Privacy Policy (GDPR)
Data Controller Identification
The data controller for personal data processed through this website and digital services is Webat’o (ID: 51831732) ("Controller" or "Webat’o").
Company ID (IČO): 51831732
Data Protection Email: contact@webato.sk
Direct Phone: +421 950 499 542
Operating Location: Bratislava, Slovak Republic
Categories of Processed Data
We process exclusively information provided voluntarily through our contact forms or direct business communication:
- Full name of contact person
- Company name
- Work email address
- Phone number
- Scope and specification of your inquiry
- Essential technical server logs for security and threat prevention
Purposes & Legal Basis for Processing
We process personal data for the following legitimate purposes:
- Inquiry handling & proposal preparation: Legal basis is pre-contractual measures taken at your direct request.
- Contractual performance: Processing required for engineering delivery and system execution.
- Legitimate interest: Safeguarding server integrity, preventing cyber threats, and maintaining business correspondence records.
Third-Party Processors & Infrastructure
We never sell personal data to third parties for marketing purposes. We utilize trusted, enterprise-grade GDPR-compliant infrastructure providers, notably hosting (Vercel Inc.) and transactional email dispatch (Resend).
Data Retention Period
Inquiry records are retained for a maximum of 24 months from last communication, or as required by statutory commercial accounting obligations for active clients.
Data Subject Rights
Under the GDPR, you have the right to:
- Request access to your personal data and confirmation of processing
- Request rectification of inaccurate or incomplete data
- Request erasure of personal data (right to be forgotten)
- Request restriction of data processing
- Object to processing based on legitimate interest
- Lodge a complaint with the Data Protection Authority
Data Security Protocols
All data transmission between your browser and our servers is encrypted via HTTPS (TLS 1.3). We apply rigorous internal access controls, two-factor authentication, and the principle of least privilege.