Skip to content
Back to Home

Privacy Policy

Last Updated: January 2026

1. Introduction and Overview

The protection of your personal data is of particular concern to us. We therefore process your data exclusively on the basis of legal provisions, in particular the General Data Protection Regulation (GDPR - Regulation (EU) 2016/679), the Slovak Data Protection Act (Zákon č. 18/2018 Z.z.), and applicable national data protection laws. This privacy policy informs you about the nature, scope, and purpose of the collection and use of personal data on our website (https://smartenic.com) and in our business relationships. By using our website, you agree to the data processing described in this privacy policy.

2. Data Controller

Controller within the meaning of the GDPR and other national data protection laws: smartenic s.r.o. Rázusovo nábrežie - HUMA 6 811 02 Bratislava - mestská časť Staré Mesto Slovak Republic IČO: 55886922 DIČ: 2122121683 IČ DPH: SK2122121683 Email: privacy@smartenic.com Phone: +43 800 007075 For data protection inquiries, please contact: privacy@smartenic.com

3. Collection and Storage of Personal Data

We collect personal data when you: • Visit our website (automatically collected data) • Fill out a contact form • Make an inquiry by email or phone • Enter into a contract with us • Use our services • Subscribe to our newsletter Automatically collected data when visiting the website: • IP address (anonymized) • Date and time of access • Browser type and version • Operating system • Referrer URL (previously visited page) • Hostname of the accessing computer • Pages visited and time spent This data is required to display the website correctly, ensure stability and security, and is automatically deleted.

4. Legal Bases for Processing

We process your personal data on the basis of the following legal grounds pursuant to Art. 6 GDPR: • Art. 6(1)(a) GDPR (Consent): When you have given us express consent to processing, e.g., for newsletters or marketing. • Art. 6(1)(b) GDPR (Contract Performance): When processing is necessary for the performance of a contract with you or for pre-contractual measures. • Art. 6(1)(c) GDPR (Legal Obligation): When processing is necessary to comply with a legal obligation, e.g., tax retention requirements. • Art. 6(1)(f) GDPR (Legitimate Interest): When processing is necessary to protect our legitimate interests and your interests do not override them, e.g., for website analysis and IT security.

5. Purposes of Data Processing

We process your data for the following purposes: • Provision and improvement of our website and services • Responding to inquiries and communicating with you • Processing contracts and orders • Sending quotations and invoices • Providing support and maintenance services • Sending newsletters (only with your consent) • Analysis and improvement of our offerings • Ensuring IT security • Compliance with legal retention obligations • Assertion, exercise, or defense of legal claims

6. Recipients and Data Sharing

Your personal data will only be shared if: • You have given your express consent • This is necessary for contract performance • A legal obligation exists • Sharing is necessary for the assertion of legal claims Categories of recipients: • Processors (Art. 28 GDPR): IT service providers, hosting providers, cloud services • Payment service providers: For payment processing • Tax advisors and auditors: To fulfill tax obligations • Authorities: When legally required • Shipping service providers: For deliveries We have concluded data processing agreements (DPA) in accordance with Art. 28 GDPR with all processors.

7. Retention Period and Deletion

We store your personal data only as long as necessary for the fulfillment of the respective purposes or as required by statutory retention periods. Specific retention periods: • Contract data: 10 years after contract termination (statutory retention obligations) • Invoices and accounting documents: 10 years (tax retention obligation) • Business correspondence: 6 years • Application documents: 6 months after completion of the application process • Newsletter data: Until revocation of consent • Server log files: 7 days • Cookies: Depending on cookie type (see Cookies section) After expiry of the respective period, data is routinely deleted or anonymized.

8. Cookies and Tracking

Our website uses cookies and comparable technologies. Cookies are small text files stored on your device. We use the following categories: • Strictly necessary cookies: Required to operate the website, for example to store your language selection and your cookie choice. They cannot be disabled. Legal basis: Art. 6(1)(f) GDPR and § 165(3) of the Austrian Telecommunications Act 2021. • Analytics cookies: We use PostHog, Google Analytics 4 and Vercel Analytics to evaluate how our website is used. These services only set cookies or comparable identifiers after your explicit consent. As long as you have not consented, PostHog runs in a cookieless mode: nothing is stored on your device, your IP address is not transmitted, and you are not recognised beyond a single page view. Google Analytics and Google Tag Manager are not loaded at all without consent. Legal basis: Art. 6(1)(a) GDPR. • Marketing cookies: Used for reach measurement and advertising via Google Ads, and loaded exclusively after your consent. Legal basis: Art. 6(1)(a) GDPR. Session replay: After you consent to analytics cookies, PostHog records anonymised session journeys so we can identify usability problems. Input fields are masked automatically, so no content you type is transmitted. Your consent is voluntary and can be withdrawn at any time with effect for the future. Use the "Cookie settings" link in the footer to change or fully withdraw your choice at any time. Your decision is stored for 12 months, after which we ask again. You can also reject or delete cookies via your browser settings; this may limit the functionality of the website.

