees’ personal data, as it determines which data is collected, the means of processing and the purposes for which the data is used.

  1. WHO IS THE DATA SUBJECT?

The data subjects are candidates for employment, Employees, former Employees, service providers and trainees of Universal Afir (“Employees”) to whom the personal data relates.

  1. WHAT IS PERSONAL DATA AND WHICH CATEGORIES OF PERSONAL DATA ARE PROCESSED?

Personal data means any information relating to an identified or identifiable natural person. Identification may take place directly or indirectly, by reference to an identifier such as a name, identification number, location data, electronic identifiers or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Universal Afir may process several categories of personal data, including:

Personal Identification Data

Such as full name, age, height, weight, sex, date of birth, address, nationality, place of birth, language, identification document, issuing authority and issue and expiry dates, photograph/image, Social Security Identification Number (NISS), Tax Identification Number (NIF), signature, Personal Income Tax Code (CIRS) information, social security bracket, marital status, name and NIF, driving licence, proof of address and CCTV images.

Employment-Related Data

Such as employer, employee number, professional category, role, employment status, workplace, department/area, employment start date, role start date, date of resumption of employment, date of suspension of employment, employment end date, reason for leaving, length of service, working hours, working-time arrangements, entry/exit date and time, attendance and absenteeism, contract type, contract duration, disciplinary sanctions, performance appraisal and vehicle data.

Recruitment Data

Such as application date, interview results, results of admission tests/assessments, curriculum vitae and qualification certificates.

Financial Data

Such as income and remuneration, financial contributions and social security contributions, regular financial commitments, personal income tax return and benefits declaration.

Special Categories of Data

Health data, type of examination, examination date, examination results, medical discharge date, number of sick leave days and fitness-for-work certificate.

Contact Data

Such as telephone/mobile number, internal extension, fax number, email address, contact date/time, source of contact, preferred contact method, contact person and emergency contact.

Data Relating to Legal Proceedings

Such as legal actions, court case number, litigation proceedings, type of proceedings, outcome of proceedings, amount claimed, criminal offences and reports, identification of the latest procedural step, date of the latest procedural step, preferential claims and attachment of claims.

Authentication and Access Data

Such as user account, username, password, creation date, access validity and entry and exit logs.

Web Browsing Data

Such as electronic identifier (MAC, IP), connection start date/time, connection end date/time, source location of web browsing, URL visited, website and host name.

Universal Afir informs Employees that, with regard to the processing of personal data for the purpose of complying with legal obligations relating to occupational medicine, it will only receive the information necessary to make employment-related decisions through the fitness-for-work certificate and will not, at any time, have access to health data.

  1. HOW AND WHEN IS EMPLOYEE PERSONAL DATA COLLECTED?

Universal Afir collects personal data mainly through direct collection, i.e. from information provided directly by you.
Personal data may also be obtained from other Employees, line managers, the Human Resources Department or third parties, such as references from a previous employer, tax information from the Tax Authority, social security contribution information or court notifications.
In certain circumstances, personal data may also be collected indirectly through monitoring devices, such as facial recognition or fingerprint systems, within the limits permitted by applicable law.

Personal data may therefore be collected in the following circumstances:

  1. When the contract is entered into;
  2. During the performance of the contract;
  3. In other duly justified situations.
  4. For the purpose of granting benefits;
  5. In other duly justified situations.
  1. PURPOSES AND LAWFUL BASES FOR PROCESSING PERSONAL DATA

Personal data is processed for human resources management purposes and for the safety of people and property, particularly in connection with the following main processing activities:

. Physical access control;

– Logical access control;

– Working time / attendance control;

– Administrative management;

– Litigation management;

– Contract management;

– Human resources management;

– Management of disciplinary sanctions;

– Management and maintenance of information systems and technologies;

– Economic and accounting management;

– Financial management;

– Professional training;

– Organisation and management of events;

– Organisation of internal training;

– Payroll and benefits processing;

– Recruitment and selection;

– Occupational Health and Safety.

The lawful bases for the processing of personal data by Universal Afir are as follows:

  • Pre-contractual Steps and/or Performance of a Contract: Personal data is necessary for entering into, performing and managing the contract concluded with Universal Afir.
  • Compliance with a Legal Obligation: Personal data is necessary for compliance with a legal obligation to which Universal Afir is subject.
  • Legitimate Interests: Personal data may be necessary to carry out certain operations related to Universal Afir’s business activities, except where the data subject’s privacy and data protection rights override those interests.
  • Consent:Personal data may be processed on the basis of a freely given, specific, informed and unambiguous indication of the data subject’s wishes, by which they signify, through a statement or clear affirmative action, agreement to the processing of their personal data.

