Privacy policy

Basic information
 
The Controller handles your personal data responsibly and therefore, pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter the “GDPR”), and pursuant to Act No. 18/2018 Coll. on Personal Data Protection and on amendments to certain acts (hereinafter the “Act”), makes available to you as the data subject (the natural person whose personal data are processed), on its website and in addition to its identification and contact details and the contact details of the data protection officer, further necessary information, which can be found in the tabs on the left.

In accordance with Article 24 of the GDPR and Section 31 of the Act, the Controller has adopted appropriate technical, organisational, personnel and security measures and safeguards, which take into account in particular:

  • the principles of personal data processing, namely lawfulness, fairness and transparency, purpose limitation and compatibility of processing purposes, as well as data minimisation, pseudonymisation and encryption, and integrity, confidentiality and availability;
  • the principles of necessity and proportionality (applying also to the scope and volume of personal data processed, the retention period and access to the data subject’s personal data) of the processing with regard to the purpose of the processing operation;
  • the nature, scope, context and purpose of the processing operation;
  • the resilience and restoration of personal data processing systems;
  • the training of the Controller’s authorised persons;
  • the adoption of measures to identify without delay whether a personal data breach has occurred and to promptly inform the supervisory authority and the data protection officer;
  • the adoption of measures to ensure the rectification or erasure of inaccurate data, or the exercise of other rights of the data subject;
  • the risks of varying likelihood and severity for the rights and freedoms of natural persons (in particular accidental or unlawful destruction of personal data, loss or alteration of personal data, misuse of personal data – unauthorised access or unauthorised disclosure, assessment of risks with regard to the origin, nature, likelihood and severity of the risk associated with the processing, and identification of best practices to mitigate the risk).
 
 

Retention period of personal data and regular review

We process your personal data only for the period necessary to fulfil the purpose for which they were obtained, or for the period required by the applicable legislation. Specifically:

PurposeCategories of dataRetention periodInternal review interval
Order processing and performance of the contractIdentification and contact details, order data10 years from completion of the order (in accordance with Section 431 of the Commercial Code and the Accounting Act)every 2 years
Marketing (sending newsletters, individualised offers)First name, surname, e‑mail, telephoneuntil consent is withdrawn, or 5 years from the last interactionevery 2 years
Customer support / handling of complaintsIdentification, contact and communication data5 years from closure of the caseevery 2 years
Statistical and analytical purposes (anonymised data)Anonymised or pseudonymised dataindefiniteevery 2 years

Once these periods have expired or the purpose has been fulfilled, the data are securely destroyed or anonymised.

 

Scope of personal data processing

We process in particular the following categories of personal data:

  • Identification data: first name, surname, title, date of birth.
  • Contact data: e‑mail address, telephone number, residential address.
  • Transaction data: data on the services ordered, date and method of payment, invoice number.
  • Communication data: the content of e‑mails, telephone or chat messages with customer support.
  • Marketing preferences: consent to receiving news, data on e‑mail opens and link clicks.
 

Purpose of personal data processing

  1. Performance of the contract and order processing – appointment bookings, issuing invoices, communication regarding the procedure.
  2. Marketing and PR – sending newsletters, discount coupons and information about new services.
  3. Customer support – handling complaints, answering questions by e‑mail, chat or telephone.
  4. Compliance with legal obligations – accounting agenda, tax records.
  5. Legitimate interest – protection of our legal claims, operational security of the website, internal statistics.
 

Legal basis for processing (grounds)

  • Consent of the data subject pursuant to Article 6(1)(a) of the GDPR for marketing purposes.
  • Performance of a contract pursuant to Article 6(1)(b) of the GDPR when our services are ordered.
  • Compliance with a legal obligation pursuant to Article 6(1)(c) of the GDPR (accounting, tax agenda).
  • Legitimate interest of the Controller pursuant to Article 6(1)(f) of the GDPR (internal administration, protection of legal claims).
 

Recipients and processors (subcontractors)

Your personal data may be made available to or processed by the following entities:

ProcessorRegistered officePurpose of processing / service
Ecomail.cz, s.r.o.Na Zderaze 1275/15, 120 00 Prague 2, Czech RepublicE‑mail marketing and newsletter automation
Webglobe, s.r.o.Karadžičova 12, 821 08 Bratislava, Slovak RepublicWeb hosting, server administration
Google Ireland LimitedGordon House, Barrow Street, Dublin 4, IrelandCloud services, targeted advertising (Google Workspace, Google Ads)
Meta Platforms Ireland4 Grand Canal Square, Grand Canal Harbour, Dublin 2, IrelandTargeted advertising on Facebook / Instagram
Accounting services providercontractual partnerBookkeeping and payroll administration

We have concluded a written personal data processing agreement pursuant to Article 28 of the GDPR with each processor, ensuring an adequate level of protection.

 
Office for Personal Data Protection of the Slovak Republic
Address:
Hraničná 12
820 07, Bratislava 27
Slovak Republic

Company ID (IČO): 36 064 220

Registry office:
Monday – Thursday: 8:00 – 15:00
Friday: 8:00 – 14:00
Telephone consultations on personal data protection:
Tuesday and Thursday from 8:00 to 12:00, +421 2 323 132 20
 
Secretariat of the President of the Office: +421 2 323 132 11
Secretariat of the Office: +421 2 323 132 14

Fax: +421 2 323 132 34

Spokesperson:
mobile: 0910 985 794
e-mail: hovorca@pdp.gov.sk
 

E-mail:

a) general enquiries: statny.dozor@pdp.gov.sk
b) for the provision of information under Act No. 211/2000 Coll.: info@pdp.gov.sk
c) website: webmaster@pdp.gov.sk
d) to submit requests for information under Act No. 211/2000 Coll. on Free Access to Information, please use the online form.
e) an e-mail address through which the Office will provide you with advice on personal data protection. It is intended for children, young people, students, teachers and parents who suspect that their personal data have been misused: ochrana@pdp.gov.sk
 

Last updated: 1 July 2025

New! CO2 Laser

Enjoy 10% off your first treatment

Coupon:

LASER10

🎄Adventný kalendár 2025

Odmeňujeme ťa každý deň špeciálnou zľavou až do výšky 30%!

Otvor si zľavu v adventom kalendári Medirectu.