LesAi logoLesAi

GDPR & Privacy Policy

This document explains how LesAi processes personal data in line with GDPR and Slovak Act No. 18/2018 Coll.

Updated: February 26, 2026

1. Controller

Controller: Ramige s.r.o.

Company ID: 53 808 673

Contact e-mail: hello@lesai.sk

Registered office and commercial register details: complete before production publishing.

2. Purposes of processing

  • handling contact form requests and follow-up communication
  • pre-contract communication and proposal preparation
  • contract and legal compliance duties after cooperation starts
  • website security, incident prevention, and logging
  • service quality improvements and internal reporting
  • traffic measurement, campaign attribution, and advertising performance measurement based on voluntary cookie consent

3. Categories of personal data

  • identity and contact data: name, e-mail, company (if provided)
  • communication content: message text and follow-up replies
  • technical data: IP address, request timestamp, user-agent, basic server logs
  • analytics and attribution data (with consent): pseudonymous visitor/session identifiers, pageview events, and campaign UTM/click-id parameters

4. Legal bases (Art. 6 GDPR)

  • Art. 6(1)(b): pre-contract steps and contract performance
  • Art. 6(1)(c): legal obligations (e.g., accounting)
  • Art. 6(1)(f): legitimate interests in security, operations, and legal claims defense
  • Art. 6(1)(a): consent for optional analytics and marketing cookies/scripts and related campaign attribution

5. Recipients and processors

Data may be processed only by authorized staff and contracted processors (e.g., hosting, e-mail infrastructure, technical system administration).

We sign data processing agreements under Art. 28 GDPR and require appropriate technical and organizational safeguards.

When marketing consent is granted, recipients may also include analytics and ad technology providers (e.g., Google Ireland Limited, Meta Platforms Ireland Limited).

6. Transfers outside the EU/EEA

If external analytics/ad tools are enabled, data transfers outside the EU/EEA (primarily to the U.S.) may occur.

Any such transfer is performed only under lawful GDPR mechanisms (adequacy decision or standard contractual clauses) with additional safeguards.

7. Retention periods

  • contact requests: typically 24 months after the last communication
  • contract/accounting agenda: statutory periods (typically up to 10 years for accounting records)
  • security logs: typically up to 90 days, longer only for incident handling or legal claims
  • internal analytics events (pageview/CTA/scroll/engagement): typically up to 400 days
  • cookie consent record: typically 12 months

8. Data subject rights

  • right of access
  • right to rectification
  • right to erasure or restriction where legally applicable
  • right to data portability
  • right to object to legitimate-interest processing
  • right to withdraw consent (where consent is the legal basis)
  • right to lodge a complaint with the Slovak Data Protection Authority

9. Automated decision-making

We do not perform solely automated decision-making with legal or similarly significant effects on data subjects on this website.

10. Security measures

  • access management and least-privilege approach
  • continuous patching, hardening, and environment isolation
  • encrypted data transport (HTTPS/TLS)
  • event logging and operational auditability

11. Rights requests and authority

For GDPR requests, contact hello@lesai.sk.

Supervisory authority: Slovak Data Protection Authority, https://dataprotection.gov.sk.

12. Document updates

This policy may be updated as needed. The latest version is always published on this page with the last update date.