Privacy Policy

Last updated: 20 July 2026

1. Who processes your personal data

The data controller is the non-governmental organization Mayors of Slovakia, Company ID (IČO) 57167575, with registered office at Karadžičova 7610/16, 821 08 Bratislava–Staré Mesto. Contact for privacy questions: info@mayorsofslovakia.sk.

If the organization appoints a data protection officer, their contact details will be added here and communicated to the relevant supervisory authority.

2. What data we process

When browsing the website, technical data may be processed to the extent necessary, in particular IP address, date and time of access, requested page, browser type, operating system, and technical logs related to the security and operation of the website.

If you contact us via the form or email, we process the data you provide, in particular name, organization, role, country, email address, subject of the message, content of the communication, and any attachments.

Please do not send us sensitive personal data or data of third parties unless it is necessary and you are authorized to provide it.

3. Purposes and legal grounds of processing

We process contact messages in order to receive, assess and handle your inquiry, cooperation proposal or project concept. The legal basis is our legitimate interest in properly communicating with prospective partners under Article 6(1)(f) GDPR. If the communication leads towards a contractual relationship, the legal basis may also be steps taken prior to entering into a contract under Article 6(1)(b) GDPR.

We process technical and security logs in order to ensure the functionality, stability and protection of the website against misuse. The legal basis is the organization's legitimate interest in the secure operation of the website under Article 6(1)(f) GDPR.

We do not use personal data for automated decision-making, profiling or targeted advertising. We will not use contact data to send marketing messages without a separate, valid legal basis.

4. How long we keep the data

We keep ordinary contact communication for a maximum of 12 months from its handling or from the last substantive communication, unless a cooperation, contractual relationship, legal claim or statutory obligation requires longer retention.

If the communication leads to cooperation or a contractual relationship, we keep the data for the duration of the relationship and afterwards for the periods resulting from accounting, archiving and other legal regulations, or for the period necessary to protect legal claims.

Technical security logs of the website should be kept only for the necessary period, recommended at a maximum of 30 days, unless a specific security incident or legal obligation justifies longer retention. The actual period depends on the hosting provider's configuration.

5. Who may have access to the data

Authorized staff of the organization and trusted providers of technical services may have access to personal data, in particular the web hosting provider, website administrator, email service provider or IT support. These entities may process data only to the necessary extent and according to our instructions, or on the basis of their own statutory obligation.

We may disclose data to public authorities if required by law or a binding decision. We do not sell personal data and do not provide it to third parties for advertising or marketing purposes.

6. Transfers outside the European Economic Area

Before publishing this section, the technical administrator must confirm the seat and data locations of the hosting, email and other technical service providers. Should personal data be transferred outside the European Economic Area, this will only take place under the conditions of the GDPR, for example on the basis of a European Commission adequacy decision or appropriate contractual safeguards.

7. Your rights

Under the conditions set out in the GDPR, you have the right to request access to your personal data, its correction, deletion or restriction of processing. In the cases provided for by the GDPR, you also have the right to data portability.

If we process data on the basis of a legitimate interest, you have the right to object to its processing for reasons relating to your particular situation. If processing were based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing before its withdrawal.

You can exercise your rights by email at info@mayorsofslovakia.sk. To protect your data, we may verify your identity in a reasonable manner. We will respond to your request without undue delay, usually within one month.

If you believe that we are processing your personal data in violation of legal regulations, you have the right to lodge a complaint with the Slovak Data Protection Authority (Úrad na ochranu osobných údajov SR).

8. Security of personal data

We take appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration or disclosure. Only persons who need it to perform their tasks have access to the data.

9. Changes to this policy

We may update this policy if the way the website operates, the technologies used, or legal requirements change. The current version will always be published on this page together with the date of the last update.

We will use data from the contact form only to handle your message and for follow-up communication. Ticking the checkbox on the form confirms that you have read this policy; it is not a consent to the processing of personal data.