Privacy Policy


Last updated: March 2026

1. Data Controller

The data controller responsible for your personal data is:

BazaDomu
Slovak Business ID (IČO): 56125496
E-mail: [email protected]
Website: bazadomu.com

2. Definitions
  • Website - bazadomu.com
  • Visitor - a person who uses the site without being logged in.
  • User - a person who has registered and logged in to the site.
  • Personal data - any information that identifies or can identify you, including: IP address, name, e-mail address, phone number, cookie identifiers, and session tokens.
  • GDPR - the General Data Protection Regulation (EU) 2016/679.
3. Data We Collect, Purposes, and Legal Basis

We collect and process personal data only for specific, explicit purposes. The table below lists each data type, why we use it, and the legal basis under GDPR Art. 6.

Data Purpose Legal basis Retention
E-mail address Account registration, authentication, and service-related notifications (e.g. password reset, account security alerts) Performance of a contract (Art. 6(1)(b)) Until account deletion, plus up to 30 days for deletion processing
First and last name Identifying you as an author of content you publish on the site Performance of a contract (Art. 6(1)(b)) Until account deletion; may be retained as part of published content - see Section 7
Phone number Optional: identity verification and account security (two-factor authentication or phone-based login) Consent (Art. 6(1)(a)) - provided voluntarily; may be withdrawn at any time Until removed from your profile or account deletion
IP address Security monitoring, detection of unauthorised access and abuse Legitimate interests (Art. 6(1)(f)) - protecting the site and its users Up to 12 months in server logs
Browser language (User-Agent) Displaying the site in your preferred language Legitimate interests (Art. 6(1)(f)) - improving user experience Not stored; processed on each request only
Session cookie (PHPSESSID) Maintaining your login session while you are on the site Strictly necessary - no consent required under ePrivacy Directive Until browser session ends or logout
Authentication token (cookie) Keeping you logged in across sessions ("remember me") Performance of a contract (Art. 6(1)(b)) Up to 30 days, or until logout
Cookie consent record Storing your acknowledgement of this policy to avoid repeated prompts Legitimate interests (Art. 6(1)(f)) Up to 12 months

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.

4. Social Login (Google, Facebook)

When you log in via Google or Facebook, the respective service shares with us only the minimum data you authorise: your name and e-mail address. We do not receive or store any other data from these providers. The provider will ask for your explicit permission before sharing anything.

These providers process your data under their own privacy policies and may transfer data to servers outside the European Economic Area. Such transfers are subject to the Standard Contractual Clauses approved by the European Commission, ensuring an adequate level of protection.

5. Data Processors

We use the following trusted third parties to operate the service. Each acts as a data processor under a written agreement:

  • Hetzner Online GmbH (Germany) - server hosting. Data is stored on servers located in the EU. Hetzner Privacy Policy.

No data is sold or shared with third parties for marketing purposes.

6. Your Rights under GDPR

You have the following rights regarding your personal data. To exercise any of them, contact us at [email protected]. We will respond within 30 days.

  • Right of access (Art. 15) - you can request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16) - you can ask us to correct inaccurate or incomplete data.
  • Right to erasure (Art. 17) - you can ask us to delete your personal data. See our Data Deletion Policy for details.
  • Right to restriction of processing (Art. 18) - you can ask us to pause processing of your data while a dispute is resolved.
  • Right to data portability (Art. 20) - you can ask us to provide your data in a structured, machine-readable format.
  • Right to object (Art. 21) - you can object to processing based on legitimate interests. We will stop unless we can demonstrate compelling grounds.
  • Right to withdraw consent - where processing is based on your consent (e.g. phone number), you can withdraw it at any time without affecting prior processing.
7. Data Retention after Account Deletion

When you delete your account, we delete your personal data within 30 calendar days. See our Data Deletion Policy for a full description of what is deleted and what may be retained.

8. Right to Complain to a Supervisory Authority

If you believe we are processing your data unlawfully, you have the right to lodge a complaint with the data protection authority in your country of residence:

We encourage you to contact us first so we can address your concern directly.

9. Changes to This Policy

We may update this policy as the service evolves. For changes that affect how we use data collected on the basis of consent, we will notify you by e-mail before the change takes effect. For other changes, the updated policy will be published on this page. The date at the top of this page indicates when it was last revised.

10. Contact

For any questions about this privacy policy or your personal data, contact us at [email protected].