• Home
  • Portfolio
  • Services
    • 3D Visualizations
    • 3D Animations
    • 360° VR Tours
    • LED Presentations
  • About Us
  • Contact
  • SK
  • Home
  • Portfolio
  • Services
  • About Us
  • Contact

Updated: August 25, 2026

Back to home

Personal Data Processing Policy and Personal Data Protection System under the GDPR

prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data pursuant to Articles 13 and 14 of the Regulation (hereinafter referred to as "GDPR") and Act No. 18/2018 Coll. on Personal Data Protection (hereinafter referred to as the "Personal Data Protection Act")

Controller

Company name: Monkeystudios s. r. o.

Registered office address: Sliačska 1212/1, 831 02 Bratislava - Nové Mesto city district

Company ID: 57480265
Tax ID: 2122772245
VAT ID: the company is not a VAT payer

Website: monkeystudios.com

Email: weare@monkeystudios.com
Phone: +421 910 954 999

(hereinafter referred to as the "Controller")

The Controller (Administrator) is not required to appoint/designate a Data Protection Officer.

Basic Terms

Personal data means any information relating to an identified or identifiable natural person, who can be identified, directly or indirectly, in particular by reference to a generally applicable identifier, another identifier such as a first name, last name, identification number, location data, or an online identifier, or by reference to one or more characteristics or traits that form part of that person's physical identity, physiological identity, genetic identity, psychological identity, mental identity, economic identity, cultural identity, or social identity.

Processing of personal data means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

Data subject means any natural person whose personal data is processed.

Controller means anyone who, alone or jointly with others, determines the purposes and means of processing personal data and processes personal data on their own behalf.

Processor means anyone who processes personal data on behalf of the controller.

Recipient means anyone to whom personal data is disclosed, regardless of whether they are a third party.

Data Protection Officer means a person appointed by the controller or processor who performs duties under this Act.

Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning the data subject's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.

Pseudonymization means processing personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.

Filing system means any structured set of personal data that is accessible according to specific criteria, regardless of whether it is centralized, decentralized, or distributed on a functional or geographical basis.

Third party means a natural or legal person, public authority, agency, or other body, other than the data subject, controller, processor, or persons who, under the direct authority of the controller or processor, are authorized to process personal data.

Sources and Categories of Personal Data

We collect and process personal data depending on the nature of your relationship with our studio from the following sources:

Directly from the data subject: information provided when completing the contact form on the website, sending an email, or making a telephone inquiry about our services; information needed to prepare a contract, quote, and invoices (identification and payment information); information provided by job applicants in resumes and cover letters; and information provided when signing up for the newsletter.

By monitoring behavior on our websites: when you visit our website, we collect information automatically through technical tools: analytical and technical data, including IP address, browser type, length of visit, and browsing history on monkeystudios.sk; information about whether you opened our newsletter or clicked a link in it (to improve its content); and information about your preferences obtained through cookies (see our Cookie Policy for more information).

From third parties: Verification of information in the Commercial Register of the Slovak Republic, the Trade Register of the Slovak Republic, or the Finstat system for invoicing and legal certainty; information from your public profiles (such as LinkedIn) if you communicate with us through these platforms or if they form part of your professional portfolio. As part of fulfilling orders, clients may provide us with materials containing personal data if needed to create visualizations, animations, or other ordered deliverables. We may also obtain information while fulfilling legal obligations, such as cooperating with the tax office or other supervisory authorities.

Legal Basis and Purpose of Personal Data Processing

Performance of a Contract and Precontractual Relations (Art. 6(1)(b) GDPR)

Purpose: Handling your inquiry about 3D visualization and visual creation services, preparing a quote, preparing contractual documentation, and performing the ordered services themselves, such as 3D interior and exterior visualizations, 3D animations, 360° VR tours, and related visual deliverables; communication as part of project management, delivery of digital deliverables, and handling any complaints.

Compliance with a Legal Obligation (Art. 6(1)(c) GDPR)

Purpose: Retaining information in accounting records, processing invoices, and fulfilling obligations to public authorities, such as the tax office and labor inspectorate; processing information about clients, especially self-employed individuals, and employees to the extent required by the Accounting Act, the Income Tax Act, and other applicable laws.

