GDPR

Privacy Policy

Transparent rules for processing personal data for the website, contact forms, newsletter, client system, cookies and IT services provided by Yenwa.

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR)
  • Act No. 18/2018 Coll. on Personal Data Protection
  • Act No. 452/2021 Coll. on Electronic Communications
  • document effective from 02. 06. 2026

General provisions

Yenwa, s.r.o., with its registered office at Potočná 1524/7, 908 51 Holíč, Slovakia, Company ID: 54319285, Tax ID: 2121630225, VAT ID: SK2121630225, as the operator of the website https://yenwa.sk and related online services, respects the privacy of website visitors, clients and contact persons.

This document explains what personal data we may process, for what purposes we use it, how long we keep it, to whom we may disclose it and what rights you have as a data subject.

When processing personal data we mainly follow:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council, known as GDPR,
  • Act No. 18/2018 Coll. on Personal Data Protection,
  • Act No. 452/2021 Coll. on Electronic Communications,
  • other applicable legal regulations of the Slovak Republic and the European Union.

Identification and contact details of the controller

Personal data controller:

Yenwa, s.r.o.
Potočná 1524/7
908 51 Holíč
Slovakia

Company ID: 54319285
Tax ID: 2121630225
VAT ID: SK2121630225

Phone: +421 911 533 932

E-mail: Zobraziť e-mail

Website: www.yenwa.sk

If you have questions about personal data processing or want to exercise your rights, contact us by e-mail, phone or in writing at the registered office address.

What personal data we process

We process only personal data necessary for operating the website, handling your request, communication, preparing an offer, providing IT services, managing client relationships or complying with legal obligations.

3.1 Data from the contact form

If you contact us through the contact form, we may process:

  • first and last name,
  • company or organisation name,
  • phone number,
  • e-mail address,
  • message subject and request content,
  • date and time of form submission,
  • technical data necessary to secure and protect the form and keep internal enquiry records, especially IP address, user-agent, browser language, URL, referrer and UTM parameters,
  • a record of the personal data processing acknowledgement when the form is submitted.

3.2 Data from e-mail, telephone and business communication

When you communicate with us, we may process contact details, communication content, request history, and data needed to prepare an offer, order, contract or other business step.

3.3 Newsletter data

If you subscribe to IT tips or news, we may process your e-mail address, exact date and time of the request, form source, URL of the page from which the form was submitted, referrer, IP address, browser user-agent, browser language, campaign UTM parameters, technical data needed to protect the form and a record of unsubscribing.

3.4 Data processed when providing IT services

When providing network administration, IT outsourcing, cloud services, Microsoft 365, cybersecurity, IT equipment service, camera systems, cabling or application development, we may process in particular, depending on the cooperation scope:

  • contact details of the client and its contact persons,
  • work contact details of users,
  • identification of devices, accounts, licences, services and access rights,
  • service communication, ticket records and request resolution history,
  • technical data needed for diagnostics, monitoring, security and documentation,
  • data to which we may have access when administering the client’s systems if necessary to provide the service.

3.5 Technical data when visiting the website

When visiting the website, technical data may be processed automatically, for example IP address, device type, browser type and version, operating system, date and time of visit, visited subpages, traffic source, server logs, cookies and similar technologies.

3.6 Accounting, contractual and invoicing data

For orders, contracts and invoicing we process identification, billing, contractual, payment and accounting data to the extent necessary for contract performance and legal obligations.

Purposes of personal data processing

We process personal data mainly for the following purposes:

4.1 Handling a contact request

If you send us a message through a form, e-mail or contact us by phone, we process your data to respond to the request, prepare a proposed solution or arrange a consultation.

We also store contact form messages in an internal database as a communication backup so that we can find submitted enquiries, check e-mail delivery status and continue communication even if an e-mail delivery problem occurs.

Legal basis: pre-contractual relationships or the controller’s legitimate interest.

4.2 Preparing an offer and contractual cooperation

We process data to prepare a price offer, order, contract, perform the service, communicate with the client, support users, document work and resolve service requests.

Legal basis: contract performance, pre-contractual relationships or legitimate interest.

4.3 Providing IT services and technical support

When providing IT services, we process data needed for administration, monitoring, diagnostics, security, recovery, service work, remote support, user administration and operational documentation.

Legal basis: contract performance, legitimate interest or processing on behalf of the client under a personal data processing agreement.

4.4 Compliance with legal obligations

Some data is processed because legal regulations require us to do so, especially accounting, tax, archiving or inspection obligations.

