Table of contents
- 01Who we are and how to contact us
- 02What personal data is
- 03Who this policy applies to
- 04Protection of persons under 16
- 05What personal data we process
- 06Where we obtain personal data
- 07Purposes and retention periods
- 08Are you obliged to provide data?
- 09Who we may disclose data to
- 10Transfers outside the EEA
- 11Website and cookies
- 12Newsletter
- 13Client zone
- 14How long we keep data
- 15How we protect data
- 16Automated decision-making and profiling
- 17Your rights
- 18How to exercise your rights
- 19Complaint to the supervisory authority
- 20Changes to this policy
This policy explains how the law firm Skellor s. r. o. processes the personal data of clients, prospective clients, representatives and contact persons of clients, opposing parties, website visitors, client-zone users, newsletter subscribers, applicants for cooperation and other persons whose data it may process.
We take care to protect your personal data, and it is important to us that you are informed about (i) who processes your personal data, (ii) to what extent, (iii) for what purposes and (iv) on what legal basis. It is equally important that you are informed about (v) what rights you have in connection with the processing of personal data. It is especially important that you familiarise yourself with this information no later than at the point your personal data is obtained, and that you understand it.
This privacy policy provides you with all of this information in accordance with the provisions of Article 13 and Article 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), which you may know under the abbreviation GDPR.
For completeness, as a law firm we are bound by a strict duty of confidentiality. We therefore protect personal data not only under the GDPR, but also under the rules governing the practice of law.
Please read the information below about how we obtain your personal data, how we handle it further and, in particular, what your rights are in connection with the processing of your personal data.
01WHO WE ARE AND HOW TO CONTACT US
As you probably do not know all of our identification details, we would like to introduce ourselves in more detail.
The controller of personal data is the law firm Skellor s. r. o., with its registered office at Stromová 2670/13, 831 01 Bratislava ‑ Nové Mesto, Slovak Republic, Company ID (IČO): 57 390 789, registered in the Commercial Register of the Bratislava III City Court, Section Sro, Insert No. 194899/B.
On matters of personal data protection you can contact us by email at office@skellor.sk, by phone at +421 948 725 764, or by post at our registered office address.
In this policy we use the terms Skellor, we or our firm.
02WHAT PERSONAL DATA IS
Personal data means any information relating to an identified or identifiable natural person, such as first name, surname, email address, telephone number, IP address, birth number, date of birth and similar.
03WHO THIS POLICY APPLIES TO
This policy applies in particular to the following categories of data subjects:
Where we process data of a legal entity, this does not constitute personal data. However, the data of natural persons who act on behalf of a legal entity or communicate with us may be personal data.
04PROTECTION OF PERSONS UNDER 16
If you are under 16, please ask your legal guardians for consent before providing us with any personal data about yourself or about them. Without such consent, you are not entitled to provide us with personal data.
05WHAT PERSONAL DATA WE PROCESS
We process in particular the data needed to provide legal services, to communicate, to fulfil statutory and professional obligations, to keep accounts, to protect legal claims, to operate the website, to send the newsletter and to run the client zone.
The scope of data depends on your relationship with us and on what we are handling for you or for our client. As a rule, this may include the following categories of data:
When providing legal services we may also process special categories of personal data, such as data on health, trade-union membership, political opinions or biometric data, where these are contained in the materials of a legal matter and their processing is necessary to provide legal services or to establish, exercise or defend legal claims. In criminal, administrative-offence and compliance matters we may, to the extent necessary, also process data relating to criminal convictions and offences, administrative offences or related security measures.
We send the newsletter solely on the basis of consent. We use analytics and marketing cookies only where you give us consent via the cookie bar. We do not carry out automated decision-making that would produce legal or similarly significant effects concerning you.
06WHERE WE OBTAIN PERSONAL DATA
We most often obtain personal data directly from you. However, when providing legal services we also frequently obtain it from the client, from a person acting for the client, from the opposing party, from public registers and publicly available sources, from courts, public authorities, notaries, court enforcement officers, experts, auditors, tax advisors or other persons involved in the legal matter.
