GDPR Privacy Policy

Your privacy and data protection rights are important to us

Last updated: December 2024

Data Controller

Company: 32bit s.r.o.

Address: Zámocká 7327/28 <br>811 01 Bratislava

Email: m.janci@32bit.sk

Phone: +421 903 109 862

Personal Data We Collect

Information you provide:
  • Contact Information: Email address for communication
  • Personal Details: First name, last name
  • Identification: Document type, document number
  • Document Images: Photos of identification documents (temporarily stored)
  • Consent: GDPR consent confirmation
Automatically collected information:
  • Technical Data: IP address, browser type, device information
  • Usage Data: Pages visited, time spent on site
  • Cookies: Session cookies for functionality

How We Use Your Data

Legal basis for processing:
  • Consent: You have given explicit consent for data processing
  • Legitimate Interest: To provide guest registration services
  • Contract: To fulfill registration obligations
Purposes of processing:
  • Process guest registrations for trips
  • Verify guest identities and documents
  • Communicate registration status and updates
  • Ensure compliance with travel regulations
  • Improve our services and user experience

Data Sharing and Transfers

We may share your data with:
  • Trip Organizers: Only the specific admin managing your trip
  • Service Providers: Email services, hosting providers (under strict contracts)
  • Legal Authorities: When required by law or to protect rights
Data transfers:
  • All data is stored within the European Economic Area (EEA)
  • Any international transfers comply with GDPR requirements
  • We use appropriate safeguards for data protection

Data Retention

Retention periods:
  • Document Images: Automatically deleted immediately after approval
  • Registration Data: Retained for 2 years after trip completion
  • Contact Information: Retained for 2 years for communication purposes
  • Technical Logs: Retained for 90 days for security purposes
Deletion process:
  • Automatic deletion of documents after approval
  • Regular review and deletion of expired data
  • Secure deletion methods to prevent recovery

Your Rights

Under GDPR, you have the following rights:

Right to Access

Request a copy of your personal data and information about how it's processed.

Right to Rectification

Request correction of inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your personal data (subject to legal requirements).

Right to Restrict Processing

Request limitation of data processing in certain circumstances.

Right to Data Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests.

Data Security

Security measures:
  • Encryption of data in transit and at rest
  • Secure file uploads with virus scanning
  • Regular security audits and updates
  • Access controls and authentication
  • Secure deletion of sensitive documents
Incident response:
  • 24/7 monitoring for security incidents
  • Immediate response to data breaches
  • Notification to authorities within 72 hours
  • Communication with affected individuals

Cookies and Tracking

Types of cookies we use:
  • Essential Cookies: Required for basic functionality
  • Session Cookies: Maintain your login session
  • Analytics Cookies: Help us improve our service (optional)
Cookie management:
  • You can control cookies through your browser settings
  • Essential cookies cannot be disabled
  • Analytics cookies are optional and can be refused

Contact Information

If you have any questions about this privacy policy or our data practices, please contact us:

Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices or applicable laws.

How we notify you of changes:
  • We will post the updated policy on our website
  • We will notify you by email for significant changes
  • The effective date will be clearly indicated