SK / EN Free consultation
Legal

Privacy Notice

This document explains what personal data we process, why, for how long, and what you can do about it. It is written to be readable without a lawyer.

Effective from 4 September 2026 · version 1.0

In short. If you do not write to us, we process nothing about you. The site uses only two technical cookies needed to submit the form, does not measure traffic and loads nothing from outside servers — the fonts are stored on ours.

When you fill in the form, we receive your name, e-mail, message and the service you ticked. We use it solely to reply. We do not sell it, do not send it anywhere for advertising, and we delete it on request.

01 — Who processes your data

The controller within the meaning of Article 4(7) GDPR is:

  • LightWeb s. r. o.
  • Registered office: Turčianske Kľačany 313, 038 61 Turčianske Kľačany, Slovakia
  • Company ID (IČO): 55 843 581
  • Registered in the Commercial Register of the District Court Žilina, section Sro, insert no. 83519/L
  • E-mail: patrik@lightweb.sk

We have not appointed a Data Protection Officer — the law does not require one from us, as we do not process data on a large scale or handle special categories of data. Patrik Halgaš answers data protection matters directly at the e-mail above.

02 — What data we process and why

SourceDataPurpose
Contact form on the home page name and company, e-mail address, message text, selected service to reply to your enquiry and prepare a quote
“Savings map” form name, e-mail, company, a description of the process you want automated, company and team size, timeline, desired outcome and whether you are the decision maker to prepare your savings map and an estimate of whether and how we can help
“Website audit” form name, e-mail, company, website address, a description of what troubles you about it, company size to prepare your website audit
Technical data when any form is submitted hashed IP address, browser type, referring page and campaign parameters from the link (utm_source, utm_medium, utm_campaign, utm_content) spam defence and knowing which channel brought you to us
An e-mail you send us everything you write in it, including the sender address to correspond with you about possible cooperation
Publicly available sources, if we approach you first company name, publicly published contact address, the source and the date we found it to approach companies we can be useful to — see section 12 in detail
The server the site runs on IP address, request time, browser type — ordinary server logs running and securing the site, defence against attacks

Filling in the form is voluntary. Without an e-mail address we cannot reply, so that is the only field we genuinely need besides the message itself.

We score enquiries. From what you enter in the form — company size, timeline, the need you describe, whether you are the decision maker — we compute an indicative score that sets the order and speed of our reply. That is profiling within the meaning of Article 4(4) GDPR and we say so plainly. It is not automated decision-making under Article 22: the score rejects nobody and accepts nobody, a human reads every enquiry and we answer all of them. On request we will tell you your score and the reasoning behind it, and you may object to it.

We do not process special categories of data under Article 9 (health, biometrics, political opinions and similar) — please do not send us any in the form.

03 — Legal basis

  • Pre-contractual steps — Article 6(1)(b) GDPR. You write to us so that we can prepare a quote; the processing is necessary for steps taken before entering a contract.
  • Legitimate interest — Article 6(1)(f) GDPR for server logs, spam defence (hashed IP) and the enquiry scoring described in section 02. Our interest is keeping the site running, protecting it from abuse and replying in a sensible order. We weighed that interest against your privacy: we do not link logs to form content, we never store an IP in readable form, and the score closes no doors — you may object to any of it under Article 21.
  • Consent — Article 6(1)(a) GDPR. This applies only if we switch on traffic measurement in the future. Until then we do not ask for consent, because there is nothing to consent to.

04 — Who we pass data to

We do not sell data and do not provide it for advertising. We pass it only to processors who handle it technically on our behalf:

ProcessorWhat it doesBased in
WebSupport, s. r. o. runs the server the site is hosted on, the database the enquiries are stored in, and the mailbox we reply to you from Slovakia

A submitted form goes nowhere else. The enquiry is stored directly in our database on a server in Slovakia. Until January 2026 it was received by the American service Formspree — we no longer use it, and this document stated otherwise until now.

There is only one processor. Hosting, the database and e-mail are all with the same company, not three separate services. Mail for lightweb.sk is delivered to WebSupport servers and leaves through them as well.

Where the law obliges us, we may provide data to public authorities. To nobody else.

05 — Transfers outside the European Union

No transfer outside the European Economic Area takes place. The site runs on a server in Slovakia, the enquiry is stored right there, and e-mail correspondence goes through Slovak servers belonging to the same provider. We use no American form services, analytics or advertising tools, and our fonts are self-hosted.

This section used to say a transfer "could occur" with e-mail. That was caution standing in for an answer — we checked the provider and it is Slovak, so we no longer claim it.

Should we ever deploy a tool with servers outside the union, we will name it in the table above together with what covers the transfer, and we will do so before switching it on.

06 — How long we keep the data

  • An enquiry that does not lead to cooperation: at most 12 months from the last message, then we delete it. Not “when we remember” — a scheduled task does the deleting every night.
  • An enquiry that leads to a contract: for the duration of the cooperation and then for the period required by accounting and tax law — usually 10 years.
  • Operational copies of the enquiry: the same data briefly also exists in the technical record of its receipt (if it arrived through an interface) and in the history of the automations that handled it. Both are deleted after 90 days, sooner than the enquiry itself. In the automation history the e-mail address is additionally masked (j***@company.com).
  • The record of steps taken on your enquiry: when it arrived, when we opened it and when its status changed. It ends together with the enquiry.
  • Server logs: usually up to 30 days, unless we need them longer to investigate a security incident.
  • Record of erasure: when we delete data at your request, all that remains is a bare record that the erasure happened and when — without your name or e-mail. Without it we could not demonstrate that we honoured the request (Article 5(2) GDPR).

