Privacy Policy

How AdBird processes personal data on the public website.

Data Controller

  • The public website is operated by AdBird.sk s.r.o., Mlynská 1059/12, 02901 Námestovo, Slovak Republic.
  • Company ID: 47812699. VAT ID: SK2024115335.
  • For privacy questions or requests, contact us at obchod@adbird.sk.
  • Version 1.0. Effective and last updated: 1 July 2026.

Data We Process

  • When you browse public pages, the hosting/runtime may process technical request data such as IP address, request URL, user agent, timestamp and security logs.
  • When you send the public contact form, we process your email address, message text, optional technical metadata needed to protect the form and the fact that you acknowledged the Privacy Policy.
  • When you use the public client-zone login, we process your email address, assigned client access, OTP challenge records, verification attempts, session data and request/security metadata needed to protect the login.
  • When you allow analytics cookies, Hotjar / Contentsquare may process analytics cookies, session behavior data, device/browser data and similar browser storage for public website usability analytics.

Purposes and Legal Bases

  • Public website operation, routing, localization and security are processed on our legitimate interest in operating a secure public website.
  • Contact inquiries are processed to handle your inquiry and reply to you. Depending on the context, this is pre-contractual communication or our legitimate interest in business communication.
  • Client-zone OTP/login data is processed to verify access, create a session and protect restricted client material. Depending on the context, this is contract performance, access control or our legitimate interest in securing the service.
  • Resend is used only to send public contact and OTP transactional emails server-side.
  • Hotjar / Contentsquare analytics are used only after your analytics consent.

Processors and Recipients

  • We disclose personal data only where needed to operate the public website, handle public inquiries, send transactional emails, secure client-zone login, provide hosting/database infrastructure or comply with law.
  • Authorized AdBird personnel may access public inquiries and client-zone access information when needed to respond, maintain access or secure the website.
  • Public-surface processors and recipients are listed below.
Provider / recipientPublic-surface roleTypical data
Resend / Plus Five Five, Inc.Transactional email delivery for contact messages and OTP codesRecipient/sender email, email content, delivery metadata
Vercel Inc.Hosting, runtime, CDN, deployment and technical/security logsIP address, request URL, headers, user agent, logs and public website assets
Neon / DatabricksPostgres database used by public client-zone login, OTP challenges, session access records and rate limitsEmail, client access records, OTP challenge metadata, hashed rate-limit keys
Hotjar / ContentsquareOptional public website analytics after consentAnalytics cookies/storage, session behavior, device/browser metadata and page interaction data
AdBird public mailbox providerReceiving public contact inquiries sent through ResendEmail address and message content submitted through the contact form
Public authorities or professional advisersLegal compliance, rights requests or claims where requiredOnly data necessary for the specific legal purpose

Retention

  • We keep public-surface personal data only for as long as reasonably necessary for the purpose described below, unless law requires or permits a longer period.
  • Where the current implementation does not include an automatic cleanup job, the retention period is stated as a practical operational retention criterion rather than a promise of automated deletion.
Data categoryRetention
Public contact emails and messagesFor as long as reasonably necessary to handle the inquiry, maintain related business context and meet legal obligations.
Resend delivery metadataAccording to Resend service retention and account settings, for as long as needed to deliver, troubleshoot and evidence transactional email delivery.
OTP challenges and client-zone login recordsOTP cookies expire after about 10 minutes. Database challenge records are retained for as long as reasonably necessary for security, abuse prevention, audit and troubleshooting.
Client-zone session cookiesPublic client sessions expire after about 24 hours. Internal/staff sessions are outside this public policy scope.
Rate-limit recordsUsually expire according to the active rate-limit window and are cleaned during rate-limit processing where implemented.
Analytics consent preferenceStored in the browser for about 180 days.
Hotjar / Contentsquare analytics dataAccording to Hotjar / Contentsquare account settings and product retention, while analytics consent remains valid or until withdrawn where browser-side removal is available.
Server, CDN and security logsFor as long as reasonably necessary to operate, secure, debug and evidence the public website and related public APIs.

Your Rights

  • To the extent provided by applicable law, you may request access, correction, deletion, restriction, portability or object to processing.
  • Where processing is based on consent, you may withdraw consent at any time. Withdrawing analytics consent does not affect processing that happened before withdrawal.
  • You can exercise your rights by email at obchod@adbird.sk.

Complaint Authority

  • You may lodge a complaint with the Office for Personal Data Protection of the Slovak Republic if you believe that personal data is processed contrary to data protection rules.
  • You may also contact the supervisory authority in your EU Member State where applicable.

International Transfers

  • Some public-surface providers are based in, or may use subprocessors in, countries outside the European Economic Area, including the United States.
  • Where needed, we rely on appropriate safeguards such as EU Standard Contractual Clauses, Data Privacy Framework participation where applicable, provider data processing agreements and supplementary security measures.

Automated Decision-Making and Children

  • The public website does not use automated decision-making with legal or similarly significant effects.
  • Hotjar / Contentsquare analytics are used for aggregate usability insight, not to identify individual visitors for decisions.
  • The public website is not directed to children. If a child contacts us through the public form, we will process only what is necessary to handle or delete the inquiry.

Hotjar / Contentsquare Analytics

  • Hotjar / Contentsquare loads only on eligible public pages and only after analytics consent is accepted.
  • We do not use Hotjar Identify, custom user IDs, user attributes or form metadata.
  • Sensitive contact-form areas are marked for Hotjar suppression.
  • When analytics are declined or withdrawn, the website removes known _hj cookies and _hj local/session storage entries that are available to browser-side JavaScript and reloads the page if Hotjar was already loaded.

Cookies and Browser Storage

  • The public website uses necessary cookies for client-zone OTP verification, client-zone sessions and storing your analytics choice.
  • The website uses URL-based localization and does not set a separate application language cookie.
  • Optional analytics cookies and similar storage are described in the Cookie Policy.

Security and Contact

  • We use technical and organizational measures intended to protect the public website, public APIs, contact messages and client-zone login flow.
  • Public API protections include same-origin checks, rate limits, input validation, generic error responses, signed HttpOnly client-zone cookies and no-store/noindex headers for private responses.
  • For privacy or security questions, contact obchod@adbird.sk.