PRIVACY POLICY
Last updated: May 2026
This Privacy Policy explains how personal data is collected, processed, stored, and protected in connection with this website (www.ludmilaharing.com), consulting services, strategic advisory work, communication, and related business operations.
This website and all related services are intended exclusively for business clients (B2B).
1. DATA CONTROLLER
The controller responsible for data processing under the General Data Protection Regulation (GDPR) is:
Saphrani s.r.o.
Nová Ľubovňa 644
065 11 Nová Ľubovňa
Slovakia
Company Registration Number (IČO): 48324604
Email: studio@ludmilaharing.com
Phone: +421 949 001 716
Website: www.ludmilaharing.com
Data Protection Contact:
For all data protection inquiries, requests, or complaints, please contact: hello@ludmilaharing.com
As a small business, Saphrani s.r.o. acts as its own Data Protection Officer (DPO) responsible for GDPR compliance.
2. PERSONAL DATA WE COLLECT
Depending on the nature of your interaction with our website and services, we may collect and process the following categories of personal data:
2.1 Contact & Identity Information
Full name
Email address
Phone number
Job title / role
Company name and address
LinkedIn profile (if voluntarily provided)
2.2 Business & Financial Information
Billing and invoicing details (company address, tax/VAT information if applicable)
Bank account information (for payment processing purposes only)
Purchase history and payment records
2.3 Project & Business Data
Strategic business information, brand positioning, market data
Collection data, SKU information, sales performance, inventory levels
Operational data (production processes, supplier information, quality metrics)
Supply chain information (for DPP and sustainability projects)
Financial data (revenue, margin analysis, cost structures — where relevant to consulting engagement)
Organizational structure, team information, stakeholder details
2.4 Employee & Collaborator Information
Names, roles, and contact details of client's employees, team members, or stakeholders involved in projects (where necessary for service delivery)
2.5 Communication Records
Email correspondence
Meeting notes, workshop materials, session summaries
Audio and/or video recordings of strategy sessions, workshops, and diagnostic interviews (with consent)
Feedback, questionnaires, and survey responses
2.6 Website & Technical Data
IP address
Browser type and version
Device type and operating system
Pages visited, time spent on pages, click behavior
Referral source (how you found the website)
Cookies and similar tracking technologies (see Section 7)
3. HOW WE COLLECT PERSONAL DATA
Personal data may be collected through:
Direct communication: Email, phone calls, video meetings, contact forms, booking requests
Service engagement: Contracts, proposals, project briefs, onboarding questionnaires
Website interaction: Contact forms, newsletter signup, cookie consent, analytics
Meetings & workshops: Information shared during strategic sessions, interviews, collaborative workshops
Third-party platforms: Information provided through collaboration tools (Google Drive, Notion, Miro, Zoom, etc.)
4. PURPOSE & LEGAL BASIS FOR PROCESSING
We process personal data for the following purposes, based on the legal grounds outlined under GDPR:
4.1 Contractual Necessity (Art. 6(1)(b) GDPR)
Purpose:
To provide consulting and strategic advisory services, fulfill contractual obligations, and deliver agreed deliverables.
Activities include:
Project management, communication, and coordination
Diagnostic analysis, strategic frameworks, and reporting
Workshops, advisory sessions, and strategic planning
Quality assurance and project review
Legal Basis:
Processing is necessary for the performance of a contract or to take steps at your request prior to entering into a contract.
4.2 Legitimate Interests (Art. 6(1)(f) GDPR)
Purpose:
To operate and improve our business, manage client relationships, ensure quality service delivery, and protect our legal rights.
Activities include:
Internal business operations, administration, and accounting
Improving service quality and developing new offerings
Fraud prevention, security, and legal compliance
Resolving disputes and enforcing contractual terms
Website functionality, analytics, and user experience optimization
Legal Basis:
Processing is necessary for our legitimate business interests, provided these do not override your fundamental rights and freedoms.
4.3 Legal Obligation (Art. 6(1)(c) GDPR)
Purpose:
To comply with legal and regulatory obligations.
Activities include:
Tax reporting, accounting, and financial record-keeping (as required under Slovak tax law)
Responding to legal requests, court orders, or regulatory inquiries
Compliance with EU and Slovak data protection laws
Legal Basis:
Processing is necessary to comply with a legal obligation to which we are subject.
4.4 Consent (Art. 6(1)(a) GDPR)
Purpose:
To send marketing communications, newsletters, or use data for purposes beyond contractual necessity.
