UX Solutions s.r.o. ("we", "us", "the Company") is committed to protecting the personal data of every individual who interacts with our website and services. This notice is issued in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation — GDPR) and the applicable Slovak national legislation implementing the GDPR (Act No. 18/2018 Coll. on Personal Data Protection, as amended).
1. Data Controller
| Company name | UX Solutions s.r.o. |
|---|---|
| Registered seat | Slovakia |
| Legal form | Limited liability company (s.r.o.) registered in the Slovak Commercial Register |
| [email protected] |
The Company acts as the data controller within the meaning of Article 4(7) GDPR for all personal data processing activities described in this notice.
2. Scope & Legal Basis
This notice applies to personal data processed in connection with:
- Visits to our website www.uxsolutions.sk;
- Enquiries submitted via the contact form;
- Pre-contractual and contractual communications with clients and prospective clients;
- Provision of IT services, hosting, software development, and consulting.
We rely on the following legal bases under Article 6 GDPR:
Where you have freely given, specific, informed, and unambiguous consent (e.g., optional marketing communications).
Processing necessary for the performance of a contract to which you are a party, or to take pre-contractual steps at your request.
Processing necessary for compliance with a legal obligation under EU or Slovak law (e.g., accounting, tax records).
Processing necessary for our legitimate interests (e.g., IT security, fraud prevention, improving our services), provided these are not overridden by your interests or fundamental rights.
3. Data We Collect
We collect only the minimum personal data necessary for the stated purposes (data minimisation principle, Art. 5(1)(c) GDPR).
3.1 Data you provide directly
- Contact form: full name, email address, subject, and message content.
- Business communications: name, job title, company name, email address, phone number, and any information you voluntarily include in correspondence.
- Service agreements: identification and billing data required by Slovak law (name/company name, address, IČO/DIČ/IČ DPH where applicable).
3.2 Data collected automatically
- Server logs: IP address, browser type and version, operating system, referring URL, pages visited, date and time of access. These are processed for security and operational purposes and are not linked to individual identities unless required for incident investigation.
- Cookies: see Section 9 below.
We do not process special categories of personal data (Art. 9 GDPR) and do not engage in automated decision-making or profiling with legal or similarly significant effects (Art. 22 GDPR).
4. Purposes of Processing
| Purpose | Legal Basis | Data Categories |
|---|---|---|
| Responding to contact form enquiries | Art. 6(1)(b) / (f) | Name, email, message |
| Entering into and performing service contracts | Art. 6(1)(b) | Identification & billing data |
| Invoicing and accounting obligations | Art. 6(1)(c) | Identification & billing data |
| Website security and abuse prevention | Art. 6(1)(f) | IP address, server logs |
| Improving website functionality | Art. 6(1)(f) | Anonymised usage data |
| Compliance with legal obligations | Art. 6(1)(c) | As required by applicable law |
5. Data Retention
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law (storage limitation principle, Art. 5(1)(e) GDPR):
- Contact form enquiries: up to 2 years from the date of the last communication, unless a contractual relationship arises.
- Contractual data: for the duration of the contract and 10 years thereafter, in accordance with Slovak accounting and commercial law (Act No. 431/2002 Coll. on Accounting; Commercial Code).
- Tax and invoicing records: 10 years from the end of the relevant tax period, pursuant to Act No. 222/2004 Coll. on Value Added Tax.
- Server logs: up to 90 days, unless retention is required for security incident investigation.
Upon expiry of the applicable retention period, personal data are securely deleted or anonymised.
6. Recipients & International Transfers
We do not sell, rent, or trade personal data. We may share data with the following categories of recipients:
- IT service providers and hosting partners acting as data processors under a Data Processing Agreement (Art. 28 GDPR), located within the EEA;
- Accounting and legal advisors bound by professional secrecy obligations;
- Public authorities where required by applicable Slovak or EU law.
We do not transfer personal data to third countries outside the European Economic Area (EEA). Should such a transfer become necessary in the future, we will ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR, or an adequacy decision pursuant to Art. 45 GDPR).
7. Your Rights
Under the GDPR and Slovak law, you have the following rights with respect to your personal data:
Art. 15 GDPR — obtain confirmation of whether we process your data and receive a copy.
Art. 16 GDPR — request correction of inaccurate or incomplete data.
Art. 17 GDPR — request deletion of your data ("right to be forgotten"), subject to legal retention obligations.
Art. 18 GDPR — request that we restrict processing of your data in certain circumstances.
Art. 20 GDPR — receive your data in a structured, machine-readable format and transmit it to another controller.
Art. 21 GDPR — object to processing based on legitimate interests or for direct marketing purposes.
Art. 7(3) GDPR — withdraw consent at any time without affecting the lawfulness of prior processing.
Art. 77 GDPR — lodge a complaint with the Slovak supervisory authority (Úrad na ochranu osobných údajov SR).
To exercise any of the above rights, please contact us at [email protected]. We will respond within 30 days of receipt of your request (extendable by a further 60 days in complex cases, with prior notice).
8. Data Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. These measures include:
- Encrypted data transmission (TLS/HTTPS) for all web communications;
- Access controls and authentication mechanisms limiting data access to authorised personnel;
- Regular security patching and monitoring of our server infrastructure;
- Pseudonymisation and minimisation of personal data where technically feasible;
- Procedures for detecting, reporting, and investigating personal data breaches in accordance with Art. 33–34 GDPR.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with Article 34 GDPR.
10. Children's Data
Our website and services are directed exclusively at businesses and professionals. We do not knowingly collect personal data from children under the age of 16. If you believe that a child has provided us with personal data without appropriate parental consent, please contact us immediately at [email protected] and we will take steps to delete such data.
11. Changes to This Notice
We may update this GDPR notice from time to time to reflect changes in our data processing activities or applicable law. The current version is always available on this page. Material changes will be communicated via a prominent notice on our website. We encourage you to review this notice periodically.
12. Contact & Complaints
For any questions, requests, or concerns regarding the processing of your personal data, please contact us:
UX Solutions s.r.o.
Email: [email protected]
Slovakia
You also have the right to lodge a complaint with the competent supervisory authority:
Úrad na ochranu osobných údajov Slovenskej republiky
(Office for Personal Data Protection of the Slovak Republic)
Hraničná 12, 820 07 Bratislava 27, Slovak Republic
Web: dataprotection.gov.sk
Email: [email protected]