Privacy Policy
Last updated: 12 June 2026
This document is a template and does not constitute legal advice. Please ensure the company's identification details are accurate and have the full text reviewed by a qualified lawyer before publication.
This Privacy Policy explains how Vitoro Motors ("we", "us") processes personal data in connection with this website, in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and applicable national law.
We are committed to protecting your privacy. We process personal data only to the extent necessary, transparently, and for clearly defined purposes.
1. Data Controller
The controller of your personal data is: Vitoro Motors, registered office at Krizna 47, Bratislava 811 07, Slovakia, Company ID (IČO): __________, Tax ID (DIČ): __________ (VAT ID: __________), registered in the Commercial Register of the District Court __________, Section: Sro, Insert No.: __________.
Contact for data protection matters: info@vitoro.eu, phone +421 911 56 56 76.
Given the nature and scope of our processing, we are not required to appoint a Data Protection Officer (DPO) and have not appointed one. For any data-protection matter, please contact us at the email address above.
2. What personal data we process
Depending on how you interact with the website, we may process:
- Contact and inquiry form data: name, email address, phone number (optional) and the content of your message.
- For a vehicle-specific inquiry, the identification of the vehicle you are interested in.
- Technical and usage data: IP address, browser and device type, date and time of access, and similar server-log data.
- Site administrator account data (internal users only): name, email and encrypted login credentials.
3. Purposes and legal bases
- Handling your inquiries and communicating with you — legal basis: steps taken at your request prior to entering into a contract and/or our legitimate interest in responding (Art. 6(1)(b) and (f) GDPR).
- Operating, securing and protecting the website against misuse — legitimate interest (Art. 6(1)(f) GDPR).
- Complying with legal obligations, e.g. accounting and tax — legal obligation (Art. 6(1)(c) GDPR).
- Processing based on consent where we ask for it — consent (Art. 6(1)(a) GDPR), which you may withdraw at any time.
4. Recipients and processors
We do not sell personal data. We share it only with service providers who process data on our behalf under contract (processors), to the extent necessary:
- Database hosting provider (Neon) — data storage; servers located in the EU (Frankfurt, Germany).
- Image hosting and CDN provider (Cloudinary) — storage and delivery of image content.
- We do not currently use any other processors (such as analytics or marketing tools); we will update this list if that changes.
- Public authorities where required by law.
5. International transfers
Data is primarily processed within the EU/EEA. Where a processor also processes data outside the EU/EEA (e.g. Cloudinary), we ensure appropriate safeguards under the GDPR, in particular the European Commission's Standard Contractual Clauses.
6. Retention
- We keep inquiries and related communication for as long as needed to handle them, and thereafter for up to 24 months for our legitimate interest, unless a contractual relationship arises.
- Accounting and tax records are kept for the period required by law (generally 10 years).
- Server logs are kept for 30 days, unless longer retention is required for security reasons.
7. Cookies
This website uses only strictly necessary and functional cookies: a cookie that remembers your language, and session cookies required for administrator login. On your first visit, the language (and the currency in which prices are displayed) is pre-set based on the country derived from your IP address; we do not store your IP address, and the cookie holds only the language code. You can change the selection at any time using the language switcher. These cookies are essential to the operation of the site and do not require consent.
We currently do not use analytics or marketing cookies and do not track you across websites. If we introduce such tools in future, we will request your prior consent.
8. Your rights
In relation to your personal data you have the right to:
- access your data (Art. 15 GDPR),
- rectify inaccurate data (Art. 16 GDPR),
- erasure of data (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- object to processing based on legitimate interest (Art. 21 GDPR),
- withdraw consent at any time where processing is based on consent (Art. 7(3) GDPR).
9. Right to lodge a complaint
If you believe your data has been processed unlawfully, you have the right to lodge a complaint with the supervisory authority: Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov SR), Galvaniho 7/B, 821 04 Bratislava, web: dataprotection.gov.sk. Please verify the authority's current contact details on its website.
10. Obligation to provide data and automated decision-making
Providing data in the forms is voluntary, but without it we may be unable to respond to your inquiry. We do not carry out automated decision-making or profiling that produces legal effects concerning you.
11. Security
We have implemented appropriate technical and organisational measures to protect personal data, including encrypted transmission (HTTPS), access controls, and storing passwords only in encrypted (hashed) form.
12. Changes to this Policy
We may update this Policy from time to time. The current version is always available on this page together with the date of the last update.