Privacy policy
This is a translation. The Slovak version is legally binding. Slovak version
In brief
- We use data only to sell and organise your course, issue documents and answer your questions.
- We do not sell data, use advertising or tracking cookies, or do profiling.
- We send news only with your consent; you can unsubscribe with one click.
- In the customer area you can download a copy of your data and send a request for correction or erasure.
- We automatically anonymise data once the periods below have passed.
1. Who processes your data
Controller: [doplňte: company name], [doplňte: registered office], Company ID (IČO): [doplňte: Company ID], registration: [doplňte: business register entry].
Contact for all personal data matters: [doplňte: contact e-mail].
We have not appointed a data protection officer (DPO) because the law does not require us to; we answer questions directly at the e-mail above.
We process data in accordance with Regulation (EU) 2016/679 (GDPR) and Slovak Act No. 18/2018 Coll. on personal data protection.
2. Why, on what basis and for how long
| Purpose | What data | Legal basis | How long |
|---|---|---|---|
| Ordering and organising the course (confirmations, instructions, reminders, change of participant, waiting list) | name, e-mail, phone, billing details for companies; names and e-mails of participants | performance of a contract and pre-contractual steps – Art. 6(1)(b) | 4 years after the course ends; unpaid and cancelled orders 12 months |
| Participants registered by someone else (e.g. an employer) | name, e-mail, attendance | legitimate interest in organising the course – Art. 6(1)(f) | as for the order |
| Attendance records and certificate of completion | name, course, attendance, certificate number | performance of a contract – Art. 6(1)(b) | as for the order |
| Invoicing and accounting | billing details, amounts, payments | legal obligation – Art. 6(1)(c) (Slovak Accounting Act, VAT Act) | 10 years from the end of the year the document relates to |
| Signing in to the customer area | e-mail, one-time sign-in link | performance of a contract – Art. 6(1)(b) | the link is valid for 15 minutes; the record is deleted within 1 day |
| Company enquiry and price proposal | contact person, company, e-mail, phone, content of the enquiry | pre-contractual steps – Art. 6(1)(b) | 2 years after the last contact; if an order follows, as for the order |
| Alert about a new course date | e-mail, selected course | your request (consent) – Art. 6(1)(a) | until you unsubscribe, at most 2 years |
| Course news by e-mail | e-mail, record of consent (when, where, wording) | consent – Art. 6(1)(a) | until consent is withdrawn; the consent record for 3 years after withdrawal as evidence |
| Course reviews | rating, comment | legitimate interest in improving courses – Art. 6(1)(f) | as for the order |
| Publishing a testimonial on the website | comment and the name under which you agreed to publication | consent – Art. 6(1)(a) | until consent is withdrawn |
| Protecting the website against misuse | IP address when ordering, records of attempts | legitimate interest in security – Art. 6(1)(f) | IP address when ordering 90 days, records of attempts 1 day |
| Visitor statistics | pages visited with an anonymous daily identifier, without IP address and without cookies | legitimate interest in improving the website – Art. 6(1)(f) | 400 days |
| Copies of e-mails sent | address, subject and content of the e-mail | legitimate interest in evidencing communication – Art. 6(1)(f) | 180 days |
| Handling your GDPR requests | e-mail, content of the request and how it was handled | legal obligation – Art. 6(1)(c) | 3 years after it was handled |
| Establishing and defending legal claims | data needed for the dispute | legitimate interest – Art. 6(1)(f) | until the dispute ends |
Once a period has passed, we anonymise the data automatically: only amounts, dates and course details remain, with no link to a specific person.
Providing the data needed for an order is a contractual requirement – without it we cannot provide the course. Consent to news is voluntary and has no effect on your order.
3. Where we get the data
You give us most of the data when you order, send an enquiry or sign up. Participants’ data may be provided by the buyer (e.g. an employer), who must inform them. We complete a company’s name and address from public registers (e.g. the Slovak Register of Legal Entities) based on its company ID.
4. Who has access to the data
We do not sell data or pass it on for other companies’ marketing. Only our employees and contractors bound by confidentiality have access, and to the extent necessary the following:
- the course instructor – participants’ names and attendance,
- Websupport s.r.o., Bratislava (webhosting) – running the website and database,
- Websupport s.r.o. (e-mailový server) – delivering e-mails,
- [doplňte: invoicing system operator] – the invoicing system in which we issue documents,
- we do not offer card payments yet – processing card payments; you enter card details directly with the gateway provider and we do not see them,
- the platform stated for the course date (e.g. Microsoft Teams, Zoom or Google Meet) – for online courses,
- accountant, auditor, lawyer and public authorities where the law requires it.
We have contracts with our processors under Art. 28 GDPR and they process data only on our instructions.
5. Transfers outside the European Union
We store data in the EU. If a provider (e.g. an online course platform) processes data outside the EU, this happens only on the basis of a European Commission adequacy decision (e.g. the EU–US Data Privacy Framework) or standard contractual clauses.
6. How we protect the data
- The whole website runs over an encrypted connection (HTTPS).
- The customer area uses no passwords; you sign in with a one-time link valid for 15 minutes.
- The administration is protected by a password with support for two-factor authentication; every staff member sees only what their role requires.
- We log changes, exports and erasure of data.
- We anonymise data automatically once the periods have passed.
7. Your rights
- Access – you can obtain a copy of all data we hold about you.
- Rectification – we will correct inaccurate or incomplete data.
- Erasure – we will erase data if we no longer need it, you withdraw consent or you successfully object. We cannot erase data we must keep by law (e.g. invoices).
- Restriction of processing – for example while the accuracy of data is being checked.
- Portability – we will give you the data in a machine-readable format (JSON).
- Objection – to processing based on legitimate interest; unless our compelling grounds prevail, we will stop.
- Withdrawal of consent – at any time, without affecting the lawfulness of earlier processing.
The quickest way is the customer area (My account → My data and privacy): download a copy of your data, change your news consent and send a request. You can also send a request by e-mail to [doplňte: contact e-mail]. To avoid giving data to the wrong person, we may verify your identity – usually by asking you to reply from the e-mail you used when ordering. We handle requests free of charge within one month; for complex requests we may tell you that we need up to two more months.
8. Automated decision-making
We do not carry out automated decision-making or profiling with legal or similarly significant effects on you.
9. Minors
Our courses are intended for people over 16. Younger participants may only be registered by a parent or guardian.
10. Complaints
If you believe we process data unlawfully, you can lodge a complaint with the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27, www.dataprotection.gov.sk, or with the data protection authority in your country of residence. We would appreciate it if you contacted us first – we can resolve most things quickly.
11. Changes to this policy
We update this policy when the way we process data changes. Significant changes will be marked on this page. This policy is effective from [doplňte: effective date].
Updated 25 Sep 2026