This notice describes how Inger s.r.o. (“we”, “us”) processes personal data collected through www.inger.sk. We process the minimum data required to respond to business inquiries and operate the site securely, in line with Regulation (EU) 2016/679 (GDPR) and Slovak Act No. 18/2018 Coll.
1. Data controller
Inger s.r.o.
Registered office: Banská Bystrica, Slovakia
ID (IČO): 50 178 831
VAT ID (IČ DPH): SK2120217781
Email: info@inger.sk
We have not appointed a Data Protection Officer — as a small engineering studio, the legal criteria for a mandatory DPO do not apply. You can raise any privacy question directly with the address above.
2. What we collect
Contact form
When you submit the contact form on this site, we process the name, email address, and message content you enter. We also capture technical metadata strictly for anti-spam: submission timestamps, a rotating token, a hashed honeypot field, coarse interaction signals (focus and input events), and the requesting IP address for rate-limiting.
Server logs
Our hosting provider records standard HTTP access logs (IP address, user agent, requested URL, timestamp, response status). These exist for operational and security purposes and are retained by the provider under their own retention schedule.
Local preferences
The site stores a single localStorage key to remember your theme preference (dark/light). This never leaves your browser and is not personal data.
3. What we do not collect
- No analytics cookies, tracking pixels, advertising SDKs, or session replay.
- No profiling, no automated decision-making with legal effects.
- No cross-site identifiers, no fingerprinting scripts.
- No sale or sharing of personal data with advertisers.
4. Legal basis & purpose
- Contact inquiries — Art. 6(1)(b) GDPR (pre-contractual steps at your request) or Art. 6(1)(f) (legitimate interest in responding to business inquiries).
- Anti-spam & security — Art. 6(1)(f) GDPR (legitimate interest in protecting the site from abuse).
- Accounting records (once an engagement starts) — Art. 6(1)(c) GDPR (legal obligations under Slovak accounting and tax law).
5. Retention
- Inquiries that do not lead to an engagement: up to 12 months, then deleted.
- Inquiries that lead to an engagement: retained for the duration of the contractual relationship and the statutory retention period for invoices and accounting records (10 years under Slovak law).
- Access logs: as set by the hosting provider, typically 30–90 days.
6. Cookies and similar technologies
This site sets no cookies. There are no analytics cookies, tracking pixels, advertising SDKs, session-replay scripts, consent management platforms, or third-party widgets that deposit cookies. The contact form submits over a first-party endpoint on the same origin; no session cookies are written. Fonts are self-hosted (no Google Fonts CDN). Images are served from our own origin.
Because no non-essential cookies are set, no cookie banner or Consent Management Platform is required under the ePrivacy Directive, Slovak Act 452/2021 §109, or EDPB guidance. The scanner finding you may see on our public ZulienScore report flags the absence of a CMP; that check is calibrated for e-commerce sites that set tracking cookies — it does not apply to a site that sets none. We document the rationale rather than installing theatre.
The only browser storage we use is a single localStorage key — theme — to remember your light/dark preference. That value never leaves your browser and is not personal data.
If you would like to verify this claim, open your browser's developer tools, load any page on this site, and inspect Application → Cookies. You will see an empty list.
7. Third parties
We use a small number of third-party services, all under written contract or their standard data-processing terms:
- o2switch (France) — web hosting and email. Processes data within the EU.
- Fonts — Inter and JetBrains Mono served directly from our own server. No third-party font CDN is called.
We do not transfer personal data outside the EU/EEA for any purpose that requires a specific transfer mechanism.
8. Your rights
Under the GDPR you have the right to:
- request access to the personal data we hold about you;
- request rectification of inaccurate data;
- request erasure (“right to be forgotten”) within the limits of our statutory retention obligations;
- restrict or object to processing based on legitimate interest;
- data portability for data you provided;
- withdraw consent at any time, where processing is based on consent;
- lodge a complaint with the Slovak supervisory authority — Office for Personal Data Protection (ÚOOÚ).
To exercise any of these rights, email us at info@inger.sk. We respond within 30 days.
9. Security
The site is served over HTTPS with HSTS. Standard security headers (Content-Security-Policy, X-Frame-Options, Referrer-Policy, Permissions-Policy) are set on all responses. The contact form is protected by rate-limiting, a rotating honeypot, a timing token, and behavioural checks. Production data for client engagements is handled under the security controls agreed in the respective contract.
10. Changes
We may update this notice to reflect changes in our practice or applicable law. Material changes will be dated at the top of the page. Historical versions are available on request.