Principles of Personal Data Processing and the Personal Data Protection System in Accordance with the GDPR
Prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, pursuant to Articles 13 and 14 of the Regulation (hereinafter referred to as „GDPR“) and Act No. 18/2018 Coll. on the Protection of Personal Data (hereinafter referred to as „The Personal Data Protection Act“)
Operator:
Company Name: Monkeymedia s.r.o.
Registered office address: Sliačska 1212/1, 831 02 Bratislava – Nové Mesto district
Company ID: 53130251
Tax ID: 2121278236
VAT ID: SK2121278236
Phone: +421 910 954 999
Email: nextlevel@monkeymedia.sk
(hereinafter referred to as „Operator“)
The operator (controller) is not required to appoint or designate a data protection officer.
Basic Concepts
Personal data data relating to an identified natural person or an identifiable natural person, that can be identified directly or indirectly, in particular on the basis of a generally applicable identifier, an identifier other than, for example, a first name, last name, identification number, location data, or online identifier, or based on one or more characteristics or traits that constitute the individual’s physical identity, physiological identity, genetic identity, psychological identity, mental identity, economic identity, cultural identity, or social identity.
Processedie personal data means a processing operation or a set of processing operations performed on personal data or sets of personal data, in particular collection, recording, organization, structuring, storage, modification, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise, alignment or combination, restriction, or erasure, whether carried out by automated or non-automated means.
Data subject is any natural person whose personal data is being processed.
Operator anyone who, alone or jointly with others, determines the purposes and means of processing personal data and processes personal data on their own behalf.
Broker anyone who processes personal data on behalf of the controller.
Recipients is any person to whom personal data is disclosed, regardless of whether that person is a third party.
The person in charge a person designated by the controller or processor who performs tasks under this Act.
Profiling means any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular the analysis or prediction of aspects of the natural person’s performance at work, financial situation, health, personal preferences, interests, reliability, behavior, location, or movements.
Pseudonymization is the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is stored separately and is subject to technical and organizational measures to ensure that the personal data is not associated with an identified or identifiable natural person.
Information System It is any structured set of personal data that is accessible according to specified criteria, regardless of whether the system is centralized, decentralized, or distributed on a functional or geographic basis.
Third Party is a natural or legal person, public authority, agency, or entity other than the data subject, the controller, a processor, and persons who, on the basis of a direct authorization from the controller or processor, are entrusted with the processing of personal data.
Sources and Categories of Personal Data
We collect and process personal data from the following sources, depending on the nature of your relationship with our agency:
Directly from the individual concerned: information provided when filling out the contact form on our website, sending an email, or making a phone inquiry about our services; information necessary for preparing contracts, price quotes, and invoices (identification and payment information), data provided by job applicants in their resumes and cover letters, or when subscribing to our newsletter.
By tracking user behavior on our website: When you visit our website, we collect data automatically using technical tools: Analytical and technical data: IP address, browser type, duration of the visit, and browsing history on monkeymedia.sk, information about whether you opened our newsletter or clicked on a link within it (to improve the quality of our content), and data about your preferences collected through cookies (see our Cookie Policy for more details).
From third parties: Verification of data in the Slovak Commercial Register, the Slovak Trade License Registry, or the Finstat system for invoicing and legal certainty purposes; information from your public profiles (e.g., LinkedIn), if you communicate with us via these platforms or if they are part of your professional portfolio., As part of client system management We obtain access to data from our clients who have entrusted us with the management of their websites and databases, as well as data obtained in connection with the fulfillment of legal obligations (e.g., cooperation with the tax office or other regulatory authorities).
Legal Basis and Purpose of Personal Data Processing
Performance of a Contract and Pre-Contractual Relationships (Article 6(1)(b) of the GDPR)
Purpose: Processing your request for marketing services, preparing a quote, drafting contract documentation, and actually providing the services you’ve ordered (e.g., website development, campaign management, graphic design), Communication within the project management system, delivery of digital outputs, and handling any complaints.
