+421 917 743 382
Free consultation

Privacy notice

Aké osobné údaje spracúvame, na akom právnom základe, ako dlho ich uchovávame a aké máte práva. Vrátane toho, čo nespracúvame vôbec.

This notice explains what personal data we process in connection with this website and our work, on what legal basis, how long we keep it and what rights you have. It also states what we do not do at all.

We write it plainly and specifically. If we do not process something, we say so.

Who processes the data

IOSEC Slovakia s. r. o. · Mariánska 2222/3, 811 08 Bratislava – mestská časť Staré Mesto · Company ID (IČO) 44 517 734 · Tax ID (DIČ) 2022758562 · VAT ID (IČ DPH) SK2022758562
Registered in the Commercial Register of the Bratislava III Municipal Court, Section Sro, Insert No. 118555/B

The controller under Regulation (EU) 2016/679 (GDPR) and Act No. 18/2018 Coll. is IOSEC Slovakia s. r. o.

Data protection officer: dpo@iosec.eu

Write to this address if you want to exercise your rights or ask anything about the processing. We reply within the statutory period.

Purposes and legal bases

1. Handling an enquiry and sending the result of an orientation test

Legal basis:

  • Article 6(1)(b) of the Regulation — where the enquiry is sent by a natural person acting on their own behalf, this constitutes steps taken at their request prior to entering into a contract;
  • Article 6(1)(f) of the Regulation — where the enquiry is sent by a person acting for a legal entity, we process their business contact details on the basis of a legitimate interest in answering a business enquiry. The legitimate interest is mutual: the sender expects a reply.

Categories of data subjects: people interested in our services and training who contacted us through a form on this website.

Categories of personal data: name and surname, organisation name, e-mail address, telephone number, subject of the enquiry, size of the organisation, message text, type of request, the page the form was sent from, confirmation that you have read this notice, and — for the orientation test — the sector, the organisation's size band, the answers given in the test (what has changed in your organisation, the state of your documentation and whether you have designated a data protection officer), its result, and a note that this is an unverified self-declaration by the sender. The list is complete — we keep nothing else from the form. The registration status with the NBÚ that the test asks about is NOT stored and is not sent to us; only the sender receives it, in their own result e-mail.

Description of the processing: We record the enquiry, answer it and prepare a quotation. If you asked for the result of the orientation test, we send it to your e-mail together with the reasoning. We also record how you answered and what came out of it — these are your own answers, which we have not verified in any way. The data is not used for automated individual decision-making, including profiling, and we do not use it to send marketing messages; that would require separate consent, which this form does not ask for.

Providing the data is voluntary. Without a contact detail we cannot answer the enquiry.

Recipients: a partner in the country where the service is to be performed, and only to the extent of data about the organisation — see Who we pass data to.

Retention period: 12 months from the last communication, if no contractual relationship arises from the enquiry. If one does, the data is kept further for the purpose of performing the contract under the relevant purpose above. The period reflects the fact that regulatory obligations run in annual cycles and an enquiry naturally returns after a year. The data forms part of server backups, which we keep for no longer than 12 months.

Transfers outside the EEA: none.

Source of the data: the data subject.

2. Registration for training

When you register for training, we process data in order to enrol you, confirm your place and deliver the training.

Scope: name and surname, e-mail, telephone, number of registered people, company name, company ID, billing address and a note.

Legal basis: Article 6(1)(b) of the Regulation — performance of a contract to which you are a party.

How long: 1 year from the date of the training. The invoice and related accounting documents are kept separately, for the period stated in point 4 — deleting a registration therefore does not delete the invoice, and vice versa.

Transfers outside the EEA: none.

3. Protecting forms against misuse

When a registration is submitted, we record data used solely to defend against automated misuse of the forms and to investigate any incident.

Scope: IP address and information about which page the form was sent from.

Legal basis: Article 6(1)(f) of the Regulation — the controller's legitimate interest in protecting its own systems against misuse. We have assessed this interest against your rights; it is the minimum amount of data and it is not used for any other purpose.

How long: together with the registration record, that is 1 year.

Transfers outside the EEA: none.

4. Processing of accounting documents

Scope: title, name, surname, address, telephone, account number, e-mail and signature.

Legal basis: Article 6(1)(c) of the Regulation — processing is necessary for compliance with a legal obligation of the controller.

How long: accounting documents are kept for 10 years under Section 35 of Act No. 431/2002 Coll. on accounting.

Transfers outside the EEA: none.

5. Operating the environment for clients' information duties

On our website we publish information about the processing of personal data for clients who have entrusted us with it. The controller of that information is always the client concerned; we provide the technical environment and act as a processor under a contract pursuant to Article 28 of Regulation (EU) 2016/679.

In that role we process the contact details of the client's data protection officer and of the contact persons the client designates, together with operational records of access to the published information — IP address, date and time of access, page address and browser identification. We process this data on the client's instructions and do not provide it to third parties.

We also use the operational records to secure and protect our own infrastructure; to that extent we are the controller and the legal basis is our legitimate interest in the security of operations. Web server logs are kept for 10 days and are then deleted automatically.

No transfers outside the EEA take place.

6. Recruitment for an advertised position

When you apply for a job with us, we process data in order to assess your suitability for the advertised position and to contact you if you proceed to the next round.

Scope: title, name and surname, contact details, information about education and previous employment, professional and language skills, certificates and any other data you include in your CV or covering letter.