07 — Cookies and local storage

This site uses two cookies and both are strictly necessary. We have no analytics, no advertising pixels and no third-party tools that would store anything on your device.

lightweb-sessionHolds the browser session. Without it the server could not match a submitted form to your window. Valid for 120 minutes from your last activity.
XSRF-TOKENProtects the contact form against misuse from another site (CSRF). Without it the enquiry could not be sent. Valid for 120 minutes from your last activity.

We do not ask for consent to these two, because ePrivacy rules do not require consent for strictly necessary cookies. Nor could they meaningfully be refused — without them the contact form would stop working. The bar you see on your first visit is therefore a notice with a single button, not a choice that would in truth be no choice at all.

Neither cookie holds a name, an e-mail or an identifier that could reveal who you are, and both expire when you close the browser or when their validity runs out.

In localStorage, under the key lw.consent, the site records only that you acknowledged the notice, together with the date. If we switched traffic measurement on in the future, your answer to the consent question would be stored in the same place.

If we did switch measurement on, this would apply: nothing runs until you click accept; refusing is as easy as agreeing; and you can withdraw consent at any time through a link in the footer. We also honour the Global Privacy Control signal if your browser sends it — in that case we do not ask and do not measure.

08 — Fonts and third parties

The Space Grotesk, Inter and JetBrains Mono fonts are stored on our server and load from our own domain. We therefore do not send your IP address to Google or any other third party while you simply browse the site.

The site embeds no videos, maps, social buttons or chat widgets. Links in the Work section lead to our clients websites — once you click, that site privacy rules apply, not ours.

09 — Your rights

Under the GDPR you have the following rights against us:

  • Access (Art. 15) — to be told whether and what data we hold about you, and to receive a copy.
  • Rectification (Art. 16) — to have inaccurate data corrected or incomplete data completed.
  • Erasure (Art. 17) — to have data deleted once we no longer need it for the purpose we obtained it for.
  • Restriction of processing (Art. 18) — to have us pause work with the data while a dispute over its accuracy or lawfulness is resolved.
  • Portability (Art. 20) — to receive the data in a machine-readable format or have it transferred to another controller.
  • Objection (Art. 21) — to object to processing based on legitimate interest.
  • Withdrawal of consent (Art. 7(3)) — at any time, without affecting the lawfulness of processing before withdrawal.

Just write to patrik@lightweb.sk. We reply within 30 days. Exercising your rights is free. If a request were manifestly unfounded or excessive, Article 12(5) GDPR lets us charge a reasonable fee or refuse it — and we will explain why.

To avoid sending data to the wrong person, we may verify your identity, usually by a reply from the e-mail address the enquiry came from.

10 — Complaint to the supervisory authority

If you believe we handle your data unlawfully, we would appreciate hearing from you first. You do, however, have the right to go straight to the supervisory authority:

  • Office for Personal Data Protection of the Slovak Republic
  • Hraničná 12, 820 07 Bratislava 27
  • Web: dataprotection.gov.sk

If you reside in another EU member state, you may contact the supervisory authority in your own country.

11 — Changes to this document

We may amend this document when the way the site works changes — for example when traffic measurement is added. A new version will carry an effective date and version number at the top. Material changes affecting enquiries already submitted will be announced to you by e-mail.

12 — When we approach you

Most enquiries come from you. Occasionally it goes the other way: we find a company we can be useful to and write to them first. In that case we hold your data without you having given it to us — and Article 14 GDPR covers exactly that situation. This is that notice.

Where we got the data

Only from publicly available sources: public job adverts (currently Profesia.sk) and public company websites. We never bypass logins, CAPTCHAs or any other protection, and we do not buy contact databases. The exact source and the date we found the contact are stated in our first message.

What data

Company name, its website, the publicly published contact address and a note on what the company does and why we think we can help. We prefer company addresses such as info@ over the addresses of named individuals. As with enquiries, we store an indicative score alongside the record — how and why is in section 02.

Why we are allowed to

The legal basis is legitimate interest under Article 6(1)(f) — offering a service directly to a company whose profile matches what we do. We weighed that interest against your privacy and limited ourselves as follows: public sources only, business contacts only, one message and one reminder, the source and an opt-out in every message, and never again after a refusal. If being approached bothers you, your interest prevails — and telling us is enough.

How long

If you do not reply, we delete the contact within 6 months of the last approach at the latest. If you refuse, we keep only your e-mail address on a list that stops us contacting you again — we use it for nothing else.

Your rights

Those in section 09 apply in full, including the right to object under Article 21. Against legitimate interest an objection is especially strong: once you raise it we stop processing for outreach immediately, and you need give no reason. Replying to our message or writing to patrik@lightweb.sk is enough.

13 — Contact

Send data protection questions, erasure requests and objections to patrik@lightweb.sk. Patrik Halgaš, founder, answers them.