VIPO a. s., with its registered office at gen. Svobodu 1069/4, 958 01 Partizánske, Company Registration Number: 31409911, as the controller of the website https://vipo.sk/(hereinafter referred to as the “controller”), has adopted appropriate technical and organisational measures to protect your personal data. In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as the “GDPR”) and Act No. 18/2018 Coll. on the protection of personal data and amending certain acts, the controller is obliged to ensure transparency when processing your personal data. In connection with its activities, the controller processes personal data for various purposes, about which you will find more detailed information in the text below.

The controller’s contact details:

VIPO a. s.
gen. Svobodu 1069/4, 958 01 Partizánske
Company registration number: 31409911
Contact email: vipo@vipo.sk

The data controller processes your personal data in the following information systems:

1. Records management

We process your personal data for the purpose of archiving the controller’s documents and keeping records of incoming and outgoing correspondence in both paper and electronic form as part of the use of the government web application www.slovensko.sk. We process the personal data you provide – comprising title, first name, surname and permanent address – on the basis of a legal obligation within the meaning of Article 6(1)(c) of the GDPR, arising from Act No. 395/2002 Coll. on archives and registries and amending certain Acts, and Act No. 305/2013 Coll. on the electronic exercise of the powers of public authorities and amending certain Acts.

We process the personal data you provide for the following periods:

  • routine correspondence – 2 years;
  • records management (records management tools, document disposal, etc.) – 10 years;
  • incoming and outgoing mail register – 2 years;
  • correspondence records (part of the client’s file) – 10 years.

2. Accounting documents

We process your personal data for the purpose of processing the accounting documents of data subjects when establishing and fulfilling pre-contractual and contractual relationships. We process the personal data you provide to the following extent:  the first name and surname of the taxable person or the name of the taxable person, the address of their registered office, place of business, business premises, place of residence or the address of the place where they usually reside, and their tax identification number under which they supplied the goods or services, or the first name and surname of the recipient of the goods or services, or the name of the recipient of the goods or services, the address of their registered office, place of business, business premises, place of residence or the address of the place where they usually reside, and their tax identification number under which the goods were supplied to them or under which the service was supplied to them, and the bank account number of a natural person.  The processing is carried out on the basis of a legal obligation within the meaning of Article 6(1)(c) of the GDPR, arising from Act No. 431/2002 Coll. on Accounting, as amended, Act No. 222/2004 Coll. on Value Added Tax, Act No. 40/1964 Coll. the Civil Code, and Act No. 513/1991 Coll. the Commercial Code. Data subjects are defined as persons who are obliged to pay for the goods or services supplied. The retention period for personal data required for the processing of accounting records is 10 years.

3. Contact form

We process your personal data for the purpose of responding to your questions or feedback sent to us via the contact form on our website. We process the personal data you provide—including company name, town, first name, surname, position/department (optional), telephone number and email address, are processed on the basis of our legitimate interest within the meaning of Article 6(1)(f) of the GDPR, our legitimate interest being to contact you in order to respond to your questions or feedback.

We process the personal data you provide for the period necessary to fulfil the purpose, but for no longer than 6 months. However, should the message concern data subject to a different processing period (e.g. accounting data, where the retention period is 10 years, and others), the period specified by legislative requirements will apply to the data being processed.

4. Enquiry

We process your personal data for the purpose of responding to your enquiry regarding the digital solution we provide, which you sent to us via the form on our website. We process the personal data you have provided – namely your name, job title, email address, company name and subject matter – on the basis of the performance of pre-contractual or contractual obligations within the meaning of Article 6(1)(b) of the GDPR.

We process the personal data you have provided for the period necessary to fulfil the purpose, but for no longer than 1 year. However, should the subject matter of the communication involve data to which a different processing period applies (e.g. accounting data, where the retention period is 10 years, and others), the period specified by legislative requirements will apply to the data being processed.

5. Shareholders

We process your personal data as part of our legal obligation arising from the Articles of Association of a public limited company when processing data from the register of shareholders, identifying shareholders, primarily for the purposes of sending out invitations to the general meeting and any other communication with shareholders, for the purposes of maintaining a register of shareholders present at the general meeting, identifying persons representing shareholders, for the purposes of recording the entry and exit of shareholders, for the purposes of counting the votes of shareholders present who take part in the general meeting, for the purpose of recording the results of shareholders’ voting, for the purpose of paying dividends to shareholders and for the purpose of providing information required by law to the National Bank of Slovakia, as well as for the purposes of obligations arising from a takeover bid. The operator processes personal data relating to the data subject (shareholder) obtained from the Central Securities Depository. The list of shareholders is maintained on behalf of the controller by the Central Securities Depository, which obtains personal data from shareholders and updates or amends it at the shareholder’s request.