We do not ask for a photograph, date of birth, marital status or other data unrelated to assessing suitability for the advertised position. If you provide them yourself, they are disregarded in the assessment.

Legal basis: Article 6(1)(b) of the Regulation — processing is necessary in order to take steps at the request of the data subject prior to entering into a contract. You are the one applying, and the application cannot be assessed without the data in the CV.

Providing the data is voluntary. If you do not provide it, we cannot assess your job application.

Where the data is: applications arrive by e-mail to kariera@iosec.eu and stay there. We do not build a database or a list from them.

How long: until the end of the recruitment procedure and then for a further six months, in case anyone challenges how it was conducted. If you have given the consent described in the next point, the period stated there applies.

We do not provide the data to anyone else and do not use it for automated decision-making or profiling.

Transfers outside the EEA: none.

7. Register of candidates for future openings

If you give us consent, we keep your CV after the recruitment procedure ends and contact you when a suitable position arises. This also happens shortly after a procedure closes — when a filled position becomes vacant during the probationary period, we approach other candidates from the same round.

Scope: the same data as for the recruitment procedure.

Legal basis: Article 6(1)(a) of the Regulation — your consent. Without it we delete your data once the period stated above expires.

You may withdraw your consent at any time, just as easily as you gave it — by e-mail to kariera@iosec.eu. After withdrawal we delete the data without undue delay, at the latest within 30 days. Withdrawal does not affect the lawfulness of processing before it.

How long: one year from the date consent was given, unless you withdraw it sooner.

Transfers outside the EEA: none.

Who we pass data to

We handle the enquiry ourselves. If it concerns a service to be performed in another country, we pass the partner in that country only data about the organisation the enquiry concerns — sector, size, scope and country — so that they can prepare a price. We do not pass on the name, e-mail or telephone number of the person who sent the enquiry.

We put you in touch with the partner only once we agree on working together. From that moment the partner processes personal data as our processor under a contract pursuant to Article 28 GDPR, and we remain responsible towards you.

What we do not do

So that it is clear what does not happen either:

  • We do not use an external form-processing service. Forms are handled by our own system, not by a third party.
  • We do not process special categories of personal data (health data, biometric data and the like).
  • No transfer of personal data outside the EEA or to an international organisation takes place.
  • No automated individual decision-making, including profiling, takes place. The orientation tests on our pages run entirely in your browser, their result has no legal effect and places no one in any category.
  • We do not sell data and do not provide it for third-party marketing purposes.

Where the data is stored

The data is processed on server hardware owned by IOSEC Slovakia s. r. o., located in the territory of the Slovak Republic — on the premises of the data centre operated by Lombard s. r. o., Školská 14, 921 01 Piešťany, which provides connectivity and physical housing for the equipment. This is a lease of space and connectivity for our own hardware: the data centre provider has no access to the data stored on that hardware and does not process personal data for us.

Access to the data is limited to authorised employees and collaborators of the controller, who are bound by confidentiality under Section 79(2) of Act No. 18/2018 Coll.

Cookies

This website uses only strictly necessary cookies. They are our own — none belongs to a third party, none is analytical or marketing, and we do not track you across websites.

  • iosec-session — maintains the session between individual requests. Without it, forms could not be submitted and the administration could not be accessed. Lifetime 2 hours. Scripts in the browser cannot read it and it is sent only over an encrypted connection.
  • XSRF-TOKEN — protects submissions against forgery from another site. It is set only in the administration; we do not set it on public pages, because there is nothing there to read it. Lifetime 2 hours.

These cookies do not require your consent — under Section 109(8) of Act No. 452/2021 Coll. on electronic communications this is technically necessary storage of data in the course of providing a service you yourself requested. The duty to inform does not disappear with it, which is why this section is here.

That is also why you will not find a cookie consent banner on this site. For these two cookies it would be factually wrong: it would ask for consent to something we may use without consent and without which the site would not work.

Your rights

As a data subject you have the right under the Regulation:

  • of access to the personal data we process about you (Art. 15)
  • to rectification of inaccurate data and completion of incomplete data (Art. 16)
  • to erasure of data where it is no longer needed or was processed unlawfully (Art. 17)
  • to restriction of processing (Art. 18)
  • to data portability for data you have provided to us (Art. 20)
  • to object to processing based on legitimate interest (Art. 21) — this concerns points 1, 3 and 5 above
  • to lodge a complaint with a supervisory authority

The rights to erasure and to restriction do not apply where retention is required of us by law — typically for accounting documents.

How to exercise a right: write to dpo@iosec.eu. We deal with the request within the statutory period, which runs from the date it is delivered. If we needed to extend it for a justified reason, we would tell you within the original period together with the reason.

If you are not satisfied with the outcome, you have the right to turn to the supervisory authority:

Úrad na ochranu osobných údajov Slovenskej republiky Galvaniho Business Centrum II, Galvaniho 7/B, 821 04 Bratislava

Changes to this notice

We may update this notice if the way we process data or the legal framework changes. The current version is always available at this address.

Effective from: ⟦DOPLNIŤ DÁTUM⟧

Please fill in your name.
Please fill in your organisation.
Please give an address we can reply to.
Please choose a topic.
Please confirm you have read the privacy notice.

No newsletter, no sales sequence — we answer the question you asked.

Call us Free consultation