Home / Privacy

Privacy and data protection

Privacy and personal data protection policy of the law firm STEINIGER | law firm (hereinafter the „Document“):

1. Identification of the controller, declarations and guarantees

  1. The law firm STEINIGER | law firm, s. r. o., with its registered office at: Ružinovská 42, 821 03 Bratislava, Slovak Republic, company ID (IČO): 47 238 135, registered in the Commercial Register of the Bratislava III City Court, section: Sro, insert no. 80481/B (hereinafter the „Controller”) processes the personal data of data subjects in its personal data information systems, whereby the Controller is responsible for the protection of the processed personal data pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter the „GDPR“). The contact e-mail address is This email address is being protected from spambots. You need JavaScript enabled to view it..
  2. The Controller cares about the protection of personal data and the privacy of data subjects, which it takes seriously, and therefore through this Document it provides data subjects not only with comprehensive information under the GDPR, but also with further information and explanations in order to create full transparency towards the data subject and to deepen mutual trust, and that also with regard to the provisions of Article 14 of the GDPR.
  3. The Controller guarantees to data subjects that it will never sell or otherwise commercially exploit personal data obtained from data subjects within its business cooperation with any third party, and will never disclose any personal data of data subjects without the data subjects having previously given their individual written consent or granted the Controller sufficient authorisation in a written power of attorney.
  4. The Controller guarantees to data subjects that it will never provide any personal data being processed in the Controller's personal data information system to a third party without the data subject having granted the Controller a specific written consent or sufficient authorisation in a written power of attorney for carrying out such a processing operation; this does not apply where the Controller is obliged to provide personal data to competent state authorities in the exercise of their statutory powers even without the data subject's consent under the relevant special laws, such as Act No. 297/2008 Coll. on protection against the legalisation of proceeds of criminal activity and on protection against the financing of terrorism and on amendments to certain acts (hereinafter the „Anti-Money-Laundering Act“).
  5. The Controller limits the personal data processed about data subjects to the necessary minimum required to achieve the purpose of processing the personal data, which is defined primarily by the need to provide legal service acts, both in terms of the passage of time and the extent of their processing. The Controller guarantees to data subjects the secure and irreversible destruction of personal data without undue delay after the purpose of their processing ends.
  6. The Controller declares that, in relation to the processing of personal data of data subjects, no decisions based solely on automated means of processing personal data will be applied, nor will so-called profiling within the meaning of Article 22(1) and (4) of the GDPR.
  7. As a business entity providing legal services, the Controller also proceeds in accordance with Act No. 586/2003 Coll. on the legal profession and on amendments to Act No. 455/1991 Coll. on trade licensing (the Trade Licensing Act), as amended, under which the Controller, as well as all of its attorneys, employees and collaborators, is obliged to observe a special duty of confidentiality regarding all facts of which it became aware in connection with the practice of law when providing individual legal service acts, and that including information that has the character of personal data of data subjects. For this reason, the Controller guarantees data subjects an increased degree of discretion and protection of their privacy by establishing special contractual liability of its employees and other collaborators for a breach of confidentiality and non-disclosure relating to the unlawful disclosure of information connected with the provision of legal services, including the personal data of clients or other natural persons involved in a legal matter.
  8. The Controller declares that it has adopted appropriate technical, organisational and personnel measures to ensure the security of processing the personal data of data subjects, which are documented in the GDPR Compliance project, whereby both standard and specific protection of personal data under Article 25 of the GDPR is sufficiently ensured.
  9. The Controller declares that, in the event of a personal data breach that could result in a high risk to the rights and freedoms of data subjects, it is prepared to inform the data subject of this fact under the conditions set out in Article 34 of the GDPR.

