Transparent information under the GDPR

Privacy Policy

This page explains how we process personal data when you visit merkle.sk or communicate with us through the contact form, by email, by telephone or through WhatsApp.

Last updated:

Graphic illustration of personal data protection and secure communication
0 external analytics or advertising tools
12 months for ordinary completed enquiries
0 analytics cookies or fingerprinting

1. Controller

The controller responsible for processing personal data is:

Merkle s. r. o.
Staré Grunty 7A
841 04 Bratislava
Slovakia
Company registration number – IČO
57 412 791
Telephone
+421 947 948 666

You may use the email address above to ask questions about the processing of personal data or to submit a request to exercise your rights.

2. Processing overview

We obtain personal data directly from you or automatically from your browser and device when you use the website.

Overview of purposes, data, legal bases and retention periods
Activity Data processed Purpose and legal basis Retention
Website visit IP address, time, requested URL, server status, volume of data transferred, referring domain and User-Agent, where available Website operation, security and internal measurement of website use in order to improve its content, structure and technical operation; legitimate interests under Article 6(1)(f) GDPR Raw logs according to the technical rotation and settings of the hosting environment; aggregated statistics may be retained for longer
Contact form, email and telephone Name, contact details, company, area of interest and communication content Responding to an enquiry, preparing an offer and pre-contractual or business communication; Article 6(1)(b) or (f) GDPR An ordinary completed enquiry is retained for no longer than 12 months
Form protection Hashed IP address, submission time, security and technical data Prevention of spam, attacks and abuse; legitimate interests under Article 6(1)(f) GDPR Rate-limit data for 24 hours and application logs for 30 days
WhatsApp Telephone number, profile details, message content and technical communication data Voluntary communication; Article 6(1)(b) or (f) GDPR According to the purpose, normally no longer than 12 months after the enquiry has been completed

If a communication results in a contract, the relevant data may be retained throughout the contractual relationship and subsequently for the applicable statutory archiving, tax, accounting and limitation periods.

3. Website visits and server logs

When you access merkle.sk, the server processes technical data required to deliver the website, diagnose faults and protect the service against attacks. This may include the IP address, access time, requested URL, server response status, referring page, browser type, operating system and User-Agent.

The legal basis is our legitimate interest in the secure, stable and reliable operation of the website and in measuring its use internally in order to improve the content, structure, clarity for users and technical operation of the website.

We evaluate server logs using our own analytics tool operated exclusively within our hosting account. The analysis does not use analytics cookies, Local Storage, Session Storage, fingerprinting or an external analytics service. It does not create cross-site tracking or an individual user profile.

The IP address and complete User-Agent are used only temporarily during calculation to estimate visits, distinguish automated access and compile aggregated information. They are not stored in the generated statistical report. Where the log contains a referrer, only the referring domain is stored in the report, not the complete referring URL. The report mainly contains aggregated page views and estimated visits, requested paths, language versions, status codes, technical errors, general device categories and any campaign parameters. Access to the report is protected by authentication.

The availability period of raw server logs is governed by the technical rotation and settings of the hosting environment. We use only records from 16 July 2026 onwards for internal statistical analysis. In the event of a specific security incident, relevant records may be retained for longer where this is necessary to investigate the incident or protect legal claims. Aggregated reports that do not contain IP addresses or complete User-Agent strings may be retained for longer to compare traffic trends and improve the website.

Hosting and email services are provided by WebHouse, s. r. o., Paulínska 20, 917 01 Trnava, Slovak Republic, which processes data as a processor when providing these services.

4. Contact form, email and telephone

The contact form requires your full name, email address, area of interest and message. The company name and telephone number are optional.

We use these data to receive and process your enquiry, respond to you, prepare an offer, agree on the next steps and conduct ordinary business or pre-contractual communication.

If your enquiry concerns the possible conclusion of a contract with you, the legal basis is Article 6(1)(b) GDPR. For general business communication, or where you act as a contact person for a legal entity, the legal basis is our legitimate interest under Article 6(1)(f) GDPR.

The contact form does not store the text of your message in the website database. The message is delivered to the company email account over an encrypted SMTP connection. An ordinary enquiry that does not result in a contract is retained for no longer than 12 months after it has been fully dealt with.

