Privacy Policy
Last updated: May 2026
1. Controller
The controller of the website winwin.sk is:
winwin architects s. r. o.
Čajkovského 2920/4, 811 04 Bratislava - Staré Mesto, Slovak Republic
Company ID (IČO): 51 899 493
Tax ID (DIČ): 2120913696
VAT ID (IČ DPH): SK2120913696
Commercial Register: Municipal Court Bratislava III, Section: Sro, File No.: 131034/B
Email: info@winwin.sk
Website: winwin.sk
2. Data Protection Officer
The company has not appointed a Data Protection Officer under Art. 37 GDPR. For privacy-related questions, contact us at info@winwin.sk.
3. Data We Process
We process contact form enquiries so that we can respond to your message. This includes your name, email address, optional phone number, and message. The legal basis is Art. 6(1)(b) GDPR, because the communication may relate to pre-contractual steps.
We process technical data for contact form security, including IP address, request headers, and request time. The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in protecting the website against spam and abuse.
We process basic analytics and performance data to operate and improve the website. This may include pages visited, device and browser type, and approximate technical metrics. The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in measuring website performance and use.
If the map on the contact page is active, Google may receive your IP address and related technical data when the map is displayed. The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in showing the studio location.
Our legitimate interests include operating the website securely, protecting the contact form against spam and abuse, improving website performance, and presenting the studio's contact information.
4. Recipients
Personal data may be processed by our technical providers:
Vercel Inc. provides hosting, CDN, Web Analytics, and Speed Insights. Resend Inc. provides email delivery for the contact form. Sanity Inc. provides website content and image management. Upstash Inc. provides contact form rate-limiting. Google LLC provides map display.
We do not sell personal data or share it with third parties for advertising purposes.
5. Transfers Outside the EEA
Some providers may process data outside the European Economic Area, especially in the United States. Transfers rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework or on Standard Contractual Clauses under Art. 46 GDPR.
6. Retention
Contact form emails are kept as needed to handle the enquiry, up to 24 months from the last communication unless longer retention is needed to protect legal claims.
Rate-limiting records in Upstash Redis are usually kept for no more than 10 minutes.
Analytics and performance data in Vercel Analytics and Speed Insights are retained according to Vercel service settings and retention periods.
After the retention period, data is deleted or anonymised.
7. Your Rights
Under the GDPR, you have the right to:
- access your personal data,
- request correction of inaccurate or incomplete data,
- request erasure of your data,
- request restriction of processing,
- object to processing based on legitimate interests,
- request data portability, where applicable,
- withdraw consent, where processing is based on consent.
To exercise your rights, contact us at info@winwin.sk. We normally respond within one month.
8. Right to Lodge a Complaint
If you believe that your personal data is being processed in breach of the GDPR, you have the right to lodge a complaint with the supervisory authority:
Úrad na ochranu osobných údajov Slovenskej republiky
Office for Personal Data Protection of the Slovak Republic
Hraničná 12, 820 07 Bratislava 27, Slovakia
Website: https://www.dataprotection.gov.sk/
9. Obligation to Provide Data
Providing your name, email, and message in the contact form is necessary for us to respond to your enquiry. Without this data, we cannot reply. Providing your phone number is voluntary.
10. Automated Decision-Making
This website does not carry out automated individual decision-making or profiling under Art. 22 GDPR.
11. Cookies and Similar Technologies
This website does not use advertising cookies or visitor profiling for advertising purposes.
The website may use similar technologies that are necessary or proportionate for operating the service:
The winwin-theme localStorage value remembers the selected light or dark mode. Vercel
Web Analytics provides anonymous traffic statistics without advertising identifiers. Vercel
Speed Insights measures page performance and user experience.
For this reason, we do not display a separate cookie banner. If we introduce non-essential cookies or analytics that require consent in the future, we will add an appropriate consent mechanism.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The current version is always published on this page and marked with the date of the latest update.