Privacy Policy

    Effective from: 01/01/2026

    1. Data Controller

    VELOX, s. r. o.

    Ivánska cesta 5285/91

    821 04 Bratislava - mestská časť Ružinov

    Slovak Republic

    IČO: 44 725 906

    DIČ: 2022805697

    IČ DPH: SK2022805697

    Contact details:

    Ing. Miroslav Baláž, MBA

    E-mail: office@velox.sk

    Phone: +421 903 657 750

    2. Introduction

    VELOX, s. r. o. (hereinafter referred to as "controller" or "we") respects your privacy and is committed to protecting your personal data. This document describes what personal data we collect, how we process it, and what your rights are regarding the protection of personal data.

    Our processing of personal data is in accordance with:

    • Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data (GDPR)
    • Act No. 18/2018 Coll. on Personal Data Protection and on amendments to certain acts

    3. What personal data we collect

    Through the contact form on our website, we collect the following personal data:

    • First name
    • Last name
    • Phone number
    • Email address

    In addition, we automatically collect technical data through cookies and analytics tools:

    • IP address
    • Browser and device information
    • Visit data (visit time, visited pages)
    • Cookie information

    4. Purpose and legal basis for processing

    4.1 Contact form

    Purpose:

    • Responding to your inquiries and providing information about our services
    • Communication within the business relationship
    • Marketing purposes (sending information about our products and services)

    Legal basis:

    • Consent to the processing of personal data (Article 6(1)(a) GDPR)
    • Legitimate interest of the controller in providing quality services and communication with interested parties (Article 6(1)(f) GDPR)

    4.2 Cookies and analytics tools

    Purpose:

    • Improving website functionality
    • Analysis of traffic and user behavior
    • Marketing purposes and content optimization

    Legal basis:

    • Consent to cookie processing through Cookiebot (Article 6(1)(a) GDPR)

    Tools used:

    • Google Analytics
    • Facebook Pixel (if implemented)
    • Cookiebot (cookie consent management)

    5. Personal data retention period

    We retain your personal data only for the time necessary to fulfill the purposes for which they were collected:

    • Contact form data: 2 years from last communication
    • Cookies and analytical data: maximum 25 months
    • Marketing purposes: until consent is withdrawn

    After this period, your personal data will be securely deleted or anonymized.

    6. Sharing of personal data

    We do not share your personal data with third parties for commercial purposes. Personal data may be disclosed only in the following cases:

    6.1 Technical service providers

    • Website hosting: Lovable (cloud infrastructure)
    • Database services: Supabase (EU data center) - storage of contact form data
    • Email services: Contact data is sent to the controller's email address
    • Analytics services: Google Analytics
    • Cookie management: Cookiebot

    These providers have access to data only to the extent necessary to provide their services and are contractually obligated to protect your data. Supabase as a database service provider stores data in data centers within the European Union, ensuring the highest level of personal data protection.

    6.2 Legal requirements

    We may provide your personal data if required by law, court decision, or government regulation.

    7. Transfer of personal data to third countries

    Your personal data from the contact form is stored in the Supabase database, which uses data centers within the European Union. This ensures that your data remains within the EEA and is protected according to European personal data protection standards.

    Some of our analytics service providers (e.g., Google Analytics) may process data outside the European Economic Area (EEA). In such cases, we ensure that data is protected through:

    • Standard contractual clauses approved by the European Commission
    • European Commission adequacy decisions
    • EU-approved certification mechanisms

    8. Personal data security

    We have implemented appropriate technical and organizational measures to protect your personal data against:

    • Unauthorized access
    • Loss or destruction
    • Unauthorized modification
    • Unauthorized disclosure

    These measures include:

    • Data encryption (SSL/TLS certificates)
    • Regular security audits
    • Limited access to personal data only for authorized persons
    • Employee training in data protection

    9. Your rights

    In connection with the processing of your personal data, you have the following rights:

    9.1 Right of access (Article 15 GDPR)

    You have the right to obtain confirmation as to whether or not we process your personal data, and if so, you have the right to access that data.

    9.2 Right to rectification (Article 16 GDPR)

    You have the right to rectify inaccurate personal data and to have incomplete data completed.

    9.3 Right to erasure - "right to be forgotten" (Article 17 GDPR)

    You have the right to request erasure of your personal data if:

    • The data is no longer necessary for the purposes for which it was collected
    • You withdraw your consent and there is no other legal basis
    • The data has been processed unlawfully
    • The data must be erased to comply with a legal obligation

    9.4 Right to restriction of processing (Article 18 GDPR)

    You have the right to request restriction of processing of your personal data.

    9.5 Right to data portability (Article 20 GDPR)

    You have the right to receive personal data that you have provided to us in a structured, commonly used, and machine-readable format.

    9.6 Right to object (Article 21 GDPR)

    You have the right to object to the processing of personal data on grounds relating to your particular situation.

    9.7 Right to withdraw consent

    If processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

    9.8 Right to lodge a complaint

    You have the right to lodge a complaint with a supervisory authority:

    Office for Personal Data Protection of the Slovak Republic

    Hraničná 12

    820 07 Bratislava 27

    Slovak Republic

    Tel.: +421 2 3231 3214

    E-mail: statny.dozor@pdp.gov.sk

    Web: https://www.dataprotection.gov.sk

    10. How to exercise your rights

    If you wish to exercise any of the above rights, please contact us:

    We will respond to your request without undue delay, no later than 1 month from receipt of the request. In justified cases, we may extend this period by another 2 months.

    11. Cookies

    11.1 What are cookies

    Cookies are small text files that are stored on your device when you visit websites. They are used to improve website functionality and provide better services.

    11.2 Types of cookies we use

    Necessary cookies:

    • Required for basic website functionality
    • No consent required (technical necessity)

    Analytical cookies:

    • Google Analytics – tracking traffic and user behavior
    • Consent required

    Marketing cookies:

    • Facebook Pixel – remarketing and targeted advertising (if implemented)
    • Consent required

    12. Changes to the privacy policy

    We may update this privacy policy. We will inform you of significant changes through our website. We recommend that you regularly review this policy.

    13. Contact

    If you have any questions regarding personal data protection, please contact us: