Privacy Policy
Valid and effective from 15 July 2026
This privacy policy contains information about the processing of personal data of data subjects by CHARME s. r. o., with its registered office at Vincenta Hložníka 3542/4, 841 05 Bratislava – Karlova Ves, Company ID (IČO): 46 479 694, registered in the Commercial Register of the Municipal Court Bratislava III, insert no. 78250/B (the “Controller”), namely on the website www.thiavittek.com or www.thiavittek.sk or on the company's social media profiles (the “website”). We process all personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (the General Data Protection Regulation, the “GDPR”) and in accordance with Act No. 18/2018 Coll. on the Protection of Personal Data (the “Act”) and other applicable personal-data-protection regulations.
The purpose of this policy is to provide you with answers as to the purpose for which your personal data is processed, how it is processed, and what your rights and obligations are in connection with the processing of personal data. This policy also provides you with other relevant information about the processing of your personal data and thus fulfils the Controller's information obligation under Art. 13 and Art. 14 of the GDPR relating to the processing of personal data on the website. The conditions for the processing of personal data that takes place outside the website are governed by the Controller's general privacy principles and other internal regulations of the Controller on the protection of personal data.
Identification details of the Controller
Your personal data is processed by CHARME s. r. o., with its registered office at Vincenta Hložníka 3542/4, 841 05 Bratislava – Karlova Ves, Company ID (IČO): 46 479 694, registered in the Commercial Register of the Municipal Court Bratislava III, insert no. 78250/B.
Contact details of the responsible person:
Name: Patrícia Viktória Vittek
E-mail: team@thiavittek.com
I. Principles of personal data processing
We process your personal data solely for the specified purpose, in the specified manner and by the specified means, and only for the period necessary in view of the purpose of the processing. We carry out the processing of your personal data in such a way as to prevent unauthorised access to your personal data, unauthorised transfer, loss, destruction, or other unauthorised processing. When processing your personal data, we observe technical and organisational measures so as to guarantee the highest level of security with regard to all possible risks. All persons authorised to process your personal data are bound by confidentiality regarding the information obtained in connection with the processing of this personal data.
II. What personal data we process
The Controller always processes your personal data in accordance with the principle of minimisation, so as to fulfil any contractual and statutory requirements, to process personal data in which it has a legitimate interest, or to process your personal data where you grant consent to its processing, always only to the extent necessary to fulfil the specified purpose of the processing. This means that the Controller does not require from you personal data that is not necessary for the specific purpose of the processing.
The Controller processes your personal data to the extent of ordinary personal data, namely: first name, surname, mobile telephone number, e-mail, contact address, online identifiers (IP address, activity on the website) and other personal data that you provide.
III. Purpose and legal basis of processing your personal data
We process your personal data under Art. 6(1)(b) of the GDPR, i.e. the processing of your personal data is necessary for the performance of a contract or to take steps prior to entering into a contract at the request of the data subject.
We proceed on the above legal basis when receiving and handling orders for the services provided, namely where you order the services we provide via a message sent through the contact form on our website, a message on a social network, our contact e-mail address, or by telephone. The retention period for this personal data is until the full settlement of legal and other claims arising from the contractual relationship, at least 3 years from the end of the contractual relationship.
We process your personal data under Art. 6(1)(a) of the GDPR, i.e. the processing of your personal data is based on your consent.
We proceed on the above legal basis where you contact us with your request through a message sent via the contact form placed on our website or through a message on a social network. The retention period for this personal data is 3 months from the date of delivery of the request or until it is handled, whichever occurs first.
We also need your consent to measure the traffic of our website and to target advertising carried out through analytical and marketing cookies. The retention period for this personal data is until the consent is withdrawn by the data subject, but no longer than 2 years.
We also process your personal data under Art. 6(1)(c) of the GDPR, i.e. the processing of your personal data is necessary for compliance with legal obligations.
We proceed on the above legal basis where you send us a request or exercise any of the rights of the data subject. The retention period for this personal data is until the request is handled.
IV. Who has access to your personal data
In certain cases the Controller is obliged to provide your personal data to public authorities or other recipients authorised to process your personal data. These recipients include courts or law-enforcement authorities.
Other recipients of your personal data also include companies operating social networks where you contact the Controller through a message on a social network (Facebook Inc) and the company Google, LLC, which is the provider of the Google Analytics service used to measure the traffic of the Controller's website.
In connection with ensuring proper operation, the Controller has concluded cooperation agreements with Processors. The Controller has selected the Processors that come into contact with your personal data so that your personal data is safe and so that these Processors meet the personal-data-protection conditions required by the GDPR and the Act. We have concluded personal-data-processing agreements with the Processors, including confidentiality.
The Processors are business companies and natural persons – entrepreneurs with whom the Controller cooperates and who supply it with services (web hosting services, accounting), a company providing online accounting and invoicing software, and a company providing an online cloud storage service.
V. Where we transfer your personal data
When the Controller processes your personal data, in some cases your personal data is transferred to third countries:
- where you grant consent to the storage of analytical cookies, your personal data will be transferred to the USA, to Google LLC, which is the provider of the Google Analytics service that the Controller uses to measure traffic and activity on the Controller's website,
- where you contact the Controller through a message on a social network, your personal data will be transferred to the USA, to Facebook Inc., which operates the Facebook social network.
The transfer of your personal data is in all the above cases secured by means of standard contractual clauses which, in accordance with the terms of use of the above services, form part of the data-processing agreements concluded with the entities specified above.