Please do not enter special categories of personal data or other sensitive or confidential information in the free-text field unless this is necessary for us to deal with your enquiry.

5. Contact form security and Cloudflare Turnstile

The form uses a security token against unauthorised submissions, a strictly necessary session, a hidden anti-bot field, a minimum submission time, rate limiting and Cloudflare Turnstile.

To limit repeated submissions, a cryptographic hash of the IP address is processed temporarily together with the submission time. These data do not include the message text and are deleted no later than 24 hours after collection. Technical application and error logs do not contain the form content and are retained for no longer than 30 days unless they are required to investigate a specific incident.

Cloudflare Turnstile is provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. During verification, it may process technical signals such as the IP address, TLS fingerprint, User-Agent, public site key, page origin and other information required to distinguish a legitimate visitor from an automated system.

The Pre-clearance feature is not enabled, so Turnstile is not configured to issue the cf_clearance cookie for other pages of the domain. The legal basis is our legitimate interest in protecting the website and the contact form.

Further information is available in the Cloudflare Turnstile privacy information .

6. Contact through WhatsApp

The website contains an ordinary external link to WhatsApp. Merely loading merkle.sk does not automatically transmit data to WhatsApp. Processing begins only when you open the link or send a message.

In that case, your telephone number, name and profile details configured in WhatsApp, message content, attachments, time and technical communication data may be processed. Using WhatsApp is voluntary; you may instead contact us by email, telephone or through the contact form.

The service for users in the European region is provided by WhatsApp Ireland Limited. Processing by that service is also governed by its own Privacy Policy .

7. Recipients and transfers to third countries

Personal data may be accessed, where necessary, by:

  • Merkle s. r. o. and persons authorised to handle communications,
  • WebHouse, s. r. o. as the hosting and email provider,
  • Cloudflare and its processors when Turnstile is used,
  • WhatsApp Ireland Limited and service providers involved in delivering WhatsApp, if you choose that channel,
  • professional legal, accounting or tax advisers where necessary,
  • public authorities or courts where disclosure is required by law or necessary to protect legal claims.

We do not sell personal data or disclose it to third parties for their own advertising or marketing purposes.

Cloudflare and WhatsApp may process data outside the European Economic Area. In their documentation, these providers describe GDPR transfer mechanisms including adequacy decisions and Standard Contractual Clauses, where applicable.

8. Is providing the data mandatory?

Technical data required to load and operate the website securely are processed automatically. Without such processing, the website cannot be provided reliably.

The full name, email address, area of interest and message are mandatory fields in the contact form. Without these data, the form cannot be submitted and we cannot respond to your enquiry. The company name and telephone number are optional.

We do not carry out automated individual decision-making or profiling that produces legal or similarly significant effects concerning you. Turnstile performs only a technical security assessment of the request in order to protect the form.

9. Your rights

Subject to the conditions laid down by the GDPR, you have the right:

  • to obtain access to your personal data,
  • to have inaccurate or incomplete data rectified,
  • to request erasure where the statutory conditions are met,
  • to request restriction of processing,
  • to data portability in the cases provided for by the GDPR,
  • to object to processing based on legitimate interests,
  • to lodge a complaint with a supervisory authority.

Send your request to info@merkle.sk. We may take reasonable steps to verify your identity before dealing with the request. We will respond without undue delay, normally within one month. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.

If you object to processing based on legitimate interests, we will cease processing unless we demonstrate compelling legitimate grounds or the data are required for the establishment, exercise or defence of legal claims.

10. Right to lodge a complaint

If you believe that we process your personal data contrary to applicable law, you may contact:

Office for Personal Data Protection of the Slovak Republic
Galvaniho Business Centrum II
Galvaniho 7/B
821 04 Bratislava
Slovak Republic

Current contact information and instructions for submitting a complaint are available on the official website of the authority .

11. Security, external links and changes

We use appropriate technical and organisational measures, including HTTPS, encrypted SMTP transmission, CSRF and spam protection, rate limiting, storage of private configuration outside the public web directory and restricted access permissions. No method of transmission or storage can, however, guarantee absolute security.

An ordinary external link does not transmit data to its operator until you click it. Once an external website is opened, the processing of personal data is governed by the rules of its operator.

We may update this information if the processing activities, technical setup, services used or legal requirements change. The current version will always be published at this address together with the date of the latest update.