Legal
Privacy notice
This notice explains what personal data izardis collects, why we hold it, how long we keep it, and what you can ask us to do with it. It is written to be read rather than to satisfy a checklist.
1. Who we are
izardis s.r.o., registered at Gorkého 12, 811 01 Bratislava, Slovakia, is the controller of the personal data described here. Our US entity, izardis LLC, acts as controller for data collected in the course of contracting with American clients, under the same practices.
We are subject to the EU General Data Protection Regulation. Where a client relationship brings other rules into play, such as state privacy laws in the United States, we apply whichever standard is stricter.
2. What we collect
We only collect what you give us, and we do not buy contact data from third parties.
3. Why, and on what basis
We do not sell personal data, and we do not use what you send us to train models.
4. How long we keep it
Enquiries that do not become projects are deleted after twelve months. Job applications are deleted within six months of a decision, unless you asked us to keep yours on file, in which case we hold it for up to two years and then delete it without asking again.
Client records are kept for the life of the relationship and for as long afterwards as accounting and liability rules require. Data stored on servers located in the European Union is held for ten years where a statutory retention period applies, and erased at the end of it.
5. Who else sees it
Inside izardis, access is limited to the people who need it: the engineer and consultant working on your enquiry, or the people hiring for the role you applied to.
Outside izardis, we use a small number of processors for email, file storage and CRM. Each is bound by a data processing agreement and none is permitted to use your data for its own purposes. Where a processor operates outside the European Economic Area, the transfer is covered by the European Commission’s standard contractual clauses.
6. Data in client projects
When we build automation inside a client’s systems, that client is the controller of the data flowing through it and we act as processor on their instructions. What we can and cannot do with it is set by the agreement between us, not by this notice.
In practice we prefer to deploy inside the client’s own cloud account, so their data never leaves their boundary. Where we do handle it, access is scoped to named engineers, every automated action is logged, and we delete our copies at the end of the engagement.
8. Your rights
Under the GDPR you can exercise all of the following, free of charge.
Ask for a copy of the data we hold about you.
Have anything inaccurate corrected or completed.
Have your data deleted where no legal duty requires us to keep it.
Pause our use of it, or object to processing based on legitimate interest.
Receive what you gave us in a machine-readable format.
Take back consent at any time, without affecting what was lawful before.
You also have the right to complain to a supervisory authority. In Slovakia that is the Office for Personal Data Protection of the Slovak Republic.
9. Making a request
Send us a request through the form below and we will answer within thirty days. We may ask one question to confirm who you are, and nothing more than that.
Data request
Ask us about your data.
Access, correction, deletion, or a question about this notice. One form, answered within thirty days by a person rather than an autoresponder.