Skip to content

Privacy Policy

This privacy policy sets out the procedures adopted by CRIF – Slovak Credit Bureau, s.r.o, Mlynské nivy 14/B; Twin City C; 821 09 Bratislava (hereinafter referred to as “CRIF SK”) regarding the processing of users’ personal data. This is general information intended for visitors to this website, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as the “General Data Protection Regulation”). When using certain services offered and provided via this website, users will provide certain information and make certain requests.

Data processing

Accessing this website may result in the processing of data relating to identified or identifiable natural persons (hereinafter referred to as ‘data subjects’). The data controller is CRIF SK. Personal data may also be processed by a data processor. The data controller is CRIF SK. Personal data may also be processed by a data processor, namely CRIF SpA, via della Beverara 21, Italy (hereinafter “CRIF”), which, like CRIF SK, has adopted appropriate organisational and technical measures to ensure the adequate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage to such data.

Data processing procedures

Personal data will be processed fairly and in full compliance with the General Data Protection Regulation (GDPR) to ensure the protection of the data and its confidentiality. The data will be processed by electronic or automated means. The data will be handled by authorised persons with the relevant skills and capabilities, who have been briefed on the content of the General Data Protection Regulation.

Types of data processed

The information systems and software procedures used to operate this website collect certain personal data in the course of their normal operation. The transmission of this data is an inherent part of the use of ICP protocols. The data is not collected with the intention of being linked to specific individuals; however, by its very nature, it could enable the identification of users through its processing and association with other data held by third parties.

This category of data includes IP addresses, ‘cookies’ and the domain names of the computers used by users connecting to the network, as well as the URI addresses of the resources requested, the time of the requests, the method used to make the requests and other parameters relating to the user’s operating system and IT environment. The voluntary submission of a user’s email address via the website results in the collection of the user’s personal data necessary to respond to that user’s enquiries. Personal data regarding the use of the website is also collected, including information on website traffic, the number of daily visits, and the average time users spend on each page.

Legal basis and purpose of processing

Article 6(1)(f) of the Regulation – the controller’s legitimate interests serve as the legal basis for the processing of personal data. The processing of the aforementioned data is necessary for the provision of services in connection with the operation of the website, and for monitoring and evaluating user activity on the website with a view to improving its functionality.

Recipients

CRIF SK may provide the information collected via the website to other companies belonging to the CRIF Group, namely CRIF S.P.A., CRIF – Czech Credit Bureau, a.s., Company Registration Number: 262 12 242, with its registered office at Štětkova 1638/18, Nusle, 140 00 Prague 4, as well as to third parties such as suppliers or other entities providing services (or products) requested by the user. We may also provide these companies with aggregate statistics on visitors, transactions or other activities on the website. Information about users may also be disclosed to other entities where required by applicable law or where necessary to protect the rights and legitimate interests of members of the GRIF Group. Third-party companies that provide additional services on this website, advertise on it or have a link to it may use ‘cookies’ on their own websites or collect information about users in other ways. CRIF SK has no control over the collection of information by these companies or over how they subsequently use it. If you have any questions regarding this data processing, please contact the operator of the relevant websites directly.

Data subjects

Users of the CRIF SK website.

Retention periods for personal data

For the duration of the cookies’ validity, or until they are removed (deleted) by the user; other data for the duration of the provision of services in connection with the operation of the website

User rights

The user has the right to request the following from CRIF SK:

  1. confirmation as to whether or not personal data concerning them is being processed,
  2. general information on the processing of personal data,
  3. the categories of the data subject’s personal data that are being processed,
  4. the rectification of personal data,
  5. the erasure of personal data:
    - which are no longer necessary for the purposes for which they were collected or otherwise processed,
    - the processing of which was carried out unlawfully,
    - which must be erased where the reason for erasure is compliance with a legal obligation,
  6. restriction of the processing of personal data,
  7. the exercise of the right to object to the processing of personal data.

The user also has the right to lodge a request to initiate proceedings under Section 100 of Act No. 18/2018 Coll. on the Protection of Personal Data. More specific conditions for the exercise of data subjects’ rights are set out in Chapter III of the Regulation. Contact details of the data controller: Mlynské Nivy 14, 821 09 Bratislava, email: dpo.sk@crif.com.