Compliance with a legal obligation (Article 6(1)(c) of the GDPR)
Purpose: Maintaining data in the accounting system, processing invoices, and fulfilling obligations to government agencies (e.g., the Tax Office, the Labor Inspectorate), Processing data on clients (particularly self-employed individuals) and employees to the extent required by the Accounting Act, the Income Tax Act, and other relevant laws.
Legitimate interest of the controller (Article 6(1)(f) of the GDPR)
Purpose: Direct marketing to existing clients and protection of the company’s financial interests. Sending information about similar services and news (client newsletter), recording communication history in the CRM for the purposes of service continuity, and securing the network and data (backups to external SSD drives).
Social Media (Interaction): Managing Social Media Profiles (Facebook, Instagram, LinkedIn, TikTok), communicating with you through messages and comments, and building a community of brand fans.
Consent of the data subject (Article 6(1)(a) of the GDPR)
Purpose: Marketing communications to potential clients, storing resumes in a database (talent pool), and the use of optional analytical/marketing cookies if you subscribe to our newsletter without being our client, or if you give us consent to retain your resume after the recruitment process has ended -Your consent is voluntary, and you have the right to withdraw it at any time (e.g., by clicking the unsubscribe link in the email).
Social Media (Marketing and Pixel): The use of social media analytics and advertising tools (e.g., Meta Pixel, LinkedIn Insight Tag, TikTok Pixel) to target relevant ads and measure campaign effectiveness. You grant your consent via the cookie banner on our website.
Retention Period
We retain your personal data only for as long as necessary to fulfill the purpose for which it was collected, or for as long as required by applicable laws. Once these periods have expired, we will securely destroy the data.
We retain data related to the performance of a contract (clients, suppliers) for the duration of the contractual relationship.
We retain accounting documents and invoices for a period of 10 years in the years following the year to which they relate (in accordance with Act No. 431/2002 Z. z. on Accounting).
We retain data on potential customers (leads) who have not entered into a contract for a period of 2 years since our last communication regarding a potential collaboration.
We retain data processed on the basis of consent for a period of 3 to 5 years, or until you revoke your consent (unsubscribe).
In cases involving a legitimate interest (existing customers), we retain the data for the duration of the business relationship and for 2 years after it ends.
Throughout the selection process and thereafter 6 months after its completion (for the purpose of protecting legal claims).
If you have given us your consent to be included in the database (talent pool), we retain your data for a period of 3 years or until consent is revoked.
We retain the data to which we have access as a data processor only for the duration of the service agreement. Upon its termination, we revoke access and delete any local backups or copies.
Upon the expiration of the specified time periods or upon withdrawal of consent, we will destroy personal data in accordance with Act No. 395/2002 Coll. on Archives and Records Management:
Digital data: They will be permanently deleted from cloud storage, the CRM system, and local storage devices.
Physical documents: They will be destroyed by shredding at the P-4 classification level.
Recipients of Personal Data
Cloud service providers and office suite providers: Providers of email services, calendars, shared storage, and document creation tools.
CRM and project management system providers: Companies that provide software solutions for managing business relationships, tracking inquiries, and managing tasks within client projects.
Accounting and Billing Service Providers: Entities responsible for handling accounting, invoicing, and fulfilling statutory tax obligations.
IT support and technical service providers web hosting: Entities responsible for operating the agency's servers and websites and for maintaining its hardware.
Operators of social media and marketing platforms: Entities that provide tools for communication, community building, traffic analysis, and the targeting of relevant ads on social media. These platforms may collect data through cookies, pixels, and other tracking technologies placed on our website, or directly through your interaction with our profiles.
Public authorities: Entities to which we are required to disclose data pursuant to specific legal regulations (e.g., tax authorities, inspectorates, courts).
Transfer of Personal Data to Third Countries
The controller informs data subjects that the use of cloud services (Google Workspace) and analytics tools involves the cross-border transfer of personal data to third countries (the United States). This transfer is legally safeguarded in accordance with the European Commission’s adequacy decision under the EU-U.S. Data Privacy Framework, which ensures that providers in the U.S. adhere to data protection standards comparable to those of the GDPR. When using social media tools whose parent companies are based in the U.S., protection is ensured through certification under EU-U.S. Data Privacy Framework or standard contract clauses.
