Plain-language summary.
This is a brochure website.
auxius.eu doesn't sell anything, doesn't ask you to sign in, and doesn't run analytics, advertising, or tracking scripts. We do not set marketing or analytics cookies.
The only personal data we knowingly receive is what you choose to send us — typically your name, e-mail address, and the contents of a message via the contact form or by writing to one of our e-mail addresses.
Like every site on the public internet, our hosting provider (Vercel) processes basic technical request data — IP address, user agent, request URL, timestamp — for the purpose of actually delivering pages and protecting the service against abuse. That data is not joined to any profile of you and we do not use it for marketing.
Who we are & who controls your data.
The data controller (prevádzkovateľ) within the meaning of Art. 4(7) GDPR is:
Full statutory company information is available on our Legal & imprint page. Given our scale and the fact that we do not engage in large-scale or sensitive processing, we have not appointed a Data Protection Officer (Art. 37 GDPR). The privacy contact above is the single point of contact for all data-protection matters.
What data is actually processed.
In the ordinary course of operating this website, the following categories of personal data may be processed:
We do not knowingly process special categories of data (Art. 9 GDPR) — such as health, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, biometric or genetic data. Please do not send us such data unsolicited.
What this site doesn't do.
For clarity — and because the absence of these practices is itself relevant under the GDPR's principles of data minimisation and transparency:
Purposes & legal basis.
Under Art. 6 GDPR every processing activity needs a defined purpose and a lawful basis. Ours:
Basis: Art. 6(1)(b) — steps taken at the request of the data subject prior to entering into a contract; or Art. 6(1)(f) — our legitimate interest in being able to reply to people who write to us.
Basis: Art. 6(1)(b) — pre-contractual measures; Art. 6(1)(f) — legitimate interest in keeping a short record of declined applications.
Basis: Art. 6(1)(f) — legitimate interest in running a secure, available service.
Basis: Art. 6(1)(c) — compliance with a legal obligation under Slovak law.
Processors & hosting.
We use a small number of third-party service providers that act as processors (sprostredkovateľ) under Art. 28 GDPR. They process personal data only on our instructions and only to the extent necessary to deliver their service to us.
vercel.com/legal/privacy-policy · DPA
Cookies & similar technologies.
auxius.eu does not set cookies. No first-party analytics cookies, no third-party advertising cookies, no consent banner — because we have nothing that would require consent under § 109 of Slovak Act No. 452/2021 Coll. on Electronic Communications (the ePrivacy implementation) or Art. 5(3) of Directive 2002/58/EC.
Your browser may still keep ordinary HTTP cache entries for static files we serve (images, fonts, stylesheets). Those are technical caching, not cookies, and contain no personal data about you.
If we ever introduce technologies that require consent — for example, embedded video, web analytics, or a chat widget — we will add a consent mechanism that asks before anything is set, and update this policy accordingly.
International transfers.
Vercel Inc. is headquartered in the United States. Although we configure our deployments to be served from Vercel's European edge regions wherever possible, certain operational and administrative functions necessarily involve transfer of data to the United States.
Such transfers take place on the basis of one or more of the following safeguards under Chapter V GDPR:
- EU–US Data Privacy Framework. Where the recipient is certified under the Data Privacy Framework, transfers rely on the European Commission's adequacy decision of 10 July 2023.
- Standard Contractual Clauses (SCCs). Module 2 (controller-to-processor) clauses adopted by the European Commission in Decision (EU) 2021/914, as incorporated in our processor's Data Processing Agreement.
- Additional safeguards. Encryption in transit (TLS), encryption at rest where provided by the processor, and contractual limits on access.
A copy of the relevant SCCs or DPF certification can be obtained by writing to hello@auxius.eu.
How long we keep things.
We hold personal data only for as long as we have a clear reason to. Indicative retention periods:
Your rights as a data subject.
Under Articles 15–22 GDPR and Slovak Act No. 18/2018 Coll. you have the following rights with respect to personal data we hold about you:
- Access. Confirmation as to whether we process your data, and a copy of it.
- Rectification. Correction of inaccurate or incomplete data.
- Erasure ("right to be forgotten"). Deletion where the data is no longer necessary or where you withdraw consent.
- Restriction. Limiting how we process your data while a question about it is resolved.
- Portability. A machine-readable copy of data you provided to us where processing is based on consent or contract.
- Objection. Objecting to processing carried out on the basis of legitimate interest.
- Withdrawal of consent. Where processing is based on consent, you may withdraw it at any time — without affecting the lawfulness of processing before withdrawal.
- Complaint to a supervisory authority. See § 10 below.
To exercise any of these rights, write to hello@auxius.eu. We will respond without undue delay and in any event within one month of receipt of the request, with a permitted extension of up to two further months for complex matters (Art. 12(3) GDPR). We do not charge a fee for reasonable requests.
Security measures.
In line with Art. 32 GDPR we maintain technical and organisational measures appropriate to the limited nature of the data we process:
- TLS encryption for all traffic between your browser and the site.
- Access controls and unique authentication for any internal system that holds correspondence or recruitment data.
- Short retention by default; deletion at the end of each period above.
- Reputable EU/EEA-aligned service providers governed by written data-processing agreements.
- Internal rules on confidentiality and on reporting suspected incidents.
No security model is absolute. Where a personal-data breach is likely to result in a risk to the rights and freedoms of natural persons, we will notify the supervisory authority within 72 hours (Art. 33 GDPR) and, where the risk is high, the affected individuals (Art. 34).
Children.
This website is intended for a business audience. It is not directed at children. We do not knowingly collect personal data from individuals under 16 years of age (the age of digital consent under § 15(1) of Slovak Act No. 18/2018 Coll.). If you believe a child has provided personal data through this site, please contact us and we will delete it.
Changes to this policy.
We may update this policy from time to time — for example, when we change a service provider, add a new way for visitors to interact with the site, or when the underlying law changes. The version number and the "Last updated" date at the top of this page always reflect the current iteration. Material changes will be summarised here for at least six months following the update.
Contact.
For anything related to this policy — questions, requests, complaints, or simply curiosity — write to:
Karpatské námestie 10A, Bratislava, 831 06, Slovak Republic