2. Purpose of processing personal data, the range of data subjects and the legal basis for processing personal data

  1. When processing the personal data of data subjects for the purposes of providing legal services under Act No. 586/2003 Coll. on the legal profession and on amendments to Act No. 455/1991 Coll. on trade licensing (the Trade Licensing Act), as amended (hereinafter the „Legal Profession Act“), the Controller acts as an independent controller. In relation to clients providing the Controller with personal data for the purpose under the first sentence of this provision of the Document, the Controller has the status of a recipient and a third party within the meaning of Article 4(9) of the GDPR.
  2. The purpose of processing the personal data of data subjects is the provision of legal services under the Legal Profession Act.
  3. For the purposes of the Document, a data subject is any natural person whose personal data are processed for the purposes of providing an attorney's legal services under the Legal Profession Act, regardless of their procedural or contractual position in relation to the Controller.
  4. The legal basis for processing the personal data of data subjects for the purpose under Article 2, point 2 of this Document is the Legal Profession Act.
  5. If you have granted the Controller consent to process your personal data, the legal basis for their processing is then this granted consent. It is in our interest to stay in contact with you and to be able to inform you about news and references of our law firm, as well as about the professional articles we publish. For this purpose we offer you the option of expressing consent to the processing of your personal data for marketing purposes in the form of sending marketing information via the so-called Newsletter.
  6. If you grant us your consent, we will, for the entire period of its validity and until you withdraw your consent, process your personal data to the extent of: e-mail address.
  7. You may withdraw any of your consents to the processing of personal data free of charge by means of your request submitted in writing to the e-mail address This email address is being protected from spambots. You need JavaScript enabled to view it.; the withdrawal of your consent does not affect the lawfulness of processing your personal data carried out before its withdrawal.

3. Period of processing personal data

  1. The Controller processes the personal data of data subjects for the duration of the provision of the attorney's legal services. After the provision of legal services ends, the entire related agenda, in particular all documents entrusted to the Controller by the client or which the Controller received on behalf of the client during the legal representation, i.e. also the personal data of data subjects whose processing purpose has ended, are handed over in person on the basis of a handover and acceptance protocol to the client or to their new legal representative.
  2. In the case of processing personal data on the basis of consent, the personal data will be processed for the entire period from the moment this consent is granted until the moment of its withdrawal.

4. Identification of processors, subcontractors and third parties

  1. When processing the personal data of data subjects for the purposes under Article 2 of this Document, the Controller uses the following sufficiently vetted and professionally competent business partners able to guarantee the security of processing the data subject's personal data, who have the status of processors within the meaning of Article 28 of the GDPR:
    • An accounting company for the purpose of performing accounting, invoicing and payroll accounting services;
    • A company managing IT services, for the purpose of the administration and maintenance of IT systems and IT security;
    • A company providing web hosting for the purpose of administering the Controller's website and web components.
  2. When processing the personal data of data subjects, the Controller uses, or may use depending on the granting of written consent to the processing of personal data, additional partners, who however have the status of independent controllers, or third parties, in the position of recipients of the personal data of data subjects, specifically:
    • A company authorised to carry out auctions, asset management, commission sales and the sale of real estate.
  3. When processing the personal data of data subjects or any of the categories of data subjects, the Controller may be obliged, depending on the nature of the matter and the specific factual situation arising in the provision of legal service acts, to provide the data subject's personal data even without their consent to the following third parties, and in particular:
    • The Financial Intelligence Unit of the National Crime Agency under the conditions set out in the Anti-Money-Laundering Act;
    • The Slovak Bar Association under the conditions set out in the Legal Profession Act;
    • The general courts of the Slovak Republic within the framework of the relevant special laws (e.g. the Code of Criminal Procedure, the Civil Contentious Procedure Code, the Administrative Judicial Procedure Code, the Civil Non-Contentious Procedure Code);
    • The Constitutional Court of the Slovak Republic under Act No. 38/1993 Coll. on the organisation of the Constitutional Court of the Slovak Republic, on proceedings before it and on the status of its judges;
    • The bodies active in criminal proceedings under Act No. 301/2005 Coll. the Code of Criminal Procedure, as amended, and under Act No. 300/2005 Coll. the Criminal Code;
    • The Court of Justice of the European Union and the European Court of Human Rights;
    • Court enforcement officers (bailiffs) under Act No. 233/1995 Coll. on court enforcement officers and enforcement activity (the Enforcement Code) and on amendments to other acts;
    • Bankruptcy trustees under Act No. 7/2005 Coll. on bankruptcy and restructuring and on amendments to certain acts;
    • Notaries under Act No. 323/1992 Coll. the Notarial Code, as amended;
    • The Ministry of Justice of the Slovak Republic under Act No. 315/2016 Coll. on the register of public sector partners and on amendments to certain acts;
    • Court interpreters and translators to the extent necessary for the proper performance of their activity;
    • Court experts to the extent necessary for the proper performance of their activity;
    • A bank under Act No. 483/2001 Coll. on banks and on amendments to certain acts;
    • Other public authorities under the relevant special laws.