The processing is carried out on the basis of a legal obligation within the meaning of Article 6(1)(c) of the GDPR. This legal obligation arises from Act No. 513/1991 Coll., the Commercial Code, as amended, and Act No. 566/2001 Coll. on Securities and Investment Services and on Amendments to Certain Acts.

The controller maintains the following list of personal data concerning shareholders and, in the case of a power of attorney, persons authorised to act on behalf of a shareholder:

The controller processes the personal data of data subjects – shareholders – obtained from the Central Securities Depository in its SOFTIP Profit information system to the following extent:first name, surname, title,  personal identification number (if assigned), permanent address, number of shares, ISIN, nationality, account type details, lien on shares, registration of the suspension of the right to dispose of shares, and the number assigned to the shareholder by the Central Securities Depository.  
Furthermore, the controller processes the following personal data relating to shareholders:identification details: maiden name, type and number of identity document;
contact details: telephone number, email address, temporary address.
Should a shareholder request the payment of dividends into a bank account, the controller also records the shareholder’s account number.
Details of persons authorised to act on behalf of a shareholder by power of attorney:regarding the principal: title, first name, surname, date of birth, personal identification number, place of residence, signature;
regarding the authorised representative: title, first name, surname, date of birth, personal identification number, address and identity card number, signature.

The controller processes personal data for a period of 10 years.
When processing personal data, the controller uses the services of a data processor pursuant to Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). The intermediary is Slovenská pošta a.s. (Partizánska cesta 9, 975 99 Banská Bystrica 1, Company Registration Number 36 631 124), acting as the processor for the payment of dividends by postal order.  

6. Data processing by third parties/security tools

On our websites, we use hCaptcha services to protect forms from bots. When a user encounters an hCaptcha widget, the service processes a combination of technical, behavioural and potentially contextual data — and many of these identifiers are considered personal data within the meaning of the GDPR. Where data processing takes place, we process personal data for the purpose of protecting our website from automated attacks, bots and fraudulent activity via the hCaptcha security service. The processing of personal data takes place whenever a form or other protected element on the controller’s website, which is secured by the hCaptcha tool, is displayed. This processing is carried out on the basis of our legitimate interest within the meaning of Article 6(1)(f) of the GDPR, which is based on protecting the website against automated attacks (bots), fraudulent form submissions and other forms of abuse, thereby ensuring the availability and integrity of the controller’s online services.

For this purpose, we process the personal data of visitors to our website who interact with forms or other elements protected by the hCaptcha tool. Specifically, we process the following data:

  • technical identifiers: IP address, browser type and version, operating system, screen resolution, device language settings;
  • behavioural data: mouse movements, timing of interactions with the form, clicking patterns;
  • cookies: the htm_id identifier (a first-party technical cookie for anonymous service-related statistics);
  • verification result: CAPTCHA challenge result (success/failure).

The data is processed for the period necessary to ensure the security of the session.

The recipient of the personal data is Intuition Machines, Inc., 2211 Selig Drive, Los Angeles, CA 90026, USA (operator of the hCaptcha tool) – acting as a separate controller in accordance with its own privacy policy available atwww.hcaptcha.com/privacy . By using this service, data is therefore transferred to third countries outside the EEA. The transfer is secured by means of Standard Contractual Clauses (SCCs) within the meaning of Article 46(2)(c) of the Regulation and certification under the EU–US Data Privacy Framework.

When processing personal data for the purposes set out above, no automated individual decision-making within the meaning of Article 22 of the Regulation takes place. The hCaptcha tool evaluates technical and behavioural signals solely for the purpose of distinguishing a human user from an automated bot.

7. Cookies

The controller uses the following categories of cookies on its website:

  1. essential cookies for the purpose of providing services in connection with the operation of the website in essential mode;
  2. analytical cookies to determine the number of visits and traffic sources – measuring and improving the website’s performance;
  3. marketing cookies used to display targeted advertising on the website, as well as to evaluate the effectiveness of the advertising and track the number of users who have been interested in the advertising.
Cookie typeLegal basis for processingType of data
necessaryLegitimate interest within the meaning of Article 6(1)(f) of the GDPR – our legitimate interest is the proper functioning of the website and its basic featuresWhen accessing and using the website, personal data is collected which the browser automatically transmits to the operator’s server. The following information is recorded automatically and stored until it is automatically deleted: the IP address of the requesting computer, the date and time of access, the name and URL of the file accessed, the website from which access is made, the browser used and, where applicable, the computer’s operating system, as well as the name of the internet service provider
analyticalConsent within the meaning of Article 6(1)(a) of the GDPR*Cookies stored on the end device
marketingConsent within the meaning of Article 6(1)(a) of the GDPR*Cookies stored on the end device