Legitimate Interest of the Controller (Art. 6(1)(f) GDPR)

Purpose: Direct marketing to existing clients and protecting the company's property interests. Sending information about similar services and news (client newsletter), recording communication history in the CRM system to ensure continuity of service, and securing the network and data (backups to external SSD drives).

Social Media (Interaction): Managing profiles on social media (Facebook, Instagram, LinkedIn, TikTok), communicating with you through messages and comments, and building a community of brand supporters.

Consent of the Data Subject (Art. 6(1)(a) GDPR)

Purpose: Marketing communications to potential clients, retaining resumes in a database (talent pool), and using optional analytics/marketing cookies if you sign up for the newsletter without being our client, or if you consent to retaining your resume after the hiring process ends - Consent is voluntary, and you have the right to withdraw it at any time, such as by clicking the unsubscribe link in an email.

Social Media (Marketing and Pixel): Using analytics and advertising tools from social media platforms, such as Meta Pixel, LinkedIn Insight Tag, and TikTok Pixel, to target relevant advertising and measure campaign effectiveness. You provide consent through the cookie banner on our website.

Retention Period

We retain your personal data only for as long as necessary to achieve the purpose for which it was collected, or for the period required by applicable law. After these periods expire, we securely destroy the data.

We retain data related to contract performance, including client and supplier data, for the duration of the contractual relationship.

We retain accounting records and invoices for 10 years following the year to which they relate, in accordance with Act No. 431/2002 Coll. on Accounting.

We retain data about potential clients (leads) who did not enter into a contract for 2 years from the last communication, for the purpose of potentially establishing a business relationship.

We retain data processed based on consent for 3 to 5 years, or until you withdraw your consent or unsubscribe.

Where we rely on a legitimate interest, such as for existing clients, we retain data for the duration of the business relationship and for 2 years after it ends.

For the duration of the hiring process and subsequently for 6 months after it ends, for the purpose of protecting legal claims.

If you have consented to being included in the database (talent pool), we retain the data for 3 years or until you withdraw your consent.

We retain data to which we have access as a processor only for the duration of the service agreement. After it ends, we revoke access and delete any local backups or copies.

After the stated periods expire or consent is withdrawn, we dispose of personal data in accordance with Act No. 395/2002 Coll. on Archives and Records Management:

Digital data: Will be permanently deleted from cloud storage, the CRM system, and local storage media.

Physical documents: Will be destroyed by shredding at security level P-4.

Recipients of Personal Data

Cloud service and office suite providers: Entities providing email communications, calendars, shared storage, and tools for creating documentation.

CRM and project system providers: Entities supplying software solutions for managing business relationships, recording inquiries, and managing tasks within client projects.

Accounting and invoicing service providers: Entities handling accounting records, invoicing, and compliance with statutory tax obligations.

IT support and technical hosting providers: Entities responsible for operating servers and websites and maintaining the studio's hardware.

Social media and marketing platform operators: Entities that provide tools for communication, community building, traffic analysis, and targeting relevant advertising on social media. These platforms may collect information through cookies, pixels, and other tracking technologies placed on our website, or directly when you interact with our profiles.

Public authorities: Entities to which we are required to disclose data under specific legal regulations, such as tax offices, inspectorates, and courts.

Transfers of Personal Data to Third Countries

The Controller informs data subjects that when using cloud services (Google Workspace) and analytics tools, personal data is transferred across borders to third countries (the USA). This transfer is legally safeguarded in accordance with the European Commission's adequacy decision under the EU-U.S. Data Privacy Framework, which guarantees that providers in the USA comply with data protection standards comparable to the GDPR. When using social media tools whose parent companies are based in the USA, protection is ensured through certification under the EU-U.S. Data Privacy Framework or standard contractual clauses.

Automated Decision-Making and Profiling

Your personal data will not be used for automated individual decision-making, including profiling, within the meaning of Article 22 of the GDPR.

Personal Data Security Measures

The Controller declares that it has adopted appropriate personnel, technical, and organizational measures to ensure the protection of personal data.

