Vlad Weby logo

Web developer & AI specialist based in Bratislava. Modern websites that earn - not just look good. Fast delivery, fair pricing.

address Bottova 2A, Bratislava
Let's Talk

Privacy Policy

Last updated: April 17, 2026

1. Introduction

This Privacy Policy explains how Vlad Weby (Vladislav Khvorov), based in Bratislava, Slovakia, collects, uses, stores and protects your personal data when you visit vlad-weby.sk or use any of our services. We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, or GDPR) and Slovak Act No. 18/2018 Coll. on Personal Data Protection.

2. Data Controller

The controller responsible for your personal data is:

Bc. Vladislav Khvorov

Vlad Weby

Bottova 2A, 811 09 Staré Mesto, Bratislava

Slovak Republic

Email: v.hvorov73@gmail.com

Phone: +421 919 208 426

3. Personal Data We Collect

Depending on how you interact with us, we may collect the following categories of personal data:

  • Identification datafirst name, last name, business/company name (if applicable).
  • Contact dataemail address, phone number, postal address (only if relevant to an invoice or contract).
  • Communication datacontent of messages you send through our contact form, email, WhatsApp, or calendar booking.
  • Project datainformation you share about your website, business, or goals during a consultation.
  • Billing datacompany registration number (IČO/DIČ), VAT ID, invoicing address, payment information.
  • Technical dataIP address, browser type, device information, referrer URL, pages visited, and timestamps — collected via server logs and analytics.
  • Cookie datainformation stored in cookies and local storage — see our Cookie Policy for details.

4. Purposes of Processing

We process your personal data only for specific, legitimate purposes:

  • Responding to your inquiries and providing a project quote
  • Concluding and performing a contract for website, SEO, AI chatbot or other services
  • Issuing invoices and meeting accounting and tax obligations
  • Sending service-related emails and project updates
  • Improving our website, services, and user experience
  • Protecting our website from fraud, abuse, and security threats
  • Complying with legal obligations under EU and Slovak law

5. Legal Basis for Processing

We process personal data on one of the following legal grounds, in line with Article 6 GDPR:

  • Performance of a contract (Art. 6(1)(b) GDPR)when we need your data to deliver the services you have ordered.
  • Legal obligation (Art. 6(1)(c) GDPR)for invoicing, tax, accounting and record-keeping duties under Slovak law.
  • Legitimate interest (Art. 6(1)(f) GDPR)to maintain website security, prevent fraud and improve our services.
  • Consent (Art. 6(1)(a) GDPR)for non-essential cookies, analytics and any optional marketing communication. Consent can be withdrawn at any time.

6. Recipients and Third Parties

We only share personal data with trusted service providers that help us run our business. These processors act on our instructions and are bound by data processing agreements:

  • Hosting providerstores website data and server logs on servers located in the European Union.
  • Email provider (Google Workspace / Gmail)used to send and receive email communication.
  • Analytics (Google Analytics 4)provides anonymised website usage statistics — only with your consent.
  • Booking tool (Google Calendar)used to schedule free consultations you request.
  • Accounting providerprocesses invoices and accounting records as required by Slovak law.

7. Data Retention

We keep your personal data only for as long as necessary to fulfil the purpose for which it was collected or as required by law:

  • Contact form and consultation messagesup to 12 months from last contact, unless a contract is concluded.
  • Contract and client datafor the duration of the contract and 10 years thereafter (Slovak accounting and tax law).
  • Invoices and accounting records10 years in line with Slovak Act No. 431/2002 Coll. on Accounting.
  • Server logsup to 6 months for security and troubleshooting.
  • Cookiesfor the lifetime defined in our Cookie Policy or until you withdraw consent.

8. International Data Transfers

Your personal data is primarily processed within the European Economic Area (EEA). Where a sub-processor (for example, Google) transfers data outside the EEA, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision to ensure an equivalent level of protection.

9. Your Rights Under GDPR

As a data subject, you have the following rights under Articles 15–22 of the GDPR:

  • Right of accessto obtain confirmation of whether we process your data and receive a copy of it.
  • Right to rectificationto have inaccurate or incomplete data corrected.
  • Right to erasureto request deletion of your data (the "right to be forgotten"), subject to legal exceptions.
  • Right to restrictionto limit how we use your data in certain situations.
  • Right to data portabilityto receive your data in a structured, commonly used machine-readable format.
  • Right to objectto processing based on legitimate interest, including profiling.
  • Right to withdraw consentat any time, without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at v.hvorov73@gmail.com. We will respond within 30 days as required by the GDPR.

10. Right to Lodge a Complaint

If you believe we have not handled your personal data in accordance with the law, you have the right to lodge a complaint with the Slovak supervisory authority:

Úrad na ochranu osobných údajov Slovenskej republiky

Hraničná 12, 820 07 Bratislava 27

Slovak Republic

Web: dataprotection.gov.sk

Email: statny.dozor@pdp.gov.sk

11. Security of Your Data

We apply appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, disclosure, or destruction. These measures include HTTPS/TLS encryption, secure hosting within the EU, access control, regular backups, and security updates. Despite our efforts, no online transmission or storage method is 100% secure.

12. Children's Privacy

Our services are intended for businesses and individuals aged 16 and over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it without delay.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or best practices. Any changes will be posted on this page with an updated revision date. We recommend reviewing this policy periodically.

14. Contact Us

If you have any questions about this Privacy Policy or the way we handle your personal data, please contact us: