Privacy Policy
Last Updated: July 30, 2026 | Effective Date: July 30, 2026
Please read this Privacy Policy carefully before using our services. By accessing or using our website, you acknowledge that you have read, understood, and agree to the practices described in this document. If you do not agree with the terms of this Privacy Policy, please discontinue use of our website and services immediately.
1. Who We Are — Data Controller Information
For the purposes of applicable data protection legislation, including the GDPR and Slovak Act No. 18/2018 Coll. on the Protection of Personal Data (Zákon o ochrane osobných údajov), the data controller responsible for your personal information is:
| Business Name | Šepot |
|---|---|
| Address | Slovakia |
| Email Address | contact@pathweplan.com |
| Website | www.pathweplan.com |
| Location | Slovakia, European Union |
As the data controller, Šepot determines the purposes and means of processing your personal data. If you have any questions, concerns, or requests regarding this Privacy Policy or the handling of your personal data, you may contact us directly using the details provided above.
2. Legal Basis for Data Processing
We process your personal data only when we have a valid legal basis for doing so. In accordance with Article 6 of the GDPR and Slovak Act No. 18/2018 Coll., we rely on the following legal bases:
- Consent (Article 6(1)(a) GDPR): Where you have given us explicit, informed, and freely given consent to process your personal data for a specific purpose, such as receiving marketing communications or the use of non-essential cookies.
- Contractual Necessity (Article 6(1)(b) GDPR): Where processing is necessary for the performance of a contract to which you are a party, or to take pre-contractual steps at your request. This applies when you engage our services or make a purchase.
- Legal Obligation (Article 6(1)(c) GDPR): Where processing is necessary for compliance with a legal obligation to which we are subject under Slovak law or EU law, such as tax, accounting, and financial reporting obligations.
- Legitimate Interests (Article 6(1)(f) GDPR): Where processing is necessary for the purposes of our legitimate interests or those of a third party, except where such interests are overridden by your interests, fundamental rights, or freedoms. This may include fraud prevention, network security, improving our services, and internal business analytics.
3. What Personal Data We Collect
We collect several types of personal data depending on how you interact with our website and services. Below is a detailed breakdown of the categories of data we may collect:
3.1 Personal Identification Information
When you register for an account, contact us, or use our services, we may collect the following identifying information:
- Full name (first name and last name)
- Email address
- Phone number (if voluntarily provided)
- Billing and shipping address
- Company name and job title (if applicable)
- Date of birth (for age verification purposes, where required)
- Profile picture or avatar (if you choose to upload one)
- Username and password (stored in encrypted form)
3.2 Financial and Transaction Data
If you make a purchase or engage in financial transactions through our platform, we may collect:
- Payment card details (note: we do not store full card numbers; these are processed securely by our payment service providers)
- Transaction history, including amounts, dates, and descriptions
- Billing information and invoices
- VAT identification numbers (where applicable under Slovak VAT law — Act No. 222/2004 Coll.)
3.3 Usage and Behavioral Data
We automatically collect certain information about how you interact with our website and services, including:
- Pages visited and time spent on each page
- Clickstream data and navigation paths
- Features and services accessed
- Search queries entered on our website
- Links clicked, including external links
- Scroll depth and interaction patterns
- Error logs and diagnostic reports
3.4 Device and Technical Information
We automatically collect technical data from the device you use to access our website:
- IP address (which may be used to determine your approximate geographic location)
- Browser type, version, and language settings
- Operating system and device type (desktop, mobile, tablet)
- Screen resolution and display settings
- Referring website or source (how you arrived at our website)
- Time zone and locale settings
- Hardware specifications (where relevant for service compatibility)
3.5 Communication Data
When you contact us through email, contact forms, support tickets, or other communication channels, we collect:
- The content of your messages, inquiries, and feedback
- Attachments and files you send us
- Email correspondence history
- Support chat transcripts (if applicable)
3.6 Cookie and Tracking Data
We use cookies and similar tracking technologies to enhance your experience on our website. For detailed information about the types of cookies we use and how to manage your preferences, please see Section 9 of this Privacy Policy.
