Privacy Policy (GDPR)
Principles of personal data protection and processing in accordance with Regulation (EU) 2016/679 (GDPR) and Slovak Act No. 18/2018 Coll.
Official internal directive specifying technical and organizational security measures, mapping of information systems (attendance registers, HR, inquiries), data subject rights, and statutory confidentiality requirements pursuant to Section 79 of the Personal Data Protection Act.
1. Data Controller and Supervisory Authority
The controller of your personal data is:
Registered office: Hraničná 19114/6, 821 05 Bratislava, Slovak Republic
Operating workplace: Tajovského 10, 974 01 Banská Bystrica, Slovak Republic
ID (IČO): 55922503 · Tax ID: 2122131974 · Reg. No.: MV SR VVS/1-900/90-67891
E-mail: development@lqdinstitute.com · Tel.: +421 907 813 351
GDPR Contact: Statutory representative, e-mail: development@lqdinstitute.com
Supervisory Authority:
Úrad na ochranu osobných údajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic)
Hraničná 12, 820 07 Bratislava 27, Slovakia · Web: dataprotection.gov.sk · E-mail: statny.dozor@pdp.gov.sk
2. Mapping of Information Systems (IS)
Pursuant to the internal directive, the controller maintains and governs the following information systems:
-
IS Attendance Registers & Educational / Project Activities:
Data processed: Name, surname, email address, year of birth (for statistical evaluation and grant eligibility verification).
Purpose: Participation management in training sessions, workshops, measurement studies, and project activities (such as Project PREMENA X²), auditing and substantiating activity delivery to project partners and supervisory authorities.
Legal bases: Art. 6(1)(b) GDPR (contract performance / event participation), Art. 6(1)(c) GDPR (statutory compliance or funding regulations), Art. 6(1)(f) GDPR (legitimate interest in project organization).
Retention period: Duration of the project plus statutory archival retention period (typically 5 to 10 years). -
IS HR & Payroll:
Processing data of employees, contractors, expert lecturers, and job applicants in compliance with labor and social security legislation. -
IS Marketing & Direct Communication:
Processing communication data (name, email, phone, organization) for inquiries received through the website or direct correspondence based on legitimate interest (Art. 6(1)(f) GDPR) and pre-contractual negotiations. -
IS Cookies & Online Identifiers:
Technical cookies required for secure site functioning and preference retention. -
Scientific Research & Validation Studies:
All empirical survey and measurement data are gathered based on explicit informed consent (Art. 6(1)(a) GDPR), strictly pseudonymized upon receipt, and fully anonymized in published datasets.
3. Technical and Organizational Security Measures
Pursuant to Art. 32 GDPR and the organizational directive, the institute implements robust safeguards:
- Electronic Data Protection: Antivirus and firewall solutions, password-protected hardware reserved exclusively for authorized personnel, encrypted transfers, and secured WPA networks with periodic credential rotations.
- Physical Document Safeguards: Hardcopy records, signed attendance sheets, and contractual files are stored in locked offices and filing cabinets accessible only to authorized personnel.
- Statutory Confidentiality (Section 79 Act No. 18/2018 Coll.): All team members and collaborators handling personal data are formally bound by strict confidentiality, persisting indefinitely even after the cessation of their collaboration or employment.
4. Data Recipients and Infrastructure
The controller does not sell or distribute personal data to unauthorized third parties. Data is shared exclusively with verified service processors:
- Google Ireland Ltd. (Google Cloud / Firebase Hosting): Technical infrastructure and hosting within EU data centers.
- Project contracting authorities and certified auditors: For verification of educational participation pursuant to binding project contracts.
5. Your Rights as a Data Subject
Under Chapter 3 of the GDPR, you have the right to request access to your personal data (Art. 15), rectification of inaccurate data (Art. 16), erasure / "right to be forgotten" (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), the right to object to processing based on legitimate interests (Art. 21), and the right to withdraw consent at any time without affecting past processing legality.
To exercise any of your rights free of charge, contact us at: development@lqdinstitute.com.