1. Controller

The controller within the meaning of Art. 4(7) of Regulation (EU) 2016/679 ("GDPR") and § 5(o) of Act No. 18/2018 Coll. on personal data protection is:

Daligence, s. r. o.
Registered office: Priemyselná 668/9, 821 09 Bratislava - mestská časť Ružinov
Reg. No. (IČO): 57 596 638
Registered in the Commercial Register of the Bratislava III City Court, Section: Sro, Insert No. 198854/B
Email: office@daligence.sk

2. Personal data we process

Depending on the situation, we process the following categories of personal data:

3. Purposes and legal bases of processing

a) Provision of legal services

Purpose: provision of legal services to clients under Act No. 586/2003 Coll. on the legal profession.
Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (legal obligations of an attorney).
Retention: for the duration of the engagement and 10 years after termination, in accordance with § 33 of the Act on the Legal Profession and archival obligations.

b) Contact form handling

Purpose: processing and answering an inquiry sent through the web form.
Legal basis: Art. 6(1)(a) GDPR (consent of the data subject).
Retention: 6 months from the last communication if no contractual relationship arises.

c) Compliance with legal obligations

Purpose: accounting, tax obligations, obligations to the Slovak Bar Association, AML.
Legal basis: Art. 6(1)(c) GDPR.
Retention: per applicable law (e.g. 10 years for accounting documents).

d) Web cookies

For details, see the Cookie Policy.

4. Recipients of personal data

Your personal data may be provided to the following categories of recipients:

5. Transfer to third countries

Personal data is generally not transferred to third countries outside the EU/EEA. Where hosting or cloud tools with servers outside the EU are used, such transfer is secured by standard contractual clauses pursuant to Art. 46 GDPR.

6. Your rights

Pursuant to Articles 15 to 22 GDPR, you have the right to:

You can exercise your rights by emailing office@daligence.sk or in writing to the registered office address.

7. Data security

We have implemented appropriate technical and organizational measures to protect personal data in accordance with Art. 32 GDPR — encrypted communication, access controls, regular backups, physical premises protection and an internal confidentiality regime.

8. Changes to the policy

We may update this policy. The current version is always published on this page with the date of the last update.