4. How We Use Your Personal Data
We use the personal data we collect for a range of purposes, all of which are grounded in a legitimate legal basis as described in Section 2 above. The specific purposes for which we process your data include:
4.1 Service Provision and Fulfillment
- Creating and managing your user account
- Processing transactions and orders
- Delivering the products, services, or content you have requested
- Sending transactional emails, including order confirmations and receipts
- Providing customer support and responding to your inquiries
- Verifying your identity and eligibility to use our services
4.2 Service Improvement and Analytics
- Analyzing usage patterns and trends to understand how users interact with our website
- Identifying technical issues, errors, and areas for improvement
- Conducting research and testing to enhance our platform's functionality
- Developing new features, products, and services
- Monitoring and maintaining the security and integrity of our systems
4.3 Marketing and Communications
- Sending newsletters, promotional offers, and marketing communications (only where you have provided consent or where permitted by applicable law)
- Personalizing content and recommendations based on your preferences and behavior
- Conducting surveys and soliciting feedback on our services
- Retargeting advertisements on third-party platforms (subject to your cookie consent)
4.4 Legal Compliance and Protection
- Complying with applicable Slovak and EU legal obligations, including tax, accounting, and financial reporting requirements
- Enforcing our Terms and Conditions and other applicable agreements
- Detecting, investigating, and preventing fraudulent activity and abuse
- Responding to lawful requests from public authorities, courts, and law enforcement agencies
- Protecting the rights, property, and safety of Šepot, our users, and third parties
5. Sharing Your Personal Data with Third Parties
We respect your privacy and do not sell, rent, or trade your personal data to third parties for their own marketing purposes. However, we may share your data in the following circumstances:
5.1 Service Providers and Data Processors
We engage trusted third-party companies and individuals to provide services on our behalf. These service providers act as data processors and are contractually obligated to process your personal data only on our instructions and in compliance with the GDPR. Categories of service providers include:
- Hosting and Infrastructure Providers: Cloud hosting companies that store and serve our website and application data.
- Payment Processors: Secure payment gateway providers that handle financial transactions on our behalf.
- Email and Communication Services: Platforms used to send transactional and marketing emails.
- Analytics Providers: Tools such as website analytics platforms that help us understand user behavior (e.g., Google Analytics or equivalent).
- Customer Support Tools: Help desk and ticketing systems used to manage and respond to support requests.
- Marketing Platforms: Advertising and marketing automation tools used for campaign management.
5.2 Legal and Regulatory Disclosure
We may disclose your personal data to competent public authorities, courts, law enforcement agencies, or regulatory bodies where we are legally required to do so under Slovak law (e.g., pursuant to Act No. 301/2005 Coll. — the Code of Criminal Procedure, or other applicable statutes) or EU law. Such disclosures will be limited to what is strictly necessary.
5.3 Business Transfers
In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, your personal data may be transferred to the acquiring entity as part of the business transaction. We will notify you of any such transfer and any changes to this Privacy Policy that may result.
5.4 With Your Consent
We may share your personal data with third parties for purposes not described in this Policy where we have obtained your explicit consent to do so.
6. International Data Transfers
As a business operating within the European Union (Slovakia), we primarily store and process your data within the European Economic Area (EEA). However, some of our third-party service providers may be located outside the EEA, which may result in your personal data being transferred to countries that may not offer the same level of data protection as Slovak and EU law.
Where we transfer personal data outside the EEA, we ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR. These safeguards may include:
- Adequacy Decisions: Transfers to countries that the European Commission has determined provide an adequate level of data protection.
- Standard Contractual Clauses (SCCs): Legally binding contractual terms approved by the European Commission, incorporated into our agreements with data processors and recipients.
- Binding Corporate Rules (BCRs): Internal rules adopted by multinational corporate groups to govern intra-group data transfers.
- Certification Mechanisms: Adherence to approved certification frameworks that ensure equivalent data protection standards.
You may request information about the specific safeguards in place for international data transfers by contacting us at contact@pathweplan.com.
7. Data Security
We take the security of your personal data extremely seriously. We have implemented a range of technical and organizational measures designed to protect your personal information from unauthorized access, disclosure, alteration, loss, or destruction, in accordance with Article 32 of the GDPR.
7.1 Technical Measures
- Encryption: All data transmitted between your browser and our servers is encrypted using industry-standard Transport Layer Security (TLS) protocols. Sensitive data, including passwords, is encrypted at rest using strong cryptographic algorithms.