Automated Decision-Making and Profiling
Your personal data will not be used for automated individual decision-making, including profiling, within the meaning of Article 22 of the GDPR.
Terms and Conditions for the Protection of Personal Data
The operator declares that it has taken appropriate personnel, technical, and organizational measures to ensure the protection of personal data.
The operator has implemented technical measures to secure data storage systems and physical files containing personal data.
The operator declares that only persons authorized by it have access to personal data.
Your rights:
Under the conditions set forth in the GDPR, you have:
The Right of Access to One's Personal Data Under Article 15 of the GDPR
The Right to Rectification of Personal Data Under Article 16 of the GDPR
The Right to Erasure under Article 17 of the GDPR
The Right to Restriction of Processing Under Article 18 of the GDPR
The Right to Data Portability Under Article 20 of the GDPR
Right to object under Article 21 of the GDPR
The right to withdraw consent under Article 7 of the GDPR (electronically or by mail)
The right to file a complaint with the Office for Personal Data Protection if you believe that your personal data protection rights under Article 77 of the GDPR have been violated
How can you exercise your rights?
Right of Access to Data
You have the right to know whether we are processing your personal data. If we are processing it, you may request access to it. Upon your request, we will issue a confirmation containing information about the processing of your personal data.
Right to Correction
You have the right to ensure that the personal data we process about you is accurate, complete, and up-to-date. If your personal data is inaccurate or out of date, you may ask us to correct or supplement it.
Right to Erasure (the „right to be forgotten“)
Under certain circumstances, you have the right to have us delete your personal data. You may request that we delete your data at any time. We will delete your personal data if:
- the personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
- the data subject withdraws consent, if the processing is based on the data subject's consent,
- the data subject objects to the processing,
- personal data was processed unlawfully,
- personal data must be erased to comply with a legal obligation,
- if you are a child or the parent of a child who has consented to the processing of personal data online.
Right to Restrict Processing
You may ask us to restrict the processing of your personal data. If we grant your request, we will only store your personal data and will not process it further. The processing of your data will be restricted if
- you notify us that your personal information is incorrect, until we verify its accuracy,
- we are processing your personal data unlawfully, but you do not consent to its erasure and instead request that we only restrict the processing of your personal data,
- We no longer need your data, but you need it to establish, exercise, or defend your rights
- You object to the processing of your personal data until we verify whether our legitimate interests outweigh your reasons.
Right to Data Portability
You have the right to request that we provide you with your personal data in an electronic format (e.g., an XML or CSV file) that will allow you to easily transfer the data to another company. You may also ask us to transfer your personal data directly to a company of your choice. We will comply with your request provided that you provided the personal data to us directly and gave us your consent to process it.
Right to Object
You have the right to object to our processing of your personal data. If we process your personal data in the following cases:
- based on our legitimate interest,
- creating a customer profile,
- You may object to the processing of your personal data if you have personal reasons for doing so.
The right not to be subject to automated individual decision-making, including profiling
You have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you.
Your rights include:
the right to human intervention by the operator
the right to express your opinion
the right to challenge such a decision
Exceptions to this right are possible if the decision:
necessary for the conclusion or performance of a contract
permitted under Union or Member State law
based on express consent
Right to Withdraw Consent
If the controller processes your personal data based on consent/explicit consent, you have the right to withdraw that consent at any time
The right to file a petition to initiate proceedings regarding the protection of personal data
If you believe that your personal data protection rights have been violated, you may file a complaint with the supervisory authority, which is the Office for Personal Data Protection, located at the following address: ,
How can you exercise these rights?
You can contact us with your request in one of the following ways:
by email: nextlevel@monkeymedia.sk
tBy phone: +421 910 954 999
or by mail to the following mailing address: Sliačska 1212/1, 831 02 Bratislava - Nové Mesto District
This Privacy Policy becomes valid and effective upon its publication on the Website.






