Legal basis: legal obligation.

4.5 Protection of rights, security and legitimate interests

We may process data to protect the website, systems, accounts, services, prove claims, resolve disputes, prevent misuse, perform security logging or investigate incidents.

Legal basis: legitimate interest of the controller or client.

4.6 Newsletter, expert content and marketing

We send IT tips, news or business information only to an appropriate and revocable extent. In an existing business relationship we may send related information based on legitimate interest if allowed by law; otherwise on the basis of consent.

Legal basis: consent or legitimate interest.

4.7 Analytics and website improvement

If analytics or marketing tools are deployed on the website, we use them to measure traffic and evaluate content and campaigns only according to the cookie consent settings.

Legal basis: consent of the data subject, unless it is technically necessary processing.

IT services, client system and Yenwa’s role in data processing

When providing IT services, depending on the situation, we may act either as a controller or as a processor of personal data.

5.1 Yenwa as controller

For our own website, contact forms, business communication, invoicing, newsletter, protection of rights and internal records, we determine the purposes and means of processing.

5.2 Yenwa as processor

When administering networks, servers, Microsoft 365, cloud, devices, user accounts, camera systems, remote support or application development, we may process data on behalf of the client according to its instructions. The scope, purpose, security measures and responsibilities are then governed by a contract or data processing agreement.

5.3 Client as controller

If we process data of employees, users, visitors, customers or other persons in the client’s environment, the legal basis and information duties towards these persons are usually ensured by the client as controller.

5.4 Client system support.yenwa.sk

When using the client system support.yenwa.sk, we may process data needed to receive, record, resolve and evaluate a service request. This mainly includes contact details, company name, request content, attachments, technical data about the device or system, resolution history, time data and data needed to securely assign the request to the client.

Do not send passwords, access keys or special categories of personal data through the client system, contact forms or e-mail unless it is necessary to resolve a specific request and has been agreed with us in advance in a secure way.

To whom personal data may be disclosed

We do not sell personal data and do not provide it to third parties for unauthorised purposes. To the necessary extent it may be processed by or made accessible mainly to:

  • providers of web hosting, servers, cloud services and technical infrastructure,
  • providers of e-mail, security, analytics or marketing tools if used,
  • providers of the client system, helpdesk or remote support tools,
  • accounting, tax, legal or audit advisers,
  • banks, insurance companies or payment partners where necessary,
  • subcontractors for IT services, service work, cabling, camera systems or infrastructure interventions where necessary and contractually covered,
  • public authorities, courts or supervisory authorities where required by law.

We conclude contractual relationships with personal data processors in accordance with GDPR requirements.

6.1 Transfer of personal data to third countries

We try to process personal data primarily within the European Union or the European Economic Area.

If cloud, analytics, marketing or technical tools involve a transfer of data to third countries, it will take place only in accordance with applicable law and appropriate safeguards, for example based on an adequacy decision, standard contractual clauses or another legally recognised mechanism.

Retention period for personal data

We keep personal data only for the time necessary to fulfil the purpose for which it was obtained, or for the period required by legal regulations.

Indicative retention periods:

  • contact form data: usually no more than 12 months after handling the request, unless a contractual relationship or legitimate reason to keep the data longer arises,
  • newsletter data: until unsubscribing or withdrawal of consent; we may keep an unsubscribe record for an appropriate time to prove that the choice was respected,
  • contractual, service and project documentation: during cooperation and afterwards according to statutory periods, limitation periods or legitimate claims,
  • accounting and tax documents: for the period set by legal regulations,
  • ticket and service records: during support and afterwards for an appropriate time needed to prove request handling, support quality or protection of rights,
  • server logs and security data: for an appropriate time needed for operation, diagnostics and security, and longer in case of an incident,
  • cookies and server-side session records: according to cookie type, consent settings, the lifetime of the specific technology and configured session lifetime.

After the retention period expires, we securely delete, anonymise or archive personal data only to the extent required by legal regulations.

Rights of the data subject

As a data subject you have, in particular, the following rights under GDPR:

8.1 Right of access

You have the right to obtain confirmation whether we process your personal data and, if so, the right to access this data and related information.

8.2 Right to rectification

You have the right to request correction of inaccurate personal data or completion of incomplete personal data.

8.3 Right to erasure

You have the right to request erasure of personal data if it is no longer necessary for the purpose for which it was obtained, if consent was withdrawn, if you object to processing or if there is no other legal basis for processing.

