INFORMATION ON THE PROCESSING OF PERSONAL DATA OF THE DATA SUBJECT

pursuant to Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR)



1. Introduction


The Controller considers compliance with the legal conditions for the processing of personal data of data subjects to be one of its priorities. All actions carried out at each stage of the personal data processing process are performed with the utmost emphasis on the protection of the fundamental rights of data subjects, in particular the protection of personality and privacy, and on compliance with the principles of lawful processing of personal data.

ELEKTROSYSTÉMY, spol. s r.o. (hereinafter also referred to as the “Controller”) processes all personal data in accordance with applicable legal regulations, with particular emphasis on Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter also referred to as the “GDPR”) and Act No. 18/2018 Coll. on Personal Data Protection.


2. Controller Details


Business name: ELEKTROSYSTÉMY, spol. s r.o.
Registered office: Viničná 1, 953 01 Zlaté Moravce
Company ID No. (IČO): 36530549
Contact details of the designated person:
E-mail: molnarova@elektrosys.sk
Correspondence address: the company’s registered office address

This information is effective as of 1 May 2026. The Controller is entitled to update it as necessary.


3. Definitions of Terms


GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
Data subject – any natural person whose personal data are processed.
Personal data – any information relating to an identified or identifiable natural person.
Controller – a natural or legal person which determines the purposes and means of the processing of personal data.


4. Principles of Personal Data Processing


When processing personal data, we are guided by the principles set out in Article 5 of the GDPR:

Lawfulness of processing – we carry out each processing operation only on a legal basis established by legal regulations.
Data minimisation – we process only the data that are necessary to achieve the purpose. We always consider the scope of processing.
Storage limitation – we retain the data only for the period necessary for the given purpose and subsequently dispose of them securely.
Integrity and confidentiality – we have adopted technical, organisational and personnel measures to protect the data against loss, damage or unauthorised access.


5. Necessity of Providing Personal Data


Your personal data are necessary for the establishment of a contractual relationship, as your identification as a contractual party is an essential element of a contract pursuant to the Commercial Code (Act No. 513/1991 Coll.). If you do not provide us with your telephone number or e-mail address, this does not prevent the conclusion of a contract; however, communication between us will not be as efficient.


6. How We Obtain Your Personal Data


We obtain personal data from corporate clients mainly:

  • when concluding and performing a contract – we process the identification and contact details of the person acting on behalf of the company or designated by the client for communication;
  • when ordering goods or services – if you place an order on behalf of a company, we process your contact details in order to ensure proper order processing;
  • through communication with customers – for example from e-mail correspondence, telephone calls or website forms;
  • from your employer/client – if you are designated as a contact person for handling contractual matters, we receive your data from them to that extent.

7. Purpose of Processing Personal Data, Legal Basis and Retention Period


The Controller processes your personal data for predefined purposes, always only on a legal basis and for the period necessary to fulfil that purpose.

Processing operation Purpose of processing Category of personal data Legal basis Retention period
Accounting and financial records Recording of business activities name, surname, address, Company ID No., VAT ID No. legal obligation 10 years
Records of business partners Information about business partners name, surname, e-mail, telephone number legitimate interest for the duration of the transaction
Payroll and personnel records Employment relationship employee data (salary, attendance, health data) legal obligation until the age of 70
Registry administration Recordkeeping of documents ordinary personal data legal obligation 10 years
Records of data subject rights Handling of requests under the GDPR name, address, other necessary data legal obligation 5 years
Complaint handling Review of complaints ordinary personal data legal obligation 5 years

8. Legal Regulations on the Basis of Which We Process Personal Data


Where we process your personal data on the legal basis of compliance with our legal obligation (Article 6(1)(c) GDPR), this may include in particular the following legal regulations:

  • Act No. 18/2018 Coll. on Personal Data Protection and Regulation (EU) 2016/679 (GDPR) – the framework for personal data processing;
  • Act No. 431/2002 Coll. on Accounting – the obligation to keep accounts and retain accounting documents;
  • Act No. 595/2003 Coll. on Income Tax – tax obligations;
  • Act No. 563/2009 Coll. on Tax Administration (Tax Code) – tax administration records and obligations towards the tax authority;
  • Act No. 222/2004 Coll. on Value Added Tax, if the company is a VAT payer;
  • Labour Code (Act No. 311/2001 Coll.) – obligations in the area of employment relationships;
  • Act No. 580/2004 Coll. on Health Insurance and Act No. 461/2003 Coll. on Social Insurance – employer obligations;
  • and possibly other specific legal regulations depending on the company’s line of business (e.g. the Commercial Code, etc.).

9. Disclosure of Personal Data


The personal data we process will not be disclosed and will be made available only to authorised entities in accordance with legal regulations.


10. Confidentiality


We would like to assure you that all our employees and collaborators who process personal data are obliged to maintain confidentiality regarding such data. The confidentiality obligation also continues after the termination of their employment or contractual relationship with the Controller.