The Controller has adopted technical measures to secure data storage and storage of personal data in physical files.

The Controller declares that only persons authorized by the Controller have access to personal data.

Your Rights

Under the conditions set out in the GDPR, you have:

  • Right of access to your personal data under Art. 15 GDPR
  • Right to rectification of personal data under Art. 16 GDPR
  • Right to erasure under Art. 17 GDPR
  • Right to restriction of processing under Art. 18 GDPR
  • Right to data portability under Art. 20 GDPR
  • Right to object under Art. 21 GDPR
  • Right to withdraw consent under Art. 7 GDPR, electronically or at the correspondence address
  • Right to lodge a complaint with the data protection authority if you believe that your data protection rights have been violated under Art. 77 GDPR

How Can You Exercise Your Rights?

Right of Access to Data

You have the right to know whether we process your personal data. If we process it, you may ask us for access to it. Upon your request, we will issue confirmation containing information about the processing of your personal data.

Right to Rectification

You have the right for the personal data we process to be accurate, complete, and up to date. If your personal data is incorrect or outdated, you may ask us to correct or supplement it.

Right to Erasure (the "Right to Be Forgotten")

Under certain circumstances, you have the right to have your personal data erased. You may ask us to erase your data at any time. We will erase your personal data if:

  • the personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
  • the data subject withdraws consent, where processing is based on the data subject's consent,
  • the data subject objects to the processing,
  • the personal data has been processed unlawfully,
  • the personal data must be erased to comply with a legal obligation,
  • you are a child or, as applicable, the parent of a child who consented to the processing of personal data online.

Right to Restriction of Processing

You may ask us to restrict the processing of your personal data. If we grant your request, we will only store your personal data and will not otherwise process it. Processing of your data will be restricted if

  • you inform us that your personal data is inaccurate, until we verify its accuracy,
  • we process your personal data unlawfully, but you do not agree to its erasure and instead ask us only to restrict the processing of your personal data,
  • we no longer need your data, but you need it to establish, exercise, or defend your legal rights
  • you object to the processing of your personal data, until we verify whether our legitimate interests outweigh your reasons.

Right to Data Portability

You have the right to ask us to provide your personal data in electronic form, such as an XML or CSV file, which allows you to easily transfer the data to another company. You may also ask us to transfer your personal data directly to a company you select. We will comply with your request if you provided the personal data directly to us and consented to its processing.

Right to Object

You have the right to object to our processing of your personal data. If we process your personal data in the following cases:

  • due to our legitimate interest,
  • to create a customer profile,
  • you may object to its processing if you have personal reasons for doing so.

Right Not to Be Subject to Automated Individual Decision-Making, Including Profiling

you have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you.

Your right includes:

  • the right to obtain human intervention from the controller
  • the right to express your point of view
  • the right to challenge such a decision

exceptions to this right may apply if the decision is:

  • necessary for entering into or performing a contract
  • authorized by European Union or Member State law
  • based on explicit consent

Right to Withdraw Consent

if the Controller processes your personal data based on consent or explicit consent, you have the right to withdraw that consent at any time

Right to Request the Initiation of Personal Data Protection Proceedings

If you believe that your data protection rights have been violated, you may lodge a complaint with the supervisory authority, the Office for Personal Data Protection of the Slovak Republic, Galvaniho Business Centrum II, Galvaniho 7/B, 821 04 Bratislava, Slovak Republic.

How Can You Exercise These Rights?

You may contact us with your request in one of the following ways:

  • by email: weare@monkeystudios.com
  • by phone: +421 910 954 999
  • or by mail at the correspondence address: Sliačska 1212/1, 831 02 Bratislava - Nové Mesto city district

These Personal Data Protection Principles become valid and effective upon publication on the Website.

Where space is created, the first impression is created too.

Legal

  • GDPR
  • Monkeystudios s. r. o.

Address

Bratislava, Sliačska 1
Slovakia

Contact

  • +421 910 954 999
  • weare@monkeystudios.com

Social media

  • Instagram
  • Facebook
  • LinkedIn
MONKEYSTUDIOS ®