Privacy Policy
What personal data we process, for what purpose, for how long and what rights you have.
Effective from 3 October 2026. This is a translation; in case of doubt the Slovak version prevails.
This document explains what personal data we process when you visit our website, write to us or order a service, why we do so, how long we keep the data and what rights you have. It is the information required by Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).
I. Who the controller is
Crystal Group, s. r. o.
Lánska 932/15, 017 01 Považská Bystrica, Slovakia
Company ID (IČO): 43863761
registered in the Commercial Register of the District Court Trenčín, section Sro, insert no. 18630/R
E-mail: info@crystalgroup.sk
Phone: +421 905 877 076
We have not appointed a data protection officer. In all data protection matters, write directly to the e-mail address above.
II. Where we get the data
- From you — when you fill in the contact form or a project inquiry, write us an e-mail, order a service or conclude a contract with us.
- From public registers — for companies we verify the registered office and identification numbers in the register of legal entities and in VIES.
- From bank statements — for payments by transfer we process the amount, variable symbol, date, counter-account number and payer name in order to match the payment to an invoice.
- Automatically when you browse the website — IP address, browser and device type and time of access in server logs.
III. What data, for what purpose, on what legal basis and for how long
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Replying to a contact form message | name, e-mail, phone, subject and text of the message | legitimate interest in replying to your message — Art. 6(1)(f) | 1 year from sending |
| Project inquiry and preparing an offer | name, company, e-mail, phone, existing website address, project type, budget, deadline and description | steps prior to entering into a contract at your request — Art. 6(1)(b) | 2 years from the last contact if no contract is concluded |
| Contract, order and provision of services | identification and contact details of the customer and of persons acting for them, details of ordered services | performance of a contract — Art. 6(1)(b) | for the term of the contract and 3 years after it ends |
| Domain registration and management | details of the domain holder and contact persons to the extent required by the domain registry | performance of a contract — Art. 6(1)(b) | for the term of the registration and 3 years after it ends |
| Invoicing and accounting | billing details, company, tax and VAT IDs, amount, variable symbol, bank statement data | legal obligation — Art. 6(1)(c) | 10 years from the end of the accounting period |
| Complaints and withdrawals from a contract | name, e-mail, service details, reason, method of settlement | legal obligation — Art. 6(1)(c) | 4 years from settlement |
| Website security and protection against abuse | IP address, device and browser data, access and error logs | legitimate interest in protecting the website and services — Art. 6(1)(f) | 6 months |
| Establishing and defending legal claims | data needed in a specific dispute | legitimate interest — Art. 6(1)(f) | until limitation periods expire |
We need the data marked as required in forms in order to reply to you or provide the service. You have no statutory obligation to provide them; without them, however, we cannot handle your inquiry or order.
We carry out no automated individual decision-making or profiling under Art. 22 GDPR. We do not send commercial communications you have not asked for.
IV. Who we disclose data to
We do not sell data. We disclose them only to the extent necessary:
- Domain registries and registrars — when registering, transferring and renewing a domain we pass the holder's details to the relevant registry (SK-NIC, a.s. for .sk domains). The registry is an independent controller and may publish part of the data under its own rules.
- Operators of the data centres where our own servers are located (processors).
- Our accountant and tax adviser to the extent of accounting documents.
- The bank holding our account, for payments by transfer.
- Google Ireland Limited to the extent of the reCAPTCHA service (section IX).
- Public authorities where the law requires it or where it is necessary to assert legal claims.
We have contracts under Art. 28 GDPR with our processors.
V. Where we process data
We run the website, mail and databases on our own servers located in data centres in the European Union. The exception is reCAPTCHA, where data may be transferred to Google LLC based in the USA. Google LLC is certified under the EU–U.S. Data Privacy Framework, for which the European Commission adopted an adequacy decision on 10 July 2023.
VI. Data you store on our hosting
If you are our customer and process other people's personal data on the hosting, in mailboxes or in databases, you are their controller. In relation to those data we are a processor: we store and transmit them solely in order to provide the service to you, and we do not look into them unless it is necessary to fix a fault or the law requires it. The conditions of processing are set out in the Terms and Conditions; we will conclude a separate data processing agreement with you on request.
VII. Your rights
- Right of access (Art. 15) — you have the right to know whether we process data about you and to obtain a copy.
- Right to rectification (Art. 16) — we will correct inaccurate data and complete incomplete data.
- Right to erasure (Art. 17) — we will erase data that are no longer needed or were processed unlawfully. We cannot erase them where the law requires us to keep them, for example accounting documents.
- Right to restriction of processing (Art. 18) — you may ask us to stop using the data temporarily, for example while we verify their accuracy.
- Right to data portability (Art. 20) — we will hand over data you provided and that we process by automated means on the basis of a contract in a commonly used, machine-readable format.
- Right to object (Art. 21) — you may object at any time to processing based on our legitimate interest. We will then stop processing the data unless we demonstrate compelling legitimate grounds that override your interests.
- Right to lodge a complaint (Art. 77) — see section VIII.
Exercise your rights by e-mail to info@crystalgroup.sk. If we cannot reliably verify your identity, we may ask for additional information. We will handle a request within one month; in justified cases we may extend the period by a further two months and will inform you. Handling is free of charge.
VIII. Complaint to the supervisory authority
If you believe that our processing of your data infringes the GDPR, you have the right to lodge a complaint with the supervisory authority:
Úrad na ochranu osobných údajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic)
Hraničná 12, 820 07 Bratislava 27, Slovakia
dataprotection.gov.sk
We would appreciate it if you contacted us first — we can resolve most matters faster.
IX. Form protection by reCAPTCHA
The contact form, the project inquiry and the withdrawal form are protected by reCAPTCHA from Google Ireland Limited. The service tells a human from a bot by evaluating visitor behaviour and sends Google data about the device and browser, including the IP address; the content of the form is not sent. The legal basis is our legitimate interest in protecting the website from abuse. Google's Privacy Policy and Terms of Service apply to the processing.
X. Cookies
The website uses no analytics or marketing cookies and does not track your behaviour. The only cookie that may be stored on your device is _GRECAPTCHA of the reCAPTCHA service (valid for 6 months). It is necessary to protect the forms and is stored only once you start filling in a form.
XI. How we protect data
Transmission between your browser and the website is encrypted (HTTPS). Only our staff and processors bound by confidentiality have access to the data, and only to the extent they need for their task. The administration is protected by a separate sign-in and we update the servers regularly.
XII. Changes to this policy
We may update this policy if the way we process data or the legislation changes. We will publish the new wording on this page together with its effective date.