Skip to content

All services

Services overview

GDPR

Last changed September 25, 2026

Privacy policy

The site collects only what we need to answer you and, with your consent, aggregate visitor statistics. It uses no advertising cookies.

Controller

Who is responsible for your data

Your personal data is processed by Matej Hlinka - eMHa. For anything about it, contact us directly.

Trading name
Matej Hlinka - eMHa
Company ID (IČO)
45499586
Place of business
Mlynská ulica 327/31, 976 11 Selce
Phone
0902 481 461

Processing

What, why and for how long

01

An enquiry through the form

What data
Your name, e-mail, phone and message, and if you choose one, the optional answer to how you heard about us. The enquiry carries the language of the page, the page your visit began on, the campaign name if the link had one, and the domain of the site you came from — not its full address, and not what you searched for.
What for
To answer you and prepare an offer. The first page tells us which links to the site work.
Legal basis
Steps taken at your request before entering into a contract, Art. 6(1)⁠(b) GDPR. The first page: our legitimate interest in knowing where enquiries come from, Art. 6(1)⁠(f).
How long
The enquiry arrives by e-mail in the firm's mailbox; the site does not store it. It stays in the mailbox while we deal with it. If it becomes a job, the data the contract and the invoice need is kept for as long as accounting and tax law require.
Required
Your name and e-mail are, or we cannot answer you. Your phone number is not.

02

A phone call or an e-mail

What data
What you tell us or write, usually your name, a contact and a description of the work.
What for
To handle your request, agree a date and do the work.
Legal basis
Steps before entering into a contract and performing it, Art. 6(1)⁠(b) GDPR.
How long
While we deal with your request. The data the contract and the invoice need for as long as accounting and tax law require.

03

Cookies and the session

What data
Two cookies: emha-elektro-session (the session) and XSRF-TOKEN (protects the form against forged requests). The session on the server holds the form's security key, the first page of your visit and, after a mistake in the form, what you had filled in, so you need not type it again.
What for
So that the form works and cannot be abused.
Legal basis
These cookies are strictly necessary and need no consent (Art. 5(3) of Directive 2002/58/EC and Slovak Act No. 452/2021 on electronic communications). The data in the session: our legitimate interest, Art. 6(1)⁠(f) GDPR.
How long
120 minutes after the last page you loaded; then the cookies and the session expire.

04

Server logs and protecting the site

What data
For every page shown, the server records the IP address, the time, the address of the page and what the browser sends, such as its name. When the form is sent, the IP address is used for a minute to limit the number of attempts.
What for
The security and running of the site: to spot an attack or a fault.
Legal basis
Our legitimate interest in the security of the site, Art. 6(1)⁠(f) GDPR.
How long
At most 15 days, then the records are deleted.

05

Visitor totals

What data
We also count visits in aggregate: how many people came to which page and from where (for example from a Google search or from a link tagged with a campaign), and how many of them wrote to us.
What for
To know what brings us customers.
Legal basis
It is not personal data: we count it on our own server, with no cookies and without storing IP addresses or anything else by which a visitor could be recognised.
How long
We keep only daily totals, for 25 months.

06

Reviews from Google

What data
The author's name as Google shows it, the rating, the text and the date of a review of our business profile on Google.
What for
To show on the site what customers say about us. Only reviews we have approved are shown.
Legal basis
Our legitimate interest, Art. 6(1)⁠(f) GDPR. The review was published on Google by its author.
How long
Until we remove it. If you have deleted your review on Google or do not want it shown here, write to us and we will remove it.

07

A request for a review by e-mail

What data
The e-mail address you give us after a finished job, and your name if we note it. Also whether you opened the review link in the e-mail, when and how many times. We do not track whether you opened the e-mail itself.
What for
To send you one e-mail asking you to review our work on Google. We send no second one.
Legal basis
Our legitimate interest in feedback from our customers, Art. 6(1)⁠(f) GDPR. You can object, and we will delete your address at once.
How long
12 months, then we delete the address and the name. Only the number of requests sent and links opened remains.

08

Protecting the form from spam

What data
On the page with the form, Cloudflare Turnstile checks invisibly that a person is filling it in. To do so it processes the IP address, what the browser sends, such as its name, and a technical fingerprint of the connection. It does not see what you write in the form.
What for
To tell people from bots that send spam.
Legal basis
Our legitimate interest in protecting the form, Art. 6(1)⁠(f) GDPR. Cloudflare processes the data on our behalf and, to improve its bot detection, also for its own purpose.
How long
The site keeps none of it. How long Cloudflare keeps the data is set out in its Turnstile terms.

09

Consent to cookies

What data
Your choice in the cookie bar. The bar is run by Cookiebot, which stores the choice in a cookie and records it as proof of consent.
What for
To remember your choice and be able to show it was made.
Legal basis
The obligation to demonstrate consent, Art. 7(1) and Art. 6(1)⁠(c) GDPR.
How long
As Cookiebot is set up. You can change your choice at any time with the Privacy settings link in the footer.

10

Visitor statistics (Google Analytics)

What data
If you accept statistics cookies in the banner, we use Google Analytics 4. It shows us which pages visitors read, where they came from and whether they contacted us (for example by tapping the phone number).
What for
We only see the data in aggregate, we do not use it for advertising or to identify anyone, and Google signals are off.
Legal basis
Your consent (Art. 6(1)⁠(a) GDPR), which you can withdraw at any time via “Privacy settings” in the footer. Withdrawal does not affect processing before it.
How long
Event data is kept for 14 months. The _ga and _ga_* cookies last up to 2 years.

Recipients

Who else works with the data

We do not sell the data. Only these providers work with it.

Web server
the hosting provider the site runs on
E-mail
the e-mail provider that delivers the form's enquiries and runs the firm's mailboxes
Site administration
the contractor who runs the site and the server for us
Form protection
Cloudflare, Inc., USA
Cookie bar
Usercentrics A/S (Cookiebot), Denmark
Visitor statistics
the processor Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland

Apart from Cloudflare, all of them keep it in the European Union. Cloudflare is certified under the EU-U.S. Data Privacy Framework, on which the transfer to the United States rests. Data from the visitor statistics may be transferred to Google LLC in the USA, which participates in the same framework.

Cloudflare's Turnstile terms

The Facebook and YouTube links in the footer are plain links. Until you click one, those services know nothing about your visit.

Your rights

What you can ask for

Write to us or call. We answer within a month at the latest.

  • To know whether we hold data about you, and to get a copy.
  • To have wrong data corrected.
  • To have data deleted when we no longer need it or have no reason to hold it.
  • To restrict its processing while something is being checked.
  • To receive the data you gave us in a common machine-readable format.
  • To object to processing that rests on our legitimate interest, for example to your review being shown.
  • To withdraw consent you gave us. Processing before the withdrawal is not affected.
Phone
0902 481 461

If you think we handle your data wrongly, you can complain to the supervisory authority.

Supervisory authority
Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27
dataprotection.gov.sk

We make no automated decisions about you and build no profiles of you.

When the way we handle data changes, we update this page.