Activities include:
Sending newsletters, industry insights, or promotional content
Creating case studies or testimonials (with explicit approval)
Using client logos or project details in marketing materials (with written consent)
Legal Basis:
You have given explicit consent for the specific purpose.
You may withdraw consent at any time by contacting hello@ludmilaharing.com or using the unsubscribe link in email communications. Withdrawal of consent does not affect the lawfulness of processing based on consent before withdrawal.
5. COMMUNICATION & COLLABORATION TOOLS
To deliver consulting services effectively, we use the following third-party platforms and tools, which may process your personal data as subprocessors under Art. 28 GDPR:
5.1 Email & Document Sharing
Google Workspace (Gmail, Google Drive, Google Docs, Google Sheets)
Used for: Email communication, document collaboration, file storage
Data location: EU data centers (GDPR-compliant)
Privacy policy: https://policies.google.com/privacy
Dropbox
Used for: File sharing and storage
Data location: EU/US (Standard Contractual Clauses in place)
Privacy policy: https://www.dropbox.com/privacy
5.2 Video Conferencing
Zoom
Used for: Video calls, strategy sessions, workshops
Data location: EU/US (GDPR-compliant, Standard Contractual Clauses)
Privacy policy: https://zoom.us/privacy
Google Meet
Used for: Video conferencing
Data location: EU data centers (GDPR-compliant)
Privacy policy: https://policies.google.com/privacy
Microsoft Teams
Used for: Video calls and collaboration (where client prefers)
Data location: EU data centers (GDPR-compliant)
Privacy policy: https://privacy.microsoft.com
5.3 Collaboration & Project Management
Notion
Used for: Project documentation, strategic frameworks, knowledge management
Data location: US (Standard Contractual Clauses in place)
Privacy policy: https://www.notion.so/privacy
Miro
Used for: Visual collaboration, workshops, brainstorming sessions
Data location: EU/US (GDPR-compliant)
Privacy policy: https://miro.com/legal/privacy-policy/
5.4 Messaging (Optional)
WhatsApp Business
Used for: Quick coordination, scheduling, informal client communication (where client prefers)
Data location: Owned by Meta; end-to-end encrypted
Privacy policy: https://www.whatsapp.com/legal/privacy-policy-eea
Note: WhatsApp is used only with client consent and for non-sensitive coordination. Confidential business information is shared via encrypted email or secure platforms.
5.5 Recording of Meetings
Strategy sessions, workshops, diagnostic interviews, and client meetings may be recorded (audio and/or video) for the following purposes:
Documentation and record-keeping
Project analysis and strategic development
Quality assurance and internal review
Transcription and accurate note-taking
Educational purposes (anonymized, with explicit consent)
By participating in meetings, you consent to such recordings where applicable.
You will be informed at the beginning of any recorded session. Recordings are:
Stored securely on encrypted cloud storage (Google Drive or local encrypted storage)
Treated as confidential under the terms of our service agreements
Not shared publicly or with third parties without explicit written consent
Retained only for the duration necessary for project purposes, then securely deleted
You may request that a meeting not be recorded by notifying us at the start of the session.
6. WEBSITE HOSTING & PLATFORM PROVIDER
6.1 Website Hosting
This website is built and hosted using onepage.io.
What onepage.io processes:
Technical data (IP addresses, browser type, device information)
Form submissions (name, email, phone, message content from contact forms)
Website analytics and usage statistics
Hosting-related data necessary for website functionality
Data location: EU/US (GDPR-compliant hosting provider)
Privacy policy: https://www.onepage.io/privacy-policy
6.2 Contact Forms
When you submit a contact form, booking request, or inquiry through the website:
Your information is transmitted securely via HTTPS encryption
Data is stored in onepage.io systems and forwarded to our business email (Google Workspace)
We respond to inquiries typically within 1–2 business days
Contact form data is retained as part of our communication records (see Section 9: Data Retention)
7. COOKIES & ANALYTICS
7.1 What Are Cookies?
Cookies are small text files placed on your device when you visit a website. They help the website recognize your device on future visits and improve functionality and user experience.
7.2 Types of Cookies We Use
Strictly Necessary Cookies:
Essential for website functionality (e.g., session management, security, basic navigation).
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) — these cannot be disabled.
Analytics Cookies:
Used to understand how visitors use the website (page views, traffic sources, user behavior).
Legal basis: Consent (Art. 6(1)(a) GDPR) — you can opt out.
