Privacy
This notice explains how KNH INVEST s. r. o. processes personal data when you visit smartgov.sk and when you communicate with us in connection with SmartGovIOT.
Data controller
KNH INVEST s. r. o., Školská 292/15, 935 32 Kalná nad Hronom, Slovak Republic, Company ID 54 218 870. For privacy questions, contact us at email contact.
What data we process and why
Website visits
When a page is loaded, the server creates technical access logs. These may include the IP address, request time, method and protocol, the requested path without query parameters, TLS technical information, response status and related operational data. Request headers are removed from the access log in the current configuration.
We use these data to operate the website securely, diagnose faults, detect abuse and protect the infrastructure. The legal basis is our legitimate interest in the secure and reliable operation of the website under Article 6(1)(f) GDPR.
Email and business communication
If you contact us, we process the data you provide, in particular your name, work contact details, organisation, job role, message content and any attachments. We use the data to handle your enquiry, prepare next steps, conduct pre-contractual communication or support an existing relationship.
Depending on the nature of the communication, the legal basis is taking steps before entering into a contract or performance of a contract under Article 6(1)(b) GDPR, our legitimate interest in handling business and professional communication under Article 6(1)(f) GDPR, or compliance with a legal obligation under Article 6(1)(c) GDPR.
Contact form
The contact form is not active in the current public version of the website and data entered in its preview are not submitted. Contact is currently handled by email. If the form is activated later, this notice will be updated before it goes live.
Cookies, analytics and tracking
The current public version of smartgov.sk does not set cookies and does not use web analytics, advertising or behavioural tracking, or third-party client-side scripts. If this changes, the privacy information and, where required, the consent mechanism will be updated before such technology is activated.
Recipients and service providers
Where necessary, personal data may be accessible to providers of server and network infrastructure, email services, technical support, security services and other authorised IT tools used for the relevant purpose. We may also disclose data to a public authority where required by law.
In our internal work with professional communication, we may use authorised automation or AI-assistance tools, for example for classification, summarisation or preparing a draft reply. Such tools are not used to make solely automated decisions producing legal or similarly significant effects for the data subject.
Transfers outside the European Economic Area
If a service provider used for a particular processing activity involves a transfer of personal data outside the European Economic Area, the transfer will take place only where the requirements of Chapter V GDPR are met, for example on the basis of an adequacy decision or appropriate safeguards.
How long we keep data
- Unsuccessful or discontinued enquiries: no longer than 12 months from the last substantive communication. An automated message or technical acknowledgement does not by itself restart this period.
- Contractual and customer communication: for as long as necessary to perform the contract, provide support, protect legal claims and comply with legal obligations. Where a message forms part of an accounting, contractual or other record subject to statutory retention, the applicable statutory period applies.
- Technical access logs: only for as long as necessary for operation, security and diagnostics according to log-rotation rules and operational needs. A record connected with a specific security incident may be isolated and retained longer where necessary to investigate the incident or protect legal rights.
- Data-subject requests: for the time necessary to handle the request and subsequently demonstrate compliance with our obligations.
Your rights
Subject to the conditions of the GDPR, you have rights including access to your personal data, rectification, erasure, restriction of processing, data portability where applicable, and the right to object to processing based on legitimate interests. If a particular processing activity is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
When handling a request, we may reasonably verify the identity of the requester to prevent disclosure of data to an unauthorised person.
How to exercise your rights and lodge a complaint
You can send a request to email contact or by post to the registered office of KNH INVEST s. r. o. If you believe that the processing of your personal data infringes applicable law, you have the right to contact the Office for Personal Data Protection of the Slovak Republic, Galvaniho 7/B, 821 04 Bratislava, Slovak Republic.
Source of data and whether you must provide them
We obtain data directly from you when you communicate with us, or the technical infrastructure creates them when you visit the website. You do not need to provide contact details merely to browse the public information on the website. If you ask for a reply or cooperation, however, we may be unable to handle the enquiry without appropriate contact and factual information.
Security and sensitive information
The website uses HTTPS and security headers, and the public area is designed without an active client-side contact form or tracking scripts. Do not send passwords, access keys or sensitive technical documentation in an ordinary email. If such material is required, we will agree an appropriate method for transferring it.
Changes to this notice
We update this notice when there is a material change in how data are processed, for example if a contact form, analytics or a new integration service is activated.
Last updated: 28 September 2026.