Privacy & Policy

INFORMATION ON THE PROCESSING AND PROTECTION OF PERSONAL DATA

(Fulfilling the controller's information obligation pursuant to Articles 13 and 14 of EU Regulation 2016/679 and Section 19 of Act No. 18/2018 Coll. on Personal Data Protection)

1. CONTROLLER IDENTIFICATION AND CONTACT DETAILS

The controller of your personal data is the company: AGENT.SK, s. r. o., registered office: Pribinova 30, 811 09 Bratislava, Slovakia, Company ID (IČO): 36 705 624, Tax ID (DIČ): 2022280623, VAT ID (IČ DPH): SK 2022280623, registered in the Commercial Register of the District Court Bratislava I, Section: Sro, Insert No.: 43366/B (hereinafter referred to as the "Controller").

Data Protection Officer contact: [email protected]

In the performance of real estate activities, the Controller acts in its own name in cooperation with contractual intermediaries (legal entities and natural persons).

In the performance of financial intermediation, the Controller holds the status of a Subordinated Financial Agent (PFA) and carries out its activities based on a contract with the Independent Financial Agent (SFA): Finportal, a. s., Company ID: 45 469 156, registered office at Pribinova 4, 811 09 Bratislava.

2. LIST OF APPLICABLE LEGISLATION

We process personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and Act No. 18/2018 Coll. on Personal Data Protection. In our operations, we follow and refer primarily to the following generally binding legal regulations of the Slovak Republic, which impose obligations on us to process and store your data:

Legislation for financial intermediation and AML:

  • Act No. 186/2009 Coll. on Financial Intermediation and Financial Advisory
  • Act No. 297/2008 Coll. on Protection Against Money Laundering and Terrorist Financing (AML Act)
  • Act No. 129/2010 Coll. on Consumer Credits and Other Credits and Loans for Consumers
  • Act No. 90/2016 Coll. on Housing Loans
  • Act No. 39/2015 Coll. on Insurance
  • Act No. 483/2001 Coll. on Banks
  • Act No. 381/2001 Coll. on Compulsory Motor Third-Party Liability Insurance

Legislation for real estate activities, general regulations, and AML:

  • Act No. 40/1964 Coll., Civil Code
  • Act No. 513/1991 Coll., Commercial Code
  • Act No. 108/2024 Coll. on Consumer Protection
  • Act No. 452/2021 Coll. on Electronic Communications (for marketing and cookies)
  • Act No. 147/2001 Coll. on Advertising
  • Act No. 297/2008 Coll. on Protection Against Money Laundering and Terrorist Financing (AML Act)

Legislation for archiving and accounting:

  • Act No. 431/2002 Coll. on Accounting
  • Act No. 395/2002 Coll. on Archives and Registries
  • Act No. 595/2003 Coll. on Income Tax

3. PURPOSES AND LEGAL BASES

We process your data for specifically defined purposes:

1. Performance of financial intermediation
a. Purpose: Identification of the client, needs analysis, intermediation of consumer loans, housing loans, insurance, and deposit acceptance, execution of activities aiming to conclude a contract with a financial institution.
b. Legal basis: Compliance with legal obligations (Art. 6(1)(c) GDPR) under Act No. 186/2009 Coll. and Act No. 297/2008 Coll.

2. Real estate activity
a. Purpose: Intermediation of purchase, sale, and lease of real estate, advertising, viewings, preparation of contractual documentation (reservation contracts, purchase contracts).
b. Legal basis: Performance of a contract and pre-contractual relations (Art. 6(1)(b) GDPR) under Act No. 297/2008 Coll.

3. Marketing and service promotion
a. Purpose: Sending information about products, services, and news (newsletter), ad targeting.
b. Legal basis:
i. Data subject consent (Art. 6(1)(a) GDPR) for non-clients (including cookies).
ii. Legitimate interest (Art. 6(1)(f) GDPR) for existing clients pursuant to Section 116 of Act No. 452/2021 Coll. on Electronic Communications (direct marketing of own services).

4. Dispute resolution and protection of legal claims
a. Purpose: Debt collection, handling complaints and disputes, proving compliance with regulations during audits.
b. Legal basis: Legitimate interest of the Controller (Art. 6(1)(f) GDPR).

