Last updated: 23 June 2026

Privacy policy

This document explains how Ambrecon s. r. o. processes personal data when you use the website, contact forms, project requests, customer accounts, and internal or client tools available after sign-in. We process personal data only to the extent necessary to provide services, communicate with customers, manage projects, keep the website secure, and meet legal obligations.

Who we are

The controller of personal data is Ambrecon s. r. o., Company ID: 57 546 614, registered office: Karpatské námestie 7770/10A, 831 06 Bratislava - Rača, registered in the Obchodný register Mestského súdu Bratislava III, oddiel Sro, vložka č. 198188/B. E-mail: info@ambrecon.com.

If you have questions about personal data protection or want to exercise your rights, contact us at info@ambrecon.com.

What data we process

We mainly process data you provide directly and technical data needed for the website and services to work.

Contact and project requests: name, e-mail, phone, company name, project details, selected services, budget, notes, and other information you provide in a form or communication.

Account and sign-in: e-mail, name or user name, technical account identifiers, and data needed for authentication and session security.

Client and internal tools: project, request, quote, invoicing, communication, or service management data if you use these tools.

Billing and business data: billing details, company or sole trader identification data, address, company ID, tax IDs, and data needed to issue documents and keep accounting records.

Technical data: IP address, device and browser type, access time, basic logs, error reports, and security events needed for operation, diagnostics, and protection.

Preferences and local storage: language, interface state, user preferences, and similar settings may be stored in the browser, for example through `localStorage` or technically necessary cookies.

Cookies and similar technologies

We use only technically necessary cookies or similar storage needed for website operation, sign-in, security, remembering preferences, or correct user interface behavior.

We currently do not use third-party marketing cookies. If we add them in the future, we will use them only in line with applicable rules and, where required, after obtaining consent.

Purposes and legal bases

Handling requests and communication: to answer questions, prepare quotes, or handle requests. The legal basis is steps prior to a contract or our legitimate interest in customer communication.

Providing services and managing projects: to deliver agreed services, manage project communication, administer customer accounts, and provide signed-in features. The legal basis is contract performance or steps prior to a contract.

Billing and accounting: to issue documents, keep accounting records, and meet legal obligations. The legal basis is compliance with a legal obligation.

Security and website operation: to protect the website, accounts, databases, and systems from abuse, resolve errors, and maintain stable operation. The legal basis is legitimate interest.

Service improvement: to evaluate website functionality, fix issues, and improve user experience using a proportionate scope of data. The legal basis is legitimate interest.

Consent: if we process data for purposes requiring consent in the future, such as optional marketing, we will ask separately. You may withdraw consent at any time.

Retention

We retain personal data only for the period necessary for the stated purposes or for the period required by law.

Contact forms and project requests: 12 months from the last communication.

Quotes not resulting in a project: 24 months from the date of the quote.

Customer accounts: for the life of the account and subsequently for the period necessary to protect legal claims, security, and technical continuity.

Technical logs: no longer than 12 months.

Accounting and billing documents: for the period required by the accounting and tax laws of the Slovak Republic.

Processors and third parties

Supabase: authentication, database, file storage, and related technical services for customer and internal tools.

Supabase processes data only to the extent necessary to provide these services and according to our instructions or its own legal obligations.

We do not sell personal data and do not provide it to third parties for their own marketing.

International transfers

Some technical infrastructure providers may process data outside the European Economic Area. In such cases, we rely on appropriate GDPR safeguards, such as Standard Contractual Clauses or other legal mechanisms used by the provider.

Data security

We use appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, or disclosure.

Access to internal tools is limited by user roles. Database data is protected by access rules, authentication, and other security measures appropriate to the nature of the service.

Your rights

Under the GDPR, you may request access to personal data, correction of inaccurate data, deletion, restriction of processing, data portability, object to processing based on legitimate interest, and withdraw consent where processing is based on consent.

You can exercise your rights by e-mail at info@ambrecon.com. For some requests we may need to verify your identity.

If you believe we process your personal data contrary to legal rules, you may also contact the Slovak Office for Personal Data Protection.

Children and educational activities

Regular website use, account registration, and contact forms are not intended for children under 16 without consent from a legal representative or the relevant school or organization.

For educational activities, workshops, or courses for schools and organizations, the scope of personal data processing is handled according to the specific agreement with the school, customer, or legal representative.

We do not knowingly process children's data outside an agreed service or legal authorization. If you believe we obtained a child's data without authorization, contact us at info@ambrecon.com.

Automated decision-making

We do not use automated decision-making or profiling that would have legal or similarly significant effects on users.

Changes to this policy

We may update this policy from time to time, especially when services, technologies, or legal requirements change. The current version will always be published on this page with the last updated date.

For material changes, we may also inform users in another reasonable way, such as by website notice or e-mail.

Contact

If you have questions about personal data protection or processing of your data, contact us: Ambrecon s. r. o., e-mail: info@ambrecon.com.