Privacy Policy
This page explains in plain language what personal data the axora-legal.com website collects, why we need it, who we share it with, how long we keep it and how you can control it.
We process data under Regulation (EU) 2016/679 (GDPR) and Slovak Act No. 18/2018 Coll. on personal data protection. You can use the site anonymously: articles and service pages need no registration. We only receive your data when you write to us yourself — through a form, the chat or a messenger.
1. Who the data controller is
The controller is the company that decides why and how your data is processed:
- Company
- Axora Group s. r. o.
- Company ID (IČO)
- 57746401
- Registered office
- Tomášikova 1498/30, 821 01 Bratislava
- Phone
- +421 952 667 601
- info@axora-legal.com
- Registry entry
- Extract from the Slovak Commercial Register
For any question about personal data, write to the e-mail above with the subject line "Personal data", or by post to the registered office. We reply within one month.
2. What data we collect and where it comes from
We collect only what is needed to answer your question and handle your request.
- Website forms — your name, phone number, e-mail or messenger handle, a short description of your situation, plus the language and the address of the page the form was sent from.
- Website chat — questions are first answered by a bot from our knowledge base, right in your browser; those messages are not sent anywhere. If you ask to connect a manager, the chat goes live: your messages, name and contact details are forwarded to our managers in Telegram and to our CRM system, and the manager’s replies appear in the same window. To keep the conversation open, your browser stores a technical session ID — it contains none of your data.
- Messengers and phone — if you write to us on WhatsApp or Telegram or call us, we receive your number or handle and the content of the conversation. The messenger operator (Meta for WhatsApp, Telegram for Telegram) also processes that conversation under its own rules, which we do not control.
- Our partner site smartstudy.sk — if you submit a request on the website of our partner Smart Study (built on the Tilda platform), it reaches our CRM and managers via a webhook, because we guide students together: your name, contact details and whatever you entered in the form.
- Cookies and browser storage — see the "Cookies" section below.
- Server logs — standard web-server records: IP address, time of the request, page address, browser type. Used for security and troubleshooting.
- Umami statistics — our own analytics on a group server in the EU. It sets no cookies, stores no IP address and collects no personal data: only anonymous counters — page views, country, device and browser type, button clicks.
We do not ask for special categories of data (health, religion, criminal records and the like) through the site — please do not enter them in forms or the chat unless necessary. If your case requires them, we will agree on that separately and under a contract.
3. Why we need the data and on what legal basis
- To answer your request, hold a consultation and provide the service — a contract with you, or steps taken at your request before entering into one (Article 6(1)(b) GDPR).
- To keep a history of requests so we do not ask the same thing twice, to protect against spam and abuse and, if needed, to prove that you contacted us — our legitimate interest (Article 6(1)(f) GDPR). You may object to this processing.
- Statistics and marketing cookies — only with your consent given in the cookie banner (Article 6(1)(a) GDPR). You can withdraw consent at any time.
We do no automated decision-making or profiling: the chat bot merely picks an answer from the knowledge base; decisions about your case are made by a person.
4. Who we share data with
We do not sell data or pass it on for anyone else’s advertising. Only people who need it for their work have access:
- The company’s managers and consultants — by role, and only to the requests they are working on.
- Messengers — requests and chat messages reach our managers in Telegram; when you correspond via WhatsApp or Telegram, the messenger operator also processes the data under its own rules. Messenger servers may be located outside the EU.
- Hosting — the website, chat, CRM and backups are hosted on Hetzner Online GmbH servers in Germany and Finland (EU). Hetzner is our processor: it works under a data processing agreement and does not use the data for its own purposes.
- Google — only if you have consented to statistics cookies: anonymised visit statistics then go to Google Analytics. Google processes data under its own policy; some processing may take place outside the EU under the conditions set out in the GDPR.
- Public authorities — only on a lawful request.
We use no other processors — no marketing agencies, call centres or mailing services. Apart from messengers and Google (with consent), data does not leave the EU.
5. How long we keep data
- Requests and correspondence (forms, chat, messengers) — while your request is being handled and then for up to 3 years from the last contact if no contract was concluded. If a contract was concluded — for its term and afterwards for the periods set by law (accounting, limitation periods).
- Server logs — 30 days.
- Umami statistics — anonymous and not linked to you, so no retention period applies.
- Your choice in the cookie banner — 12 months, then we ask again.
When the period ends we delete the data or anonymise it irreversibly; it disappears from backups as they are rotated.
6. Your rights
Under the GDPR you can:
- find out what data we hold about you and get a copy (access);
- correct inaccurate or incomplete data;
- ask us to delete the data;
- restrict processing;
- receive your data in a machine-readable format and transfer it to another controller (portability);
- object to processing based on legitimate interest;
- withdraw consent at any time — this does not affect the lawfulness of processing before withdrawal;
- lodge a complaint with the supervisory authority: Úrad na ochranu osobných údajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic), Hraničná 12, 820 07 Bratislava, dataprotection.gov.sk.
To exercise your rights, write to the e-mail given in section 1. We may ask you to confirm that the request really comes from you. We reply within one month; in complex cases the period may be extended by a further two months — we will let you know.
8. Security
The connection to the site and the chat is protected by TLS (HTTPS). Access to requests and correspondence is role-based and limited to staff who need it for their work. Backups are encrypted; the servers are in Hetzner data centres in the EU. There is no such thing as 100% security online: should an incident affecting your data occur, we will notify the supervisory authority and you as the GDPR requires.
9. Changes to this policy
We may update this policy — for example when we add a new tool or change retention periods. The current version is always on this page, with the version date shown at the top. We will announce significant changes on the site.
Legal notice
The content of axora-legal.com — articles, service descriptions, bot answers, tests and overviews — is for information only and is not legal advice. We check it as of the publication date, but laws, fees and the practice of authorities change: before making a decision, verify the current requirements with us at a consultation or with the competent authority.
AXORA (Axora Group s. r. o.) is a consultancy: we help you make sense of the procedures, prepare documents and accompany you when filing. We are not a law firm; if your matter calls for an attorney, we will say so plainly.
Links to third-party sites — partners, authorities, messengers — are provided for convenience; we are not responsible for their content or their data-processing rules.