5. Transfer of personal data to the partner law firm

  1. Provided that the data subject requests the Controller to provide legal services in the Czech Republic and grants the Controller a power of attorney for representation in proceedings before public administration authorities or other persons in the Czech Republic, the Controller will provide the data subject's personal data to its partner law firm STEINIGER law firm, s.r.o., registered at the Municipal Court in Prague under file no.: C 276050, registered office: Národní 416/37, Staré Město, 110 00 Praha 1, IČO: 06096476 (recipient of personal data).
  2. Our partner law firm acts as an independent controller of personal data for the purposes of providing legal services with authorisation for the territory of the Czech Republic, whereby the provision of personal data takes place on the basis of our mutual contract governing the services within the meaning of the preceding point.

6. The extent of personal data processed about data subjects

  1. The Controller processes the personal data of data subjects in accordance with Article 6(1)(b) and (c) and in connection with Section 18(6) of the Legal Profession Act to the extent necessary to achieve the purpose of processing the data subject's personal data; this generally concerns all personal data that are a necessary and inseparable part of the documents forming the case file of a specific legal matter, including related electronic documents and electronic mail.
  2. The Controller also processes particularly sensitive personal data falling within the special category of personal data within the meaning of Article 9 of the GDPR to the extent necessary for the establishment, exercise or defence of legal claims before the competent public authorities. Within its internal procedures and measures adopted to ensure the security of processing personal data, the Controller places increased emphasis on the protection of the special category of personal data.