8.4 Right to restriction of processing

You have the right to request restriction of personal data processing in cases set out by GDPR.

8.5 Right to object

You have the right to object to personal data processing based on legitimate interest, including direct marketing.

8.6 Right to data portability

If processing is automated and based on consent or contract, you have the right to receive personal data in a structured, commonly used and machine-readable format.

8.7 Right to withdraw consent

If we process personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

8.8 Right to lodge a complaint

If you believe that we process your personal data contrary to legal regulations, you have the right to file a motion to initiate proceedings or a complaint with the Personal Data Protection Office of the Slovak Republic.

Personal Data Protection Office of the Slovak Republic
Hraničná 12
820 07 Bratislava 27
Website: www.dataprotection.gov.sk

Security of personal data

We adopt appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration, damage or unauthorised processing.

Access to personal data is granted only to authorised persons who need it to perform work or contractual tasks. In IT services we emphasise access and password management, MFA, secure remote connection, logging, documentation and appropriate technical safeguards according to the nature of the service.

The website uses a secure HTTPS connection where available and properly configured.

Cookies

The website may use cookies and similar technologies. Cookies are small text files stored on your device when visiting a website. They help ensure proper website operation, remember settings, analyse traffic and, with consent, evaluate marketing activities.

Storing information in the user’s terminal device or accessing information already stored in the device is governed mainly by Section 109(8) of Act No. 452/2021 Coll. on Electronic Communications. Optional cookies are used only after demonstrable consent; consent is not required only for technical storage or access whose sole purpose is message transmission, facilitating message transmission or providing an information society service explicitly requested by the user.

If cookies involve personal data processing, the legal basis for optional analytics and marketing cookies is consent under GDPR. Consent should be freely given, specific, informed and unambiguous; the user may refuse it or later withdraw it without affecting basic website use.

10.1 Necessary cookies

Necessary cookies are required for proper operation of the website, forms, security features or consent settings. They are used only to the extent needed for website operation, form security, remembering the cookie choice and providing the service used or explicitly requested by the user. For the session cookie, the related server-side record is stored in the database and may contain the session ID, optional logged-in user ID, IP address, user-agent, encrypted session payload and last activity time.

10.2 Analytics cookies

Analytics cookies help us understand how visitors use the website, which pages they visit and how they move through the website. We use them only based on your consent if such tools are deployed. Without consent, analytics storage in Google Consent Mode remains denied.

10.3 Functional cookies

Functional cookies may allow selected settings to be remembered or make the website more convenient to use. We use them to the necessary extent or based on consent if they are not required for basic functionality.

10.4 Marketing cookies

Marketing cookies may be used to evaluate advertising campaigns, remarketing, advertising measurement or possible ad personalisation. We use them only based on your consent if such tools are deployed. Without consent, advertising signals in Google Consent Mode remain denied.

10.5 Managing and refusing cookies

On the first visit you can use the cookie bar to accept all optional cookies, refuse optional cookies or save your own selection by categories. You can later change or withdraw your choice through the Cookies link in the website footer. You can also block or delete cookies directly in browser settings. Refusing analytics or marketing cookies will not restrict basic website use.

Contact form, newsletter and external links

11.1 Contact form

When using the contact form, we process the personal data entered in the form to handle your message. We also store the message in an internal database as a communication backup, including e-mail delivery status and technical submission data. By submitting the form you confirm that you provide the data voluntarily and have been informed about this Privacy Policy.

11.2 Newsletter

If you subscribe to the newsletter or IT tips, we use your e-mail address to send expert content, news and related information. When the form is submitted, we also record technical and analytical submission data, especially exact date and time, IP address, user-agent, form source, page URL, referrer and UTM parameters, so that we can prove the request, protect the form from misuse and evaluate content effectiveness. You can unsubscribe at any time through the link in the message or by contacting Yenwa.

11.3 External links and social networks

Our website may contain links to other websites, for example the client system, map services, information portals or social networks. We are not responsible for the content, security or personal data protection on external websites. We recommend reviewing their own privacy policies before using them.

If you contact us or follow us through social networks, personal data processing may also be governed by the rules of that social network. We process only data you voluntarily provide through a message, comment or other interaction.

Final provisions

We do not use personal data for automated individual decision-making with legal or similarly significant effects. Profiling for analytics or marketing purposes may take place only to the extent allowed by the user through cookie consent if such tools are deployed.

We may update this policy when the website, services, technologies used or legal obligations change. The current version of the policy will always be available on this page.

This policy is effective from 02. 06. 2026.