MK-HolzMont s.r.o.

Privacy policy

Effective from: 10 August 2026

1. Who processes your data

ControllerMK-HolzMont s.r.o.
Registered officeUlica Poriečie 1246/200, 029 56 Zákamenné, Slovensko
Company ID55917453
Registered inObchodný register Okresného súdu Žilina, oddiel Sro, vložka č. 83773/L
Managing directorMarek Kovalčík
E-mailmk.holzmont@gmail.com
Websitemk-holzmont.eu

We process personal data in line with Regulation (EU) 2016/679 (GDPR) and Slovak Act No. 18/2018 Coll. on personal data protection.

This website is a company presentation. We do not sell goods through it and there are no user accounts or newsletters.

2. What data we process

2.1 Enquiry form

Data:
first and last name, e-mail, phone, company name, content of the enquiry and, where relevant, the requested installation date.
Purpose:
handling the enquiry, preparing a quote, communication before entering into a contract.
Legal basis:
Art. 6(1)(b) GDPR – pre-contractual steps at the request of the data subject.
Retention period:
3 years from the last communication. If the enquiry leads to a business relationship, we keep the data under accounting and tax rules (10 years, Sec. 35 of Act No. 431/2002 Coll.).

2.2 Communication by e-mail and phone

Data:
contact details and the content of the communication.
Purpose:
handling your request.
Legal basis:
Art. 6(1)(b) or (f) GDPR – pre-contractual steps, or legitimate interest in handling the communication.
Retention period:
3 years after the communication ends.

2.3 Website operation and security

Data:
IP address, browser type, time of access, page visited.
Purpose:
website functionality and security, protection against attacks and misuse.
Legal basis:
Art. 6(1)(f) GDPR – legitimate interest in secure operation.
Retention period:
briefly in the provider's infrastructure logs, usually up to 30 days.

2.4 Traffic measurement

Data:
aggregated, non-identifying data about visits (page viewed, traffic source/referrer, country, device and browser type, language) and on-site events (clicks on e-mail, phone, Instagram, enquiry submission).
Purpose:
understanding how the site is used and improving it.
Legal basis:
Art. 6(1)(f) GDPR – legitimate interest. We use Umami (Umami Cloud), which stores no cookies or other identifiers on your device, does not process your IP address in an identifiable form and builds no visitor profile.
Retention period:
as configured in the service, in aggregated form.

3. Who we share data with

We do not sell your data and do not share it with third parties for marketing. We use the following providers to run the website and communicate with you:

Cloudflare, Inc. (processor under Art. 28 GDPR) – 101 Townsend St, San Francisco, CA 94107, USA

Purpose: website hosting (Cloudflare Pages/Workers), DNS, protection against attacks and secure operation.

DPA: cloudflare.com/cloudflare-customer-dpa

Umami Software, Inc. (processor under Art. 28 GDPR) – USA, Umami Cloud service

Purpose: cookieless traffic measurement without profiling. Only aggregated, non-identifying data about visits and events is processed.

Umami privacy policy

Formspree, Inc. (processor under Art. 28 GDPR) – USA

Purpose: technical processing and delivery of form enquiries, temporary storage of submitted enquiries. Formspree provides a DPA and processes data on infrastructure in the USA.

Google Ireland Limited – Gordon House, Barrow Street, Dublin 4, Ireland (parent company Google LLC, USA)

Purpose: delivery and storage of e-mail notifications about enquiries in the controller's mailbox (Gmail).

Google privacy policy

Other recipients: the company's accountant (to the extent needed for bookkeeping) and public authorities to the extent required by law.

4. Transfers outside the EU

Cloudflare, Umami Software and Formspree are based in the USA and part of the processing may take place outside the EU/EEA. Google Ireland Limited processes data within the EU, but transfers to the USA may occur within the Google group.

Safeguards under Art. 44 et seq. GDPR:

  • EU–US Data Privacy Framework – Commission Decision (EU) 2023/1795; list of certified organisations: dataprivacyframework.gov/list
  • Standard Contractual Clauses (SCC) – Commission Decision (EU) 2021/914 for entities outside the DPF.

We will provide a copy of the safeguards on request at the e-mail listed in section 1.

5. Your rights

Under Art. 15 to 22 GDPR you have the right:

  • to access your data
  • to rectify inaccurate data
  • to erasure
  • to restriction of processing
  • to data portability
  • to object to processing based on legitimate interest

Send your request by e-mail to the address in section 1. We will handle it within 1 month; for complex requests the period may be extended by 2 months, and we will inform you.

6. Complaints

If you believe we process data unlawfully, you may file a complaint with:

Office for Personal Data Protection of the Slovak Republic

Hraničná 12, 820 07 Bratislava 27, Slovakia

statny.dozor@pdp.gov.sk

dataprotection.gov.sk

7. Security

We apply appropriate technical and organisational measures under Art. 32 GDPR – encrypted transfer (HTTPS/TLS), access control for the website administration and regular updates.

8. Further information

We do not carry out automated decision-making or profiling under Art. 22 GDPR.

The website is not intended for people under 16 and we do not knowingly process data of minors.

9. Changes

We may update this policy. The current version is always published on the website together with its effective date.

Related documents: Terms, Cookie policy.