7. Privacy principles when using the website

  1. The Controller currently, on the website www.steinigers.com (resp. na všetkých relevantných národných doménach ako www.steinigers.sk a www.steinigers.cz, which function only as its language versions with relevant content in the respective language) uses cookie files. A cookie is a small text file that a website stores on your computer or mobile device when you browse it. Thanks to this file, the website retains information about your actions and preferences for a certain time (such as login name, language, font size and other display settings), so that you do not have to re-enter them on your next visit to the website or when browsing its individual sub-pages.
  2. The Controller uses its own cookie files (so-called first party cookies) for the purpose of optimising the website's functions and improving the user comfort of the website visitor, as well as third-party cookies (so-called third party cookies) for the purpose of displaying so-called behavioural advertising.
  3. The website also uses so-called short-term cookies, which are automatically deleted from the computer system of data subjects or other end users of the software application after the use of the internet browser ends. However, in some cases so-called long-term cookies may also be processed, which remain in the end user's device and allow the Controller to recognise that the website is being revisited by the given end user's device, which may, depending on the settings made by the user of the software application, be associated e.g. with remembering a pre-set access password to the software application, and the like.
  4. The Controller informs data subjects and all website visitors that all cookie files which the website may store in the end device of any website visitor can be controlled and deleted. By appropriately setting the internet browser it is possible to effectively and completely prevent the use of cookie files. Specific information and instructions for the settings of the individual types of internet browsers can be found here: How to control cookies a informácie potrebné k vymazaniu súborov typu cookies z technického zariadenia používateľa je možné nájsť tu: How to delete cookies. In general, it can be stated that it is necessary to enable in the internet browser the function usually referred to as „Tracking Protection“.
  5. The Controller informs data subjects that where the internet browser used by the end user's device to access and view the content of the website permits the website to use cookie files, the Controller is entitled to consider this as an expression of valid legal consent by the end user of the technical device in which the cookie files are stored, in accordance with the (draft) Regulation of the European Parliament and of the Council on respect for private life and the protection of personal data in electronic communications and repealing Directive 2002/58/EC (the ePrivacy directive) (hereinafter the „e-Privacy Regulation“).
  6. The Controller informs data subjects that in the case of so-called third-party cookies used to display behavioural advertising, the website will require the data subject to explicitly grant consent before installing these cookie files into the device of the website's end user.
  7. On the website the Controller also uses an internet analytics service from Google Inc., whereby, however, the Controller does not process any personal data or other identifiers usable for indirect identification (e.g. IP address) of data subjects. This does not, however, mean that personal data is not processed in this way by Google Inc., which is the controller of the Google Analytics and Google AdWords service.
  8. To analyse your behaviour on the website, Google Analytics and Google AdWords also use cookie files that are stored in the device of the website's end user (computer, tablet, smartphone). Google anonymises part of the IP address associated with the device of the website's end user immediately upon obtaining it, which strengthens the protection of the data subject's privacy. Google Inc. uses the information obtained during the data subject's use of the website to evaluate the use of the website by users, to compile reports on website activity and to provide the Controller with further services connected with the use of the website and the use of the internet. This data processing by Google Analytics and Google AdWords can again be prevented by an appropriate setting of the internet browser into which you install a browser plug-in available via the following link: Google – Opt out.
  9. The Controller may also use the Google Analytics and Google AdWords service on the website to generate online advertising through remarketing, i.e. the outputs of the Controller's marketing communication may also be displayed by different providers of digital services and internet content including Google Inc., on various internet pages which in the future, after the visit to the website ends, will be displayed on the device of the end user, or the data subject. 
  10. The Controller also uses Google Analytics reports so that it can conduct more effective marketing communication, whereby there may also be processing of demographic characteristics and interests associated with data subjects (e.g. age, gender, interests) obtained by Google Inc., which the Controller may also use. However, when processing data through the use of the Google Analytics service, the Controller will not process the personal data of data subjects, because it will not possess a sufficient identifier that would allow direct or indirect identification of data subjects. 
  11. Data subjects using the website may refuse the display of personalised advertising banners by Google via the following link.
  12. Data subjects can find further information about the use of data by Google Inc. in the context of using the website here: Google – Privacy – Partners.
  13. The Controller advises data subjects that if, during their visit to and use of the website, they are logged into other internet services of Google Inc., the processing of the data subject's personal data may take place on the part of Google Inc. The Controller has no reach or influence over this processing of personal data and does not participate in it in any way.
  14. In connection with the use of the website by data subjects, Google Inc. is a third party in the position of an independent controller. Data subjects can find more information about the current privacy rules adopted by Google Inc. here: Google - Privacy.