Accordingly, the Data Controller will process personal data as follows:

Legal Basis

Purposes – Examples

Pre-contractual Steps and/or

Performance of a Contract

Entering into, performing and managing the contract concluded between the Employee and Universal Afir.

Compliance with a Legal Obligation

Access control, working time and attendance control, notification of Employee admissions to Social Security, submission of monthly remuneration declarations to the Tax Authority, reporting serious workplace accidents, submission of the annual report to the Tax Authority and ACT, among others.

Legitimate Interests

Performance appraisals, management of benefits and compensation and litigation management.

Consent

Granting benefits, such as education plans, social expenses, and enrolment in and payment of insurance premiums, where such insurance is not legally mandatory, subscribed to by the Employee.

  1. RETENTION PERIOD FOR PERSONAL DATA

Universal Afir retains data subjects’ personal data only for the period strictly necessary to fulfil the purpose for which it was collected.

In certain cases, the law requires data to be retained for a specific period, particularly data required for reporting to the Tax Authority, which will be retained for 10 years in accordance with applicable legislation.

Universal Afir also retains data for the duration of its contractual relationship with the Employee and for the period required to comply with legal obligations following termination of the contractual relationship.

Where legal proceedings exist, particularly those arising from a workplace accident or occupational illness, information may be retained beyond that period for as long as necessary, including for the purpose of judicial review of incapacity.

The Employee’s individual file is retained for historical purposes in a secure backup repository, and Universal Afir is responsible for ensuring appropriate security measures for the protection of personal data.

For certain purposes, the retention period may be shorter, in which case personal data will be retained only for as long as necessary for the purpose for which it was collected.

  1. DISCLOSURE OF PERSONAL DATA

Employees’ personal data will only be disclosed where necessary for the purposes described above.

Personal data may also be provided to companies contracted to provide services to Universal Afir. These companies, acting as processors and bound to Universal Afir by written agreement, may only process personal data for the purposes specifically established and are not authorised to process it, directly or indirectly, for any other purpose, whether for their own benefit or that of a third party.

In compliance with legal and/or contractual obligations, personal data may also be disclosed to third parties for their own purposes, including banks and insurance companies, judicial, administrative, supervisory or regulatory authorities, as well as entities lawfully carrying out data compilation activities, fraud prevention and detection activities or statistical studies.

Employees’ personal data may therefore be disclosed, in particular, to the following entities:

  • IGFSS – Instituto de Gestão Financeira da Segurança Social;
  • ISS – Instituto de Segurança Social;
  • AT – Autoridade Tributária;
  • Universal Afir’s banking institution and the banking institution designated by the Employee;
  • Insurance companies for the provision of workplace accident, life or other insurance;
  • ACT – Autoridade para as Condições do Trabalho;
  • FCT – Fundo de Compensação do Trabalho;
  • FGCT – Fundo de Garantia de Compensação do Trabalho;
  1. INTERNATIONAL TRANSFERS OF DATA TO OTHER ENTITIES

As a general rule, personal data collected and used by Universal Afir is not made available to third parties established outside the European Union. If international transfers of personal data take place, Universal Afir undertakes to ensure that such transfers comply with applicable legal provisions, in particular those relating to the determination of the adequacy of the third country’s level of data protection and the requirements applicable to such transfers.

  1. SECURITY PROCEDURES

Personal data is processed by Universal Afir for the purposes described above and within the limits established by the Portuguese Labour Code, in accordance with this Employee Policy and internal rules, using appropriate technical and organisational measures to promote its security and confidentiality, particularly against unauthorised or unlawful processing and against accidental loss, destruction or damage. The data may subsequently also be processed for statistical purposes.

In accordance with applicable data protection and cybersecurity legislation, appropriate procedures have been adopted to prevent unauthorised access to and misuse of personal data.

Only authorised personnel are permitted to access personal data in the course of performing their duties.

  1. EMPLOYEE OBLIGATIONS REGARDING PERSONAL DATA PROTECTION

Employees are required to act in accordance with applicable legal rules relating to personal data protection and with the internal rules in force in this area, including internal regulations and work instructions relating to data protection and information security, personal data protection legislation and all supplementary rules. Employees expressly acknowledge that they are familiar with the terms of this Employee Policy approved by the Data Controller.

