Legal information

PRIVACY POLICY – BILVAO s. r. o.

Valid and effective from 01.11.2025, updated 07.09.2026

This English text is a translation provided for convenience. Only the Slovak wording of this document is legally binding.

1. IDENTIFICATION OF THE CONTROLLER AND GENERAL INFORMATION

This Privacy Policy (hereinafter the “Policy”) provides information on the processing of your personal data by BILVAO s. r. o., with its registered office at Janka Jesenského 564/9, 957 01 Bánovce nad Bebravou, Company ID No.: 53 399 978, registered in the Commercial Register of the District Court Trenčín, Section: Sro, Insert No. 41118/R, which operated under the business name BJ accounting services s. r. o. until 28. 08. 2026 (hereinafter the “Controller”), which takes place on the Controller’s website at www.bilvao.com (hereinafter the “Website”), on the Controller’s social media profiles and in the course of the Controller’s business and commercial activities.

Information on personal data processing that takes place outside the Website or social media is documented by the Controller in the relevant internal policies and will be provided to you where relevant.

Through this Policy, the Controller provides you with information about why and how your personal data are processed, how long the Controller retains them, your rights in connection with the processing of your personal data, and other relevant information concerning the processing of your personal data. Through this Policy, the Controller fulfils its duty to provide information to all data subjects, both where the Controller has obtained personal data directly from you as the data subject and where it has obtained your personal data from another source.

The Controller processes your personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter the “Regulation”), the applicable laws of the Slovak Republic, in particular Act No. 18/2018 Coll. on Personal Data Protection and on Amendments to Certain Acts (hereinafter the “Act”), and other personal data protection legislation (the Regulation, the Act and the other personal data protection legislation hereinafter collectively also referred to as the “Data Protection Laws”).

You may contact the Controller in matters concerning the processing and protection of personal data at BILVAO s. r. o., Janka Jesenského 564/9, 957 01 Bánovce nad Bebravou, or by email at info@bilvao.com.

2. INFORMATION ON PROCESSING OPERATIONS – LEGAL BASES, PURPOSES OF PROCESSING, CATEGORIES OF PERSONAL DATA AND RETENTION PERIODS

The Controller processes your personal data only for justified purposes, for a limited period and using the highest possible level of security. We process your personal data in accordance with the principle of lawfulness, meaning only where an appropriate legal basis for the processing exists under Article 6(1) of the Regulation, specifically on the following legal bases:

IN CONNECTION WITH THE OPERATION OF THE CONTROLLER’S WEBSITE:

IN CONNECTION WITH THE CONTROLLER’S BUSINESS ACTIVITIES:

IN RELATION TO JOB APPLICANTS:

The Controller processes only personal data that are necessary for the relevant processing operation (purpose of processing), always in accordance with the principle of data minimisation, so that we can meet contractual and legal requirements or process only personal data for which we have a legitimate interest, and only to the extent necessary to fulfil the specified purpose of processing. This means that we do not request personal data from you that are not necessary for the specific purpose of processing.

The Controller always retains personal data in accordance with the principle of storage limitation. This means that personal data are processed only for as long as it is necessary to retain them. Once that period has expired, the Controller will erase the personal data unless the law provides otherwise. The Controller has determined the retention period for your personal data in accordance with the applicable legislation, as set out above in the table of purposes.

3. BILVAO S. R. O. AS PROCESSOR

In certain cases, BILVAO s. r. o. processes your personal data in the capacity of a processor within the meaning of Article 4(8) of the Regulation. BILVAO s. r. o. processes your personal data as processor when providing the following services:

  • bookkeeping and tax records,

  • payroll and human resources administration and related administrative services,

  • including professional advisory services in the fields of accounting, tax, human resources, and the processing of wages and remuneration; and

  • consultations and analyses as part of pre-contractual cooperation for the purpose of assessing the possibility of entering into an Agreement for the Provision of Services and Bookkeeping.

Where BILVAO s. r. o. acts as processor on behalf of its business partner, that business partner determines the purposes and means of processing personal data as controller. In such a case, we will inform you who the controller of your personal data is.

