Skip to content
PRIVACY POLICY
Last updated: May 2026
This Privacy Policy explains how personal data is collected, processed, stored, and protected in connection with this website (www.ludmilaharing.com), consulting services, strategic advisory work, communication, and related business operations. This website and all related services are intended exclusively for business clients (B2B). 1. DATA CONTROLLER The controller responsible for data processing under the General Data Protection Regulation (GDPR) is: Saphrani s.r.o. Nová Ľubovňa 644 065 11 Nová Ľubovňa Slovakia
Company Registration Number (IČO): 48324604 Email: studio@ludmilaharing.com Phone: +421 949 001 716 Website: www.ludmilaharing.com Data Protection Contact: For all data protection inquiries, requests, or complaints, please contact: hello@ludmilaharing.com As a small business, Saphrani s.r.o. acts as its own Data Protection Officer (DPO) responsible for GDPR compliance. 2. PERSONAL DATA WE COLLECT Depending on the nature of your interaction with our website and services, we may collect and process the following categories of personal data: 2.1 Contact & Identity Information Full name Email address Phone number Job title / role Company name and address LinkedIn profile (if voluntarily provided) 2.2 Business & Financial Information Billing and invoicing details (company address, tax/VAT information if applicable) Bank account information (for payment processing purposes only) Purchase history and payment records 2.3 Project & Business Data Strategic business information, brand positioning, market data Collection data, SKU information, sales performance, inventory levels Operational data (production processes, supplier information, quality metrics) Supply chain information (for DPP and sustainability projects) Financial data (revenue, margin analysis, cost structures — where relevant to consulting engagement) Organizational structure, team information, stakeholder details 2.4 Employee & Collaborator Information Names, roles, and contact details of client's employees, team members, or stakeholders involved in projects (where necessary for service delivery) 2.5 Communication Records Email correspondence Meeting notes, workshop materials, session summaries Audio and/or video recordings of strategy sessions, workshops, and diagnostic interviews (with consent) Feedback, questionnaires, and survey responses 2.6 Website & Technical Data IP address Browser type and version Device type and operating system Pages visited, time spent on pages, click behavior Referral source (how you found the website) Cookies and similar tracking technologies (see Section 7) 3. HOW WE COLLECT PERSONAL DATA Personal data may be collected through: Direct communication: Email, phone calls, video meetings, contact forms, booking requests Service engagement: Contracts, proposals, project briefs, onboarding questionnaires Website interaction: Contact forms, newsletter signup, cookie consent, analytics Meetings & workshops: Information shared during strategic sessions, interviews, collaborative workshops Third-party platforms: Information provided through collaboration tools (Google Drive, Notion, Miro, Zoom, etc.) 4. PURPOSE & LEGAL BASIS FOR PROCESSING We process personal data for the following purposes, based on the legal grounds outlined under GDPR: 4.1 Contractual Necessity (Art. 6(1)(b) GDPR) Purpose: To provide consulting and strategic advisory services, fulfill contractual obligations, and deliver agreed deliverables. Activities include: Project management, communication, and coordination Diagnostic analysis, strategic frameworks, and reporting Workshops, advisory sessions, and strategic planning Quality assurance and project review Legal Basis: Processing is necessary for the performance of a contract or to take steps at your request prior to entering into a contract. 4.2 Legitimate Interests (Art. 6(1)(f) GDPR) Purpose: To operate and improve our business, manage client relationships, ensure quality service delivery, and protect our legal rights. Activities include: Internal business operations, administration, and accounting Improving service quality and developing new offerings Fraud prevention, security, and legal compliance Resolving disputes and enforcing contractual terms Website functionality, analytics, and user experience optimization Legal Basis: Processing is necessary for our legitimate business interests, provided these do not override your fundamental rights and freedoms. 4.3 Legal Obligation (Art. 6(1)(c) GDPR) Purpose: To comply with legal and regulatory obligations. Activities include: Tax reporting, accounting, and financial record-keeping (as required under Slovak tax law) Responding to legal requests, court orders, or regulatory inquiries Compliance with EU and Slovak data protection laws Legal Basis: Processing is necessary to comply with a legal obligation to which we are subject. 