- Access Controls: Access to personal data is restricted to authorized personnel only, on a strict need-to-know basis. Multi-factor authentication (MFA) is used for administrative access.
- Firewalls and Intrusion Detection: We deploy firewalls, intrusion detection systems, and security monitoring tools to protect our infrastructure.
- Regular Security Audits: We conduct periodic security assessments and vulnerability scans to identify and address potential weaknesses.
- Secure Data Backups: Data is regularly backed up to secure, encrypted storage to ensure availability and recovery in the event of an incident.
7.2 Organizational Measures
- Regular staff training and awareness programs on data protection and information security.
- Internal data protection policies and procedures aligned with the GDPR and Slovak law.
- Data processing agreements (DPAs) with all third-party processors handling personal data on our behalf.
- A data breach response plan to ensure timely detection, investigation, and notification of data incidents as required by Article 33 of the GDPR.
8. Your Rights Under Data Protection Law
As a data subject under the GDPR and Slovak Act No. 18/2018 Coll. on the Protection of Personal Data, you have a comprehensive set of rights regarding your personal data. We are committed to upholding these rights and facilitating their exercise in a timely and transparent manner.
8.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of the personal data we hold about you, along with information about the purposes of processing, categories of data, recipients, retention periods, and your other rights.
8.2 Right to Rectification (Article 16 GDPR)
If any personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or supplement it without undue delay.
8.3 Right to Erasure — "Right to Be Forgotten" (Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected, when you withdraw your consent, or when the data has been unlawfully processed. Please note that this right is subject to certain exceptions under applicable law.
8.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or when you object to processing based on legitimate interests, pending our verification of those interests.
8.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or on a contract, and processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance from us.
8.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data where we rely on legitimate interests as the legal basis for processing. You also have the right to object at any time to the processing of your personal data for direct marketing purposes, including profiling related to direct marketing. Upon receipt of an objection to direct marketing, we will cease such processing immediately.
8.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you, unless such processing is necessary for a contract, authorized by law, or based on your explicit consent.
8.8 Right to Withdraw Consent
Where we process your personal data based on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing carried out prior to the withdrawal.
How to Exercise Your Rights
To exercise any of the rights listed above, please submit a written request to us using the following contact details:
- Email: contact@pathweplan.com
- Website: www.pathweplan.com
We will respond to your request within one month of receipt. This period may be extended by a further two months where necessary, taking into account the complexity and number of requests. We will inform you of any such extension within one month of receiving your request. We may need to verify your identity before processing certain requests.
9. Cookie Policy
Our website uses cookies and similar tracking technologies (such as web beacons, pixels, and local storage) to enhance your browsing experience, analyze website traffic, and support our marketing activities.
9.1 What Are Cookies?
Cookies are small text files that are stored on your device (computer, smartphone, or tablet) when you visit a website. They allow the website to recognize your device, remember your preferences, and provide a more personalized experience.
9.2 Types of Cookies We Use
| Cookie Category | Purpose | Legal Basis |
|---|---|---|
| Strictly Necessary | Essential for the website to function properly. Includes session management, security tokens, and load balancing. Cannot be disabled. | Legitimate Interests / Contractual Necessity |
| Functional / Preference | Remember your preferences, such as language settings, region, and login status, to provide a more personalized experience. | Consent |
| Analytics / Performance | Collect anonymized or pseudonymized data about how visitors use our website, helping us improve performance and usability. | Consent |
| Marketing / Targeting | Track your browsing activity across our website and other sites to deliver relevant advertising and measure the effectiveness of campaigns. | Consent |
9.3 Managing Your Cookie Preferences
When you first visit our website, you will be presented with a cookie consent banner allowing you to accept or decline non-essential cookies. You may also manage your cookie preferences at any time through our Cookie Settings tool available on our website. Additionally, most web browsers allow you to control cookie settings through the browser's settings or preferences menu.
Please note that disabling certain cookies may affect the functionality and performance of our website. For detailed information about the specific cookies we use, their lifespans, and how to manage them, please refer to our full Cookie Policy, available on our website.
