Privacy Policy & Data Protection Information
The company TiboLogic s.r.o., with its registered office at Šalviová 15374/27, 080 01 Prešov, Slovak Republic, Company ID (IČO): 54743605, registered in the Commercial Register of the Municipal Court Košice, Section: Sro, Insertion No.: 54897/V (hereinafter referred to as "we" or "TiboLogic"), as the data controller, hereby informs about the processing of personal data pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and Act No. 18/2018 Coll. on Personal Data Protection.
1. What Personal Data Do We Process?
We process the following categories of personal data:
- First and last name
- Email address
- Company name (optional — provided at your discretion via the contact form)
- Project description and selected area of interest (provided via the contact form)
- Business name and registered office (if you are a natural person – entrepreneur, in the context of a contractual relationship)
- Company ID (IČO), Tax ID (DIČ), VAT ID (IČ DPH) — where applicable, in the context of a contractual relationship
- Phone number (where provided)
- IP address and related technical request data — processed transiently for website security and abuse prevention; not used for analytics or retained as a persistent log
- Mutual communication
2. Purposes and Legal Bases for Processing
We process your data only for justified purposes and based on the following legal grounds:
Handling Your Contact Form Inquiry
Receiving your inquiry, responding to it, discussing the project, preparing a potential offer
Art. 6(1)(b) GDPR – steps taken at your request prior to entering into a contract. Providing your name, email address and project description is necessary to process your inquiry; without this information we may not be able to respond.
Performance of a Contract
Delivery of agreed work, ongoing project collaboration
Art. 6(1)(b) GDPR – performance of a contract to which you are a party.
Invoicing and Compliance with Legal Obligations
Accounting, taxes, statutory archiving
Art. 6(1)(c) GDPR – compliance with a legal obligation.
Routine Business Communication
Art. 6(1)(f) GDPR – legitimate interest in maintaining communication with clients and in the proper provision of our services.
Website Security and Abuse Prevention
Protection of the contact form, prevention of spam and automated submissions, rate limiting
Art. 6(1)(f) GDPR – legitimate interest in the security and integrity of the website. IP addresses used for this purpose are processed transiently and are not retained as a persistent log.
Protection of Legal Claims
Defence or enforcement in the event of a legal dispute
Art. 6(1)(f) GDPR – legitimate interest in protecting our rights.
3. Cookies
We use one necessary technical cookie (NEXT_LOCALE) that stores your selected language preference (English or Slovak). This cookie is set when you visit the website and is required for the site to display in your chosen language. It does not track your activity and contains no personal information beyond the selected language code. No cookie consent banner is displayed because no optional cookies are used.
- No analytics, advertising or tracking cookies are used.
- Google Analytics and third-party analytics or marketing platforms are not used.
- The contact form is protected by Cloudflare Turnstile, a spam and bot prevention service operated by Cloudflare, Inc. When the form is loaded, Cloudflare's systems may process technical browser signals to assess whether a submission is automated. This is a security measure, not an analytics or marketing service. For details, see Cloudflare's Privacy Policy at cloudflare.com/privacypolicy/.
4. Who Can the Data Be Provided to? (Recipients)
We use the following trusted processors and partners:
- Hosting and cloud infrastructure: Amazon Web Services (AWS), Websupport s.r.o.
- Email delivery: Resend — used to deliver email notifications generated by the contact form.
- Spam and bot prevention: Cloudflare, Inc. — Cloudflare Turnstile is used to protect the contact form against automated submissions. Cloudflare acts as a data processor for this purpose.
- External advisors: accounting and tax advisors, IT support providers and software development contractors, where necessary for our operations.
- Public authorities: competent state authorities and institutions, where required by applicable law.
5. Transfers to Third Countries
Some of our service providers operate outside the EU/EEA. Personal data may be transferred to the United States in connection with the following services: Amazon Web Services (hosting and cloud infrastructure), Resend (email delivery for contact form notifications) and Cloudflare, Inc. (Turnstile spam and bot protection for the contact form). These transfers are safeguarded in accordance with the GDPR through the European Commission's adequacy decision (EU–US Data Privacy Framework) or through Standard Contractual Clauses (SCCs) approved by the European Commission, depending on the provider.
6. Data Security and Encryption
We protect your personal data using modern technical and organizational measures:
- Data is encrypted during transmission (via secure HTTPS protocol) and at rest on servers (database encryption).
- We regularly update systems, audit accesses, and minimize security vulnerabilities.
- Only authorized and trained personnel bound by confidentiality have access to the data.
7. Data Retention Period
We retain personal data only for as long as necessary for the relevant purpose:
- Contact form inquiries: retained for as long as necessary to process your inquiry and communicate with you. If no contractual relationship follows, data is retained only where necessary to protect potential legal claims, and deleted once that purpose no longer applies.
- Contractual data: retained for the duration of the contractual relationship and for the period necessary to protect legal claims after its termination.
- Accounting and tax records: retained for the period required by law (in Slovakia, typically 10 years).
- Data retained for the protection of legal claims: retained within the applicable statutory limitation periods.
- Language preference cookie (NEXT_LOCALE): retained until you clear your browser cookies or change your language setting on the website.
8. Your Rights as a Data Subject
Under the GDPR, you have the following rights:
- Right of access – you may request a copy of the personal data we hold about you.
- Right to rectification – you may request correction of inaccurate or incomplete data.
- Right to erasure – you may request deletion of your data where the processing purpose has ceased, subject to any overriding legal obligations or legitimate interests.
- Right to restriction of processing.
- Right to object – where processing is based on legitimate interest (Art. 6(1)(f)), you have the right to object; we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
- Right to data portability – where processing is based on a contract and carried out by automated means.
- Right to lodge a complaint with the supervisory authority: Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava, https://dataprotection.gov.sk.
- Right to withdraw consent – where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing that took place before withdrawal. Note: most processing described in this document is based on legal grounds other than consent (contract, legal obligation or legitimate interest).
9. Contact Details
- Controller: TiboLogic s.r.o.
- Registered Office: Šalviová 15374/27, 080 01 Prešov, Slovak Republic
- Email: contact@tibologic.sk
- Data Protection Officer / GDPR Contact: Tibor Fecko (you can contact him directly at contact@tibologic.sk)