Marketing/Preference Cookies:
Used to deliver relevant content and measure marketing effectiveness.
Legal basis: Consent (Art. 6(1)(a) GDPR) — you can opt out.
7.3 Analytics Tools
We may use the following analytics services:
Google Analytics (if implemented)
Used for: Website traffic analysis, user behavior insights
Data location: EU/US (anonymized IP where possible)
Privacy policy: https://policies.google.com/privacy
Opt-out: https://tools.google.com/dlpage/gaoptout
onepage.io built-in analytics
Used for: Website performance monitoring
Privacy policy: https://www.onepage.io/privacy-policy
7.4 Managing Cookie Preferences
You can control cookies through:
Cookie consent banner — accept or reject non-essential cookies
Browser settings — most browsers allow you to block or delete cookies
Chrome: Settings > Privacy and security > Cookies
Firefox: Settings > Privacy & Security > Cookies
Safari: Preferences > Privacy > Cookies
Edge: Settings > Privacy > Cookies
Note: Disabling necessary cookies may affect website functionality (e.g., forms may not submit properly, sessions may not persist).
8. NEWSLETTER & EMAIL MARKETING
8.1 Newsletter Service
Email communication, newsletters, and marketing campaigns may be managed using Brevo (formerly Sendinblue).
Brevo processes:
Email addresses
Name and contact details
Email interaction statistics (opens, clicks, engagement)
Subscription preferences and consent records
Data location: EU (GDPR-compliant)
Privacy policy: https://www.brevo.com/legal/privacypolicy/
8.2 How We Use Your Email
Transactional emails (always sent, no consent required):
Booking confirmations, payment receipts, invoices
Project updates, deliverable notifications
Responses to inquiries and support requests
Marketing emails (requires consent):
Newsletters with industry insights, strategic guidance, and thought leadership content
Announcements of new services, workshops, or resources
Invitations to webinars, events, or educational content
8.3 Unsubscribing
You may unsubscribe from marketing emails at any time by:
Clicking the "Unsubscribe" link at the bottom of any marketing email
Sending an email request to hello@ludmilaharing.com with the subject "Unsubscribe"
Unsubscribing from marketing emails does not affect:
Transactional emails related to active projects or services
Legal or contractual communications
9. DATA SHARING & THIRD-PARTY PROCESSORS
9.1 Who We Share Data With
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
Personal data may be shared with trusted third-party service providers acting as data processors under Art. 28 GDPR, including:
Service ProviderPurposeData LocationSafeguards
Google Workspace - Email, document collaboration, storage - EU - GDPR-compliant, DPA in place
Brevo - Email marketing, newsletters - EU - GDPR-compliant, DPA in place
Zoom - Video conferencing, workshops - EU/US - Standard Contractual Clauses (SCCs)
Microsoft Teams - Video calls, collaboration - EU - GDPR-compliant, DPA in place
onepage.io - Website hosting, forms - EU/US - GDPR-compliant hosting
Notion - Project management, documentation - US - Standard Contractual Clauses (SCCs)
Miro - Visual collaboration, workshops - EU/US - GDPR-compliant
WhatsApp BusinessClient communication (optional)Meta/US - End-to-end encryption
Dropbox - File sharing, storage - EU/US - Standard Contractual Clauses (SCCs)
9.2 International Data Transfers
Some service providers may process data outside the European Economic Area (EEA).
When data is transferred internationally, we ensure appropriate safeguards are in place:
Standard Contractual Clauses (SCCs) approved by the European Commission
Adequacy decisions (e.g., for countries deemed to provide adequate data protection)
Privacy Shield successor frameworks (where applicable and legally valid)
Data Processing Agreements (DPAs) with GDPR-compliant processors
You may request more information about specific international transfers and safeguards by contacting hello@ludmilaharing.com.
9.3 Legal Disclosure
We may disclose personal data if required to do so by law or in response to:
Court orders, subpoenas, or legal processes
Regulatory inquiries or government investigations
Protection of our legal rights, safety, or property
Detection, prevention, or investigation of fraud or security issues
In such cases, we will disclose only the minimum data necessary and will notify you where legally permitted.
10. DATA RETENTION
10.1 How Long We Keep Your Data
We retain personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce agreements.