11. Security of Personal Data


In accordance with Articles 24, 25 and 32 of the GDPR, we have adopted appropriate technical and organisational measures to ensure an adequate level of personal data protection. When setting these measures, we take into account the nature and scope of processing, the risks to the rights and freedoms of natural persons, available technologies and the costs of implementation.

Our measures include in particular:

  • protection of the confidentiality, integrity and availability of data;
  • control of physical and electronic access to data;
  • rules for entering, sharing and retaining data;
  • procedures for the exercise of data subject rights;
  • ensuring the erasure of data and response to personal data breaches.

We take the protection of personal data into account already when selecting technologies, software and procedures, in accordance with the principles of “privacy by design” and “privacy by default”.


12. Cookies on Our Website


We are entitled to collect and process data about visitors and users of our website through tools used for automated data collection, in particular through Cookies, logs and other commonly used technologies.

A Cookie may be understood as a small amount of data sent as a file to your device (computer, tablet, smartphone) from the website you are currently visiting. This file is stored on your device and, on each subsequent visit to the same website, sends information back to our server.

Cookies are used by most websites, including ours. Their purpose is to make the use of our website easier and more convenient for you. A Cookie enables the website to recognise whether you have visited it before and which sections interested you. Cookies allow you to save user settings, such as language selection or remembering a login name.

Through Cookies, we store data that are not intended for your direct identification and are not linked to a specific person on their own. The use of Cookies is not dangerous for you – they cannot transmit viruses or read data from the hard drive of your device.

Legal basis:

  • Section 109(8) of Act No. 452/2021 Coll. (technically necessary Cookies),
  • Article 6(1)(a) GDPR (statistical/marketing Cookies – consent required).

Cookie settings:
You can manage Cookies in your browser (accept/reject, notifications, blocking). Help links:


13. Data Subject


A data subject is any natural person whose personal data we process. This may include, in particular, our customers, business partners – natural persons, job applicants, employees, visitors to our premises or users of our website.


14. Rights of Data Subjects under the GDPR and the Personal Data Protection Act


Your personal data are your data. In connection with their processing, you have the following rights:

  • Right of access
    (Article 15 GDPR, Section 21 of the Act)
    An employee has the right to know whether the employer processes their personal data and, if so, to obtain a copy of such data and information on how they are processed.
  • Right to rectification
    (Article 16 GDPR, Section 22 of the Act)
    If the data are inaccurate or incomplete, the employee has the right to have them corrected or completed.
  • Right to erasure (“right to be forgotten”)
    (Article 17 GDPR, Section 23 of the Act)
    In certain cases, the employee may request the erasure of their data (e.g. if they are no longer necessary for the purpose for which they were obtained, or if consent has been withdrawn). However, this right does not apply where processing is required by law (e.g. accounting or employment law regulations).
  • Right to restriction of processing
    (Article 18 GDPR, Section 24 of the Act)
    The employee may request temporary restriction of the use of the data, for example if they dispute their accuracy or the lawfulness of the processing.
  • Right to data portability
    (Article 20 GDPR, Section 26 of the Act)
    The employee may request the transfer of personal data that they have provided on the basis of a contract or consent to another controller, where technically feasible.
  • Right to object
    (Article 21 GDPR, Section 27 of the Act)
    The employee may object to processing based on the legitimate interest of the employer. In such a case, the employer may continue to use the data only if it demonstrates compelling legitimate grounds.
  • Rights in relation to automated decision-making and profiling
    (Article 22 GDPR, Section 28 of the Act)
    The employee has the right not to be subject to a decision based solely on automated processing, including profiling, if it would have legal or similarly significant effects on them.
  • Right to withdraw consent
    (Article 7(3) GDPR, Section 14 of the Act)
    If the employer processes data on the basis of consent (e.g. a photograph on the website), the employee may withdraw consent at any time.
  • Right to lodge a complaint – if you believe that we are handling your data unlawfully or unfairly, you may lodge a complaint:
    • directly with us as the Controller, or
    • with the Office for Personal Data Protection of the Slovak Republic, Park One Building, Námestie 1. mája 18, 811 06 Bratislava, Website: dataprotection.gov.sk

👉 However, we would appreciate it if, in the event of any questions or doubts, you contact us first – we will do our best to process your request to your satisfaction.


15. How to Exercise Your Rights


You may exercise your rights directly with the Controller who processes your personal data. If the Controller has designated a responsible person, you may also address your request to that person. A request may be submitted in writing, electronically, orally or by other means – however, we recommend written or electronic form in particular.

In order for us to identify you and provide you with the relevant data, please prepare your basic identification details.

We will respond to your request free of charge within 30 days. In the case of complex or numerous requests, we may extend the deadline by a further 60 days, of which we will inform you in advance. In the case of repeated requests, we may charge a reasonable administrative fee to cover the costs.

The processing we carry out does not include automated decision-making or profiling, and therefore the right to object to such processing cannot be exercised.


16. Conclusion


If you have any questions regarding personal data protection, you may contact the Controller at any time by e-mail or by post at its registered office address. If, when exercising any of your rights under legal regulations, it is not possible to verify your identity, or if we have reasonable doubts about the identity of the person submitting the request, we reserve the right to request additional information necessary to confirm your identity.