webstellation logo

Table Of Contents

Privacy Policy

Effective Date: July 26, 2026

Last Updated: July 26, 2026

Your privacy is paramount to us. Webstellation (“we”, “us”, or “our”) is committed to protecting your personal data in full compliance with the European Union General Data Protection Regulation (EU GDPR – Regulation 2016/679), the EU AI Act (Regulation 2024/1689), and applicable national data protection legislation.

This Privacy Policy applies to personal data collected through our website (https://www.webstellation.com) and any associated web applications, products, or services operated by Webstellation.

1. Data Controller Information

For the purposes of the GDPR, Webstellation acts as the Data Controller for the personal data collected directly through our services.

2. Personal Data We Collect

Personal data refers to any information relating to an identified or identifiable natural person. We collect and process data in two ways:

Voluntarily Provided Data

When you contact us, request a service, or interact with our channels, we may collect:

  • Identity & Contact Data: Name, email address, phone number, company name.
  • Communication Content: Email inquiries, form submissions, and customer service records.

Automatically Collected Technical Data

When you access our platform, our servers and service providers standardly log:

  • Device & Connection Details: IP address (anonymized/truncated where feasible), browser type and version, operating system, language preferences, and time zone settings.
  • Usage Data: Pages visited, duration of session, click paths, referring website URLs.
  • Diagnostic & Error Logs: Technical error reports generated during site malfunctions.

3. Lawful Bases for Processing (GDPR Article 6)

We only process your personal data where we have a valid lawful basis under Article 6 of the GDPR:

Purpose of ProcessingCategory of DataLegal Basis (GDPR Art. 6)
Responding to inquiries & customer supportContact & Communication DataContract / Pre-contractual steps (Art. 6(1)(b)) or Consent (Art. 6(1)(a))
Providing core website features & stabilityTechnical & Diagnostic DataLegitimate Interest (Art. 6(1)(f))
Direct Marketing & NewslettersContact DataConsent (Art. 6(1)(a))
Website Analytics & PerformanceUsage & Cookie DataConsent (Art. 6(1)(a))
Legal Compliance & Tax ObligationsTransaction & Identity DataLegal Obligation (Art. 6(1)(c))

4. Artificial Intelligence & Automated Processing (EU AI Act Compliance)

In accordance with Article 50 of the EU AI Act:

  1. Automated Interactions: If you interact with any AI-powered automated tools or virtual assistants on our platform, you will be explicitly notified at the beginning of the interaction.
  2. AI Model Training: Webstellation does not use your personal data to train public or foundational artificial intelligence models without your explicit, opt-in consent.
  3. Automated Decision-Making (GDPR Art. 22): You will not be subject to decisions based solely on automated processing, including profiling, which produce legal or similarly significant effects concerning you.

5. Cookies and Web Tracking

We use cookies, tags, and local storage to operate our website and analyze web traffic.

  • Essential Cookies: Required for basic site operations (security, session handling). These do not require user consent.
  • Non-Essential Cookies (Analytics & Performance): We use Google Analytics to analyze site usage. These cookies are only set if you provide explicit consent via our Cookie Banner.

You can modify or withdraw your consent at any time through our on-site Cookie Preferences panel or via your browser settings.

6. Disclosure of Personal Data to Third Parties

We do not sell, rent, or trade your personal data. Data is shared strictly with trusted Data Processors operating under strict binding data processing agreements (DPAs) in compliance with GDPR Article 28:

  • IT & Hosting Infrastructure Providers: Server and cloud hosting platforms within the EU/EEA.
  • Analytics Providers: Google Ireland Limited (Google Analytics) — subject to IP anonymization and privacy safeguards.
  • Error Logging & Security Providers: Diagnostic services designed to secure our network against attacks or site crashes.
  • Legal Authorities: Regulatory agencies, law enforcement, or courts only when mandated by EU or Member State law.

7. International Data Transfers (Outside the EEA)

Whenever personal data is transferred outside the European Economic Area (EEA), we ensure a similar degree of protection is afforded to it by executing at least one of the following safeguards:

  • Adequacy Decisions: Transferring data to countries deemed by the European Commission to offer an adequate level of data protection.
  • Standard Contractual Clauses (SCCs): Using standard data protection clauses approved by the European Commission (pursuant to GDPR Art. 46(2)) alongside supplementary security measures (such as end-to-end encryption).

8. Data Retention Criteria

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements:

  • Inquiry & Contact Records: Retained for the duration of the active correspondence and deleted or anonymized within 12 months of the matter being closed.
  • Analytics & Performance Data: Retained for a maximum of 14 months before automatic deletion or full aggregation.
  • Legal & Business Records: Retained for the statutory period required by relevant EU Member State law (typically up to 7–10 years for tax and commercial records).

9. Your Data Protection Rights under GDPR

If you reside in the EU/EEA, you possess the following statutory rights regarding your personal data:

  • Right of Access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.
  • Right to Erasure / “Right to be Forgotten” (Art. 17): Request deletion of your data when it is no longer necessary or when consent is withdrawn.
  • Right to Restrict Processing (Art. 18): Request that we temporarily suspend processing your personal data under specific conditions.
  • Right to Data Portability (Art. 20): Request your data in a structured, commonly used, and machine-readable format (e.g., CSV or JSON).
  • Right to Object (Art. 21): Object to data processing based on Legitimate Interests or direct marketing.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, email us at terms@webstellation.com. We will respond to your request within 30 days free of charge.

10. Filing a Complaint

If you believe that Webstellation has processed your personal data in violation of applicable data protection laws, you have the right to lodge a complaint with a Data Protection Supervisory Authority. You may do so in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement.

11. Security Measures

We implement appropriate technical and organizational measures (e.g., HTTPS encryption in transit, strict access control, pseudonymization) in accordance with GDPR Article 32 to ensure a level of security appropriate to the risk.

12. Updates to This Policy

We may update this Privacy Policy periodically to reflect technological changes or updates in legal obligations. The effective date at the top of this policy indicates when it was last revised. Material changes will be communicated via a prominent notice on our website.

13. Contact Details

For all questions, data rights requests, or supervisory matters, please contact:

Webstellation s.r.o

Karpatské námestie 7770/10A
Bratislava – mestská časť Rača 831 06
Slovak Republic

Attention: Privacy Officer / Data Protection Officer

Email: terms@webstellation.com

Website: https://www.webstellation.com

© 2023-2026, All Rights Reserved