  1. DUTY OF SECRECY AND CONFIDENTIALITY

Employees are bound by duties of secrecy and confidentiality whenever they process personal data, in accordance with applicable legislation and contractual provisions.

Employees must ensure the confidentiality of all personal data falling within the scope of their professional responsibilities and undertake to comply with all procedural, technical and organisational measures necessary to preserve the confidentiality of personal data or information. Such data must be processed in a manner that ensures its security, including protection against unauthorised or unlawful processing and against unauthorised access, alteration, disclosure, use, accidental destruction or damage, with appropriate measures being adopted for this purpose.

  1. DUTY TO NOTIFY PERSONAL DATA BREACHES

Employees must be familiar with and comply with the rules governing the management of incidents involving personal data and information security.

Employees must notify Universal Afir in writing of any personal data breach, regardless of whether it is likely to result in a risk or high risk to the rights and freedoms of natural persons, within a maximum of 2 (two) hours of becoming aware of it. As soon as possible, and within a maximum of 6 (six) hours, the Employee must provide at least the following information, in addition to any other information Universal Afir considers relevant:

  1. A description of the nature of the personal data breach, including, where possible, the categories and approximate number of data subjects affected and the categories and approximate number of personal data records concerned;
  2. A description of the likely consequences of the personal data breach, where possible;
  3. A description of the measures taken or proposed by the Employee to address the personal data breach;
  4. An indication of whether the breach is likely to result in a risk or high risk to the rights and freedoms of natural persons;
  5. Where the breach represents a high risk, a description of whether appropriate technical and organisational protection measures can be taken and whether such measures have been applied to the personal data affected by the breach, particularly measures rendering the personal data unintelligible to any person not authorised to access it, such as encryption;
  6. Where the breach represents a high risk, a description of whether subsequent measures can be taken to ensure that the high risk to the rights and freedoms of data subjects is no longer likely to materialise.
  1. PROCESSING FOR MOTIVATIONAL, TRAINING, LEISURE, CULTURAL AND RECREATIONAL PURPOSES AND FOR EMPLOYEE BENEFITS

Within the employment relationship, Employees’ contact details may be processed for the purpose of carrying out motivational, training, leisure, cultural, recreational or entertainment activities organised by Universal Afir.
Images of participation in such events may also be collected and published, whether through photographs or videos, for human resources motivation, professional training, communication and internal communication purposes, without commercial intent.

The processing of personal data for the purpose of granting employee benefits by the employer may involve the disclosure of such data to third-party entities contracted by the employer and responsible for managing the provision of those benefits to the Employee.

  1. RIGHTS OF DATA SUBJECTS AND RESPONSES TO DATA SUBJECT REQUESTS

Employees have the right to request from Universal Afir access to their personal data, as well as its rectification, erasure and restriction of processing. They also have the right to object to the processing of their personal data and the right to data portability, where legally applicable.

Where any of the legal bases for processing is consent, Employees have the right to withdraw that consent at any time, without affecting the lawfulness of processing carried out on the basis of consent given prior to its withdrawal.

Employees also have the right to lodge a complaint with the national supervisory authority, the Portuguese Data Protection Authority – Comissão Nacional de Proteção de Dados (CNPD).

Universal Afir does not make automated decisions.

  1. EXERCISE OF DATA SUBJECT RIGHTS

Data subjects may exercise their rights free of charge, except where a request is manifestly unfounded or excessive, in which case a reasonable fee may be charged taking into account the associated costs. Such requests will be answered within a maximum period of 30 days, except in cases of greater complexity.

Employees may exercise their rights by letter or email:

By letter to:

Human Resources Department

Avenida de Régua

3884 – 004

Ovar, Portugal

By email:

comercial@universalafir.pt

This Employee Policy may be updated. Updated versions will be made available through the usual locations and platforms.

  1. OTHER PRIVACY NOTICES AND INTERNAL REGULATIONS

Without prejudice to the information contained in this document, Universal Afir may process other personal data or additional categories of personal data where necessary for a particular purpose and in accordance with applicable legislation. Employees will be notified in advance before such personal data is processed.

As part of their duties, Employees must establish the structural conditions necessary for the processing of personal data by Universal Afir and ensure an appropriate level of personal data protection in accordance with the Internal Data Protection Regulation.

  1. AMENDMENTS TO THE POLICY

Universal Afir may amend this Policy at any time in accordance with new legal or regulatory requirements or update it whenever justified.We recommend regularly consulting this Policy to ensure that you are aware of the most recent version.