4. SCOPE OF PROCESSED DATA

We process personal data to the extent necessary to achieve the specified purpose and in accordance with the principle of data minimisation (Section 8 of the Act on Personal Data Protection): Identification data: Title, first name, surname, national identification number / personal ID number (in accordance with Section 78 of Act No. 18/2018 Coll. and the Act on Banks/Insurance), date of birth, identity document number, nationality. Contact data: Permanent/temporary residence address, phone number, email. Economic data: Data on income, liabilities, assets, bank account number (necessary for creditworthiness assessment for loans and for AML). Real estate data: Real estate register (cadastre) data, technical condition of the property, photo documentation.

5. RECIPIENTS OF PERSONAL DATA

We provide your personal data to the necessary extent to the following categories of recipients:

  1. Independent Financial Agent (SFA): Finportal, a. s., Company ID: 45 469 156
  2. Cooperating Subordinated Financial Agents (PFA): Legal entities and natural persons registered with the National Bank of Slovakia (NBS)
  3. Financial institutions: Banks, branches of foreign banks, insurance companies with which you conclude an intermediated contract.
  4. Cooperating real estate agents: Legal entities and natural persons
  5. Contractual partners and suppliers: IT service providers, accounting firm, and legal counsel.
  6. State authorities and institutions: National Bank of Slovakia (NBS), Office for Personal Data Protection of the Slovak Republic, Financial Intelligence Unit (FIU), tax offices, courts, and law enforcement agencies (when required by law).

Transfer of personal data to third countries: The Controller uses services of reputable IT providers, including the Google Workspace cloud solution (Google Ireland, Ltd. in the EU). In case of data transfers to the USA (Google LLC), this transfer is carried out based on the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework, of which Google LLC is a certified participant. The list of certified entities is available at www.dataprivacyframework.gov

6. DATA RETENTION PERIOD

We store your personal data in a form that permits identification for no longer than is necessary for the purposes for which the personal data are processed (Section 10 of the Act on Personal Data Protection). Specific retention periods result from specific legal regulations mentioned in Article 2 of this document:

  • Accounting documents: For the period specified by Act No. 431/2002 Coll. on Accounting.
  • Financial intermediation documentation: For the period specified by Act No. 186/2009 Coll. on Financial Intermediation.
  • AML legislation documentation: For the period specified by Act No. 297/2008 Coll.
  • Contractual documentation for real estate activity: For the duration of the contractual relationship and subsequently until the expiration of the statutes of limitation for asserting legal claims under the Civil Code.
  • Marketing data: For the duration of consent or legitimate interest and subsequently for the period necessary to demonstrate the lawfulness of the procedure specified in Act No. 452/2021 Coll. on Electronic Communications. In the case of direct marketing intended for existing clients (so-called soft opt-in), the Controller guarantees that the data subject was given the opportunity to refuse such use of data at the time of collection.

7. RIGHTS OF THE DATA SUBJECT

In connection with the processing of your personal data, under the GDPR and the Act on Personal Data Protection, you have the following rights:

  • Right of access to data.
  • Right to rectification of incorrect data.
  • Right to erasure (right to be forgotten) if the purpose of processing has lapsed or consent has been withdrawn.
  • Right to restriction of processing.
  • Right to data portability.
  • Right to object to processing (in particular regarding direct marketing and legitimate interest).
  • Right to withdraw consent at any time (where processing is based on consent).

You may exercise your rights by email at: [email protected], or in writing at the registered office address of the Controller. If you believe that your data processing violates regulations, you have the right to lodge a petition to initiate proceedings on personal data protection (Section 100 of Act No. 18/2018 Coll.) with the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava, https://dataprotection.gov.sk

8. AUTOMATED DECISION-MAKING AND PROFILING

The Controller does not carry out automated individual decision-making with legal effects for the data subject within its internal processes pursuant to Art. 22 GDPR. However, please note that in financial service intermediation (e.g., loans or insurance), financial institutions (banks, insurance companies) may use profiling and automated systems to assess client creditworthiness or risk. These processes are governed by the terms of the specific financial institution.