Privacy Policy
TI Capital s.r.o., with its registered office at Talichova 2110/2, 841 02 Bratislava – Dúbravka district. Company ID (IČO): 55941362, Tax ID (DIČ): 2122141516, registered in the Commercial Register of the Bratislava III District Court, Section Sro, Insert No. 175070/B. Tel.: +421 940 984 000, Email: info@ti-capital.sk
1. Protection of Personal Data
1.1. The Contracting Parties acknowledge and agree that, within the contractual relationship established by the Agreement, the provider is a Processor under Article 28 of Regulation (EU) 2016/679 (GDPR) and the client is the Controller under Article 4(7) GDPR. Further conditions of personal data processing shall be agreed between the parties in a separate contract concluded under Article 28(3) GDPR.
1.2. The provider is authorised to process personal data on the client's behalf as Processor from the effective date of the Agreement. The client and the provider agree that Article 1 of this Privacy Policy fully replaces the contract within the meaning of Sections 34 et seq. of Act No. 18/2018 Coll. on Personal Data Protection.
1.3. The subject of this Article is the client's instructions to the provider in the process of personal data processing.
1.4. When the purpose of personal data processing has ended, and at the latest before the Agreement expires, the provider shall promptly hand over to the client all personal data and related processing documents in its information system that were provided by the client or by data subjects, including in an accessible electronic form where one exists. Documents containing personal data that are delivered by email are sent by the provider in an encrypted format (ZIP or PDF), protected by a password that meets the provider's password security policy. If handover of the data is not possible, the provider shall ensure their immediate destruction. After the purpose of processing has ended, the client shall ensure the storage and protection of the personal data in accordance with applicable law.
1.5. Personal data are processed by both automated and non-automated means.
1.6. The purpose of personal data processing, the name of the information system, and the list or scope of the personal data processed are specified in Appendix 1 to this Privacy Policy.
1.7. For the purposes of this Article, data subjects are primarily natural persons — the client's customers (clients) and staff (employees).
1.8. Obligations and Rights of the Client
a) The client shall provide the provider with all cooperation necessary for the fulfilment of this Article.
b) The client has the right to request from the provider regular reports on the state of protection of the personal data processed, and the provider must provide them without undue delay.
c) If the client entrusted the provider with personal data processing only after the personal data were collected, the client must ensure that data subjects are notified of this fact at the first contact with them, and no later than three months from the date the provider was entrusted. This also applies where processing is taken over by the client's legal successor within the meaning of Section 69 of the Commercial Code.
1.9. Obligations of the Provider
a) Process personal data only on the basis of the client's written instructions.
b) Ensure that persons authorised to process personal data (e.g., the provider's employees) have committed themselves to confidentiality regarding the information they learn.
c) Follow the security measures under Section 39 of the Personal Data Protection Act when processing personal data.
d) Assist the client, through appropriate technical and organisational measures, in fulfilling the client's obligation to act on data subjects' requests under the Personal Data Protection Act.
e) Return personal data to the client after the provision of services relating to personal data processing has ended.
f) Erase existing copies containing personal data upon the client's decision.
g) Provide the client with the information necessary to demonstrate compliance with its obligations, and cooperate with personal data protection audits and inspections carried out by the client or by an auditor appointed by the client.
h) Inform the client without undue delay if, in the provider's view, an instruction of the client infringes the GDPR, the Personal Data Protection Act, another special law, or an international treaty binding on the Slovak Republic concerning personal data protection.
i) Notify the client without undue delay of any personal data breach after becoming aware of it.
j) At the first contact with a data subject, always inform them that their personal data are processed on the client's behalf for a defined or established purpose.
k) Not share the client's personal data with third parties, except where necessary for filing tax returns with the tax office or where required by applicable law.
l) Ensure technical and organisational measures, including the use of servers within the EU. Data transmission is secured using TLS 1.2 or higher, and stored data are encrypted with the AES-256 standard. Regular security audits and system testing are performed as needed.
m) Retain personal data processed in connection with electronic services (E-forms) for 5 years from the client's last activity.
1.10. Personal Data Processing Conditions
a) The provider shall ensure, in accordance with the GDPR, the Personal Data Protection Act, and appropriate technical and organisational measures, that personal data are processed and disclosed to the competent institutions under special laws in a way that secures the purpose of processing and the protection of the personal data.
b) The provider shall ensure the protection of data subjects' personal data — in particular their confidentiality, integrity, and availability — in accordance with the GDPR, the Personal Data Protection Act, and technical, organisational, and personnel security measures.
