Data Protection

Privacy Policy

Effective from: 23 July 2026

HBTEC s.r.o. (hereinafter: the "Controller") is committed to protecting personal data. This privacy policy informs you, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation, "GDPR"), about what personal data we process when you use the harbula.com website, for what purposes, on what legal basis and for how long, as well as about the rights you are entitled to.

1. The Data Controller

Name: HBTEC s.r.o.

Registered office: Slovakia

Representative: Csaba Harbula, owner and managing director

E-mail: info@harbula.com

Phone: +36 70 218 6916

Website: https://harbula.com

2. Categories of personal data processed

a) Contact form: name, e-mail address, phone number (optional), subject and the text of your message. We only process these data if you fill in and submit the form to us.

b) Technical data (server logs): during the operation of the website, the hosting provider's server may automatically log your IP address, browser type, the time of your visit and the pages viewed. These data serve the secure operation of the website and are not used to identify individuals.

c) Cookies: the website uses only cookies that are strictly necessary for its operation (session identifier and security/CSRF cookie). We do not use marketing, statistical or tracking cookies, therefore no cookie consent is required.

3. Purpose and legal basis of processing

a) Contact and quotations: we process the data provided in the form in order to answer your enquiry, prepare a quotation and establish a business relationship. Legal basis: processing is necessary in order to take steps prior to entering into a contract (Article 6(1)(b) GDPR), or your consent (Article 6(1)(a) GDPR).

b) Technical data and cookies: ensuring the secure and proper operation of the website. Legal basis: the legitimate interest of the Controller (Article 6(1)(f) GDPR).

4. Duration of processing

Messages received via the contact form are retained for as long as necessary to answer the enquiry and to conduct any resulting business relationship, but for no longer than 2 years from receipt, unless further retention is required by law or necessary for the performance of a contract.

Server logs are typically stored for a maximum of 30 days, depending on the hosting provider's settings.

Session cookies are automatically deleted when you close your browser or within a short period of time.

5. Access to data, data transfers

Personal data may only be accessed by the Controller and its staff involved in data processing, to the extent necessary for the performance of their duties.

The website's hosting provider participates in the processing as a data processor, operating the servers. The hosting provider may process personal data solely in accordance with the Controller's instructions.

We do not transfer personal data to third parties, do not sell them and do not use them for marketing purposes. No data is transferred to third countries (outside the European Economic Area).

In the event of a request from an authority or court, we will comply with our statutory disclosure obligations.

6. Data security

The Controller ensures the security of personal data through appropriate technical and organisational measures, in particular against unauthorised access, alteration, transfer, disclosure, deletion or destruction, as well as accidental destruction and damage. The website is accessible via an encrypted (HTTPS/TLS) connection.

7. Your rights

Under the GDPR you have the right to: a) request information about and access to your personal data (right of access, Article 15); b) request the rectification of inaccurate data (right to rectification, Article 16); c) request the erasure of your data ("right to be forgotten", Article 17); d) request the restriction of processing (Article 18); e) receive your data in a structured, commonly used, machine-readable format (right to data portability, Article 20); f) object to processing based on legitimate interest (Article 21); g) withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

You may submit your request to info@harbula.com. We respond to requests without undue delay and at the latest within one month.

8. Remedies

If you consider that the processing of your personal data infringes the GDPR, you may lodge a complaint with a supervisory authority. The authority competent for the Controller's registered office: Úrad na ochranu osobných údajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic), Hraničná 12, 820 07 Bratislava, Slovakia, https://dataprotection.gov.sk.

You may also lodge a complaint with the supervisory authority of your own EU member state of residence — in Hungary this is the National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9–11, Hungary; e-mail: ugyfelszolgalat@naih.hu; web: https://naih.hu.

You also have the right to seek a judicial remedy if you believe your rights have been violated.

9. Amendments to this policy

The Controller reserves the right to unilaterally amend this privacy policy. The version in force at any time is available on the website. Please check regularly for any changes.