Privacy policy
What we know about you, why we need it, and what you can do about it. Without the legalese.
Last updated:
This is a translation provided for convenience. The Slovak version of this document is the binding one.
The short version
Finančná Logika is an educational platform. You can read the calculators, the encyclopedia and the articles with no account at all, and without us finding anything out about you.
We use no analytics tools, we do not measure traffic, we run no advertising or retargeting scripts, and we sell data to nobody. The fonts are stored on our own server, so loading a page does not even send a request to Google.
In practice we receive a personal detail from you only when you give us one yourself: an email address when you subscribe to the newsletter, the contents of a message if you write to us, and account details if you create an account. None of that happens automatically, and none of it is needed to use the site.
Who the controller is
The controller determining the purposes and means of processing is MC&JC Trade s. r. o., registered office Karpatské námestie 7770/10A, 831 06 Bratislava – mestská časť Rača, company ID 56905947, tax ID 2122493296, entered in the Obchodnom registri Mestského súdu Bratislava III, oddiel Sro, vložka č. 187128/B. The company operates the financnalogika.sk website.
On data protection matters you can reach us at or through the contact form. The address is rendered as an image so that bots cannot harvest it; clicking it opens your mail client.
We have not appointed a Data Protection Officer. We do not process personal data on a large scale, we do not systematically monitor visitors, and we process no special categories of data, so the obligation under Article 37 GDPR does not arise.
What data we process
If you do not create an account: we obtain no personal data from you at all. Your browser may store a display preference and a record of your cookie decision. Both stay on your device and are never sent to us.
If you subscribe to the newsletter, we process:
- Your email address, the only detail we need in order to send the newsletter. We store it without capitals and without spaces, so that one mailbox is always one record.
- The wording of your consent and the time you gave it. GDPR requires us to be able to demonstrate exactly what you agreed to.
- The subscription status (awaiting confirmation, confirmed, unsubscribed) and where on the site you signed up, the footer for example.
- Technical tokens, one to confirm the address (we store only its irreversible fingerprint) and one for one-click unsubscribe.
We do not ask for a name when you subscribe and we record none anywhere, which is why the newsletter addresses you in general terms.
If you write to us through the contact form, we process your name, email address, topic and the text of the message. The details are in a separate section below.
If you create an account, we process:
- Your email address, used for signing in, verifying the account and resetting the password.
- Your password. We never see it and never store it in readable form. It is held solely as a cryptographic fingerprint at our authentication provider.
- A display name, optional, which you provide yourself at registration.
- Your role in the system (ordinary user, editor, administrator), which determines what you have access to.
- Technical account details: the date it was created, the date of the last sign-in, and whether your email is verified.
The figures you enter into the calculators, your income, the size of a mortgage, your savings and so on, never leave your browser. The calculation runs on your own device and those numbers never reach us.
Purpose and legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Sending the newsletter | Email, wording and time of consent, subscription status | Consent, Article 6(1)(a) GDPR |
| Handling a message from the contact form | Name, email, topic, message text | Legitimate interest, Article 6(1)(f) GDPR |
| Running user accounts and sign-in | Email, password, name, role | Performance of a contract, Article 6(1)(b) GDPR |
| Email verification and password reset | Performance of a contract, Article 6(1)(b) GDPR | |
| Security of the service and protection against abuse | Sign-in cookies | Legitimate interest, Article 6(1)(f) GDPR |
| Remembering settings in your browser | Appearance preference | Consent, Article 6(1)(a) GDPR |
How long we keep data
- Newsletter subscription: until you unsubscribe. After that we keep only the record that the subscription was cancelled, so that we do not send you the newsletter again by mistake.
- An unconfirmed address: the confirmation link is valid for 48 hours. If you do not use it, the subscription never activates and we send nothing to the address.
- Messages from the contact form: until the matter is settled and for a reasonable time afterwards, the same as ordinary email correspondence.
- Account data: for as long as the account exists. After it is closed we delete the data within 30 days at the latest, unless the law requires us to keep it longer.
Data stored in your browser is yours to manage. You can clear it at any time in your browser settings or through the cookie settings.
Who we share data with
We do not sell personal data and we do not disclose it for marketing purposes. We do use providers without which the service would not run:
- Supabase: the database and sign-in. It processes subscriber email addresses, the password fingerprint and account data.
- Brevo: sending email (subscription confirmations, the newsletter, messages from the contact form). It processes the recipient’s email address and the content of the message.
- Vercel: hosting. It processes technical connection data including the IP address in server logs, which serve operations and security, not tracking.
With each of them we have a processor relationship under Article 28 GDPR. Where one of them processes data outside the EU or EEA, that is done on the basis of standard contractual clauses approved by the European Commission.
Beyond those, we disclose data to nobody, except where the law requires it (at the request of a law enforcement authority, for instance).
Newsletter
Subscribing is voluntary and runs purely on your consent. The only detail we need for it is an email address.
We use double opt-in: once you enter an address we send an email with a confirmation link, valid for 48 hours. Until you click it the subscription is not active and we send you nothing. That protects you too, since nobody can subscribe you at somebody else’s address this way.
You can unsubscribe at any time with a single click. The link is in the footer of every email you receive from us. Unsubscribing is immediate, and you need neither explain anything nor sign in anywhere to do it.
Subscriber addresses are held in our database and mirrored at our delivery provider (Brevo), which technically delivers the mail. We sell the address to nobody, disclose it to no advertiser, and use it for nothing other than news about the content on Finančná Logika.
Contact form
The Contact page has a form you can write to us through. It processes your name, email address, topic and message text, solely for the purpose of handling your message and replying to it.
A submitted message is not saved to the database. It is delivered by email to our inbox, so it is retained the same way as ordinary email correspondence. We delete it once it is no longer needed to handle the matter or to show how we handled it.
The legal basis is our legitimate interest in replying to correspondence we receive; when you submit the form you additionally confirm your consent to the processing of the details given. The same applies if you contact us directly by email or by message on Instagram (@financna.logika). Messages on Instagram are also governed by the terms of that network, which we do not operate.
Analytics and tracking
We use none. The site contains no Google Analytics or any other measurement service, no advertising pixels, no retargeting scripts and no third-party SDKs apart from authentication. We build no visitor profiles and we combine no data across sites.
If we ever introduce analytics, it will start only after your explicit consent, and not before.
Cookies
The detailed list is on the Cookies page. In short: strictly necessary cookies serve sign-in and security, and the optional ones only remember your settings.
Security
Communication is encrypted over HTTPS. Passwords are held solely as cryptographic fingerprints, never in readable form. Access to the administration is restricted by role and is verified on the server on every request.
No measure is perfect. Should a personal data breach occur that is likely to present a risk to your rights, we will notify the supervisory authority within 72 hours, and you as well in the cases the law prescribes.
Your rights
As a data subject you have the right under GDPR:
- of access: to find out whether and what data we process about you, and to receive a copy of it
- to rectification: to have inaccurate data corrected or incomplete data completed
- to erasure: to have data deleted when it is no longer needed or when you withdraw consent
- to restriction of processing: to have processing suspended temporarily
- to portability: to receive your data in a commonly used, machine-readable format
- to object: to processing based on legitimate interest
- to withdraw consent: at any time, without affecting the lawfulness of processing carried out beforehand
- to lodge a complaint with the supervisory authority
Exercise these rights at or through the contact form. We reply within one month at the latest. If it is only a newsletter unsubscribe, there is no need to write to us: the link in the email footer is enough.
The supervisory authority is the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava.
Changes to this document
If the scope of processing changes, we will update this document and revise the date above. For a material change affecting consent, we will ask for consent afresh.