4.4 Consent (Art. 6(1)(a) GDPR) Purpose: To send marketing communications, newsletters, or use data for purposes beyond contractual necessity. Activities include: Sending newsletters, industry insights, or promotional content Creating case studies or testimonials (with explicit approval) Using client logos or project details in marketing materials (with written consent) Legal Basis: You have given explicit consent for the specific purpose. You may withdraw consent at any time by contacting hello@ludmilaharing.com or using the unsubscribe link in email communications. Withdrawal of consent does not affect the lawfulness of processing based on consent before withdrawal. 5. COMMUNICATION & COLLABORATION TOOLS To deliver consulting services effectively, we use the following third-party platforms and tools, which may process your personal data as subprocessors under Art. 28 GDPR: 5.1 Email & Document Sharing Google Workspace (Gmail, Google Drive, Google Docs, Google Sheets) Used for: Email communication, document collaboration, file storage Data location: EU data centers (GDPR-compliant) Privacy policy: https://policies.google.com/privacy Dropbox Used for: File sharing and storage Data location: EU/US (Standard Contractual Clauses in place) Privacy policy: https://www.dropbox.com/privacy 5.2 Video Conferencing Zoom Used for: Video calls, strategy sessions, workshops Data location: EU/US (GDPR-compliant, Standard Contractual Clauses) Privacy policy: https://zoom.us/privacy Google Meet Used for: Video conferencing Data location: EU data centers (GDPR-compliant) Privacy policy: https://policies.google.com/privacy Microsoft Teams Used for: Video calls and collaboration (where client prefers) Data location: EU data centers (GDPR-compliant) Privacy policy: https://privacy.microsoft.com 5.3 Collaboration & Project Management Notion Used for: Project documentation, strategic frameworks, knowledge management Data location: US (Standard Contractual Clauses in place) Privacy policy: https://www.notion.so/privacy Miro Used for: Visual collaboration, workshops, brainstorming sessions Data location: EU/US (GDPR-compliant) Privacy policy: https://miro.com/legal/privacy-policy/ 5.4 Messaging (Optional) WhatsApp Business Used for: Quick coordination, scheduling, informal client communication (where client prefers) Data location: Owned by Meta; end-to-end encrypted Privacy policy: https://www.whatsapp.com/legal/privacy-policy-eea Note: WhatsApp is used only with client consent and for non-sensitive coordination. Confidential business information is shared via encrypted email or secure platforms. 5.5 Recording of Meetings Strategy sessions, workshops, diagnostic interviews, and client meetings may be recorded (audio and/or video) for the following purposes: Documentation and record-keeping Project analysis and strategic development Quality assurance and internal review Transcription and accurate note-taking Educational purposes (anonymized, with explicit consent) By participating in meetings, you consent to such recordings where applicable. You will be informed at the beginning of any recorded session. Recordings are: Stored securely on encrypted cloud storage (Google Drive or local encrypted storage) Treated as confidential under the terms of our service agreements Not shared publicly or with third parties without explicit written consent Retained only for the duration necessary for project purposes, then securely deleted You may request that a meeting not be recorded by notifying us at the start of the session. 6. WEBSITE HOSTING & PLATFORM PROVIDER 6.1 Website Hosting This website is built and hosted using onepage.io. What onepage.io processes: Technical data (IP addresses, browser type, device information) Form submissions (name, email, phone, message content from contact forms) Website analytics and usage statistics Hosting-related data necessary for website functionality Data location: EU/US (GDPR-compliant hosting provider) Privacy policy: https://www.onepage.io/privacy-policy 6.2 Contact Forms When you submit a contact form, booking request, or inquiry through the website: Your information is transmitted securely via HTTPS encryption Data is stored in onepage.io systems and forwarded to our business email (Google Workspace) We respond to inquiries typically within 1–2 business days Contact form data is retained as part of our communication records (see Section 9: Data Retention) 7. COOKIES & ANALYTICS 7.1 What Are Cookies? Cookies are small text files placed on your device when you visit a website. They help the website recognize your device on future visits and improve functionality and user experience. 7.2 Types of Cookies We Use Strictly Necessary Cookies: Essential for website functionality (e.g., session management, security, basic navigation). Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) — these cannot be disabled. Analytics Cookies: Used to understand how visitors use the website (page views, traffic sources, user behavior). Legal basis: Consent (Art. 6(1)(a) GDPR) — you can opt out. Marketing/Preference Cookies: Used to deliver relevant content and measure marketing effectiveness. Legal basis: Consent (Art. 6(1)(a) GDPR) — you can opt out. 7.3 Analytics Tools We may use the following analytics services: Google Analytics (if implemented) Used for: Website traffic analysis, user behavior insights Data location: EU/US (anonymized IP where possible) Privacy policy: https://policies.google.com/privacy Opt-out: https://tools.google.com/dlpage/gaoptout onepage.io built-in analytics Used for: Website performance monitoring Privacy policy: https://www.onepage.io/privacy-policy 7.4 Managing Cookie Preferences You can control cookies through: Cookie consent banner — accept or reject non-essential cookies Browser settings — most browsers allow you to block or delete cookies Chrome: Settings > Privacy and security > Cookies Firefox: Settings > Privacy & Security > Cookies Safari: Preferences > Privacy > Cookies Edge: Settings > Privacy > Cookies Note: Disabling necessary cookies may affect website functionality (e.g., forms may not submit properly, sessions may not persist). 8. NEWSLETTER & EMAIL MARKETING 8.1 Newsletter Service Email communication, newsletters, and marketing campaigns may be managed using Brevo (formerly Sendinblue). Brevo processes: Email addresses Name and contact details Email interaction statistics (opens, clicks, engagement) Subscription preferences and consent records Data location: EU (GDPR-compliant) Privacy policy: https://www.brevo.com/legal/privacypolicy/ 8.2 How We Use Your Email Transactional emails (always sent, no consent required): Booking confirmations, payment receipts, invoices Project updates, deliverable notifications Responses to inquiries and support requests Marketing emails (requires consent): Newsletters with industry insights, strategic guidance, and thought leadership content Announcements of new services, workshops, or resources Invitations to webinars, events, or educational content 8.3 Unsubscribing You may unsubscribe from marketing emails at any time by: Clicking the "Unsubscribe" link at the bottom of any marketing email Sending an email request to hello@ludmilaharing.com with the subject "Unsubscribe" Unsubscribing from marketing emails does not affect: Transactional emails related to active projects or services Legal or contractual communications 9. DATA SHARING & THIRD-PARTY PROCESSORS 9.1 Who We Share Data With
We do not sell, rent, or trade your personal data to third parties for marketing purposes. Personal data may be shared with trusted third-party service providers acting as data processors under Art. 28 GDPR, including: Service ProviderPurposeData LocationSafeguards
Google Workspace - Email, document collaboration, storage - EU - GDPR-compliant, DPA in place
Brevo - Email marketing, newsletters - EU - GDPR-compliant, DPA in place
Zoom - Video conferencing, workshops - EU/US - Standard Contractual Clauses (SCCs)
Microsoft Teams - Video calls, collaboration - EU - GDPR-compliant, DPA in place
onepage.io - Website hosting, forms - EU/US - GDPR-compliant hosting
Notion - Project management, documentation - US - Standard Contractual Clauses (SCCs)
Miro - Visual collaboration, workshops - EU/US - GDPR-compliant
WhatsApp BusinessClient communication (optional)Meta/US - End-to-end encryption
Dropbox - File sharing, storage - EU/US - Standard Contractual Clauses (SCCs) 9.2 International Data Transfers Some service providers may process data outside the European Economic Area (EEA). When data is transferred internationally, we ensure appropriate safeguards are in place: Standard Contractual Clauses (SCCs) approved by the European Commission Adequacy decisions (e.g., for countries deemed to provide adequate data protection) Privacy Shield successor frameworks (where applicable and legally valid) Data Processing Agreements (DPAs) with GDPR-compliant processors You may request more information about specific international transfers and safeguards by contacting hello@ludmilaharing.com. 9.3 Legal Disclosure We may disclose personal data if required to do so by law or in response to: Court orders, subpoenas, or legal processes Regulatory inquiries or government investigations Protection of our legal rights, safety, or property Detection, prevention, or investigation of fraud or security issues In such cases, we will disclose only the minimum data necessary and will notify you where legally permitted. 10. DATA RETENTION 10.1 How Long We Keep Your Data
We retain personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods:
Project-related data (strategic documents, reports, analyses)- Duration of engagement + 3 years - Contractual necessity, legal obligations
Accounting & invoicing data - 7–10 years - Slovak tax law requirements
Communication records (emails, meeting notes)- Duration of engagement + 3 years - Contractual necessity, dispute resolution
