Privacy Policy
How AdBird processes personal data on the public website.
Data Controller
- The public website is operated by AdBird.sk s.r.o., Mlynská 1059/12, 02901 Námestovo, Slovak Republic.
- Company ID: 47812699. VAT ID: SK2024115335.
- For privacy questions or requests, contact us at obchod@adbird.sk.
- Version 1.0. Effective and last updated: 1 July 2026.
Data We Process
- When you browse public pages, the hosting/runtime may process technical request data such as IP address, request URL, user agent, timestamp and security logs.
- When you send the public contact form, we process your email address, message text, optional technical metadata needed to protect the form and the fact that you acknowledged the Privacy Policy.
- When you use the public client-zone login, we process your email address, assigned client access, OTP challenge records, verification attempts, session data and request/security metadata needed to protect the login.
- When you allow analytics cookies, Hotjar / Contentsquare may process analytics cookies, session behavior data, device/browser data and similar browser storage for public website usability analytics.
Purposes and Legal Bases
- Public website operation, routing, localization and security are processed on our legitimate interest in operating a secure public website.
- Contact inquiries are processed to handle your inquiry and reply to you. Depending on the context, this is pre-contractual communication or our legitimate interest in business communication.
- Client-zone OTP/login data is processed to verify access, create a session and protect restricted client material. Depending on the context, this is contract performance, access control or our legitimate interest in securing the service.
- Resend is used only to send public contact and OTP transactional emails server-side.
- Hotjar / Contentsquare analytics are used only after your analytics consent.
Processors and Recipients
- We disclose personal data only where needed to operate the public website, handle public inquiries, send transactional emails, secure client-zone login, provide hosting/database infrastructure or comply with law.
- Authorized AdBird personnel may access public inquiries and client-zone access information when needed to respond, maintain access or secure the website.
- Public-surface processors and recipients are listed below.
| Provider / recipient | Public-surface role | Typical data |
|---|---|---|
| Resend / Plus Five Five, Inc. | Transactional email delivery for contact messages and OTP codes | Recipient/sender email, email content, delivery metadata |
| Vercel Inc. | Hosting, runtime, CDN, deployment and technical/security logs | IP address, request URL, headers, user agent, logs and public website assets |
| Neon / Databricks | Postgres database used by public client-zone login, OTP challenges, session access records and rate limits | Email, client access records, OTP challenge metadata, hashed rate-limit keys |
| Hotjar / Contentsquare | Optional public website analytics after consent | Analytics cookies/storage, session behavior, device/browser metadata and page interaction data |
| AdBird public mailbox provider | Receiving public contact inquiries sent through Resend | Email address and message content submitted through the contact form |
| Public authorities or professional advisers | Legal compliance, rights requests or claims where required | Only data necessary for the specific legal purpose |
Retention
- We keep public-surface personal data only for as long as reasonably necessary for the purpose described below, unless law requires or permits a longer period.
- Where the current implementation does not include an automatic cleanup job, the retention period is stated as a practical operational retention criterion rather than a promise of automated deletion.
| Data category | Retention |
|---|---|
| Public contact emails and messages | For as long as reasonably necessary to handle the inquiry, maintain related business context and meet legal obligations. |
| Resend delivery metadata | According to Resend service retention and account settings, for as long as needed to deliver, troubleshoot and evidence transactional email delivery. |
| OTP challenges and client-zone login records | OTP cookies expire after about 10 minutes. Database challenge records are retained for as long as reasonably necessary for security, abuse prevention, audit and troubleshooting. |
| Client-zone session cookies | Public client sessions expire after about 24 hours. Internal/staff sessions are outside this public policy scope. |
| Rate-limit records | Usually expire according to the active rate-limit window and are cleaned during rate-limit processing where implemented. |
| Analytics consent preference | Stored in the browser for about 180 days. |
| Hotjar / Contentsquare analytics data | According to Hotjar / Contentsquare account settings and product retention, while analytics consent remains valid or until withdrawn where browser-side removal is available. |
| Server, CDN and security logs | For as long as reasonably necessary to operate, secure, debug and evidence the public website and related public APIs. |
Your Rights
- To the extent provided by applicable law, you may request access, correction, deletion, restriction, portability or object to processing.
- Where processing is based on consent, you may withdraw consent at any time. Withdrawing analytics consent does not affect processing that happened before withdrawal.
- You can exercise your rights by email at obchod@adbird.sk.
Complaint Authority
- You may lodge a complaint with the Office for Personal Data Protection of the Slovak Republic if you believe that personal data is processed contrary to data protection rules.
- You may also contact the supervisory authority in your EU Member State where applicable.
International Transfers
- Some public-surface providers are based in, or may use subprocessors in, countries outside the European Economic Area, including the United States.
- Where needed, we rely on appropriate safeguards such as EU Standard Contractual Clauses, Data Privacy Framework participation where applicable, provider data processing agreements and supplementary security measures.
Automated Decision-Making and Children
- The public website does not use automated decision-making with legal or similarly significant effects.
- Hotjar / Contentsquare analytics are used for aggregate usability insight, not to identify individual visitors for decisions.
- The public website is not directed to children. If a child contacts us through the public form, we will process only what is necessary to handle or delete the inquiry.
Hotjar / Contentsquare Analytics
- Hotjar / Contentsquare loads only on eligible public pages and only after analytics consent is accepted.
- We do not use Hotjar Identify, custom user IDs, user attributes or form metadata.
- Sensitive contact-form areas are marked for Hotjar suppression.
- When analytics are declined or withdrawn, the website removes known _hj cookies and _hj local/session storage entries that are available to browser-side JavaScript and reloads the page if Hotjar was already loaded.
Cookies and Browser Storage
- The public website uses necessary cookies for client-zone OTP verification, client-zone sessions and storing your analytics choice.
- The website uses URL-based localization and does not set a separate application language cookie.
- Optional analytics cookies and similar storage are described in the Cookie Policy.
Security and Contact
- We use technical and organizational measures intended to protect the public website, public APIs, contact messages and client-zone login flow.
- Public API protections include same-origin checks, rate limits, input validation, generic error responses, signed HttpOnly client-zone cookies and no-store/noindex headers for private responses.
- For privacy or security questions, contact obchod@adbird.sk.