Personal Data Protection & GDPR

Privacy Policy (GDPR)

Comprehensive guidance on personal data handling and safeguarding on Crowdiz pursuant to Regulation (EU) 2016/679 (GDPR) and Act No. 18/2018 Coll.

Last Updated: September 2026
Effective Date: September 1, 2026
Governing Law & Jurisdiction: Slovak Republic & European Union (GDPR)
Estimated Reading Time: 6 min read

Key Highlights

Core legal points and terms summarized clearly for swift orientation

Data Minimization

We process only the strictly necessary technical server telemetry and details voluntarily submitted by you during contact or partner inquiries.

Full GDPR Compliance

All procedures adhere strictly to Regulation (EU) 2016/679 (GDPR) and Slovak Act No. 18/2018 Coll. on Personal Data Protection.

Comprehensive Data Rights

You possess guaranteed rights of access, rectification, erasure ('right to be forgotten'), processing restriction, and portability.

Supervisory Authority in Slovakia

You maintain the statutory right to file a complaint with the Office for Personal Data Protection of the Slovak Republic in Bratislava.

01

1. Data Controller Identification and Contact Details

The Data Controller pursuant to Article 4(7) of Regulation (EU) 2016/679 (GDPR) and Act No. 18/2018 Coll. is: • Name / Controller: Milan – CROWDIZ (independent operator of the analytical portal crowdiz.com) • Domicile: Bratislava, Slovak Republic • Email for privacy inquiries: info@crowdiz.com The Controller is not mandated to designate a Data Protection Officer (DPO). Inquiries and requests are addressed directly by the operator via the contact email specified above.
02

2. Categories of Personal Data Processed

The nature of personal data collected depends on your interaction with Crowdiz: 1. Website Visitors: • Server Log Telemetry: IP address, date and time of request, browser version, operating system, referrer URL, and diagnostic response codes. • Cookie Information: Anonymized session IDs and aggregated navigation metrics (solely if analytics consent was provided). 2. Individuals Contacting Us: • Contact Data: Name/handle, email address, and correspondence content sent to our mailbox. 3. Platform Partners & Administrators: • Verification & Authentication: Email credentials, authentication tokens, contact representative details for managing partner platform profiles.
03

3. Purposes and Legal Grounds for Processing (Art. 6 GDPR)

Personal records are processed exclusively under established lawful grounds: • Technical Operation & Cyber Defense: Legal Basis: Legitimate interest under Art. 6(1)(f) GDPR for guaranteeing uptime, fault isolation, and defending against DDoS or automated exploit attempts. • Inquiry Handling & User Communications: Legal Basis: Legitimate interest in responding to user questions under Art. 6(1)(f) GDPR, or pre-contractual measures at your request under Art. 6(1)(b) GDPR. • Traffic Analytics (Google Analytics): Legal Basis: Your prior freely given consent under Art. 6(1)(a) GDPR supplied through our cookie banner. • Statutory Compliance: Legal Basis: Compliance with legal obligations under Art. 6(1)(c) GDPR when required by applicable statutory bodies or courts.
04

4. Data Recipients and Service Processors

We never sell, lease, or distribute your personal records. We cooperate with verified technical processors under data processing agreements: • Google Cloud / Firebase (Google Ireland Limited): Hosting architecture, Firestore database, and authentication. • Google Analytics (Google Ireland Limited): Aggregated anonymized traffic telemetry. • Email and DNS Providers: Ensuring reliable message delivery and infrastructure integrity. • Law Enforcement & Courts: Solely when compelled under valid legal warrants.
05

5. International Data Transfers Outside the EEA

Our primary storage infrastructure resides in European Union data centers. In instances involving Google LLC technical services, data may be transferred to the US under the EU-U.S. Data Privacy Framework (DPF) adequacy decision and Standard Contractual Clauses (SCCs).
06

6. Retention Schedules

Personal data is preserved only as long as necessary to fulfill designated objectives: • Server Security Logs: Kept for 30 to 90 days, then overwritten. • Email Inquiries: Kept for the duration of correspondence and up to 12 months thereafter. • Analytics Records: Kept for up to 14 months in anonymized format. • Administrative Accounts: Kept for the duration of active management duties.
07

7. Your Rights Under the GDPR

As a data subject, Articles 15 through 22 of the GDPR confer extensive rights. Review the table below for a structured breakdown and instructions on exercising them.
Data Subject RightGDPR ArticleSummary & ScopeHow to Exercise
Right of AccessArt. 15 GDPRRight to obtain confirmation on whether your data is processed, alongside a copy of the data.Email info@crowdiz.com
Right to RectificationArt. 16 GDPRRight to prompt correction of inaccurate or incomplete personal records.Email info@crowdiz.com
Right to Erasure (To be Forgotten)Art. 17 GDPRRight to permanent deletion of personal records when original purposes no longer apply.Email info@crowdiz.com
Right to RestrictionArt. 18 GDPRRight to request a hold on processing while data accuracy or objections are verified.Email info@crowdiz.com
Right to Data PortabilityArt. 20 GDPRRight to obtain your data in a structured, commonly used, machine-readable format.Email info@crowdiz.com
Right to ObjectArt. 21 GDPRRight to object at any time to data processing carried out under legitimate interest grounds.Email info@crowdiz.com
Right to Withdraw ConsentArt. 7(3) GDPRRight to revoke previously granted voluntary consent without affecting prior lawful processing.Via cookie banner or email
08

8. Security Architecture and Safeguards

We enforce rigorous administrative and technical safeguards to secure personal data against unauthorized disclosure or loss: • End-to-end 256-bit TLS/HTTPS encryption across all portal routes. • Secured credential hashing, strong administrative access controls, and multi-factor authentication. • Continuous dependency auditing to mitigate known software vulnerabilities.
09

9. Automated Decision-Making & Profiling

Crowdiz performs no automated individual decision-making or profiling under Article 22 GDPR producing legal or similarly substantial effects.
10

10. Right to Lodge a Complaint with Supervisory Authorities

If you believe your personal data processing violates the GDPR or national legislation, you have the right to lodge a complaint with the competent supervisory body: • Office for Personal Data Protection of the Slovak Republic • Address: Hraničná 12, 820 07 Bratislava 27, Slovak Republic • Website: https://dataprotection.gov.sk • Email: statny.dozor@pdp.gov.sk
Have questions regarding our legal terms or privacy?

We believe in full transparency and respect your rights. If you have any inquiries regarding personal data processing, cookies, or terms of use, please reach out to us. info@crowdiz.com.

    Privacy Policy (GDPR) | crowdiz