9. Third-Party Services

We use the following third-party services on our website: • Hosting: Vercel Inc., San Francisco, USA — standard contractual clauses pursuant to Art. 46(2)(c) GDPR. Delivered from the Frankfurt region (fra1). • Content Delivery Network (CDN): For optimal load times worldwide. • Contact form and email delivery: Processed on EU servers. • Product analytics: PostHog, EU Cloud with data stored in Frankfurt am Main, Germany. Collection runs through our own domain (/ingest) and a data processing agreement is in place. Without your consent the service operates cookieless and without transmitting your IP address. • Google Analytics 4 and Google Tag Manager: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. These services are loaded exclusively after your consent. We use Google Consent Mode v2, so nothing is stored on your device without consent. • Vercel Analytics: Cookieless reach measurement, activated only after consent to analytics cookies. We do not use social media plugins that automatically transmit data to third parties. Links to social media platforms are plain links. When using services outside the EEA, we ensure an adequate level of data protection through appropriate safeguards (standard contractual clauses, adequacy decisions).

10. Data Transfer to Third Countries

A transfer of personal data to countries outside the EU/EEA (third countries) only occurs: • When an adequacy decision by the EU Commission exists (Art. 45 GDPR) • On the basis of Standard Contractual Clauses (Art. 46(2)(c) GDPR) • With your express consent (Art. 49(1)(a) GDPR) When using US services, data transfer is based on the EU-US Data Privacy Framework or EU Standard Contractual Clauses with additional protective measures. Copies of the Standard Contractual Clauses can be requested at privacy@smartenic.com.

11. Data Security

We implement extensive technical and organizational measures to protect your personal data from unauthorized access, loss, destruction, or alteration: • SSL/TLS encryption (HTTPS) for all data transmissions • Encrypted storage of sensitive data • Access control and permission management • Regular security updates and patches • Firewall and intrusion detection systems • Regular security audits • Employee training in data protection • Physical security of server locations Despite all security measures, no data transmission over the Internet can be guaranteed to be 100% secure.

12. Your Rights as a Data Subject

  • Right to Information (Art. 15 GDPR): You have the right to obtain information about your personal data stored by us, including processing purposes, categories, and recipients.
  • Right to Rectification (Art. 16 GDPR): You have the right to demand immediate rectification of inaccurate data or completion of incomplete data.
  • Right to Erasure (Art. 17 GDPR): You have the right to erasure of your data, unless statutory retention obligations or legitimate interests prevent this.
  • Right to Restriction of Processing (Art. 18 GDPR): Under certain conditions, you may request restriction of the processing of your data.
  • Right to Data Portability (Art. 20 GDPR): You have the right to receive your data in a structured, commonly used, and machine-readable format or to have it transferred to another controller.
  • Right to Object (Art. 21 GDPR): You have the right to object to the processing of your data at any time on grounds relating to your particular situation.
  • Right to Withdraw Consent (Art. 7(3) GDPR): You may withdraw consent given at any time with effect for the future.

13. Right to Complain to Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR. Competent supervisory authority in Slovakia: Úrad na ochranu osobných údajov Slovenskej republiky Hraničná 12 820 07 Bratislava Slovak Republic Email: statny.dozor@pdp.gov.sk Website: https://dataprotection.gov.sk You may also contact the supervisory authority of your place of residence or habitual abode.

14. Changes to this Privacy Policy

We reserve the right to amend this privacy policy to adapt it to changed legal situations or when there are changes to our services. The current version can always be found on our website. We will notify you of material changes separately where possible. The version published at the time of your visit to this website always applies. We recommend that you review this privacy policy regularly.

15. Contact for Data Protection Inquiries

For questions about data protection, to exercise your rights, or for complaints, please contact: smartenic s.r.o. Data Protection Rázusovo nábrežie - HUMA 6 811 02 Bratislava Slovak Republic Email: privacy@smartenic.com Phone: +43 800 007075 We will respond to your inquiry as soon as possible, but no later than within one month.

Questions about this document?