Retention periods:
Project-related data (strategic documents, reports, analyses)- Duration of engagement + 3 years - Contractual necessity, legal obligations
Accounting & invoicing data - 7–10 years - Slovak tax law requirements
Communication records (emails, meeting notes)- Duration of engagement + 3 years - Contractual necessity, dispute resolution
Recorded meetings (audio/video)- Duration of project + 1 year (or until deliverable completion)- Legitimate interest (quality assurance)
Marketing consent data - Until consent is withdrawn - Consent (Art. 6(1)(a) GDPR)
Website analytics & cookies - Up to 26 months (Google Analytics standard) - Legitimate interest
Anonymized case study data - Indefinitely (no personally identifiable information) - No personal data retained
10.2 Deletion & Anonymization
After the retention period expires, personal data is:
Securely deleted from active systems and backups
Anonymized (stripped of all personally identifiable information) if retained for statistical or research purposes
You may request early deletion of your data (see Section 11: Your Rights), subject to legal retention obligations.
11. YOUR RIGHTS UNDER GDPR
Under the General Data Protection Regulation (GDPR) and Slovak data protection laws, you have the following rights:
11.1 Right to Access (Art. 15 GDPR)
You have the right to request a copy of the personal data we hold about you.
What you'll receive:
Confirmation of whether we process your personal data
Categories of data processed
Purposes of processing
Recipients or categories of recipients
Retention period
A copy of your personal data in a commonly used electronic format
11.2 Right to Rectification (Art. 16 GDPR)
You have the right to request correction of inaccurate or incomplete personal data.
Example: If your contact details, company name, or billing information is incorrect, we will update it promptly.
11.3 Right to Erasure / "Right to Be Forgotten" (Art. 17 GDPR)
You have the right to request deletion of your personal data under certain circumstances:
The data is no longer necessary for the purposes for which it was collected
You withdraw consent (where processing is based on consent)
You object to processing and there are no overriding legitimate grounds
The data has been unlawfully processed
Deletion is required to comply with a legal obligation
Exceptions:
We may retain data if required for:
Legal obligations (e.g., tax and accounting records must be kept for 7–10 years under Slovak law)
Establishment, exercise, or defense of legal claims
Archiving purposes in the public interest (anonymized data)
11.4 Right to Restriction of Processing (Art. 18 GDPR)
You have the right to restrict how we use your data in certain situations:
You contest the accuracy of the data (we will restrict processing while verifying accuracy)
Processing is unlawful, but you prefer restriction over deletion
We no longer need the data, but you require it for legal claims
You have objected to processing, pending verification of our legitimate grounds
When processing is restricted, we may only store the data (not use it) except with your consent or for legal claims.
11.5 Right to Data Portability (Art. 20 GDPR)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., CSV, JSON, PDF) and to transmit it to another controller.
This right applies when:
Processing is based on consent or contract
Processing is carried out by automated means
11.6 Right to Object (Art. 21 GDPR)
You have the right to object to processing of your personal data where:
Processing is based on legitimate interests (Art. 6(1)(f) GDPR)
Processing is for direct marketing purposes
If you object to direct marketing, we will stop processing your data for that purpose immediately.
For other objections, we will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
11.7 Right to Withdraw Consent (Art. 7(3) GDPR)
Where processing is based on consent (e.g., marketing emails, case study use), you have the right to withdraw consent at any time.
Withdrawal does not affect the lawfulness of processing before withdrawal.
11.8 Right to Lodge a Complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority.
Slovak supervisory authority:
Úrad na ochranu osobných údajov Slovenskej republiky (ÚOOÚ)
Hraničná 12, 820 07 Bratislava, Slovakia
Website: https://www.dataprotection.gov.sk
Email: statny.dozor@pdp.gov.sk
Phone: +421 2 3231 3214
You may also lodge a complaint with the supervisory authority in your country of residence or place of work.
11.9 How to Exercise Your Rights
To exercise any of these rights, please contact us at:
Email: hello@ludmilaharing.com
Subject line: "GDPR Data Subject Request"
Please include:
Your full name and contact details
Specific right you wish to exercise (access, deletion, etc.)
Details of the data concerned (if applicable)
Proof of identity (to prevent unauthorized access)
We will respond to your request within 30 days as required by GDPR. In complex cases, we may extend this by an additional 60 days and will inform you of the extension.