If we did not obtain your data directly from you, this may be because you are named in the documents of a legal matter or you act as a representative, contact person, witness, opposing party or other person connected with the matter. In some cases we may not need to contact you separately, in particular where this would be impossible, would require disproportionate effort, or would jeopardise the purpose of the legal service, the client's rights or the duty of legal confidentiality.
07PURPOSES AND RETENTION PERIODS
We process personal data only where we have a specific purpose and legal basis for doing so. An overview of the main purposes is set out below.
If you contact us, we process the data needed to respond, assess the enquiry, prepare an offer or agree on the provision of legal services.
Art. 6(1)(b) GDPR where these are steps taken prior to entering into a contract with you; otherwise Art. 6(1)(f) GDPR. We keep the data as a rule for 3 years from the last communication, unless a legal matter or claim arises from it.
Before accepting a matter, or during it, we verify whether we can provide the legal service without a conflict of interest.
Art. 6(1)(c) GDPR in conjunction with the rules of legal practice. We keep the records for the period necessary to demonstrate compliance with this obligation, as a rule for 10 years after the matter ends.
We process the data needed for legal advice, drafting documents, representation, defence, negotiations, due diligence, transactions, compliance and other legal work.
Art. 6(1)(b) and (c) GDPR depending on the type of person and matter. For special categories of data in particular Art. 9(2)(f) GDPR. For data on criminal offences, Art. 10 GDPR to the extent permitted by the law of the Slovak Republic. We keep the client file as a rule for 10 years after the matter ends, or longer where necessary for a legal claim, a legal obligation or the protection of the client's rights.
We comply with obligations under the legal-profession rules, AML rules, tax and accounting rules, records-management rules and other legislation.
Art. 6(1)(c) GDPR. We keep AML data as a rule for 5 years from the end of the contractual relationship or the execution of the transaction, unless the law or a competent authority requires a longer period. We keep accounting records as a rule for 10 years.
We issue invoices, keep accounts, process payments and fulfil tax obligations.
Art. 6(1)(c) GDPR; for contractual data also Art. 6(1)(b) GDPR. We keep accounting and tax documents as a rule for 10 years.
We may process data where we need to establish, exercise or defend the rights of ourselves, the client or another person.
Art. 6(1)(f) GDPR; for special categories of data Art. 9(2)(f) GDPR. We keep the data for the duration of the relevant limitation, complaint or procedural periods, as a rule for no more than 10 years, unless specific circumstances require longer retention.
We ensure the technical functioning of the website, protection against misuse, basic display of content and the security of forms.
Art. 6(1)(f) GDPR. We keep necessary cookies and technical records for the technically required period according to each tool's settings.
If you consent, we may measure website traffic, improve its content or use marketing tools.
Art. 6(1)(a) GDPR. You can withdraw consent at any time in the cookie settings. The retention period depends on the specific tool and is stated in the cookie bar.
If you subscribe, we send you legal news, invitations, commentary and information about our services.
Art. 6(1)(a) GDPR. We process the data until consent is withdrawn. We may keep a record of the giving or withdrawal of consent as a rule for 3 years to demonstrate the lawfulness of processing.
If you create an account or obtain access to the client zone, we process the data needed for registration, login, account management, access to manuals and checklists, and compliance with the terms of use.
Art. 6(1)(b) GDPR where this concerns performance of the terms of use or a contract; Art. 6(1)(f) GDPR for security logs and protection of the service. We keep the account for its duration and, as a rule, for 3 years after it is cancelled, unless a longer period is needed for claims or accounting. We keep security logs as a rule for no more than 12 months.
If you exercise your rights under the GDPR, we process the data needed to handle the request, verify identity and record how it was dealt with.
Art. 6(1)(c) GDPR. We keep requests and related communication as a rule for 5 years from when the request was handled.
If you send us a CV or respond to an offer of cooperation, we process the data needed to assess your application.
Art. 6(1)(b) GDPR for steps taken prior to entering into a contract; Art. 6(1)(f) GDPR for the protection of claims; consent where you wish to be included in a database of applicants. Without consent we keep the data as a rule for 6 months after the selection ends; with consent for no more than 2 years.
We process the data of contact persons of suppliers, advisors, experts, IT service providers and other partners.
Art. 6(1)(b) GDPR where you are a contracting party; otherwise Art. 6(1)(f) GDPR. We keep contractual communication for the duration of the relationship and, as a rule, for 10 years after it ends where it relates to accounting or claims.
