Skip to content
Renovation and construction
ServicesApproachAboutContact
Start an enquiry
ServicesApproachAboutContact
+359 87 6751415mariyan.makkysro@gmail.com
Data protection

Privacy notice

Information under Article 13 of Regulation (EU) 2016/679 (GDPR) and Act No. 18/2018 Coll. on personal data protection.

Last updated: 22 September 2026
ControllerWhat is processedWhere the data comes fromPurposes and legal basesHow long data is keptRecipients and processorsTransfers outside the EEAHow data is protectedYour rightsHow to exercise your rightsRight to lodge a complaintCookies and local storageIs providing data requiredAutomated decision-makingChildren's dataChanges to this notice

Controller

The controller of your personal data is MAKKY s. r. o., Budatínska 16, 851 06 Bratislava – mestská časť Petržalka, Slovak Republic, Company ID (IČO) 54 494 141, registered with Mestský súd Bratislava III, Section Sro, File no. 160811/B.

For any question about this notice, or to exercise a right, write to mariyan.makkysro@gmail.com or call +359 87 6751415. The company has not appointed a data protection officer, because it is not required to do so under Article 37 of the GDPR.

What is processed

Visiting the website

This website has no contact form, no analytics, no advertising technology and no social media embeds. It collects nothing from you directly. To deliver and protect the pages, the hosting provider processes standard server data: the IP address of the request, the date and time, the page requested, the referring address where your browser sends one, the browser and operating system identification, and security events such as blocked requests.

Contacting the company

If you write or call, the company processes what you choose to provide: your name, email address, telephone number, the address or description of the property, photographs you attach, the work you are considering, your timing, and the content of the correspondence itself.

Carrying out an agreed project

If a project is agreed, the company additionally processes the data needed to perform and invoice it: the site address and access arrangements, the contractual and billing details, and the records that accounting and tax law require to be kept.

No special categories of personal data under Article 9 of the GDPR are sought, and none should be sent in an enquiry.

Where the data comes from

All personal data comes from you, in your message or call, or arises from the technical delivery of the pages you request. The company does not buy contact data, does not collect it from directories or social networks, and does not enrich it from other sources.

Purposes and legal bases

  • Delivering and securing the website. Legitimate interest in operating a functioning and protected website — Article 6(1)(f) GDPR.
  • Answering your enquiry and preparing a possible contract. Steps taken at your request before entering into a contract — Article 6(1)(b) GDPR.
  • Performing an agreed project, including scheduling, site access and invoicing. Performance of a contract — Article 6(1)(b) GDPR.
  • Meeting accounting, tax and archiving obligations. Compliance with a legal obligation — Article 6(1)(c) GDPR, in particular Act No. 431/2002 Coll. on accounting.
  • Establishing, exercising or defending legal claims. Legitimate interest in protecting the company's rights — Article 6(1)(f) GDPR.

The company does not use your contact details for marketing messages, and does not sell or rent personal data to anyone.

How long data is kept

  • Enquiries that do not lead to a contract: up to one year from the last message, then deleted.
  • Correspondence and documents connected to an agreed project: for the duration of the project and then for the statutory limitation period, normally up to four years after completion.
  • Accounting and tax records: ten years from the end of the accounting period to which they relate, under Act No. 431/2002 Coll.
  • Server and security logs held by the hosting provider: the short retention periods set by that provider, typically measured in days.

Where a legal claim is pending, the data concerned is kept until that matter is closed, even if a period above has expired.

Recipients and processors

Personal data is not disclosed to anyone except where it is necessary to operate the business, or where the law requires it. The categories of recipients are:

  • Website hosting and content delivery. The website is served as static files by Cloudflare, Inc. through Cloudflare Pages, which also provides the network protection described above.
  • Email. Messages sent to the address above are received through Google's Gmail service, operated for users in the European Economic Area by Google Ireland Limited.
  • Telephone. The mobile network operator carrying the call.
  • Accounting, tax and legal advisers engaged by the company and bound by confidentiality.
  • Subcontractors engaged for a specific agreed project, and only with the data they need to carry out their part of it.
  • Public authorities, where disclosure is required by law, such as tax or supervisory authorities.

Transfers outside the EEA

The providers named above belong to groups established in the United States and may process data outside the European Economic Area. Such transfers take place on the basis of the European Commission's adequacy decision for the EU–US Data Privacy Framework where the recipient is certified under it, or otherwise on the basis of the Commission's standard contractual clauses together with the supplementary measures applied by those providers. A copy of the safeguards can be requested at the contact address above.

How data is protected

The website is served over HTTPS only, with transport security and a restrictive content security policy set at the hosting layer, and it loads no third-party scripts, fonts or embeds. Enquiries stay in the company's own email account, and access to enquiry and project records is limited to the managing director and to advisers and subcontractors bound by confidentiality. These are the technical and organisational measures appropriate to the scale of this processing under Article 32 of the GDPR. No measure can guarantee that an email cannot be read in transit, so please do not send documents by email that you would not want a third party to see.

Your rights

Under the GDPR you have the right to:

  • be told whether your data is processed and to obtain a copy of it (Article 15);
  • have inaccurate data corrected, or incomplete data completed (Article 16);
  • have data erased where one of the grounds in Article 17 applies;
  • have processing restricted in the cases listed in Article 18 (Article 19 also requires the company to inform recipients of any correction, erasure or restriction);
  • receive the data you provided in a structured, machine-readable format and have it transmitted to another controller, where the processing is based on consent or contract and is carried out by automated means (Article 20);
  • object at any time, on grounds relating to your particular situation, to processing based on legitimate interest (Article 21);
  • withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before the withdrawal;
  • lodge a complaint with a supervisory authority (Article 77), as set out below.

How to exercise your rights

Write to mariyan.makkysro@gmail.com, or to the registered office address above, and say which right you wish to exercise. No particular form is required. If there is genuine doubt about who is making the request, the company may ask for further information to confirm your identity, and will ask only for what is needed for that.

Requests are answered without undue delay and within one month of receipt. That period may be extended by two further months where a request is complex, in which case you will be told within the first month and given the reason. Exercising these rights is free of charge, unless a request is manifestly unfounded or excessive.

Right to lodge a complaint

If you believe your data is processed unlawfully, you may lodge a complaint with the Slovak supervisory authority: Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava 27, Slovak Republic, dataprotection.gov.sk (opens in a new tab). You may also complain to the supervisory authority of the EU member state where you live or work, or where the alleged infringement took place. This does not affect your right to a judicial remedy.

Cookies and local storage

This website sets no cookies of its own, uses no local or session storage, and runs no tracking or profiling scripts, so no consent banner is shown. The full position is set out in the cookie notice.

Is providing data required

Providing personal data is neither a statutory nor a contractual requirement, and you are under no obligation to provide it. Without contact details and a description of the space, however, an enquiry cannot be answered and a project cannot be prepared or carried out.

Automated decision-making

No decision affecting you is taken by automated means, and no profiling within the meaning of Article 22 of the GDPR is carried out.

Children's data

This website is not directed at children, and the company does not knowingly process the data of anyone under 16 through it. If such data reaches the company, it is deleted once that is established.

Changes to this notice

This notice is reviewed whenever the way the company handles enquiries changes, and whenever a new provider or technology is introduced. The date of the current version is shown beside the contents list.

Renovation and construction work for residential and commercial spaces, carried out from Bratislava.

Contact+359 87 6751415mariyan.makkysro@gmail.com
Registered officeBudatínska 16
851 06 Bratislava, Slovakia (opens in a new tab)
© 2026 MAKKY s. r. o. · IČO 54 494 141
Legal noticePrivacy noticeCookies