Data Protection & Privacy Policy (GDPR)
Information for data subjects regarding the processing of personal data by ACW Servis.
1. Identity of the Controller
Pursuant to the General Data Protection Regulation (EU) 2016/679 (hereinafter "GDPR") and the Personal Data Protection Act No. 18/2018 Coll., the controller of your personal data is:
Matej Uríček – ACW Servis
Priehradná 34, 031 01 Liptovský Mikuláš, Slovakia
ID No. (IČO): 50681818
Tax ID (DIČ): 1086725860
E-mail: servis@acw.sk
Phone: +421 902 58 62 62
The business entity is registered in the Trade Register of the Liptovský Mikuláš District Office under No. 540-20234.
The security of your data and its lawful processing is of paramount importance to us. Below you will find detailed information on what data we collect, why we need it, and what your rights are.
2. What personal data do we process, for what purpose, and on what legal basis?
We strictly collect only the personal data that is necessary to provide our services, communicate with you, or fulfill statutory obligations. We process data for the following purposes:
A. Execution of Contract and Pre-contractual Relations (Orders, Service)
- Processed data: First name, last name, title, delivery/billing address, email address, phone number, physical identifiers, tax information (for companies), and device data (e.g., serial number).
- Purpose: Processing orders, hardware diagnostics, service execution, delivery of goods, and related communication.
- Legal Basis: Art. 6(1)(b) GDPR – processing is necessary for the performance of a contract or to take steps at your request prior to entering into a contract.
- Retention period: For the duration of the contractual relationship and for archiving purposes for 10 years following the end of the year in which the contract was fulfilled (as per the Accounting Act).
B. Fulfillment of Legal Obligations (Accounting and Taxes)
- Spracúvané údaje: Billing and payment data.
- Účel: Issuing invoices, bookkeeping, and fulfilling tax obligations.
- Právny základ: Art. 6(1)(c) GDPR – processing is necessary for compliance with a legal obligation (Accounting Act, VAT Act).
- Doba uchovávania: 10 years from the year following the year in which the document was issued.
C. Communication via Contact Forms or Email
- Spracúvané údaje: Email address, potentially name, phone, and message content.
- Účel: Responding to your inquiries, providing price estimates, or preliminary consultations.
- Právny základ: Art. 6(1)(f) GDPR – legitimate interest of the controller (providing customer support) or pre-contractual relations.
- Doba uchovávania: Maximum of 1 year after the conclusion of communication, provided no contract is formed.
D. Website Operation, Analytics, and Cookies
Our website utilizes Google tools to analyze traffic and optimize performance. We do not run any advertising campaigns (no remarketing or personalized ads via ad networks).
- Spracúvané údaje: IP address (anonymized), browser information, screen resolution, approximate location, and visitor behavior on the site (Cookies).
- Tools utilized:
1. Google Analytics – štatistické vyhodnocovanie návštevnosti webu.
2. Google Search Console – sledovanie výkonnosti stránky vo vyhľadávaní.
3. Google Tag Manager (GTM) – správa meracích kódov a analytických značiek na webe. - Právny základ: For strictly necessary technical cookies: Art. 6(1)(f) GDPR (legitimate interest in delivering a functional website). For analytical tools (Google Analytics): Art. 6(1)(a) GDPR (your voluntary consent via the Cookie banner).
- Doba uchovávania: Varies depending on the specific cookie (ranging from session length to several months). You may change your cookie settings at any time.
3. Who has access to the data (Data Recipients)?
We do not publish, disclose, or sell your personal data to other entities, except when it is strictly necessary for the fulfillment of our services. In such instances, we provide data to processors bound by confidentiality and a data processing agreement. These include:
- Carriers: Slovenská pošta, a.s., and other delivery transport companies (used to deliver goods to your specified address).
- Accounting firms: External accounting entities ensuring proper maintenance of our accounting records.
- IT Services and Analytics: Our web hosting providers and Google platform services (Google Ireland Limited) for analytical purposes and IT management.
4. Hardware Inspection, Repair, and Data Backups (Important Notice)
During computer servicing and diagnostics, we may come into contact with data on your storage media (hard drive). We do not examine, systematically process, or copy these data for our own use. Access is strictly limited to verifying hardware functionality or installing an operating system.
If you request a Data Backup as part of the service order: your data will be temporarily stored on our heavily encrypted internal storage, exclusively for the purpose of transferring it to your new drive or another medium we hand over to you. No later than 14 days after returning the functional device, any copies of your files from our storage are irreversibly and securely destroyed.
5. Your Rights Under GDPR
According to the GDPR, you hold the right to exercise complete control over your data. As a data subject, you have the following rights:
- Right of access: You have the right to request confirmation as to whether we process your data, what data it is, and to obtain a copy.
- Right to rectification: If you discover that we hold incorrect or outdated data about you (e.g., you changed your address), you have the right to request correction.
- Right to erasure (right to be forgotten): Under certain circumstances, you can request that we completely delete your data. This right cannot be exercised where our legal obligation to retain data prevails (e.g., archiving accounting invoices for 10 years).
- Right to restriction of processing: You may request us to move your data into a so-called "safe mode," for instance, if you contest its accuracy.
- Right to data portability: You have the right to obtain data you voluntarily provided to us (in a machine-readable format) and to transmit those data to another controller.
- Right to object: You have the right to object at any time to the processing of your data performed on the basis of our legitimate interest.
- Right to withdraw consent: Where processing is based on your consent (Analytical cookies), you have the right to withdraw your consent at any time. The withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, please contact us at servis@acw.sk. We will process your request within 30 days.
6. Right to Lodge a Complaint with a Supervisory Authority
If you believe we are processing your personal data in violation of applicable legislation, you have the right to lodge a complaint with the supervisory authority, which is:
Office for Personal Data Protection of the Slovak Republic
Hraničná 12
820 07 Bratislava 27
Slovak Republic
Web: https://dataprotection.gov.sk/