This document is a draft. It must be reviewed and approved by a lawyer before publication and use.
Fields in [square brackets] must be completed with concrete details (e.g. legal name, company ID, contacts) before use.
Legal document
Privacy Policy
This policy explains what personal data we process in connection with the tesla-ke.sk portal (the MSART service referral program), for what purposes, on what legal basis, how long we keep it, and what your rights are.
1. Who we are (controller)
The controller is [TO COMPLETE: legal name], registered office [TO COMPLETE: address], company ID [TO COMPLETE: ID No.], registered in [TO COMPLETE: register and entry number]. Data protection contact: [TO COMPLETE: e-mail], [TO COMPLETE: phone]. Data protection officer (if appointed): [TO COMPLETE: name and contact].
2. What personal data we process
- Identification and contact data: name, e-mail address, optionally phone number.
- Login and security data: password (stored only in hashed form), one-time 2FA codes, login records.
- Referral and reward data: referral code, referrer–referred link, status and value of claims.
- Order and payment data: ordered services, amounts, dates (as needed for the program and accounting).
- Technical data: IP address, device and browser type, cookies and similar technologies.
- Consent records: which consents you gave or withdrew and when.
3. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Registration and account management | Performance of a contract (Art. 6(1)(b)) |
| Login, 2FA and account security | Legitimate interest / legal obligation (Art. 6(1)(f)/(c)) |
| Referral program and reward management | Performance of a contract / program rules (Art. 6(1)(b)) |
| Orders, payments and accounting | Legal obligation (Art. 6(1)(c)) |
| Operational service notification e-mails | Performance of a contract / legitimate interest (Art. 6(1)(b)/(f)) |
| Marketing communication | Consent (Art. 6(1)(a)) |
| Analytics and marketing cookies | Consent (Art. 6(1)(a)) |
| Handling rights, disputes and complaints | Legitimate interest / legal obligation |
4. Recipients and processors
We share data only with trusted providers operating the portal for us, under data processing agreements. We never sell it.
- Hosting and database: Websupport, s.r.o. (Slovakia) – data in SK/EU.
- Transactional e-mail (2FA and notifications): [TO COMPLETE: e.g. Scaleway TEM (France, EU)].
- Application error monitoring: [TO COMPLETE: e.g. Sentry – EU data region (Frankfurt)].
- Accounting and tax services: [TO COMPLETE: provider].
5. Transfers to third countries
We process data within the EU/EEA and do not plan transfers to third countries. If one occurs exceptionally, we will ensure appropriate safeguards under the GDPR (e.g. standard contractual clauses). [TO COMPLETE / verify with processors]
6. Retention periods
| Data category | Retention (proposed – to confirm) |
|---|---|
| Account and profile | for the duration of registration; after closure [proposed: 30 days], then deletion/anonymisation |
| Accounting documents and invoices | 10 years (Slovak Accounting Act) |
| Audit log and security records | [proposed: 12 months] |
| One-time 2FA / login codes | minutes – deleted after expiry or use |
| Consent records | for their validity + [proposed: 3–4 years] for evidence after withdrawal |
| Marketing (based on consent) | until consent is withdrawn |
7. Your rights
You have the right to access, rectification, erasure, restriction, data portability, to object, and to withdraw consent at any time (without affecting prior processing). You may also lodge a complaint with the supervisory authority.
To exercise your rights, contact [TO COMPLETE: e-mail]. We respond within one month. A logged-in customer can export their data and request erasure directly from the Profile section.
8. How we protect data
We use encrypted transport (TLS), store passwords only hashed, apply role-based access (customer / staff / administrator), protect logins with two-factor authentication, log key events, and back up data regularly.
9. Cookies
Cookies and consent management are governed by a separate Cookie Policy.
10. Changes to this policy
We may update this policy. We will notify you of material changes on the portal or by e-mail. The version published on the portal applies.
11. Contact and supervisory authority
Contact: [TO COMPLETE: e-mail and address]. Supervisory authority: Office for Personal Data Protection of the Slovak Republic (ÚOOÚ), Hraničná 12, 820 07 Bratislava [verify current ÚOOÚ details].