*Consent is always voluntary and unconditional; therefore, even if the data subject does not give their consent, they may still visit and use the website, online services and products to the extent that cookies are not necessary for their functionality and accessibility. If the use of cookies is disabled or restricted, this may affect the functionality and accessibility of the controller’s websites and services, and it may be the case that all or part of the services will not be fully functional or accessible.

Essential cookies are temporary and are automatically deleted when you close your web browser. Other types of cookies are classified as persistent and remain on your device until they expire, for a maximum of 13 months, or until you delete them yourself. As a visitor to the website, you can delete cookies at any time, regardless of whether they are persistent or temporary.

The operator uses third-party services on its website, such as Google Analytics or Meta’s marketing tools. To use these services, the operator loads third-party codes, which may require the storage of cookies to function fully. This results in the acceptance of cookies from third parties. If you accept the use of third-party cookies, your data may be transferred to countries outside the EEA (e.g. the USA, China).

Please note:

pursuant to Article 49(1)(a) of the Regulation, when transferring personal data to third parties that are unlikely to provide the level of personal data protection customary in EEA countries:

Granting consent to the provision or disclosure of personal data via social media and other means of communication whose operators are based outside the EEA (countries without an adequacy decision and without adequate safeguards – ‘countries not considered safe in terms of the protection and processing of personal data’) entails risks such as:

               loss of control over the personal data transferred,
               loss of privacy,
               lack of awareness regarding the transfer of personal data provided to other entities,
               failure to provide further information on the purposes for which personal data will be further processed,
               misuse and identity theft,
               the provision of personal data obtained to security agencies and secret services (e.g. the Russian Federation, the USA, China),
               the inability of data subjects to exercise their rights in the manner guaranteed by the European General Data Protection Regulation (GDPR) on the part of a controller established in a third country.

No automated individual decision-making, including profiling, takes place in connection with this processing.

General and supplementary information on the processing of personal data by the controller

Technical and organisational measures:

Organisational and technical measures for the protection of personal data are set out in the controller’s internal regulations. Security measures are implemented in the areas of physical and premises security, information security, encryption of information, personnel and administrative security, and the protection of sensitive information, with precisely defined powers and responsibilities set out in the security policy.

Categories of personal data:

For the purposes mentioned above, we process standard personal data.

Disclosure of personal data:

Personal data is not disclosed for any of the purposes mentioned above.

Automated processing, including profiling:

The controller does not use automated decision-making or profiling in the processing of personal data.

Rights of data subjects:

Data subjects have the right to request from the controller access to the personal data being processed about them; they have the right to rectification of personal data, the right to erasure or restriction of processing, the right to object to the processing of personal data, the right not to be subject to automated individual decision-making, including profiling, the right to data portability, and the right to lodge a complaint with a supervisory authority. Where the controller processes personal data on the basis of the data subject’s consent, the data subject has the right to withdraw their consent to the processing of personal data at any time. Withdrawal of consent does not affect the lawfulness of the processing of personal data based on consent prior to its withdrawal. The data subject may exercise their rights by sending an email to the controller’s address or in writing to the controller’s address. Requests from data subjects are handled on a case-by-case basis by a person designated by the controller.

As a data subject, you may exercise your right to lodge a complaint with the supervisory authority if you believe that your rights regarding personal data have been infringed. The supervisory authority is the Office for Personal Data Protection of the Slovak Republic, Galvaniho Business Centre II, Galvaniho 7/B, 821 04 Bratislava.

Recipients of personal data and other authorised entities:

Recipients of personal data:
Registry AdministrationMinistry of the Interior of the Slovak Republic (relevant archive) Act No. 395/2002 Coll. on archives and registries and amending certain acts, as amended.
Accounting documentsTax Office Act No. 222/2004 Coll. on value added tax.
ShareholdersAuthorised persons of the operator VIPO a.s. pursuant to Article 6(1)(b) Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
CookiesGoogle (which subsequently becomes a separate data controller) pursuant to Article 6(1)(a) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
Other authorised entities:
Other authorised entity  pursuant to Article 6(1)(c) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
State authorities, public authorities and other bodies specified by lawpursuant to Article 6(1)(c) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).