8. Use of social networks

  1. The Controller's official website www.steinigers.com (resp. všetky relevantné národné domény ako www.steinigers.sk a www.steinigers.cz, which function only as its language versions with relevant content in the respective language) contains several add-on modules (plugins) linking to the Controller's official profiles set up on social networks operated by independent controllers in the position of a third party. These may be activated through an interaction initiated by the data subject (clicking on the relevant pictogram depicting the social network Facebook, Twitter, LinkedIn, Google+). Unless the data subject carries out an interaction (a click), the plugins in question will be inactive and no data processing will take place. In the event of initiating any of the stated plugins linking to the Controller's profiles set up on a social network, processing of data about the data subject may occur on the part of the relevant social network operator. The Controller has no reach or influence over such data processing, except for the part within which it can manage the content of its page on the relevant social network in accordance with the terms of use of the particular social network. You can learn more about the processing of personal data and other data by social network operators here: 
  2. The Controller respects and complies with the privacy policies adopted by the social network operators specified in Article 8, point 1 of this Document. The Controller administers its official profiles on the social networks specified in Article 8, point 1 of this Document and ensures the ongoing and prompt removal of any defamatory, insulting, hateful, vulgar, sexual or extremist expressions by other social network users which cannot, in a democratic society, be regarded as compatible with the exercise of the constitutionally enshrined freedom of expression. 
  3. The Controller does not use social networks to obtain about registered members of the social network any information and personal data other than the information and personal data stated, or disclosed, by the data subject themselves within the Controller's official profile on the social network specified in Article 8, point 1 of this Document. The Controller in no way uses (in particular does not obtain, become acquainted with, store, share, disclose) any information and personal data that the data subject states about themselves on their own (private) profile set up on any social network specified in Article 8, point 1 of this Document. 
  4. The Controller does not use the social networks specified in Article 8, point 1 of this Document to conduct marketing communication, but uses them exclusively for informational and educational purposes about its activity, the daily functioning of its team and its professional focus.

9. Monitoring of office premises by a camera system

  1. The Controller monitors the premises situated in the interior of the Controller's law office at Ružinovská Street No. 42 (hereinafter the „Office“) in Bratislava pursuant to the provision of Article 6(1)(f) of the GDPR for the purposes of protecting property and preventing the commission of criminal activity, as well as to support the Controller's internal security measures.

10. The controller's approach to the use of cloud services

  1. The Controller currently uses the services of cloud computing service providers, primarily at the level of cloud infrastructure as a service (IaaS) and cloud software as a service (SaaS), whereby data, including personal data, is stored on the remote virtual servers of the cloud service provider, or other processing operations with the personal data of data subjects take place. When using cloud computing services, the Controller eliminates to the greatest possible extent the risks associated with a possible leak of personal data and confidential information. For this purpose it therefore uses only verified providers of such services, which possess the most modern security solutions and comply with the strictest security standards.
  2. The Controller currently also uses its own data storage and its own modern IT infrastructure, which provides clients with sufficient user comfort and security of their data, including personal data.
  3. In the case of using cloud services, the Controller undertakes to:
    • use cloud computing services only in justified cases which, with regard to the effectiveness of achieving work objectives, cost, competitiveness and innovativeness, cannot be achieved equally effectively by other means;
    • use only sufficiently vetted cloud service providers able to provide real and legal guarantees for achieving a sufficient degree of security;
    • proceed, when vetting cloud service providers, according to the internal rules set out in the internal security directive;
    • conclude with the cloud service provider contracts guaranteeing the availability of services (a so-called SLA – Service Level Agreement) and compliance with confidentiality, and a contract meeting the requirements for the protection of personal data under Article 28(3) of the GDPR;
    • not use cloud computing services in which a cross-border transfer of personal data to third countries not guaranteeing an adequate level of personal data protection could occur, with the exception of entities established in the USA which are certified as reliable entities for the processing of personal data under the „Privacy Shield“ system.

11. Cross-border transfer of personal data

  1. The Controller will not carry out any cross-border transfer of personal data obtained from data subjects to a third country not guaranteeing an adequate level of personal data protection.
  2. None of the personal data that will be processed by the Controller's business partners listed in Article 4 of this Document will be transferred from the territory of the member states of the European Union to third countries. 

12. Source of the personal data that is subject to processing

  1. The source of the personal data that is subject to processing by the Controller for the purpose under Article 2, point 2 of this Document is primarily always the data subject or another natural or legal person authorised to act on behalf of the data subject on the basis of a written power of attorney, who has, in relation to the Controller, the position of a client of legal service acts. 
  2. The personal data that is subject to processing for the purposes under Article 2, point 2 of this Document may also originate: 
    • from publicly available sources or from the information resources of third parties, if the Controller has a legal claim to obtain them when providing legal services under the Legal Profession Act;
    • from the procedural acts and documents of third parties carried out within various legal proceedings in which the Controller participates as the attorney of one of the parties to the proceedings;
    • from the procedural acts and documents of another attorney, provided that they were granted a substitution power of attorney by the Controller in a specific legal matter to carry out legal service acts.

