Privacy Policy
In this document you will find detailed information about how we process your data, what rights you have and how you can contact us.
1. Introduction
This Privacy Policy explains how LASERCUT, as the controller, processes the personal data of natural persons.
By using the LASERCUT website, you confirm that you have read and understand this Policy.
2. Service operator
LASERCUT s.r.o.
Rožňavská 2 821 04, Bratislava, Slovak Republic
IČO: 55033130
DIČ DPH: SK2121843625
3. Legal basis and purpose of processing
We process personal data in accordance with:
- Regulation (EU) 2016/679 — GDPR
- Act No. 18/2018 Coll. on Personal Data Protection
- Act No. 22/2004 Coll. on Electronic Commerce
- ePrivacy Directive 2002/58/EC
Purposes of processing:
1.1 Conclusion and performance of a contract (B2B / B2C): processing of orders, manufacturing of laser-cut parts, bending, CNC, issuance of invoices, delivery notes, contracts, technical documentation
1.2 Communication with the customer: responses to inquiries, consultations on drawings, technical support
1.3 Marketing and analytics: newsletter, traffic monitoring (Google Analytics, Meta Pixel), remarketing and website optimization
1.4 Website security and operation: prevention of service misuse, attack detection, server logs
1.5 Fulfilment of legal obligations: accounting documents, tax obligations, archiving in accordance with the legislation of the Slovak Republic
4. Categories of data processed
2.1 Identification and contact data: first and last name, company name, IČO, DIČ, IČ DPH, address, billing details, telephone, e-mail
2.2 Business data: information about orders, customer history, communication
2.3 Technical data (automatically collected): IP address, device type, browser, OS, cookies, time and duration of the visit
2.4 Data uploaded by the user: drawings, technical documentation, CAD files, DXF/DWG/STEP/PDF. We process them solely for manufacturing purposes and do not transfer them to third parties without a legal basis.
2.5 Data from contact forms: subject of the message, files, additional information about the project
5. Legal bases for processing
Processing is carried out pursuant to Article 6 of the GDPR:
- 6(1)(b) – performance of a contract
- 6(1)(c) – legal obligation
- 6(1)(f) – legitimate interest (security, fraud prevention, B2B marketing)
- 6(1)(a) – consent (newsletter, cookies)
6. Storage and retention period of data
We retain data as follows:
- Orders, invoices: 10 years
- Technical documentation: 1–5 years depending on the type of project
- Marketing data: until consent is withdrawn
- Server logs: 6 months
- Cookies: 1 month – 2 years (depending on the type)
8. Provision of data to third parties
We provide data only to:
- IT service providers
- carriers (DHL, TopTrans)
- accountants and auditors
- legal advisors
- payment gateways (if implemented)
Each recipient processes the data exclusively on the basis of a data processing agreement in accordance with the GDPR.
9. Transfer of data outside the EU
As a rule, the controller does not transfer personal data outside the EU/EEA.
If, exceptionally, data is transferred (e.g. with Google analytical tools):
- it always takes place under the standard contractual clauses (SCC)
- with additional security measures (encryption, pseudonymization)
10. Rights of the data subject
Every data subject has the right:
- to access their data
- to rectification
- to erasure (the right to be forgotten)
- to restriction of processing
- to data portability
- to object to processing
- to withdraw consent
- to lodge a complaint with the Office for Personal Data Protection of the Slovak Republic
Úrad na ochranu osobných údajov SR
Hraničná 12, 820 07 Bratislava 27
11. Security of processing
The controller has implemented technical and organizational measures:
- data encryption
- firewall and antivirus protection
- strict access control
- regular security audits
- physical protection of servers
- GDPR training for employees
Customers' technical documentation is stored in encrypted repositories and is not processed for marketing purposes.
12. Automated decision-making
The controller does not carry out:
- automated decision-making with legal effects
- profiling of customers without consent
Analytical tools are anonymized.
13. Protection of children and minors
The LASERCUT website is not intended for persons under 16 years of age. Data obtained unintentionally will be deleted immediately.
14. Changes to the Policy
The controller reserves the right to update this Policy. The current version is always available on this page.
Users will be informed of significant changes by e-mail or by banner.
15. Contact details
LASERCUT s.r.o. (LASERCUT Service)
E-mail: [email protected]
Correspondence address: Rožňavská 2 821 04, Bratislava, Slovak Republic