10. Data Retention
We retain your personal data only for as long as is necessary to fulfill the purposes for which it was collected, unless a longer retention period is required or permitted by applicable Slovak or EU law. The criteria used to determine retention periods include:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account and registration data | Duration of account + 2 years after closure | Service provision and potential dispute resolution |
| Transaction and financial records | 10 years | Slovak accounting and tax obligations (Act No. 431/2002 Coll. on Accounting) |
| Marketing consent records | Until consent is withdrawn + 3 years | Proof of consent and legal compliance |
| Customer support communications | 3 years after resolution | Quality assurance and dispute resolution |
| Website usage and analytics data | Up to 26 months | Service improvement and analytics |
| Cookie consent records | 1 year from consent date | Compliance with ePrivacy requirements |
| Security and access logs | 12 months | Security monitoring and incident investigation |
When personal data is no longer required for any legitimate purpose, we will securely delete, destroy, or anonymize it in accordance with our internal data retention and disposal procedures.
11. Children's Privacy
If you are under the age of 18, you are not permitted to use our website or services, create an account, or provide any personal data to us. By using our services, you represent and warrant that you are at least 18 years of age.
If we become aware that we have inadvertently collected personal data from a person under the age of 18 without verified parental consent, we will take immediate steps to delete such data from our records. If you are a parent or guardian and believe that your child under 18 may have provided personal data to us, please contact us immediately at contact@pathweplan.com.
For users between the ages of 16 and 18 (if applicable under a specific legal context), the processing of personal data may require the consent of a parent or guardian in accordance with Article 8 of the GDPR and Slovak Act No. 18/2018 Coll.
12. Filing a Complaint with the Data Protection Authority
If you believe that our processing of your personal data infringes your rights under the GDPR or Slovak data protection law, you have the right to lodge a complaint with the competent supervisory authority. In Slovakia, the supervisory authority responsible for data protection is:
| Address | Hraničná 12, 820 07 Bratislava, Slovak Republic |
|---|---|
| Website | www.dataprotection.gov.sk |
| statny.dozor@pdp.gov.sk | |
| Phone | +421 2 3231 3214 |
We kindly ask that you contact us first at contact@pathweplan.com before filing a complaint with the supervisory authority, as many issues can be resolved quickly and informally through direct communication with us. However, you retain the absolute right to approach the authority directly at any time.
You may also have the right to lodge a complaint with the supervisory authority of an EU member state in which you habitually reside, work, or where the alleged infringement took place, if different from Slovakia.
13. Third-Party Websites and Links
Our website may contain links to third-party websites, applications, or services that are operated independently of Šepot. When you click on such links and leave our website, you are subject to the privacy policies and practices of those third-party sites. We are not responsible for the content, privacy practices, or data handling of any third-party websites, and we encourage you to review the privacy policies of any sites you visit.
The inclusion of any link on our website does not constitute an endorsement, recommendation, or guarantee of the third-party website or its services.
14. Changes to This Privacy Policy
We reserve the right to update, modify, or revise this Privacy Policy at any time to reflect changes in our data processing practices, legal requirements, or business operations. When we make material changes to this Policy, we will:
- Post the updated Privacy Policy on this page with a revised "Last Updated" date;
- Notify registered users by email where the changes are significant; and/or
- Display a prominent notice on our website informing users of the changes.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our website and services after the effective date of any changes constitutes your acknowledgment of the updated Privacy Policy.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, the processing of your personal data, or the exercise of your data subject rights, please do not hesitate to contact us:
| Business Name | Šepot |
|---|---|
| Location | Slovakia, European Union |
| contact@pathweplan.com | |
| Website | www.pathweplan.com |
We aim to acknowledge all privacy-related inquiries within 72 hours and to provide a full response within one calendar month, as required by Article 12 of the GDPR. If your request is complex or involves multiple data subjects, we may extend this period by a further two months and will notify you accordingly.
Governing Law: This Privacy Policy is governed by and construed in accordance with the laws of the Slovak Republic, including Act No. 18/2018 Coll. on the Protection of Personal Data, and applicable European Union law, including Regulation (EU) 2016/679 (GDPR). Any disputes arising under this Policy shall be subject to the jurisdiction of the competent courts of the Slovak Republic.
Effective Date: This Privacy Policy is effective as of July 30, 2026.