Recorded meetings (audio/video)- Duration of project + 1 year (or until deliverable completion)- Legitimate interest (quality assurance)
Marketing consent data - Until consent is withdrawn - Consent (Art. 6(1)(a) GDPR)
Website analytics & cookies - Up to 26 months (Google Analytics standard) - Legitimate interest
Anonymized case study data - Indefinitely (no personally identifiable information) - No personal data retained 10.2 Deletion & Anonymization After the retention period expires, personal data is: Securely deleted from active systems and backups Anonymized (stripped of all personally identifiable information) if retained for statistical or research purposes You may request early deletion of your data (see Section 11: Your Rights), subject to legal retention obligations. 11. YOUR RIGHTS UNDER GDPR Under the General Data Protection Regulation (GDPR) and Slovak data protection laws, you have the following rights: 11.1 Right to Access (Art. 15 GDPR) You have the right to request a copy of the personal data we hold about you. What you'll receive: Confirmation of whether we process your personal data Categories of data processed Purposes of processing Recipients or categories of recipients Retention period A copy of your personal data in a commonly used electronic format 11.2 Right to Rectification (Art. 16 GDPR) You have the right to request correction of inaccurate or incomplete personal data. Example: If your contact details, company name, or billing information is incorrect, we will update it promptly. 11.3 Right to Erasure / "Right to Be Forgotten" (Art. 17 GDPR) You have the right to request deletion of your personal data under certain circumstances: The data is no longer necessary for the purposes for which it was collected You withdraw consent (where processing is based on consent) You object to processing and there are no overriding legitimate grounds The data has been unlawfully processed Deletion is required to comply with a legal obligation Exceptions: We may retain data if required for: Legal obligations (e.g., tax and accounting records must be kept for 7–10 years under Slovak law) Establishment, exercise, or defense of legal claims Archiving purposes in the public interest (anonymized data) 11.4 Right to Restriction of Processing (Art. 18 GDPR) You have the right to restrict how we use your data in certain situations: You contest the accuracy of the data (we will restrict processing while verifying accuracy) Processing is unlawful, but you prefer restriction over deletion We no longer need the data, but you require it for legal claims You have objected to processing, pending verification of our legitimate grounds When processing is restricted, we may only store the data (not use it) except with your consent or for legal claims. 11.5 Right to Data Portability (Art. 20 GDPR) You have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., CSV, JSON, PDF) and to transmit it to another controller. This right applies when: Processing is based on consent or contract Processing is carried out by automated means 11.6 Right to Object (Art. 21 GDPR) You have the right to object to processing of your personal data where: Processing is based on legitimate interests (Art. 6(1)(f) GDPR) Processing is for direct marketing purposes If you object to direct marketing, we will stop processing your data for that purpose immediately. For other objections, we will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms. 11.7 Right to Withdraw Consent (Art. 7(3) GDPR) Where processing is based on consent (e.g., marketing emails, case study use), you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal. 11.8 Right to Lodge a Complaint If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. Slovak supervisory authority:
Úrad na ochranu osobných údajov Slovenskej republiky (ÚOOÚ) Hraničná 12, 820 07 Bratislava, Slovakia Website: https://www.dataprotection.gov.sk Email: statny.dozor@pdp.gov.sk Phone: +421 2 3231 3214 You may also lodge a complaint with the supervisory authority in your country of residence or place of work. 11.9 How to Exercise Your Rights To exercise any of these rights, please contact us at: Email: hello@ludmilaharing.com Subject line: "GDPR Data Subject Request" Please include: Your full name and contact details Specific right you wish to exercise (access, deletion, etc.) Details of the data concerned (if applicable) Proof of identity (to prevent unauthorized access) We will respond to your request within 30 days as required by GDPR. In complex cases, we may extend this by an additional 60 days and will inform you of the extension. 