Where the legal basis is consent, giving it is voluntary and you can withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before it was withdrawn.
Where the legal basis is legitimate interest, you have the right to object to the processing on grounds relating to your particular situation. In the case of direct marketing, you have the right to object at any time and without giving a reason.
08ARE YOU OBLIGED TO PROVIDE DATA?
Where we need the data to enter into or perform a contract, without providing it we may be unable to provide the legal service, set up a client-zone account or handle your request.
Where we need the data to fulfil a legal obligation, failure to provide it may mean we cannot accept a matter or continue with it. This concerns in particular client identification, AML obligations, accounting or obligations arising from the legal-profession rules.
Where we process data on the basis of consent, providing the data is voluntary. Refusing or withdrawing consent does not affect the provision of legal services, unless we need that data on another legal basis.
09WHO WE MAY DISCLOSE DATA TO
Personal data is accessible only to persons who need it to fulfil the relevant purpose and who are bound by confidentiality or another appropriate duty of confidentiality. Depending on the circumstances, we may disclose personal data to the following recipients or categories of recipients:
- attorneys, trainee attorneys, collaborators and authorised persons of our firm;
- the client, where necessary to provide legal services or protect the client's rights;
- courts, arbitration tribunals, public authorities, law-enforcement authorities, administrative bodies, notaries, court enforcement officers, registers, the Slovak Bar Association and other bodies, where required by the legal matter or by law;
- opposing parties, their legal representatives, experts, auditors, tax advisors, translators, interpreters, notaries, banks, insurers or other persons, where necessary for the legal matter;
- providers of IT, web, hosting, cloud, security and administrative services;
- the provider of the Wix web platform and services related to the operation of the website;
- the provider of the Proton Mail email service, i.e. Proton AG or companies of the Proton group;
- the provider of the client zone, if we use one;
- the provider of the newsletter distribution tool, if we use one;
- external accountants, tax advisors, auditors, banks and payment-service providers;
- delivery and courier services and providers of electronic signing or storage, where we use them for a specific matter.
Where we use processors, we ensure that they process the data only on our instructions, for the agreed purposes, with appropriate security measures and under a data-processing agreement.
10TRANSFERS OF DATA OUTSIDE THE EUROPEAN ECONOMIC AREA
We aim to process personal data within the European Economic Area or in countries that the European Commission has decided ensure an adequate level of protection of personal data.
In providing our services, email communication and website operation, we also use service providers that have a registered office, infrastructure, group companies or sub-processors outside the European Economic Area (EEA). In some cases, personal data may therefore be transferred to third countries, i.e. to countries outside the EEA.
We carry out such a transfer only where one of the mechanisms under the GDPR is met. Most often this will be:
- a transfer to a country that the European Commission has decided ensures an adequate level of protection of personal data;
- a transfer based on standard contractual clauses approved by the European Commission;
- another appropriate mechanism or derogation under the GDPR, where applicable in the specific case.
Email communication
For email communication we use the Proton Mail service provided by Proton AG, based in Switzerland. Switzerland is not part of the EEA and is therefore a third country. However, the European Commission has decided that Switzerland ensures an adequate level of protection of personal data. The transfer of personal data to Switzerland therefore takes place on the basis of an adequacy decision under Article 45 GDPR.
In email communication we process, as controller, in particular the email addresses of senders and recipients, the content of messages, attachments and technical data related to the delivery and record-keeping of communication. At the same time, we protect the content of legal communication as confidential information subject to legal privilege.
Proton Mail uses encryption designed to limit the service provider's own access to the content of communication. The bodies of messages and attachments stored in our Proton Mail mailbox are protected by zero-access encryption. This means that, under normal circumstances, Proton should not have the technical ability to read the content of stored messages or attachments once they have been encrypted.
This does not mean, however, that Proton does not process any personal data related to email communication. For technical reasons connected with how email works, Proton may process in particular email metadata, such as the email addresses of the sender and recipient, the IP address from which an incoming message arrived, the attachment name, the message subject and the time a message was sent or received. Proton may also process account-activity data, for example the number of messages sent, storage space used, the total number of messages and the time of the last login.