12. DATA SECURITY
12.1 Security Measures
We implement reasonable technical and organizational measures to protect personal data against:
Unauthorized access or disclosure
Accidental or unlawful destruction
Loss, alteration, or damage
Misuse or unauthorized processing
Specific measures include:
Technical safeguards:
Encryption: HTTPS/TLS encryption for website traffic, encrypted email communication (where supported), end-to-end encryption for sensitive messaging (WhatsApp)
Password protection: Strong password policies, two-factor authentication (2FA) on critical accounts
Access controls: Role-based access, principle of least privilege (only authorized personnel access client data)
Secure storage: Cloud providers with GDPR-compliant infrastructure (Google Workspace, Dropbox), encrypted local storage where applicable
Regular backups: Automated backups with encryption, tested recovery procedures
Organizational safeguards:
Confidentiality agreements: All team members and subcontractors bound by confidentiality obligations
Data minimization: We collect only data necessary for service delivery
Staff training: Awareness of GDPR obligations and data protection best practices
Incident response plan: Procedures for detecting, investigating, and responding to data breaches
12.2 Limitation of Security
While we take data security seriously, no digital transmission or storage system can be guaranteed as completely secure.
We cannot guarantee absolute security of data transmitted over the internet or stored electronically. You acknowledge and accept this inherent risk when using our services.
12.3 Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
Notify you within 72 hours of becoming aware of the breach (as required by Art. 33 GDPR)
Provide details of the nature of the breach, categories of data affected, likely consequences, and measures taken or proposed
Notify the relevant supervisory authority (ÚOOÚ in Slovakia) where legally required
Take immediate steps to contain and mitigate the breach
13. THIRD-PARTY LINKS
This website may contain links to third-party websites, tools, or resources (e.g., LinkedIn, industry publications, service providers).
We are not responsible for:
The privacy practices of third-party websites
The content or security of external sites
When you click on a third-party link, you leave our website and this Privacy Policy no longer applies. We encourage you to review the privacy policies of any third-party sites you visit.
14. CHILDREN'S PRIVACY
Our services are not directed at children under the age of 16.
We do not knowingly collect personal data from individuals under 16 years of age. If we become aware that we have inadvertently collected data from a child under 16, we will take steps to delete it as soon as possible.
If you believe we have collected data from a child under 16, please contact us immediately at hello@ludmilaharing.com.
15. CHANGES TO THIS PRIVACY POLICY
15.1 Updates
We may update this Privacy Policy from time to time to reflect:
Changes in applicable laws or regulations (e.g., GDPR updates)
New data processing activities or service providers
Changes in our business practices or technology
Feedback from supervisory authorities or legal advisors
15.2 Notification of Changes
The current version of this Privacy Policy will always be available on our website at: www.ludmilaharing.com/privacy
The "Last updated" date at the top of this policy indicates when it was last revised.
For material changes (e.g., new purposes of processing, new third-party processors, changes affecting your rights), we will:
Notify you via email (if we have your contact details)
Display a prominent notice on the website
15.3 Effect of Changes
For ongoing client engagements:
Existing projects remain governed by the privacy terms in effect at the time of contract acceptance, unless you agree otherwise
Updated terms apply to new data collected after the update date
For website users and newsletter subscribers:
Continued use of the website or services after the update date constitutes acceptance of the revised Privacy Policy
If you do not agree with the changes, you may discontinue use of the website and request deletion of your data (subject to legal retention obligations)
16. CONTACT & DATA PROTECTION INQUIRIES
For any questions, concerns, or requests regarding this Privacy Policy or data protection practices, please contact:
Saphrani s.r.o.
Data Protection Contact
Email: hello@ludmilaharing.com
Phone: +421 949 001 716
Address: Nová Ľubovňa 644, 065 11 Nová Ľubovňa, Slovakia
We will respond to inquiries within:
5 business days for general questions
30 days for GDPR data subject requests (may be extended to 90 days in complex cases, with notification)
17. SUPERVISORY AUTHORITY
If you have concerns about how we handle your personal data, you may contact the Slovak supervisory authority:
Úrad na ochranu osobných údajov Slovenskej republiky (ÚOOÚ)
Hraničná 12
820 07 Bratislava
Slovakia
Website: https://www.dataprotection.gov.sk
Email: statny.dozor@pdp.gov.sk
Phone: +421 2 3231 3214
You may also contact the data protection authority in your EU member state of residence or place of work.
END OF PRIVACY POLICY
Saphrani s.r.o.
Nová Ľubovňa 644, 065 11 Nová Ľubovňa, Slovakia
studio@ludmilaharing.com | +421 949 001 716
www.ludmilaharing.com
Last updated: May 2026