Data Controller
Name: Mladí programátori s. r. o. Address: Trieda Andreja Hlinku 606/39, Nitra 949 01, Slovak Republic ID: 55 655 203 Tax ID: 2322051602 Registration: Commercial Register of the District Court Nitra, Section: Sro, Insert No. 61121/N Contact: info@prebi.eu
As a data controller under Section 5 of Act No. 18/2018 Coll., we are responsible for ensuring compliance of personal data processing with applicable regulations.
What data we process
In accordance with Art. 13(1)(c) and (e) GDPR and Section 6 of Act No. 18/2018 Coll., we process personal data only lawfully without violating your fundamental rights:
- Identification and contact data: Name, email, phone, company
- Reservation and communication data: Time, channel, interaction content
- Technical data (personal data under Art. 4(1) GDPR): IP address, cookies, device identifiers
Purposes and legal bases
Personal data processing is based on valid legal grounds under Art. 6 GDPR and Section 6 of Act No. 18/2018 Coll.:
- Art. 6(1)(b) — Service provision and contract performance: Processing necessary for contract execution
- Art. 6(1)(f) — Legitimate interest: Service improvement and security. Legitimate interest is balanced with your rights under Section 6 of Act No. 18/2018 Coll.
- Art. 6(1)(a) — Consent (Section 15 of Act No. 18/2018 Coll.): Marketing and analytics. Consent must be free and informed under Art. 7 GDPR. For persons under 16, consent from legal guardian is required.
Retention period
In accordance with Art. 5(1)(e) GDPR and Section 11 of Act No. 18/2018 Coll., we retain personal data only for the period necessary to achieve the processing purpose:
- Contract-based data: For the duration of the contract and a reasonable period after termination (determined by processing purpose)
- Consent-based data: Until consent withdrawal
- Ensuring integrity and confidentiality: All data is protected by appropriate measures under Section 11 of Act No. 18/2018 Coll.
Recipients and transfers
In accordance with Art. 13(1)(e) and (f) GDPR and Chapter V GDPR, personal data may be processed by trusted processors (hosting, analytics, communication).
Transfers outside EEA: For transfers of personal data outside the European Economic Area, we use appropriate safeguards under Art. 44-50 GDPR, particularly Standard Contractual Clauses (SCC), which ensure adequate level of protection for your data.
Data subject rights
Under GDPR, you have the following rights regarding your personal data:
- Right of access: Obtain a copy of your data
- Right to rectification: Correct incorrect data
- Right to erasure (Section 23 of Act No. 18/2018 Coll.): Request deletion if data is no longer necessary, consent withdrawn, objection justified or processing unlawful. Controller will erase without undue delay.
- Right to restriction of processing (Art. 18 GDPR): Restrict processing under certain circumstances
- Right to lodge a complaint: Lodge a complaint with the Office for Personal Data Protection of the Slovak Republic (dataprotection.gov.sk)
- Right to data portability: Transfer data to another provider
- Right to object: Object to processing
- Right to withdraw consent: Withdraw consent anytime
Cookies and Local Storage
We use two types of client-side storage on our website to ensure functionality and improve your experience:
HTTP Cookies: Set by third parties (Google Analytics, Google Tag Manager) for analytical and marketing purposes. Loaded only after your consent. Data transfer to USA is secured using Standard Contractual Clauses (SCC).
Local Storage: Used for storing your preferences (theme, cookie consent) directly in your browser. This data is never sent to the server and remains only in your device. Items: cookie-consent.v1, cookie_consent_timestamp, ai-voice-ui-theme, exit-intent-popup-dismissed, authToken (admin only), authUser (admin only).
Details about all cookies and local storage items can be found in the Cookie Policy. You can change your preferences at any time.
Security
In accordance with Art. 32 GDPR and Section 11 of Act No. 18/2018 Coll., we implement appropriate technical and organizational measures to protect personal data from unauthorized or unlawful processing, loss, erasure or damage. These measures include:
- Encryption of data in transit and at rest
- Access control to personal data
- Regular security audits
- Employee training on data protection
Breach notification: In case of a personal data breach, we will follow Art. 33 and 34 GDPR and promptly inform you if the breach may result in a high risk to your rights and freedoms.
Exercise your rights. If you wish to exercise any of the above rights or have questions regarding the processing of your personal data, contact us at info@prebi.eu or read our Terms of Service.
Legal References
- GDPR: Regulation (EU) 2016/679
- Slovak Act: Act No. 18/2018 Coll. on Personal Data Protection
- Office for Personal Data Protection of the Slovak Republic: dataprotection.gov.sk