13. Information and instructions on the rights of the data subject

  1. The Controller cares about the protection of your personal data, and therefore strives for their strong security through individual, modern technical and organisational security measures, as well as through the possibility to exercise at any time your rights as a data subject under the GDPR by means of a written, personally signed request from which your identity and the right whose exercise you request will be evident. Requests to exercise a data subject's right addressed to the Controller may be sent to the address of the Controller's registered office. In the event of any questions concerning the exercise of your rights as a data subject, you may contact us via the contact details stated in Article 1, point 1 of this Document.
  2. With effect from 25 May 2018 you have new rights that should give you more effective control and an overview of your personal data processed by our company as the Controller. Specifically, these are the right of access to data (Article 15 GDPR), the right to rectification (Article 16 GDPR), the right to erasure (Article 17 GDPR), the right to restriction of processing (Article 18 GDPR), and the right to data portability (Article 20 GDPR). As a data subject you also have the right to lodge a complaint with a supervisory authority at any time – more information can be found on the website www.dataprotection.gov.sk
  3. In view of the conditions of processing personal data created by the Controller, we would like to inform you that you do not acquire the right to object to individual decisions based on automated processing (Article 21 and Article 22 GDPR), because we do not carry out any processing operations with your personal data without the involvement of the human factor, solely by means of technologies and software means of processing personal data. By the information stated above we in no way wish to discourage you from exercising your rights, but wish only to provide you with certain guidance for the purpose of more effectively handling this agenda.
  4. Each request to exercise a data subject's right under the GDPR may be submitted on the basis of a written and personally signed request sent to the address of the Controller's registered office. We would like to advise you that when handling your request we may ask you for a trustworthy verification of your identity, in the event that you request the exercise of your right in a manner other than a written letter with your personal signature (e.g. by an e-mail request) or in person at the Controller's registered office.
  5. The exercise of your rights as a data subject stated in Article 12 of this Document may also be arranged in advance at the Controller's registered office, whereby, however, we always require personal verification of your identity by proving it through the presentation of your identity document.
  6. In the event that we process your personal data on the basis of the consent to the processing of personal data granted by you as a data subject, you always have the option to withdraw this consent simply and at any time, including by means of electronic mail sent from the e-mail address that we process together with your other personal data.
  7. Each request to exercise a data subject's right that is delivered to us will be individually and competently assessed, whereby we will always inform you of the result no later than within one month of receiving your request. The process of handling your request connected with the exercise of your right as a data subject under the GDPR is free of charge. In the event that we did not handle your request to exercise a data subject's right, in your opinion, in accordance with the GDPR, you have the option to lodge a complaint with the supervisory authority (www.dataprotection.gov.sk) or to apply a judicial remedy directly at the competent court.
  8. In the event of any questions concerning the protection of your personal data and the exercise of your rights, please do not hesitate to contact us via the contact details published on our website www.steinigers.com
  9. Under certain conditions established by law, the Controller is entitled to restrict the exercise of a data subject's right, and that mainly in the case where the requested personal data (information) must remain confidential on the basis of the duty of confidentiality established by the Legal Profession Act.

14. Contact details of the data protection officer

  1. The Controller has entrusted the supervision of the processing of personal data to its employee, who performs for the Controller the function of a contact person for the purposes of personal data protection.
  2. In the event of any questions concerning the topic of personal data protection and privacy protection, or in the event of a request to exercise a data subject's right, data subjects may contact directly the Controller's contact person via electronic mail at the address: This email address is being protected from spambots. You need JavaScript enabled to view it..

Approved in Bratislava, Slovak Republic, on 26 March 2026
JUDr. Ondrej Steiniger, Managing Director of STEINIGER | law firm, s.r.o.

Facebook Twitter Google+ LinkedIn