12. DATA SECURITY 12.1 Security Measures We implement reasonable technical and organizational measures to protect personal data against: Unauthorized access or disclosure Accidental or unlawful destruction Loss, alteration, or damage Misuse or unauthorized processing Specific measures include: Technical safeguards: Encryption: HTTPS/TLS encryption for website traffic, encrypted email communication (where supported), end-to-end encryption for sensitive messaging (WhatsApp) Password protection: Strong password policies, two-factor authentication (2FA) on critical accounts Access controls: Role-based access, principle of least privilege (only authorized personnel access client data) Secure storage: Cloud providers with GDPR-compliant infrastructure (Google Workspace, Dropbox), encrypted local storage where applicable Regular backups: Automated backups with encryption, tested recovery procedures Organizational safeguards: Confidentiality agreements: All team members and subcontractors bound by confidentiality obligations Data minimization: We collect only data necessary for service delivery Staff training: Awareness of GDPR obligations and data protection best practices Incident response plan: Procedures for detecting, investigating, and responding to data breaches 12.2 Limitation of Security While we take data security seriously, no digital transmission or storage system can be guaranteed as completely secure. We cannot guarantee absolute security of data transmitted over the internet or stored electronically. You acknowledge and accept this inherent risk when using our services. 12.3 Data Breach Notification In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will: Notify you within 72 hours of becoming aware of the breach (as required by Art. 33 GDPR) Provide details of the nature of the breach, categories of data affected, likely consequences, and measures taken or proposed Notify the relevant supervisory authority (ÚOOÚ in Slovakia) where legally required Take immediate steps to contain and mitigate the breach 13. THIRD-PARTY LINKS This website may contain links to third-party websites, tools, or resources (e.g., LinkedIn, industry publications, service providers). We are not responsible for: The privacy practices of third-party websites The content or security of external sites When you click on a third-party link, you leave our website and this Privacy Policy no longer applies. We encourage you to review the privacy policies of any third-party sites you visit. 14. CHILDREN'S PRIVACY Our services are not directed at children under the age of 16. We do not knowingly collect personal data from individuals under 16 years of age. If we become aware that we have inadvertently collected data from a child under 16, we will take steps to delete it as soon as possible. If you believe we have collected data from a child under 16, please contact us immediately at hello@ludmilaharing.com. 15. CHANGES TO THIS PRIVACY POLICY 15.1 Updates We may update this Privacy Policy from time to time to reflect: Changes in applicable laws or regulations (e.g., GDPR updates) New data processing activities or service providers Changes in our business practices or technology Feedback from supervisory authorities or legal advisors 15.2 Notification of Changes The current version of this Privacy Policy will always be available on our website at: www.ludmilaharing.com/privacy The "Last updated" date at the top of this policy indicates when it was last revised. For material changes (e.g., new purposes of processing, new third-party processors, changes affecting your rights), we will: Notify you via email (if we have your contact details) Display a prominent notice on the website 15.3 Effect of Changes For ongoing client engagements: Existing projects remain governed by the privacy terms in effect at the time of contract acceptance, unless you agree otherwise Updated terms apply to new data collected after the update date For website users and newsletter subscribers: Continued use of the website or services after the update date constitutes acceptance of the revised Privacy Policy If you do not agree with the changes, you may discontinue use of the website and request deletion of your data (subject to legal retention obligations) 16. CONTACT & DATA PROTECTION INQUIRIES For any questions, concerns, or requests regarding this Privacy Policy or data protection practices, please contact: Saphrani s.r.o. Data Protection Contact Email: hello@ludmilaharing.com Phone: +421 949 001 716 Address: Nová Ľubovňa 644, 065 11 Nová Ľubovňa, Slovakia We will respond to inquiries within: 5 business days for general questions 30 days for GDPR data subject requests (may be extended to 90 days in complex cases, with notification) 17. SUPERVISORY AUTHORITY If you have concerns about how we handle your personal data, you may contact the Slovak supervisory authority: Úrad na ochranu osobných údajov Slovenskej republiky (ÚOOÚ) Hraničná 12 820 07 Bratislava Slovakia Website: https://www.dataprotection.gov.sk Email: statny.dozor@pdp.gov.sk Phone: +421 2 3231 3214 You may also contact the data protection authority in your EU member state of residence or place of work. END OF PRIVACY POLICY Saphrani s.r.o. Nová Ľubovňa 644, 065 11 Nová Ľubovňa, Slovakia studio@ludmilaharing.com | +421 949 001 716 www.ludmilaharing.com
Last updated: May 2026