GDPR Privacy Policy
Your privacy and data protection rights are important to us
Last updated: December 2024
Important Notice
This privacy policy explains how we collect, use, and protect your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
Data Controller
Company: 32bit s.r.o.
Address: Zámocká 7327/28 <br>811 01 Bratislava
Email: m.janci@32bit.sk
Phone: +421 903 109 862
Personal Data We Collect
Information you provide:
- Contact Information: Email address for communication
- Personal Details: First name, last name
- Identification: Document type, document number
- Document Images: Photos of identification documents (temporarily stored)
- Consent: GDPR consent confirmation
Automatically collected information:
- Technical Data: IP address, browser type, device information
- Usage Data: Pages visited, time spent on site
- Cookies: Session cookies for functionality
How We Use Your Data
Legal basis for processing:
- Consent: You have given explicit consent for data processing
- Legitimate Interest: To provide guest registration services
- Contract: To fulfill registration obligations
Purposes of processing:
- Process guest registrations for trips
- Verify guest identities and documents
- Communicate registration status and updates
- Ensure compliance with travel regulations
- Improve our services and user experience
Data Sharing and Transfers
We may share your data with:
- Trip Organizers: Only the specific admin managing your trip
- Service Providers: Email services, hosting providers (under strict contracts)
- Legal Authorities: When required by law or to protect rights
Data transfers:
- All data is stored within the European Economic Area (EEA)
- Any international transfers comply with GDPR requirements
- We use appropriate safeguards for data protection
Data Retention
Retention periods:
- Document Images: Automatically deleted immediately after approval
- Registration Data: Retained for 2 years after trip completion
- Contact Information: Retained for 2 years for communication purposes
- Technical Logs: Retained for 90 days for security purposes
Deletion process:
- Automatic deletion of documents after approval
- Regular review and deletion of expired data
- Secure deletion methods to prevent recovery
Your Rights
Under GDPR, you have the following rights:
Right to Access
Request a copy of your personal data and information about how it's processed.
Right to Rectification
Request correction of inaccurate or incomplete personal data.
Right to Erasure
Request deletion of your personal data (subject to legal requirements).
Right to Restrict Processing
Request limitation of data processing in certain circumstances.
Right to Data Portability
Receive your data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests.
How to Exercise Your Rights
To exercise any of these rights, please contact us at m.janci@32bit.sk with your request. We will respond within 30 days.
Data Security
Security measures:
- Encryption of data in transit and at rest
- Secure file uploads with virus scanning
- Regular security audits and updates
- Access controls and authentication
- Secure deletion of sensitive documents
Incident response:
- 24/7 monitoring for security incidents
- Immediate response to data breaches
- Notification to authorities within 72 hours
- Communication with affected individuals
Cookies and Tracking
Types of cookies we use:
- Essential Cookies: Required for basic functionality
- Session Cookies: Maintain your login session
- Analytics Cookies: Help us improve our service (optional)
Cookie management:
- You can control cookies through your browser settings
- Essential cookies cannot be disabled
- Analytics cookies are optional and can be refused
Contact Information
If you have any questions about this privacy policy or our data practices, please contact us:
Phone
Data Protection Officer
For complex data protection inquiries, you may also contact our Data Protection Officer at the same contact details above.
Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or applicable laws.
How we notify you of changes:
- We will post the updated policy on our website
- We will notify you by email for significant changes
- The effective date will be clearly indicated
Your Rights
If you disagree with any changes to this policy, you have the right to request deletion of your data and discontinue use of our services.