Where we communicate with a Proton Mail user or with a person using compatible end-to-end encryption, the content of the message may be protected by end-to-end encryption. Where we communicate with a person who uses an ordinary external email service without end-to-end encryption, the message is generally encrypted in transit, but at the external provider of the recipient or sender it may not be protected in the same way as in Proton Mail. In such cases Proton may, for unencrypted external messages, carry out technical checks to protect the service, in particular spam and virus checks, and then store the message in encrypted form.
In limited cases Proton may also involve companies of the Proton group or other sub-processors. If this were to result in a transfer of personal data to a country for which no adequacy decision exists, such a transfer is to be secured in particular by standard contractual clauses or another appropriate mechanism under the GDPR.
Copy of the safeguards
Where a transfer of personal data is based on appropriate safeguards under the GDPR, you may ask us for further information about these safeguards or how to obtain a copy of them. In handling such a request we may take into account trade secrets, security reasons, contractual restrictions, the rights of others and legal privilege.
With some services, in particular the Proton Mail email service, newsletter tools, cloud or analytics services, a transfer or remote access may also occur outside the European Economic Area. In such a case we use an appropriate mechanism under the GDPR, in particular an adequacy decision, standard contractual clauses, a data-processing addendum or other appropriate safeguards under Chapter V GDPR.
13CLIENT ZONE
Access to the client zone should be based on acceptance of the terms of use. We will process the personal data needed for registration, login, account management, securing access and performance of the terms of use mainly on a contractual legal basis. We will process security records and basic logs on the basis of our legitimate interest in protecting the account, the content and the website.
If we make access to selected free content conditional on registration, this should not automatically mean consent to the newsletter. The newsletter must remain separate and voluntary. The user obtains access to the content under the client-zone terms without being forced to consent to marketing communication, unless the newsletter is a separately and clearly explained consideration for specific content.
Manuals and checklists in the client zone may carry a separate notice that they constitute general informational content, not legal advice on a specific matter, unless agreed otherwise with us.
14HOW LONG WE KEEP DATA
We keep personal data only for the period necessary for the purpose for which we process it, or for the period required by law. Where several periods apply to the same data, the period that is necessary and lawful in the specific case applies.
After the relevant period expires, we delete, anonymise or securely restrict the processing of the data, where we still need to retain it, for example because of a legal claim, a legal obligation or legal privilege.
15HOW WE PROTECT DATA
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, disclosure or damage. This includes in particular restricting access, using secured accounts, passwords and multi-factor authentication where appropriate, encrypted communication, backups, the selection of trustworthy service providers and internal rules for working with documents.
In the case of legal services we additionally apply the rules of legal privilege and the principle of need-to-know access. This means that only persons who need the data for a specific legal matter or related administration work with it.
16AUTOMATED DECISION-MAKING AND PROFILING
We do not carry out automated individual decision-making, including profiling, that would produce legal effects concerning you or similarly significantly affect you.
When you use the website or the newsletter, some tools may technically evaluate basic data on traffic, security or deliverability. We do not use such processing to make decisions about your rights or a legal matter.
17YOUR RIGHTS
Under applicable data-protection law, as a data subject you have the following rights.
You have the right to be provided with a copy of the personal data we hold about you, as well as information about how we use your personal data. In most cases your personal data will be provided to you in written, hard-copy form, unless you request otherwise. If you requested this information by electronic means, it will be provided to you electronically where technically possible.
We take reasonable steps to ensure the accuracy, completeness and currency of the information we hold about you. If you believe that the data we hold is inaccurate, incomplete or out of date, please do not hesitate to ask us to amend, update or supplement this information. As a data subject you have the right to have personal data concerning you rectified where it is incorrect, or completed where it is incomplete. We are obliged to comply with your request for rectification or supplementation of personal data without undue delay.
In certain circumstances you have the right to ask us to erase your personal data, for example where the personal data we obtained about you is no longer needed to fulfil the original purpose of processing, or where you withdraw your consent to processing. However, your right must be assessed in light of all relevant circumstances. For example, where processing your data is necessary to fulfil our legal obligation or to establish, exercise or defend legal claims, we may not be able to comply with your request.
