This translation is for information only. The binding version is the Slovak wording available at callania.eu/ochrana-udajov. In case of any discrepancy, the Slovak text prevails.
1. Who is the controller
- Company: MACET, s.r.o. · Registered office: Nitrianska 32/189, 949 11 Nitra · Company ID (IČO): 35 953 781
- Contact: booking@callania.eu
We have not appointed a Data Protection Officer (DPO) — we do not meet the conditions of Article 37 GDPR. If that changes, we will add the contact here.
2. Two different roles that need to be told apart
As a controller we process the data of people who create an account with us — our clients and prospects. That is what this document describes.
As a processor we process the data of our clients’ customers — people who book an appointment through the system. That data belongs to the client, who determines the purpose and the scope, and we only do with it what the client instructs. The relationship is governed by the Data Processing Agreement.
If you booked an appointment with someone and want to exercise your rights, contact that business. We will help them do it, but we cannot decide about their data.
3. What data we process as a controller
| Category | What it is | Legal basis | For how long |
|---|---|---|---|
| Account | email, password (stored as a hash, never readable), business name, language | performance of a contract | for the life of the account and 14 days after the account is closed |
| Billing details | company name, registered office, company ID, tax ID, payment history | performance of a contract and legal obligation | 10 years under the Accounting Act |
| Operational records | sign-ins, IP address, settings changes, audit | legitimate interest — security of the service | 12 months |
| Technical logs | request paths, errors (tokens and phone numbers are masked) | legitimate interest — operating the service and investigating incidents | 30 days |
| Contact form and prospects | email, name, message, where they came from | legitimate interest — replying to an enquiry | until handled, at most 24 months |
| Marketing communication | consent | until consent is withdrawn |
We do not process special categories of data (health, biometrics and the like) about our clients and we do not carry out automated decision-making or profiling with legal effect.
4. Where the data is held
The servers are in Germany, in the data centre of Hetzner Online GmbH. The data does not leave the European Economic Area.
5. Who receives the data
| Recipient | Why | Where |
|---|---|---|
| Hetzner Online GmbH | hosting and backups | Germany |
| Webglobe, a.s. (company ID 52486567) | sending email (SMTP) | Slovakia |
| BulkGate s. r. o. | sending SMS | Czechia |
We do not sell the data and do not provide it for advertising purposes. We hand it to public authorities only where the law requires it.
6. Cookies and measurement
We use technical cookies necessary for sign-in and security (session, CSRF protection) — these are required for the service to work and cannot be switched off.
With every booking we store the source of the visit (where the person came from — campaign, social network, QR code, partner link). The value is first-party, lasts 30 days and helps the business know what brings it customers. We do not combine it with third-party advertising identifiers and we do not track people across other websites.
We do not use third-party analytics. If that changes, we will state here which tool, on what legal basis, and how to opt out.
7. Your rights
You have the right of access to your data, to rectification, erasure, restriction of processing, portability, and the right to object to processing based on legitimate interest. Consent, if you gave it, can be withdrawn at any time — withdrawal does not affect processing carried out before it.
Closing your account
You can close your account yourself under My account → Close account. It is confirmed with your password, not a checkbox.
What happens:
- We sign you out on every device and email your address a link that undoes the closure. - For 14 days the account is only marked. During that time one click reverses it. Signing in alone does not undo it — you have to click. - After 14 days the account is deleted: email, name, password hash, memberships, sign-ins, tokens, stored consents and unfinished business drafts.
The business does not disappear with you. If you are its only owner and someone else is still there, the closure first asks you to name a successor, who becomes the owner immediately. If you are there alone, you close the business first (it has its own period) and only then the account.
What stays even after deletion, and why:
| What | Why | For how long |
|---|---|---|
| Issued invoices, including the customer’s name and address | the Accounting Act; GDPR allows this in Art. 17(3)(b) — a legal obligation takes precedence over erasure. A document must also not be altered afterwards; rewriting the name would make it invalid | 10 years |
| Audit records (who did what) | otherwise the audit could be emptied simply by closing an account. The link to the account is removed, only the record of the action remains | 12 months |
| Bookings you entered over the phone | they belong to the business and the guest, not to you. The system does not link your account to them at all | per the business’s retention setting |
We can show exactly what was deleted and what merely lost its link — every deletion writes a breakdown by record type into the audit.
Write to booking@callania.eu. We reply within one month; if it were to take longer, we will say why.
If you believe we handle your data incorrectly, you can contact the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky), Hraničná 12, 820 07 Bratislava.
8. How we protect the data
- transfer exclusively over an encrypted connection (HTTPS)
- passwords stored with argon2id, never readable
- the database is not reachable from the internet; server access by key only, no passwords, no root
- data of individual businesses is separated, verified by automated tests
- backups are encrypted and once a month we automatically verify that they can be restored
- tokens and phone numbers are masked in operational logs
- access and changes are written to the audit
Should a personal data breach with a risk to people’s rights occur nevertheless, we will notify the authority within 72 hours and the people concerned without undue delay.
9. Changes
We may update this document. We will announce material changes to clients by email at least 30 days in advance; the date of the last change is shown at the top.