VI. How we ensure the protection of your personal data
The security of your personal data is our priority. To ensure the protection of your personal data, we have adopted the necessary technical and organisational measures. As technologies improve, we also improve these security systems; we use virus-presence checks, antivirus programs and a firewall.
If our systems were to be attacked by a hacker attack, or our system were otherwise compromised, or another security incident occurred and there were even a threat of a data breach and harm to your rights, you will be informed within 72 hours of the measures taken, and within the same period we will also inform the supervisory authority in the field of personal-data protection in the Slovak Republic, which is the Office for Personal Data Protection.
VII. Information on the rights of the data subject
As a data subject whose personal data the Controller processes, you have the right to be informed of all the facts stated above, as well as of the fact that you have the following rights:
a) the right to request access from the Controller to the personal data it processes about you
If you wish to know which personal data the Controller processes about you, we will be happy to provide it to you on request. Simply send your request to the e-mail: team@thiavittek.com and we will handle it without delay, but no later than 30 days from the delivery of your request.
b) the right to rectification of your personal data
If the data you have provided to us is out of date, has changed, contains any inaccuracy, or is incomplete, let us know at our e-mail address team@thiavittek.com and we will correct it without delay. At the same time, we will inform all our Processors who process your personal data so that they likewise correct your personal data, and we will give you feedback that this rectification of your personal data has taken place.
c) the right to erasure of your personal data
If you are not satisfied with how we process your personal data, you also have the right to erasure of your personal data. You also have the right to be forgotten – the right to have the personal data provided erased after the purpose of its provision has been achieved, i.e. after performance of the contract, or after the end of the period of its mandatory retention under the special regulations of the Slovak Republic. The right to erasure of your personal data is therefore not absolute. If we need your data to fulfil our legal obligations, we will have to continue processing it for the purpose of fulfilling our legal obligations. We no longer process or retain personal data that has fulfilled its purpose. We will inform you of the erasure of your personal data.
d) the right to restriction of the processing of your personal data
As a data subject, you have the right to request restriction of the processing of your personal data, namely where you contest the accuracy of the personal data, during the period of verifying its accuracy; or where the processing of personal data is unlawful and, instead of erasure of the data, you request restriction of its processing; and also where the Controller no longer needs your personal data for the purpose it stated, but you need it to establish or defend your legal claims. When processing is restricted, your data will remain in our systems, but we will no longer use it for our purposes. We will inform you that we have restricted the processing of your personal data.
e) the right to object to the processing of your personal data
As a data subject, you have the right to object to the processing of your personal data on grounds relating to your particular situation carried out under Section 13(1)(e) or (f), including profiling based on those provisions. Where your data is processed on the basis of a legitimate interest, the Controller is obliged to demonstrate that its legitimate interests in processing the personal data override the rights or interests of the data subject, or the grounds for exercising a legal claim; otherwise it may not further process this personal data.
f) the right to portability of your personal data
You also have the right to request the transfer of your personal data to another Controller whose details you notify to us in writing. Technically, we are able to carry out such a transfer in the case of transferring an e-mail address; other data, given the different purpose of its processing compared to the processing of the e-mail address (see above), we will provide depending on the circumstances of the case. The Controller is entitled to refuse a data subject's request for data transfer if the requested transfer could have adverse effects on the rights and freedoms of others and the statutory conditions for exercising the right to portability under the GDPR are not met.
VIII. If you are not satisfied
If you are not satisfied with how we process your personal data, you can inform us at the e-mail team@thiavittek.com. You also have the option to lodge a complaint, or a motion to initiate proceedings, with the Office for Personal Data Protection if you believe that we process your personal data unlawfully. You can find a template motion on the website of the Office for Personal Data Protection. The contact details of the Office for Personal Data Protection of the Slovak Republic are as follows: address Hraničná 12, 820 07 Bratislava 27; website: dataprotection.gov.sk, tel.: 02 3231 3214; e-mail: statny.dozor@pdp.gov.sk.
IX. Does the Controller use profiling and automated decision-making?
When processing your personal data, the Controller does not use profiling and does not process personal data by any form of automated individual decision-making that would evaluate your personal aspects.
X. The Controller as a processor processing personal data on behalf of another controller
When providing services for the Controller's clients (the “clients”), the Controller may process the personal data of data subjects on behalf of its clients. When processing the personal data of data subjects on behalf of clients, the Controller acts as a processor of personal data under Art. 4(8) of the GDPR, whereby the controller determining the purposes and means of processing the personal data is, in the case of processing by the Controller acting as a processor, always the client.
The Controller concludes a personal-data-processing agreement with its clients, setting out the conditions for the processing of data subjects' personal data by the Controller as a processor on behalf of its clients, and the obligations relating to ensuring an adequate level of protection of the personal data processed.
The purposes, legal bases, scope and range of recipients of the personal data processed by the Controller as a processor on behalf of clients are determined by the clients, whereby in cases where the Controller processes the personal data of data subjects on behalf of its clients, it acts exclusively in accordance with the instructions of its clients and the relevant legal regulations, fulfils the obligations of a processor under the provisions of the GDPR and the Act, and carries out no processing operations with the personal data other than those arising for the Controller from the concluded personal-data-processing agreement and the processing purposes determined by the client.
XI. Final provisions
These updated Privacy Principles are valid and effective from 15 July 2026. As it may be necessary in the future to update the information on the processing of personal data contained in these Privacy Principles, the Controller is entitled to amend and update these Privacy Principles at any time. In such a case, the Controller will inform you accordingly.