1.11. Permitted Personal Data Operations
a) The provider's permitted activities in the information systems listed in Appendix 1 consist of performing operations, or sets of operations, with personal data, including collection, recording, organising, structuring, alteration, retrieval, consultation, use, disclosure, combination, storage, deletion, and other lawful operations, to the extent and under the conditions laid down in applicable law and agreed in this Privacy Policy.
b) The provider may obtain and process personal data only from the persons listed in Appendix 1, and only to the extent necessary to provide the services.
c) The provider shall not use or combine personal data obtained from the client for purposes other than those specified in Appendix 1.
d) The provider shall implement technical, organisational, and personnel measures proportionate to the processing risk, taking into account the confidentiality and importance of the data and the potential risks to the security and functionality of its information systems.
e) The provider and its employees must maintain the confidentiality of personal data obtained from the client that they come into contact with in the course of providing services, and remain bound by it after the assignment ends.
f) The provider warrants that it will not process personal data contrary to the data subjects' legitimate interests and will not infringe their rights or their privacy.
g) The provider shall ensure that persons who, on its instruction, come or may come into contact with personal data are informed of their rights, obligations, and responsibilities before the first instruction is issued.
h) The provider shall process personal data in accordance with good morals and all applicable laws.
1.12. Personal Data Processing via Electronic Services (E-forms) and Contact Forms
a) The provider processes personal, financial, and contact data entered by the client through the web application, in accordance with the GDPR and applicable law.
b) Data processed via E-forms are used exclusively for the preparation and filing of tax returns and for communication with the customer.
c) Contact forms are used for the client's communication with the provider; only the minimum necessary data are collected. The legal basis for processing is Article 6(1)(b) GDPR (necessity for performance of a contract or pre-contractual measures) and Article 6(1)(f) GDPR (the provider's legitimate interest in communication). Data collected through contact forms are not used for advertising or profiling purposes.
d) Personal data are not shared with third parties, except where necessary for filing tax returns or where required by law.
e) Data are stored on EU-based servers, transmitted via TLS 1.2+, and encrypted at rest with AES-256.
f) Personal data processed via E-forms and contact forms are retained for five years from the client's last activity.
g) The client may request access to their data upon identity verification; if no data exist, the client will be informed accordingly.
1.13. Website Analytics and Cookies
a) The provider's website does not use advertising or tracking cookies. No consent banner is displayed because no cookies requiring consent are set.
b) To understand which pages of this website are visited and how often, the provider uses a privacy-friendly, self-hosted analytics tool running on the provider's own servers within the EU. This tool does not set cookies, does not store any information on user devices, does not collect data that can identify users personally, and processes only aggregate anonymous statistics such as page views and referring sites. Because no cookies or personal identifiers are used, this measurement does not require consent under Article 5(3) of Directive 2002/58/EC (ePrivacy Directive). User data are never sold or shared with advertising networks.
c) The website does not use Google Analytics, Google Tag Manager, Google Ads, Google Maps, Facebook Pixel (Meta), Stripe, reCAPTCHA, or any other advertising network tools. Fonts are self-hosted on the provider's servers; no requests are made to Google Fonts or other external font services on page load.
d) In the client portal (login area), strictly necessary session cookies may be used. These cookies expire at the end of the session or shortly after logout, serve exclusively to maintain the authenticated session, do not transfer personal data to third parties, and do not require consent.
1.14. When providing services, the provider may use automated document processing tools, including third-party artificial intelligence services acting as sub-processors under Article 28 GDPR. Such services are used exclusively for the structured extraction of data from accounting documents. The provider guarantees that sub-processors: (i) process data within the EU; (ii) are bound by a data processing agreement (DPA) with terms no less stringent than this Privacy Policy; (iii) do not use the client's data for model training or any other purpose; (iv) delete data no later than 30 days after processing.
Appendix 1 (dated 15 October 2025)
Information System Name and Processed Data
| Information System Name | Purpose of Personal Data Processing | Categories of Personal Data |
|---|---|---|
| Simple Accounting and Tax Returns for Individuals | Accounting records and preparation of tax returns for individuals | Full name; Tax identification number; Contact details; Financial data; Income and expense data; Bank account information; Tax benefit data |
| Client Database | Storage and maintenance of client contact information, management of contractual relationships | Full name; Address; Phone number; Email; Tax identification number; Interaction history; Contractual terms information |
| HR Records and Payroll | Maintaining personnel records, calculating salaries and taxes | Full name; Passport data; Position; Salary; Tax information; Bank details; Leave and sick leave information |
| Double-Entry Accounting and Tax Returns for Legal Entities | Maintaining accounting records and preparation of tax returns for legal entities | Organisation name; Tax identification number; Contact details; Financial statements; Bank account data; Tax documents |
| Business Travel | Recording and monitoring employee business trips, calculation of compensations | Employee full name; Travel dates and locations; Route; Expenses; Supporting documents |
| Electronic Services ("E-forms") | Collection of data for preparation and submission of tax returns and other formal documents via electronic forms | Personal data (full name, address, contacts); Tax data; Income and expense data; Bank details |
| Contact Forms | Receiving and processing inquiries and requests from clients via contact forms on the website | Full name; Contact phone number; Email address; Inquiry content |
| (AI) Automated Recognition and Structuring of Accounting Documents | Automated recognition and structuring of invoices for accounting purposes | Organisation name; IČO, DIČ, IČ DPH; Address; Bank details; Amounts; Description of goods/services |