4. SOURCE OF PERSONAL DATA

We obtain your personal data directly from you as the data subject where you provide them to us (when you contact us through the Website, engage in business communications, enter into a contractual relationship with the Controller or apply for a job). As a service provider, we also hold personal data relating to employees, contractual partners and other persons that our clients provide to us. In such cases, we act as processor and the controller of the personal data (the client/contractual partner) fulfils its obligations under the Regulation directly towards the data subjects.

If, in certain cases, you did not provide us with your personal data where we act as Controller, we would be unable, as Controller, to provide you with a service, enter into a contract with you, respond to your message, include you among job applicants, etc.

5. TO WHOM DOES THE CONTROLLER DISCLOSE YOUR PERSONAL DATA?

In certain cases, the Controller is required to disclose your personal data to public authorities authorised to process them, such as courts, law-enforcement authorities and authorities supervising the operation of electronic commerce (for example, the Slovak Trade Inspection).

The Controller also discloses your personal data to its processors, i.e. external entities that process your personal data on behalf of the Controller. Processors process personal data under an agreement concluded with the Controller, in which they have undertaken to implement appropriate technical and organisational measures to ensure the secure processing of your personal data. The Controller’s processors include, for example:

  • a processor providing IT services and the management and development of internal systems,

  • processors providing hosting and email-hosting services,

  • a processor providing marketing and newsletter distribution services,

  • a processor providing satisfaction-survey services and contacting prospective clients.

Recipients of your personal data also include Google Ireland Limited, which provides analytics and marketing services through cookies placed on your device by the Controller’s Website.

6. TRANSFERS TO THIRD COUNTRIES AND INTERNATIONAL ORGANISATIONS

In certain cases, your personal data may be transferred to a third country, namely the USA:

  • Meta Inc. and LinkedIn Corporation, for example where you contact the Controller by sending a message through the relevant social network.

The transfer of your personal data is safeguarded by appropriate measures for transfers of personal data to third countries in accordance with the Data Protection Laws, in particular by using standard contractual clauses forming part of the terms of use of the services referred to above, together with supplementary transfer safeguards adopted by the providers of those services. A transfer may occur only in exceptional circumstances and on the basis of the applicable laws in force in the relevant third country (USA) that apply to those service providers (FISA).

7. SOCIAL MEDIA, PROFILING AND AUTOMATED DECISION-MAKING

To support marketing and advertising, the Controller’s Website contains links to various social networks, such as Facebook. The Controller hereby informs you that, once you click a plug-in on the Website and proceed to a social network, the privacy policy of the operator of that social network will apply, except where you contact the Controller through a message on the social network or consent to the publication of your photograph on the Controller’s social media profiles (in which case the processing of your personal data is also governed by this Policy and your personal data are processed by the Controller in accordance with the information set out above).

Further information on the processing of your personal data by social network operators is available at the following links: (i) Facebook, (ii) Instagram and (iii) LinkedIn.

The Controller does not use profiling when processing your personal data and does not process personal data by any form of automated individual decision-making involving the evaluation of personal aspects relating to you.

8. SECURITY OF PERSONAL DATA PROCESSING

In connection with securing personal data, the Controller has adopted relevant internal documentation setting out in greater detail the appropriate security measures implemented by the Controller to secure your personal data (for example, deployment of an SSL certificate on the Website, secure access management, etc.).

The security measures adopted comply with information security standards. We also take measures to secure personal data at organisational and personnel levels, for which purpose we have adopted internal processes and procedures.

9. WHAT RIGHTS DO YOU HAVE IN CONNECTION WITH THE PROCESSING OF PERSONAL DATA?

In connection with the processing of your personal data, you have the following rights as a data subject:

You may exercise the rights set out in the table above against the Controller using the contact details provided at the beginning of this document. The Controller will respond to the exercise of your rights free of charge. In the case of repeated, manifestly unfounded or excessive requests to exercise your rights, the Controller may charge a reasonable fee for providing the information. The Controller will respond within 1 month from the date on which you exercise your rights. In certain cases, the Controller may extend this period where warranted by the number or complexity of data-subject requests, but by no more than 2 months. The Controller will always inform you of any extension.

10. VALIDITY

This Policy is valid and effective from 01.11.2025 and was updated on 07.09.2026. As the information on personal data processing contained in this Policy may need to be updated in the future, the Controller may update this Policy at any time. In such a case, however, the Controller will inform you accordingly in an appropriate manner.