Basic information
The Controller handles your personal data responsibly and therefore, pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter the “GDPR”), and pursuant to Act No. 18/2018 Coll. on Personal Data Protection and on amendments to certain acts (hereinafter the “Act”), makes available to you as the data subject (the natural person whose personal data are processed), on its website and in addition to its identification and contact details and the contact details of the data protection officer, further necessary information, which can be found in the tabs on the left.
In accordance with Article 24 of the GDPR and Section 31 of the Act, the Controller has adopted appropriate technical, organisational, personnel and security measures and safeguards, which take into account in particular:
the principles of personal data processing, namely lawfulness, fairness and transparency, purpose limitation and compatibility of processing purposes, as well as data minimisation, pseudonymisation and encryption, and integrity, confidentiality and availability;
the principles of necessity and proportionality (applying also to the scope and volume of personal data processed, the retention period and access to the data subject’s personal data) of the processing with regard to the purpose of the processing operation;
the nature, scope, context and purpose of the processing operation;
the resilience and restoration of personal data processing systems;
the training of the Controller’s authorised persons;
the adoption of measures to identify without delay whether a personal data breach has occurred and to promptly inform the supervisory authority and the data protection officer;
the adoption of measures to ensure the rectification or erasure of inaccurate data, or the exercise of other rights of the data subject;
the risks of varying likelihood and severity for the rights and freedoms of natural persons (in particular accidental or unlawful destruction of personal data, loss or alteration of personal data, misuse of personal data – unauthorised access or unauthorised disclosure, assessment of risks with regard to the origin, nature, likelihood and severity of the risk associated with the processing, and identification of best practices to mitigate the risk).
Retention period of personal data and regular review
We process your personal data only for the period necessary to fulfil the purpose for which they were obtained, or for the period required by the applicable legislation. Specifically:
| Purpose | Categories of data | Retention period | Internal review interval |
|---|
| Order processing and performance of the contract | Identification and contact details, order data | 10 years from completion of the order (in accordance with Section 431 of the Commercial Code and the Accounting Act) | every 2 years |
| Marketing (sending newsletters, individualised offers) | First name, surname, e‑mail, telephone | until consent is withdrawn, or 5 years from the last interaction | every 2 years |
| Customer support / handling of complaints | Identification, contact and communication data | 5 years from closure of the case | every 2 years |
| Statistical and analytical purposes (anonymised data) | Anonymised or pseudonymised data | indefinite | every 2 years |
Once these periods have expired or the purpose has been fulfilled, the data are securely destroyed or anonymised.
Scope of personal data processing
We process in particular the following categories of personal data:
- Identification data: first name, surname, title, date of birth.
- Contact data: e‑mail address, telephone number, residential address.
- Transaction data: data on the services ordered, date and method of payment, invoice number.
- Communication data: the content of e‑mails, telephone or chat messages with customer support.
- Marketing preferences: consent to receiving news, data on e‑mail opens and link clicks.
Purpose of personal data processing
- Performance of the contract and order processing – appointment bookings, issuing invoices, communication regarding the procedure.
- Marketing and PR – sending newsletters, discount coupons and information about new services.
- Customer support – handling complaints, answering questions by e‑mail, chat or telephone.
- Compliance with legal obligations – accounting agenda, tax records.
- Legitimate interest – protection of our legal claims, operational security of the website, internal statistics.
Legal basis for processing (grounds)
- Consent of the data subject pursuant to Article 6(1)(a) of the GDPR for marketing purposes.
- Performance of a contract pursuant to Article 6(1)(b) of the GDPR when our services are ordered.
- Compliance with a legal obligation pursuant to Article 6(1)(c) of the GDPR (accounting, tax agenda).
- Legitimate interest of the Controller pursuant to Article 6(1)(f) of the GDPR (internal administration, protection of legal claims).
Recipients and processors (subcontractors)
Your personal data may be made available to or processed by the following entities:
| Processor | Registered office | Purpose of processing / service |
| Ecomail.cz, s.r.o. | Na Zderaze 1275/15, 120 00 Prague 2, Czech Republic | E‑mail marketing and newsletter automation |
| Webglobe, s.r.o. | Karadžičova 12, 821 08 Bratislava, Slovak Republic | Web hosting, server administration |
| Google Ireland Limited | Gordon House, Barrow Street, Dublin 4, Ireland | Cloud services, targeted advertising (Google Workspace, Google Ads) |
| Meta Platforms Ireland | 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland | Targeted advertising on Facebook / Instagram |
| Accounting services provider | contractual partner | Bookkeeping and payroll administration |
We have concluded a written personal data processing agreement pursuant to Article 28 of the GDPR with each processor, ensuring an adequate level of protection.
Office for Personal Data Protection of the Slovak Republic
Address:
Hraničná 12
820 07, Bratislava 27
Slovak Republic
Company ID (IČO): 36 064 220
Registry office:
Monday – Thursday: 8:00 – 15:00
Friday: 8:00 – 14:00
Telephone consultations on personal data protection:
Tuesday and Thursday from 8:00 to 12:00, +421 2 323 132 20
Secretariat of the President of the Office: +421 2 323 132 11
Secretariat of the Office: +421 2 323 132 14
Spokesperson:
mobile: 0910 985 794
e-mail: hovorca@pdp.gov.sk
b) for the provision of information under Act No. 211/2000 Coll.:
info@pdp.gov.skc) website:
webmaster@pdp.gov.skd) to submit requests for information under Act No. 211/2000 Coll. on Free Access to Information, please use the
online form.
e) an e-mail address through which the Office will provide you with advice on personal data protection. It is intended for children, young people, students, teachers and parents who suspect that their personal data have been misused:
ochrana@pdp.gov.sk
Last updated: 1 July 2025