Privacy Policy
Last update: 18/09/2026
These privacy conditions explain how we process personal data when providing our services within the company symetra s. r. o., with its registered office at: 29. augusta 891/7, Zvolen 960 01, ID No. (IČO): 54 254 949, registration: Commercial Register of the District Court Banská Bystrica, Section: Sro, Insertion No. 42593/S (hereinafter referred to as the „Controller“ or „we“). This document serves as your contact point for answering any questions regarding the protection of personal data or the receipt and processing of requests from data subjects.
Controller’s Contact Details:
- E-mail: info@symetra.sk
- Phone number: +421 944 289 292
- Correspondence address: 29. augusta 891/7, Zvolen 960 01
These privacy conditions primarily serve to fulfill the information obligations under Articles 13 and 14 of the GDPR toward data subjects whose personal data we process. Typically, this applies to employees of our business partners, clients, or suppliers. When processing personal data, we are guided primarily by the EU General Data Protection Regulation („GDPR“), which also regulates your rights as a data subject, as well as those provisions of Act No. 18/2018 Coll. on Personal Data Protection, which apply to us, and other legal regulations. If you do not fully understand any information listed in these conditions, please do not hesitate to contact us.
Why do we process personal data?
The processing of personal data is necessary on our part in order to:
- Provide our services and products and, for this purpose, process the personal data of our clients, suppliers, business partners, employees, and other individuals.
- Effectively manage our human resources.
- Fulfill various legal and contractual obligations.
- Protect our legitimate interests.
For what purposes and on what legal bases do we process personal data?
We process personal data for the following purposes based on the following legal bases:
# | Purpose of processing personal data | Legal basis |
1. | Establishing a relationship with a client (order processing) | Performance of a contract |
2. | Execution of IT service works | Performance of a contract |
3. | Providing IT consultancy | Performance of a contract |
4. | Processing and publishing reviews to build the good reputation of the controller | Consent |
5. | Entering into contractual relationships with business and other partners | Performance of a contract |
6. | Proving, exercising, or defending legal claims (legal agenda) | Legitimate interest |
7. | Agenda of the rights of data subjects | Compliance with legal obligations |
8. | Operating social media profiles | Legitimate interest |
9. | Marketing and PR purposes | Consent and/or legitimate interest |
10. | Accounting and tax purposes | Compliance with legal obligations |
11. | Archival purposes and registry management | Art. 89 GDPR |
12. | Statistical purposes | Art. 89 GDPR |
What are the legitimate interests we pursue?
For the following purposes, we rely on the legal basis of legitimate interest according to Art. 6(1)(f) of the GDPR:
- Proving, exercising, or defending legal claims (legal agenda): In rare cases, we must prove, exercise, or defend our legal claims through judicial or extrajudicial channels, or notify certain facts to public authorities, which we consider our legitimate interest.
- Operation and management of social media profiles, including discussion forums: If we operate our own profiles on social networks (LinkedIn), we rely on our legitimate interest, which is to increase awareness of our company in the online environment.
- Marketing and PR purposes: If we organize various events and actions to which we invite our business partners, or if we contact potential clients, we rely on our legitimate interest, which is direct marketing. According to Recital 47 of the GDPR: „The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.“
What personal data do we process about you?
Ordinary personal data such as title, first name, surname, billing data, delivery data, and contact information. Data about business partners, the price for purchased goods or services, and signatures in the case of contracts. In the case of a complaint, we process the submission, description of the complaint, and the date and time of submission.
To whom do we provide your personal data?
We take confidentiality very seriously. Your data is shared only with authorized employees or vetted third parties on a „need-to-know“ basis. We provide data only to the extent necessary to the following categories of recipients:
- Our vetted and legally bound processors.
- Our professional advisors (e.g., lawyers, auditors).
- Payroll and accounting companies (Dana Ema Janigová, ID No.: 33294585).
- Providers of software equipment and cloud services (e.g., Websupport s.r.o. or DigitalOcean, LLC).
- Technical (IT) and organizational (event agencies) support providers of our company.
- Social Insurance Agency, pension management companies, supplementary pension insurance companies, health insurance companies, Office of Labor, Social Affairs and Family.
- Postal couriers and employees of the above-mentioned entities.
If you are interested in information regarding our current processors, please do not hesitate to contact us via the contact details provided above.
To which countries do we transfer your personal data?
By default, we restrict any cross-border transfers of personal data to third countries outside the European Economic Area (EU, Iceland, Norway, and Liechtenstein).
How long do we store your personal data?
We store personal data for no longer than is necessary for the purposes for which the personal data are processed. If you revoke your consent, we are obliged not to further process the personal data for that purpose. General retention periods are as follows:
- Client relationships & IT services/consulting: For the duration of the contractual relationship.
- Processing and publishing reviews: For the period specified in the consent, typically 10 years.
- Contracts with business partners: For the duration of the contract and subsequently for 10 years.
- Legal claims & Data subject rights agenda: Until the statute of limitations of the legal claim.
- Social media profiles: Until the post is removed by the data subject or us, or until a erasure request is made. Social network messages are deleted once every 2 years.
- Marketing and PR (Newsletter): For the period specified in the consent. In the case of a newsletter, until an objection against processing is received or until unsubscription from the newsletter.
- Accounting and tax purposes: For 10 years following the accounting year to which the documents relate.
How do we obtain personal data from you?
Most often, we obtain personal data directly from you (contract process, communication, web forms, social media) and its provision is voluntary. We may also obtain it from your employer if we negotiate or conclude a contract with them. Any accidentally obtained personal data is not systematically processed further.
What rights do you have as a data subject?
If we process your personal data based on consent, you have the right to withdraw your consent at any time. You have the right to object at any time to processing for direct marketing purposes, including profiling. You also have the right to object to processing based on legitimate interests.
According to the GDPR, you have:
- The right to request access to your personal data (Art. 15 GDPR).
- The right to rectification and completion of data (Art. 16 GDPR).
- The right to erasure („right to be forgotten“ – Art. 17 GDPR).
- The right to restriction of processing (Art. 18 GDPR).
- The right to data portability (Art. 20 GDPR).
You also have the right to file a complaint at any time with the Office for Personal Data Protection of the Slovak Republic:
Úrad na ochranu osobných údajov SR
Galvaniho Business Centrum II
Galvaniho 7/B
821 04 Bratislava
Does automated individual decision-making take place?
No, currently we do not perform processing operations where decisions would be made with a legal effect or other significant influence on your person based exclusively on fully automated processing in the sense of Art. 22 of the GDPR.
External Websites & Cookies
Our websites may contain links to third-party services (e.g., Google reCAPTCHA) and we are not responsible for their content.
We use cookies primarily for measuring website traffic. You can control or delete cookies at your discretion via your browser settings; for details, visit aboutcookies.org.
Changes to the Privacy Conditions
We reserve the right to modify and change these conditions at any time to any extent. If we change these conditions in a material way, we will bring this change to your attention (e.g., via a general notice on this website or by email).
symetra s.r.o.
In Zvolen, September 18, 2026