In certain circumstances you are entitled to ask us to stop using your personal data. This may concern, for example, situations where you believe that the personal data we hold about you is inaccurate or that we no longer need to use your personal data. Where processing has been restricted in accordance with Art. 18(1) GDPR, such personal data is, with the exception of storage, processed: (a) only with the data subject's consent; or (b) for the establishment, exercise or defence of legal claims; or (c) for the protection of the rights of another natural or legal person; or (d) for reasons of important public interest of the Union or a Member State.
In certain circumstances you have the right to ask us to transfer the personal data you have provided to us to another third party of your choice. Where processing is based on consent or on a contract and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and the right to transmit that data to another controller. Where technically feasible, you have the right to have the data transmitted directly from one controller to another.
Where processing is based on our legitimate interests (Article 6(1)(f) GDPR), you have the right at any time to object, on grounds relating to your particular situation, to such processing of personal data concerning you, including profiling based on those interests. In such a case we must no longer process your personal data unless (i) we demonstrate compelling legitimate grounds that override your interests, rights and freedoms as a data subject, or (ii) grounds for the establishment, exercise or defence of legal claims. Where you object to the processing of personal data for direct-marketing purposes, including profiling to the extent it is related to such direct marketing, the personal data may no longer be processed for such purposes.
You have the right to refuse automated decision-making, including profiling, which produces a legal or similarly significant effect for you.
In most cases we do not process your personal data on the basis of your consent. Where, in specific cases, we do process your data on the basis of your consent, you have the right to withdraw your consent to the further use of your personal data.
As a data subject you also have the right to lodge a complaint at any time with the supervisory authority, which is the Office for Personal Data Protection of the Slovak Republic (more information can be found at www.dataprotection.gov.sk), or to bring an action before the competent court.
18HOW TO EXERCISE YOUR RIGHTS
We care about protecting your personal data, and we therefore seek to secure it through individual, modern technical and organisational measures, as well as through the ability to exercise your data-subject rights under the GDPR at any time by making a request.
You can send requests to exercise a data-subject right electronically or in writing to the contact details given above. This is without prejudice to your right to withdraw the consent you gave to the processing of personal data, which you can always withdraw as easily as you gave it (for example, if you gave consent electronically, you can always withdraw it by email or via the contact interface on our website without needing to send a written request to our registered office), or your right to object by automated means using technical specifications where available.
We recommend that, in each request, you explain in as much detail as possible which right under the GDPR you are exercising, what your identification details are (for identity verification), and, where applicable, which purposes and data the request concerns. For requests that are too general, we must ask for clarification.
The GDPR sets out general conditions for the exercise of your individual rights. Their existence does not, however, automatically mean that when you exercise individual rights we will comply with them, since in a specific case exceptions may apply, or some rights are tied to specific conditions that may not be met in every case. We will always consider your request concerning a specific right and examine it from the perspective of the legislation and our internal policy for handling data-subject requests.
If we are not competent to assess your request to exercise a data-subject right, we will forward your request without delay to the competent controller.
Every request to exercise a data-subject right that we receive will be individually and competently assessed, and we will always inform you of the outcome no later than one month from receiving your request.
Please note that when handling your request to exercise a data-subject right under the GDPR, we may ask you for reliable verification of your identity, in particular where there are doubts about your identity. It is our duty to prevent personal data about you from being provided to an unauthorised person. The process of handling your request in connection with the exercise of your data-subject right under the GDPR is free of charge. Where your request is manifestly unfounded or excessive, in particular because it is repetitive, we are entitled to charge a reasonable fee reflecting the administrative costs.
19COMPLAINT TO THE SUPERVISORY AUTHORITY
If you believe that the processing of your personal data is not in compliance with the law, you can contact the Office for Personal Data Protection of the Slovak Republic, Galvaniho Business Centrum II, Galvaniho 7/B, 821 04 Bratislava, Slovak Republic. The right to bring an action before a court is not affected by this.
20CHANGES TO THIS POLICY
We may update this policy, in particular where our services, website, client zone, the tools we use, legislation or decision-making practice change. The current version will always be available on our website.
Where we make a material change, we will bring it to your attention appropriately, for example by a notice on the website or by email, where this is appropriate given the nature of the change.
This version of the policy was issued on 5 July 2026.